Privacy Policy

Last updated: [EFFECTIVE DATE]
Template only, not legal advice. billt processes personal data and connects to payment and identity providers, so a lawyer should review this before publication - particularly for GDPR/CCPA obligations and your role as processor for your customers' end-users.

1. Who we are

billt is operated by [LEGAL ENTITY] ("we", "us"). This policy explains what personal data we collect, why, and your rights. For questions, contact [CONTACT EMAIL].

2. Our two roles

We act as a data controller for the accounts of our direct customers ("founders") who sign up to billt. We act as a data processor for the end-user data that founders process through billt - for that data, the founder is the controller and is responsible for the lawful basis and notices to their users.

3. Data we collect

CategoryExamplesPurpose
Founder accountEmail, Google account ID, nameCreate and secure your account
End-user auth dataEmail, provider ID of your usersProvide login on your behalf
Payment metadataPlan, subscription status, payment IDs (via Stripe)Manage subscriptions and entitlements
TechnicalTokens (in cookies), IP, logs, timestampsSecurity, session management, debugging

We do not collect or store full card numbers; payment card data is handled by the payment processor (e.g. Stripe).

4. How we use data

5. Legal bases (GDPR)

Where GDPR applies, we rely on: performance of a contract (providing the Service), legitimate interests (security, service improvement), consent (where required), and legal obligation.

6. Sub-processors & third parties

7. Data retention

We retain personal data while your account is active and as needed to provide the Service, then delete or anonymize it within a reasonable period, unless a longer retention is required by law.

8. Security

We use technical and organizational measures to protect data, including encryption in transit, encryption of sensitive credentials at rest, hashed refresh tokens, and access controls. No method is 100% secure, but we work to protect your data.

9. Your rights

Depending on your location, you may have the right to access, correct, delete, port, or restrict processing of your personal data, and to object or withdraw consent. To exercise these rights, contact [CONTACT EMAIL]. End-users of a founder's app should contact that founder directly.

10. International transfers

Your data may be processed in countries other than your own. Where required, we use appropriate safeguards (e.g. standard contractual clauses) for such transfers.

11. Children

The Service is not directed to children under 16, and we do not knowingly collect their data.

12. Cookies

We use essential cookies for authentication and session management. See our Cookie Policy for details.

13. Changes

We may update this policy. Material changes will be communicated; the "last updated" date reflects the latest version.

14. Contact

Privacy questions: [CONTACT EMAIL]. Data protection contact: [DPO EMAIL].