Legal
Xero Integration Privacy
Last updated: 26 August 2026
This page covers the BuildScope connection to Xero. It sets out exactly what BuildScope reads from your Xero organisation, what it writes back, where that information is held and what happens when you disconnect.
It sits alongside our Privacy Policy, which covers BuildScope as a whole. Where this page is more specific about Xero data, this page applies.
These documents are general draft website policies and should be reviewed by an Australian lawyer before publication.
1. Connecting Xero
Xero is connected by someone with owner or admin access to the BuildScope company account, who also has the rights to authorise apps on the Xero organisation. Nobody else can connect it on your behalf.
The connection uses OAuth 2.0. You sign in to Xero on Xero's own site and approve the access there. BuildScope never asks for, sees or stores your Xero username, password or two-factor codes.
If your login covers more than one Xero organisation, BuildScope asks you to choose which one it quotes into. It does not pick for you.
Access can be withdrawn at any time, from either side: Disconnect on the BuildScope Integrations page, or remove BuildScope under Connected Apps in Xero.
2. What BuildScope reads from Xero
BuildScope does not browse your Xero file. It reads only what it needs to raise one quote correctly, and only when you send a scope across:
- The name, country and base currency of the organisation you connected, so the connection knows which business it belongs to
- Your sales tax rates, so the quote lines carry the right GST
- Your revenue account codes, so the quote lines post to the right account
- Whether a contact already exists under the client name you typed, so it is reused instead of duplicated
- The status of a quote BuildScope raised earlier for that job, so a draft is updated rather than duplicated
That is the lot. BuildScope does not read your invoices, bills, payments, payroll, bank feeds, bank account details, reports, or any contact other than the one on the quote it is raising. It has no access to your accounting records at all beyond the items listed above.
3. What BuildScope writes back
Nothing is written until you press Send to Xero on a finished scope, and confirm who the quote is for. When you do, BuildScope writes:
- A draft quote, with your scope lines, section headings, quantities and prices
- The exclusions and clarifications, into the quote terms
- The Scope of Works PDF, attached to that quote. A very large PDF is left off rather than failing the quote, and BuildScope tells you when that happens
- A contact for the client, but only if no contact of that name already exists
The quote is left as a draft. BuildScope does not send it, does not email your client, does not approve it and does not raise an invoice. Sending it is your decision, made in Xero.
Send the same job again and BuildScope updates the draft it raised earlier. If you have already sent, accepted or invoiced that quote, it is left untouched and a new draft is raised beside it.
4. The permissions we ask for
Xero shows you a list of permissions when you connect. In plain terms:
- Invoices and related documents: create and update the draft quote. Xero groups quotes with invoices, which is why the consent screen words it this way. BuildScope does not create, read or alter invoices
- Contacts: find the client, or create them if they are new
- Attachments: put the finished PDF on the quote
- Settings (read only): read your tax rates and revenue accounts. BuildScope cannot change your chart of accounts, your tax rates or any other Xero setting
- Offline access: keep the connection alive so you do not have to sign in to Xero every half hour
BuildScope asks for the minimum the integration needs, and every permission on that list is used by a feature described on this page. It never asks for payroll, bank feeds or reporting access.
5. Where the information is held
The connection is stored as a single record holding your Xero organisation identifier and name, the connection status, the dates it was connected or disconnected, which permissions were granted, and when it last spoke to Xero. Alongside it we keep the tax rate and revenue account code you quote against, so the next quote does not have to look them up again.
The access keys that let BuildScope talk to Xero on your behalf are encrypted at rest with AES-256-GCM before they are written down. They are never sent to your browser, never shown in the app and never written into logs.
The Scope of Works PDF is built in your browser and passed straight through to Xero. BuildScope does not keep a copy of it.
Your scope itself lives in your BuildScope company account as it always has, in Firebase / Firestore with Vercel hosting. Company data separation applies: see Data & Security.
6. AI and the Xero connection
Nothing read from Xero is sent to our AI provider. The estimator works on the scope you built in BuildScope; the Xero connection runs afterwards, purely to write that finished scope out as a quote.
How the estimator handles your scope is covered in our AI Use Policy.
7. Who else sees it
Information exchanged with Xero is handled by the same providers that run the rest of BuildScope: cloud hosting and our database. Nobody else receives it.
BuildScope does not sell it, and never passes Xero data to advertising networks, data brokers or any other third party for their own purposes. Client details, quote totals and accounting settings are not sent to our email or analytics tools.
8. Disconnecting, and what happens to your data
Disconnect from the BuildScope Integrations page, or remove BuildScope under Connected Apps in Xero. Either way:
- The stored access keys are deleted immediately, and BuildScope can no longer reach your Xero organisation
- Quotes, contacts and attachments already in Xero stay in Xero, exactly as they are, under your control
- Scopes you already built stay in your BuildScope account, because they are your work
- A record of which BuildScope job matched which Xero quote is kept, identifiers only and no personal details, so reconnecting updates the same drafts instead of duplicating them
To have everything removed, including the connection record, email admin@buildscope.app or delete your BuildScope account, which removes your company data with it.
9. Who is responsible for what
BuildScope is responsible for handling Xero data as described on this page, keeping the access keys secure, and asking for no more access than the integration needs.
You decide whether to connect Xero, which Xero organisation to connect, who in your business may use it, and which scopes get sent across. Every draft quote is yours to check before you send it, as set out in our Disclaimer.
Xero is responsible for the data held in your Xero organisation, under Xero's own terms and privacy policy. Once BuildScope has written a quote, contact or attachment into your organisation, that information sits in Xero and is governed by their policy.
BuildScope is a separate product with its own account and its own subscription. It is not built, owned or operated by Xero, and it is not accounting software or accounting advice.
10. Contact
For any question about this integration, or to request access to or deletion of data exchanged with Xero, contact admin@buildscope.app.
