Musopay
Open the app

Privacy, in plain English

Musopay exists because musicians shouldn't have to hand their TFN and bank details to a different spreadsheet every week. That only works if you can trust us more than the spreadsheet. Here's exactly what we do.

What we collect, and why

Only what's needed to pay you and pay your super: name, contact details, date of birth, address, bank account, super fund details, and — if you choose — your TFN. Super funds require the DOB/address/TFN parts to match contributions to your account; none of it is used for anything else. Purpose limitation means exactly that: your details go into payment and super files for gigs you're attached to, and nowhere else. We don't sell data, run ads, or "share with partners".

Your TFN specifically

TFNs are protected by the Privacy (Tax File Number) Rule 2015, and we treat that as a floor, not a ceiling. Your TFN is requested under superannuation law so it can be passed to your super fund with contributions. Providing it is voluntary and declining is not an offence; without it, your fund may tax contributions at the highest rate or take longer to match them. You choose: store it encrypted, or have us ask you each time — in that mode it's written into the generated file and destroyed, never kept.

No directory. No search. Ever.

A bandleader can only ever see musicians who explicitly accepted their invite or shared their personal link with them. There is no browsing, no lookup, no "find musicians near you". This is permanent product policy, not a v1 limitation.

Encryption

TFNs, bank account numbers, dates of birth and super member numbers are encrypted at the application layer (AES-256-GCM) with keys held outside the database. If the database were ever stolen, those fields are gibberish without the keys. On screen, sensitive values only ever appear masked (like ****4521); the real values exist only inside the payment files generated for your gigs — and those files expire and are deleted after 7 days.

Access logging

Every time your details are decrypted into a payment file, and every download of files containing them, is logged — and the log is shown to you, in the app, with who and when. Not on request. Always.

Real deletion

Delete your account and your personal data — including the encrypted values — is destroyed. The one exception: gig and payment records already baked into a bandleader's generated documents (they're legally required to keep payment records). Those keep your name and the amounts, nothing more.

If something goes wrong

We designed for the Notifiable Data Breaches scheme: if a breach likely to cause serious harm ever occurs, we assess it fast, notify the OAIC, and tell you directly what happened and what to do — no burying it.

Who's asking for your details

Bandleader accounts must verify an ABN against the Australian Business Register before they can send invites, and every invite shows you the verified entity name. If an invite smells wrong, the report button freezes that account's file generation immediately, pending review.

Questions, complaints, or a privacy request? Email privacy@musopay.com. This page is a plain-English summary of how Musopay works, not legal advice.

Musopay — payday super for working musos.