Privacy Policy
Last updated: March 2026
Thank you for using Joy Pilot. We may change this Privacy Policy and will use reasonable endeavours to notify you of these changes. This Privacy Policy describes how we collect, use, process, and disclose your information, including personal information, in conjunction with your access to and use of Joy Pilot. When this policy mentions “Joy Pilot”, “we”, “us”, or “our”, it refers to Joy Pilot Limited, a limited company registered in New Zealand.
1. Information We Collect
1.1 Information you give to us
We ask for and collect the following personal information about you when you use Joy Pilot. This information is necessary for the adequate performance of the contract between you and us and to allow us to comply with our legal obligations. Without it, we may not be able to provide you with all the requested services.
- Account Information. When you sign up for a Joy Pilot account, we require certain information such as your first name, last name, and email address. You may also provide a phone number for account security purposes (e.g. multi-factor authentication).
- Business Information. To use our accounting features, you will provide business details such as your company name, trading name, business address, tax registration numbers (e.g. GST, VAT, HMRC references), industry type, and financial year dates.
- Financial Data. In the course of using Joy Pilot, you will enter financial information including invoices, expenses, receipts, bank transactions, and contact details for your customers and suppliers. This data is stored securely and is essential to the provision of our accounting services.
- Payment Information. To subscribe to our service, we require payment details (such as credit or debit card information) to facilitate the processing of subscription fees. Payment processing is handled by our PCI DSS-compliant payment provider, Stripe. Joy Pilot does not store your full card details on our servers.
- Communications with Joy Pilot. When you communicate with Joy Pilot — including via email, our help centre, or our in-app AI assistant Jodie — we collect information about your communication and any information you choose to provide.
1.2 Information you choose to give us
You may choose to provide us with additional personal information in order to obtain a better user experience when using Joy Pilot. This additional information will be processed based on your consent.
- Profile Information. You may choose to provide additional information as part of your Joy Pilot profile, such as a profile photo, preferred language, or personal tax reference information.
- Uploaded Documents. You may upload documents such as receipts, bank statements, business cards, and other financial records for processing by our AI-powered scanning and data-extraction features.
- Voice and Audio Data. If you use our voice features (such as voice invoicing, voice expenses, or speaking with Jodie), we process audio recordings to transcribe and action your requests. Audio data is processed in real time and is not retained after transcription unless required to complete the associated transaction.
- Other Information. You may otherwise choose to provide us information when you fill in a form, conduct a search, update or add information to your Joy Pilot Account, respond to surveys, or use other features of Joy Pilot.
1.3 Information we automatically collect from your use of the Service
When you use Joy Pilot, we automatically collect information, including personal information, about the services you use and how you use them. This information is necessary for the adequate performance of the contract between you and us, to enable us to comply with legal obligations, and given our legitimate interest in being able to provide and improve the functionalities of Joy Pilot.
- Usage Information. We collect information about your interactions with Joy Pilot such as the pages or content you view, features you use, and other actions within Joy Pilot.
- Log Data and Device Information. We automatically collect log data and device information when you access and use Joy Pilot. This includes IP address, access dates and times, browser type, operating system, device information, and cookie data.
- Location Information. We may determine your approximate location from your IP address. This is used to provide localised features such as currency defaults, tax jurisdiction settings, and regional compliance. We do not collect precise GPS location data.
- Cookies and Similar Technologies. We use cookies to store and collect information about your usage of the Service in order to maintain your session, enhance your experience, and help us improve the quality of our services. For full details, please see our Cookie Policy.
1.4 Information we collect from third parties
Joy Pilot may collect information, including personal information, from third-party services that you choose to connect with your account. We do not control how these third parties process your personal data, and any requests regarding the disclosure of your personal information to us should be directed to such third parties.
- Single Sign-On Services. If you log in to Joy Pilot using a third-party service (e.g. Google), that service may send us information such as your name and email address from your account with that service. This information varies and is controlled by that service or as authorised by you via your privacy settings at that service.
- Bank Feed Services. If you connect bank feeds, we will collect your bank account details and banking transaction information from the bank feed provider you authorise us to connect through. These connections use secure OAuth 2.0 authorisation and comply with PSD2 regulations where applicable. Joy Pilot never has access to your bank login credentials.
- Payment Providers. Our payment provider (Stripe) may share limited transaction information with us to confirm the status of your subscription payments.
2. How We Use Information We Collect
2.1 We use, store, and process information, including personal information, about you to provide, understand, improve, and develop Joy Pilot, maintain a secure environment, and comply with our legal obligations.
2.2 Provide, Improve, and Develop Joy Pilot
We use, store, and process information to:
- enable you to access and use Joy Pilot, including processing your financial data, generating invoices, reconciling bank transactions, and producing reports;
- power our AI features, including Jodie (our AI assistant), smart bank reconciliation, receipt and document scanning, voice transcription, and natural-language accounting. Your data may be processed by third-party AI providers (such as OpenAI and Google) under strict data-processing agreements. These providers do not use your data for their own training purposes;
- operate, protect, improve, and optimise Joy Pilot and the user experience, such as by performing analytics and conducting research;
- provide customer service and technical support;
- send you service or support messages, updates, security alerts, and account notifications.
We process this information given our legitimate interest in improving Joy Pilot and our users’ experience with it, and where it is necessary for the adequate performance of the contract with you.
2.3 Marketing and Communications
With your consent, we may use your information to:
- send you promotional messages, product updates, and other information about Joy Pilot that may be of interest to you;
- measure the effectiveness of our marketing campaigns through analytics tools such as Google Analytics and conversion tracking.
You can opt out of receiving marketing communications at any time by following the unsubscribe instructions included in our emails or by changing your notification settings within your Joy Pilot Account. Opting out of marketing communications does not affect service-related messages (such as security alerts or billing notifications).
3. AI Data Processing
3.1 Joy Pilot uses artificial intelligence to provide core features of our service. We believe in being transparent about how your data is used in connection with AI.
3.2 What data is processed by AI. Depending on the features you use, the following data may be processed by our AI systems: uploaded receipts and invoices (for data extraction), bank statements (for transaction categorisation), business cards (for contact extraction), bank transaction descriptions (for smart reconciliation), voice recordings (for transcription), and text conversations with Jodie (our AI assistant).
3.3 Third-party AI providers. We use trusted third-party AI providers including OpenAI and Google to power certain features. Data sent to these providers is transmitted securely, processed under data-processing agreements, and is not used by those providers to train their general-purpose models. We only send the minimum data necessary to perform the requested function.
3.4 Data retention for AI. Voice and audio data is processed in real time and discarded after transcription. Document scans are processed and the extracted data is stored in your account; original documents are retained only as long as your account is active or as required for the service. AI conversation history with Jodie is retained to provide context within your current session and may be stored to improve service quality.
3.5 Your control. Use of AI features is optional. You can choose to enter data manually rather than using AI-powered scanning, voice, or chat features. If you have concerns about AI data processing, please contact us at [email protected].
4. Sharing and Disclosure
4.1 With your Consent. Where you have provided consent, we share your information, including personal information, as described at the time of consent, such as when you authorise a third-party service to access your Joy Pilot Account (e.g. connecting a bank feed) or when you add additional users to your Joy Pilot Account.
4.2 Service Providers. We use third-party service providers to help us operate and improve Joy Pilot. These include cloud hosting (Amazon Web Services), payment processing (Stripe), AI and machine-learning providers (OpenAI, Google), document scanning services, email delivery services, and analytics providers. These service providers have access to your information only to perform tasks on our behalf and are obligated not to disclose or use it for any other purpose.
4.3 Compliance with Law, Responding to Legal Requests, Preventing Harm and Protection of our Rights. Joy Pilot may disclose your information, including personal information, to courts, law enforcement or governmental authorities, or authorised third parties, if and to the extent we are required or permitted to do so by law or if such disclosure is reasonably necessary: (i) to comply with our legal obligations, (ii) to comply with legal process and to respond to claims asserted against Joy Pilot, (iii) to respond to verified requests relating to a criminal investigation or alleged or suspected illegal activity or any other activity that may expose us, you, or any other of our users to legal liability, (iv) to enforce and administer our Terms of Service or other agreements, or (v) to protect the rights, property or personal safety of Joy Pilot, its employees, its users, or members of the public.
4.4 Business Transfers. If Joy Pilot undertakes or is involved in any merger, acquisition, reorganisation, sale of assets, bankruptcy, or insolvency event, then we may sell, transfer or share some or all of our assets, including your information in connection with such transaction or in contemplation of such transaction (e.g., due diligence). In this event, we will notify you before your personal information is transferred and becomes subject to a different privacy policy.
4.5 Aggregated Data. We may share aggregated information (information about our users that we combine together so that it no longer identifies or references an individual user) and other anonymised information for regulatory compliance, industry analysis, and other business purposes.
5. Third-Party Partners and Integrations
5.1 Joy Pilot integrates with a number of third-party services to provide its full functionality, including bank feed providers, AI and machine-learning services, payment processors, and document scanning services. When you use these integrations, you may be providing information to both Joy Pilot and the third-party provider.
5.2 These Third-Party Partners have their own privacy policies governing the collection, use, and disclosure of your information. We encourage you to review the privacy policies of any third-party services you connect to through Joy Pilot.
6. Your Rights
6.1 You may exercise any of the rights described in this section by sending an email to [email protected]. Please note that we may ask you to verify your identity before taking further action on your request.
6.2 Managing Your Information. You may access and update your information through your Account settings. If you have connected your Joy Pilot Account to a third-party service, you can disconnect it through your Account settings. You are responsible for keeping your personal information up to date.
6.3 Rectification of Inaccurate or Incomplete Information. You have the right to ask us to correct inaccurate or incomplete personal information concerning you (and which you cannot update yourself within your Joy Pilot Account).
6.4 Data Access and Portability. In some jurisdictions, applicable law may entitle you to request copies of your personal information held by us. You may also be entitled to request copies of personal information that you have provided to us in a structured, commonly used, and machine-readable format and/or request us to transmit this information to another service provider (where technically feasible).
6.5 Data Retention and Erasure. We generally retain your personal information for as long as is necessary for the performance of the contract between you and us and to comply with our legal obligations. If you no longer want us to use your information to provide our Service to you, you can request that we erase your personal information and close your Joy Pilot Account. Please note that if you request the erasure of your personal information:
- We may retain and use your personal information to the extent necessary to comply with our legal obligations. For example, Joy Pilot may keep some of your information for tax, legal reporting and auditing obligations.
- Some copies of your information (e.g., log records) may remain in our database, but are disassociated from personal identifiers.
- Because we maintain the Service to protect from accidental or malicious loss and destruction, residual copies of your personal information may not be removed from our backup systems for a limited period of time.
6.6 Withdrawing Consent and Restriction of Processing. Where you have provided your consent to the processing of your personal information by Joy Pilot you may withdraw your consent at any time by changing your Account settings or by sending a communication to Joy Pilot specifying which consent you are withdrawing. Please note that the withdrawal of your consent does not affect the lawfulness of any processing activities based on such consent before its withdrawal. Additionally, in some jurisdictions, applicable law may give you the right to limit the ways in which we use your personal information, in particular where (i) you contest the accuracy of your personal information; (ii) the processing is unlawful and you oppose the erasure of your personal information; (iii) we no longer need your personal information for the purposes of the processing, but you require the information for the establishment, exercise or defence of legal claims; or (iv) you have objected to the processing and pending the verification whether the legitimate grounds of Joy Pilot override your own.
6.7 Objection to Processing. In some jurisdictions, applicable law may entitle you to require Joy Pilot not to process your personal information for certain specific purposes where such processing is based on legitimate interest. If you object to such processing, Joy Pilot will no longer process your personal information for these purposes unless we can demonstrate compelling legitimate grounds for such processing or such processing is required for the establishment, exercise or defence of legal claims. Where your personal information is processed for direct marketing purposes, you may at any time ask Joy Pilot to cease processing your data for these direct marketing purposes by sending an email to [email protected].
6.8 Lodging Complaints. You have the right to lodge complaints about the data processing activities carried out by Joy Pilot before the competent data protection authorities.
7. Security
7.1 We are continuously implementing and updating administrative, technical, and physical security measures to help protect your information against unauthorised access, loss, destruction, or alteration. Our security measures include TLS encryption in transit, AES-256 encryption at rest, multi-factor authentication, brute-force protection, and regular security monitoring. For more details, please see our Security & Trust page.
7.2 If you know or have reason to believe that your Joy Pilot Account credentials have been lost, stolen, misappropriated, or otherwise compromised, or in case of any actual or suspected unauthorised use of your Joy Pilot Account, please contact us immediately at [email protected].
8. International Data Transfers
8.1 Joy Pilot is based in New Zealand and our primary infrastructure is hosted on Amazon Web Services. Your data may be processed in countries outside of your country of residence, including New Zealand, the United States (for AI processing services), and other locations where our service providers operate.
8.2 Where we transfer personal data internationally, we ensure that appropriate safeguards are in place, including data-processing agreements with our service providers that include standard contractual clauses or equivalent protections as required by applicable data protection law.
9. Changes to This Privacy Policy
9.1 Joy Pilot reserves the right to modify this Privacy Policy at any time in accordance with this provision. If we make changes to this Privacy Policy, we will post the revised Privacy Policy on the Website and update the “Last Updated” date at the top of this Privacy Policy. We will also provide you with notice of the modification by email at least thirty (30) days before the date they become effective. If you disagree with the revised Privacy Policy, you may cancel your Account. If you do not cancel your Account before the date the revised Privacy Policy becomes effective, your continued access to or use of the Website will be subject to the revised Privacy Policy.
10. Contact Us
10.1 If you have any questions or complaints about this Privacy Policy or Joy Pilot’s information handling practices, you may contact us at [email protected].