billt is operated by [LEGAL ENTITY] ("we", "us"). This policy explains what personal data we collect, why, and your rights. For questions, contact [CONTACT EMAIL].
We act as a data controller for the accounts of our direct customers ("founders") who sign up to billt. We act as a data processor for the end-user data that founders process through billt - for that data, the founder is the controller and is responsible for the lawful basis and notices to their users.
| Category | Examples | Purpose |
|---|---|---|
| Founder account | Email, Google account ID, name | Create and secure your account |
| End-user auth data | Email, provider ID of your users | Provide login on your behalf |
| Payment metadata | Plan, subscription status, payment IDs (via Stripe) | Manage subscriptions and entitlements |
| Technical | Tokens (in cookies), IP, logs, timestamps | Security, session management, debugging |
We do not collect or store full card numbers; payment card data is handled by the payment processor (e.g. Stripe).
Where GDPR applies, we rely on: performance of a contract (providing the Service), legitimate interests (security, service improvement), consent (where required), and legal obligation.
We retain personal data while your account is active and as needed to provide the Service, then delete or anonymize it within a reasonable period, unless a longer retention is required by law.
We use technical and organizational measures to protect data, including encryption in transit, encryption of sensitive credentials at rest, hashed refresh tokens, and access controls. No method is 100% secure, but we work to protect your data.
Depending on your location, you may have the right to access, correct, delete, port, or restrict processing of your personal data, and to object or withdraw consent. To exercise these rights, contact [CONTACT EMAIL]. End-users of a founder's app should contact that founder directly.
Your data may be processed in countries other than your own. Where required, we use appropriate safeguards (e.g. standard contractual clauses) for such transfers.
The Service is not directed to children under 16, and we do not knowingly collect their data.
We use essential cookies for authentication and session management. See our Cookie Policy for details.
We may update this policy. Material changes will be communicated; the "last updated" date reflects the latest version.
Privacy questions: [CONTACT EMAIL]. Data protection contact: [DPO EMAIL].