Privacy notice

Collect less. Explain it clearly.

Effective 28 September 2026.

Who this notice covers

Roar Bookkeeping is the registered business name of Kimberly Leesa Ryan, sole trader, ABN 63 228 359 336. Privacy questions, access or correction requests, and privacy complaints can be sent to [email protected].

Information the website may collect

  • Contact details you enter, such as your name, business, work email and optional phone number.
  • Your requested service, response preference and brief non-confidential outline.
  • Basic technical and security logs needed to operate and protect the website.

The books health check runs in your browser and does not require personal or financial figures. The website does not provide file uploads and does not use advertising pixels.

Why information is used

Enquiry details are used to respond, assess service fit, arrange a conversation, protect the form from abuse and keep an appropriate enquiry record. Submitting the enquiry form does not subscribe you to marketing.

Do not send sensitive information

The public form is not a client portal

Do not enter tax file numbers, bank details, passwords, identity documents or financial documents. Secure access and client-verification steps are arranged only after scope and identity checks.

Service providers and overseas processing

Roar uses Micipedia-operated website infrastructure, Resend to deliver website enquiries to Roar’s managed business email, Microsoft OneDrive for working file storage and sharing, and Xero, MYOB or QuickBooks when selected for client work. Roar also uses Australian Government services such as Relationship Authorisation Manager and Online services for agents where required.

Only providers needed for an enquiry or accepted engagement receive information, and access is limited to that purpose. Commercial providers may store or process information outside Australia. The engagement identifies the providers used for client work, and Roar obtains permission where required before disclosing confidential client information.

Retention and security

Enquiry records are kept only as long as needed for response, legitimate administration, legal obligations, disputes and security. Clients remain responsible for retaining their source records for the periods required by law. Roar separately retains records that evidence the BAS services it provides for at least five years. Deletion requests remain subject to those and any other applicable recordkeeping obligations.

Roar’s approved operating process requires individual access, secure sharing, access checks and documented incident handling. Multi-factor authentication is enabled for Microsoft OneDrive. No website or storage service can guarantee absolute security.

Access, correction and complaints

Contact [email protected] to request access to or correction of personal information, or to raise a privacy complaint. Roar handles tax file number information under applicable law, including the TFN Rule, and assesses suspected eligible data breaches under the Notifiable Data Breaches scheme where it applies.

Analytics and cookies

The website does not use behavioural advertising, cross-site tracking or analytics cookies. Where browser privacy signals permit it, the site creates a random identifier in your browser’s session storage and sends it with limited first-party event records to count broad actions such as viewing a service, completing the fit check, starting an enquiry or selecting an email link. The same first-visit page, referring website hostname and any campaign labels in the landing link may be attached to an enquiry so Roar can understand how the enquiry arrived.

These measurement events do not include the form’s name, contact details, free-text outline, financial values, uploaded files or full referring URL. The fit-check workload bands remain in the browser; only the broad recommended plan and service type are attached to its completion event. The selected software category may be included with an enquiry. Live event records are retained for up to 90 days and reporting is aggregate-only; protected backups expire under the normal backup lifecycle. Essential hosting and security logs may still record technical network information needed to operate and protect the website.

Acquisition research is separate

Prospect research for Roar is not fed from client books or website enquiry content. No client ledger, identity, financial or BAS information is permitted in the acquisition engine. Commercial electronic messaging must have its own lawful consent or documented basis, sender identity and working unsubscribe controls.