Privacy Policy
Last updated: August 1, 2026
On this page
Who we are
BillTheBill is operated by Numerra LLC. For your account data we are the data controller, which means we decide what happens to it and we are the ones answerable for it.
Numerra LLC
8 The Green, Suite R, Dover, DE 19901, USA
Email: support@billthebill.com
This policy covers billthebill.com and the BillTheBill app. That one address handles everything — privacy questions, requests about your data, ordinary support.
Two kinds of data, and our two different roles
Your account data — your email address, your business details, your subscription, how you use the product. We decide what happens to it, so we are its controller and the rest of this policy explains what we do.
What is inside your invoices — your clients' names, addresses, emails and tax numbers. That is your data about your clients. You decide what goes in; we store it, turn it into a PDF and send it where you tell us. For that data we are your processor: we act on your instructions, we use it only to run the service for you, and we never use it for our own purposes, sell it or mine it.
That puts something on you too: you are responsible for having a lawful reason to hold your clients' details, and for telling them what you do with them. If one asks you to erase theirs, you can delete the client outright in the app as long as you have never invoiced them. Once you have issued an invoice, that invoice is fixed — a document you have already sent has to stay what it was — so the details on it stay too. Email us in that case and we will work out what can be removed.
If you need a signed data processing agreement, email us and we will sort one out.
What we collect
Almost all of it is data you type in yourself:
- Your account — email address; your name and picture if you sign in with Google; your language and format preferences.
- Your business profile — company name, address, tax and registration numbers, phone, email, the bank details you want printed on invoices, and your logo.
- Your clients — name, contact person, email, postal address and VAT number, as you enter them.
- Your invoices — numbers, dates, currency, line items, notes, totals, status history, and the PDFs and credit notes generated from them.
- Your subscription — your plan, your customer and subscription identifiers at Polar, billing period dates, usage counters, and any voucher or promotional credit applied to your account. We never see or store your card details.
- Payments to you — if you connect Stripe, your Stripe account identifier and whether it is cleared to take charges. Your clients' card details go straight to Stripe and never reach us.
- Sign-in and security — sessions with IP address and browser user-agent, magic-link tokens (stored hashed), your Google account id and the tokens Google issues alongside it, and audit logs of significant actions such as sign-ins and invoice changes.
- When you contact us — your name, your email address, and whatever you write or attach, kept in our support inbox so we can answer you.
We do not store passwords, because there are none. We do not ask for special-category data such as health or beliefs, and you should not put any into an invoice.
We hold all of it because we need it to run the service you signed up for and to bill you. Audit and rate-limit logs rest on our legitimate interest in a service that is not abused, and our own tax records on a legal obligation.
Where your data lives
Your database records, your invoices and your files are stored and processed in the European Union, in Frankfurt, Germany. That covers the substance of it: the database, the file storage and the PDF rendering.
Three services around the edges are US-based: Polar for subscriptions, Stripe for payments to you, and Google if you sign in with Google. Those transfers rely on the EU-US Data Privacy Framework and standard contractual clauses.
And to be straight with you: Numerra LLC is a US company, so we can in principle be compelled by US legal process. If that happens we will tell you, unless we are legally barred from doing so.
Who else touches it
We do not sell your data and we never share it for advertising. These are the companies that process data on our behalf:
| Company | What they do | Where |
|---|---|---|
| Neon | Database — everything you enter | EU (Frankfurt) |
| Vercel | App hosting and file storage — PDFs, logos, attachments | EU (Frankfurt) |
| Fly.io | Turns invoices into PDFs; keeps nothing afterwards | EU (Frankfurt) |
| Resend | Sends your invoices and our account emails | EU |
| Cloudflare | DNS, and forwards email sent to our support address | USA |
| Zoho | Our support inbox — the email you send us | EU |
| PostHog | Product analytics | EU |
| Polar | Subscription billing, merchant of record | USA |
| Stripe | Payments from your clients to you | USA |
| Sentry | Error monitoring | EU (Germany) |
| Sign in with Google — only if you use it | USA |
PostHog needs a note, because analytics usually means tracking and here it does not. It runs without cookies, with session recording off and no automatic capture of what is on your screen, so a screen full of your clients' details is never scraped. It identifies you by an internal account id; we deliberately do not send it your email address.
Sentry receives error reports when something breaks. They are keyed to your internal account id — we deliberately do not send it your email address — and access tokens are stripped out of the report first.
Beyond that we share data only where the law requires it, or where we need to in order to protect the service against fraud or abuse.
Cookies
Three cookies sign you in and keep you signed in, and one remembers your language. That is the lot: no analytics cookies, no advertising, no third-party trackers — and therefore no consent banner to dismiss. The Cookie Policy lists them individually.
How long we keep it
We keep your data until you delete it. There is no dormancy rule — we do not delete accounts for being unused, so if you leave one alone for two years your invoices will still be there when you come back.
The short-lived exceptions: sign-in sessions expire after 7 days, sign-in links after 10 minutes, email-verification links after 24 hours, and audit logs are deleted automatically after 90 days.
Where you have paid for a subscription, Polar keeps the order and tax record it has to keep as the seller, and we keep our own billing history for as long as tax law requires. Both outlast your account.
Getting your data out, and deleting it
Export. Settings gives you a one-click export: a zip containing your profile, clients, invoices with line items and status history, company profiles, saved templates, credit notes, and the PDFs of both your invoices and your credit notes.
Deletion. You can delete your account from settings, and we mean it literally. Your invoices and credit notes, clients, company profiles, sessions, notifications and stored files — PDFs, logos, attachments — are all removed, and we ask Polar to anonymise your customer record. Audit entries are detached from your account immediately; until the routine 90-day cleanup clears them they still record the IP address and browser an action came from, with nothing tying them back to you.
Three honest caveats: our database provider keeps encrypted backups on a rolling cycle, so a copy can survive there briefly before it is overwritten; our analytics and error-monitoring records, which are keyed to an account id and never held your name, fall away on their own retention schedules rather than the moment you press delete; and anything already sent — an invoice emailed to a client — has left our hands entirely. None of it can be undone, so export first.
Your rights
You can ask us for a copy of your data, correct it, delete it, take it elsewhere in a portable format, object to what we do with it, or ask us to restrict it. Most of that you can do yourself in settings.
For anything else, email us: we will deal with it within 30 days, we do not charge, and we will not ask you why.
If you think we have got it wrong, you can complain to your local data protection authority. We would rather you told us first, but that is your call.
How we protect it
The measures that actually matter here:
- Data is encrypted in transit and at rest, and card details never touch our servers.
- Sign-in cookies are HTTP-only and secure, and magic-link tokens are stored hashed — a database read yields no usable login. There are no passwords, so there is no password database to leak.
- Every query in the app is scoped to your account — the one exception is our own admin tooling, which we use only when running the service requires it — and significant actions are written to an audit log.
No system is perfect. If there is a breach that affects you, we will tell you and the relevant authority within the time the law allows.
Children
BillTheBill is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children; if you think we have, tell us and we will delete it.
Changes to this policy
We will update this policy as the product changes — the date at the top shows when we last did. For anything significant we will email you or show a notice in the app rather than quietly editing the page.
Contact
Anything at all about your data:
Numerra LLC
8 The Green, Suite R, Dover, DE 19901, USA
Email: support@billthebill.com