Legal

Privacy Policy

Last updated: August 1, 2026

On this page

Who we are

BillTheBill is operated by Numerra LLC. For your account data we are the data controller, which means we decide what happens to it and we are the ones answerable for it.

Numerra LLC
8 The Green, Suite R, Dover, DE 19901, USA
Email: support@billthebill.com

This policy covers billthebill.com and the BillTheBill app. That one address handles everything — privacy questions, requests about your data, ordinary support.

Two kinds of data, and our two different roles

Your account data — your email address, your business details, your subscription, how you use the product. We decide what happens to it, so we are its controller and the rest of this policy explains what we do.

What is inside your invoices — your clients' names, addresses, emails and tax numbers. That is your data about your clients. You decide what goes in; we store it, turn it into a PDF and send it where you tell us. For that data we are your processor: we act on your instructions, we use it only to run the service for you, and we never use it for our own purposes, sell it or mine it.

That puts something on you too: you are responsible for having a lawful reason to hold your clients' details, and for telling them what you do with them. If one asks you to erase theirs, you can delete the client outright in the app as long as you have never invoiced them. Once you have issued an invoice, that invoice is fixed — a document you have already sent has to stay what it was — so the details on it stay too. Email us in that case and we will work out what can be removed.

If you need a signed data processing agreement, email us and we will sort one out.

What we collect

Almost all of it is data you type in yourself:

  • Your account — email address; your name and picture if you sign in with Google; your language and format preferences.
  • Your business profile — company name, address, tax and registration numbers, phone, email, the bank details you want printed on invoices, and your logo.
  • Your clients — name, contact person, email, postal address and VAT number, as you enter them.
  • Your invoices — numbers, dates, currency, line items, notes, totals, status history, and the PDFs and credit notes generated from them.
  • Your subscription — your plan, your customer and subscription identifiers at Polar, billing period dates, usage counters, and any voucher or promotional credit applied to your account. We never see or store your card details.
  • Payments to you — if you connect Stripe, your Stripe account identifier and whether it is cleared to take charges. Your clients' card details go straight to Stripe and never reach us.
  • Sign-in and security — sessions with IP address and browser user-agent, magic-link tokens (stored hashed), your Google account id and the tokens Google issues alongside it, and audit logs of significant actions such as sign-ins and invoice changes.
  • When you contact us — your name, your email address, and whatever you write or attach, kept in our support inbox so we can answer you.

We do not store passwords, because there are none. We do not ask for special-category data such as health or beliefs, and you should not put any into an invoice.

We hold all of it because we need it to run the service you signed up for and to bill you. Audit and rate-limit logs rest on our legitimate interest in a service that is not abused, and our own tax records on a legal obligation.

Where your data lives

Your database records, your invoices and your files are stored and processed in the European Union, in Frankfurt, Germany. That covers the substance of it: the database, the file storage and the PDF rendering.

Three services around the edges are US-based: Polar for subscriptions, Stripe for payments to you, and Google if you sign in with Google. Those transfers rely on the EU-US Data Privacy Framework and standard contractual clauses.

And to be straight with you: Numerra LLC is a US company, so we can in principle be compelled by US legal process. If that happens we will tell you, unless we are legally barred from doing so.

Who else touches it

We do not sell your data and we never share it for advertising. These are the companies that process data on our behalf:

CompanyWhat they doWhere
NeonDatabase — everything you enterEU (Frankfurt)
VercelApp hosting and file storage — PDFs, logos, attachmentsEU (Frankfurt)
Fly.ioTurns invoices into PDFs; keeps nothing afterwardsEU (Frankfurt)
ResendSends your invoices and our account emailsEU
CloudflareDNS, and forwards email sent to our support addressUSA
ZohoOur support inbox — the email you send usEU
PostHogProduct analyticsEU
PolarSubscription billing, merchant of recordUSA
StripePayments from your clients to youUSA
SentryError monitoringEU (Germany)
GoogleSign in with Google — only if you use itUSA

PostHog needs a note, because analytics usually means tracking and here it does not. It runs without cookies, with session recording off and no automatic capture of what is on your screen, so a screen full of your clients' details is never scraped. It identifies you by an internal account id; we deliberately do not send it your email address.

Sentry receives error reports when something breaks. They are keyed to your internal account id — we deliberately do not send it your email address — and access tokens are stripped out of the report first.

Beyond that we share data only where the law requires it, or where we need to in order to protect the service against fraud or abuse.

Cookies

Three cookies sign you in and keep you signed in, and one remembers your language. That is the lot: no analytics cookies, no advertising, no third-party trackers — and therefore no consent banner to dismiss. The Cookie Policy lists them individually.

How long we keep it

We keep your data until you delete it. There is no dormancy rule — we do not delete accounts for being unused, so if you leave one alone for two years your invoices will still be there when you come back.

The short-lived exceptions: sign-in sessions expire after 7 days, sign-in links after 10 minutes, email-verification links after 24 hours, and audit logs are deleted automatically after 90 days.

Where you have paid for a subscription, Polar keeps the order and tax record it has to keep as the seller, and we keep our own billing history for as long as tax law requires. Both outlast your account.

Getting your data out, and deleting it

Export. Settings gives you a one-click export: a zip containing your profile, clients, invoices with line items and status history, company profiles, saved templates, credit notes, and the PDFs of both your invoices and your credit notes.

Deletion. You can delete your account from settings, and we mean it literally. Your invoices and credit notes, clients, company profiles, sessions, notifications and stored files — PDFs, logos, attachments — are all removed, and we ask Polar to anonymise your customer record. Audit entries are detached from your account immediately; until the routine 90-day cleanup clears them they still record the IP address and browser an action came from, with nothing tying them back to you.

Three honest caveats: our database provider keeps encrypted backups on a rolling cycle, so a copy can survive there briefly before it is overwritten; our analytics and error-monitoring records, which are keyed to an account id and never held your name, fall away on their own retention schedules rather than the moment you press delete; and anything already sent — an invoice emailed to a client — has left our hands entirely. None of it can be undone, so export first.

Your rights

You can ask us for a copy of your data, correct it, delete it, take it elsewhere in a portable format, object to what we do with it, or ask us to restrict it. Most of that you can do yourself in settings.

For anything else, email us: we will deal with it within 30 days, we do not charge, and we will not ask you why.

If you think we have got it wrong, you can complain to your local data protection authority. We would rather you told us first, but that is your call.

How we protect it

The measures that actually matter here:

  • Data is encrypted in transit and at rest, and card details never touch our servers.
  • Sign-in cookies are HTTP-only and secure, and magic-link tokens are stored hashed — a database read yields no usable login. There are no passwords, so there is no password database to leak.
  • Every query in the app is scoped to your account — the one exception is our own admin tooling, which we use only when running the service requires it — and significant actions are written to an audit log.

No system is perfect. If there is a breach that affects you, we will tell you and the relevant authority within the time the law allows.

Children

BillTheBill is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children; if you think we have, tell us and we will delete it.

Changes to this policy

We will update this policy as the product changes — the date at the top shows when we last did. For anything significant we will email you or show a notice in the app rather than quietly editing the page.

Contact

Anything at all about your data:

Numerra LLC
8 The Green, Suite R, Dover, DE 19901, USA
Email: support@billthebill.com