This Privacy Policy explains how Netonic ("Netonic", "Billebly", "we", "us") handles personal data across billebly.com and the Billebly application at app.billebly.com (together, the "Service"). If anything here is unclear, email support@billebly.com.
1. Who's responsible for your data
Netonic is the company behind Billebly. Our registered office address and company registration details are available on request by emailing support@billebly.com. Because of how Billebly works, we play a different role depending on whose data it is:
- Your own account and business data (you signed up to run your business on Billebly): we're the controller.
- Personal data about your own clients that you enter into Billebly (name, email, invoice details): you're the controller, and we're the processor acting on your instructions, under our Data Processing Agreement.
- If you're a client who received an invoice or payment link and never created an account, the business that invoiced you is the controller of your data. See section 8 below.
2. What we collect
- Merchant account data: your name, email, business profile (address, phone, website, registration/VAT number), currency and payment settings, and any referral relationship between businesses.
- Data you enter about your own clients: company/contact name, email, phone, address, VAT number, plus the projects, time entries, and invoice line items you create for them.
- Payment data: we never see or store card numbers or bank account details. Stripe's own embedded checkout and onboarding components collect those directly, on Stripe's own servers. What we do store: whether a payment succeeded, its amount and currency, a masked description of the method used (e.g. "Visa ending in 4242"), and Stripe's own reference IDs.
- Identity verification (KYC) data: a representative's legal name, date of birth, national ID number, a government-issued ID photo, and bank account/IBAN details are collected directly by Stripe as part of setting up your connected account. We never receive, see, or store these ourselves.
- Technical data: standard server logs, IP address, browser/device information, and error reports (via Sentry) when something breaks.
- Cookies: only on billebly.com, the marketing site (see section 11). The application itself (app.billebly.com) doesn't use analytics or marketing cookies.
- Support communications: whatever you tell us when you email us.
3. Why we process it
To provide the Service and perform our contract with you (running your account, building invoices, processing payments); for our legitimate interests (fraud prevention, keeping the Service secure, improving it); to meet a legal obligation (bookkeeping/tax retention, or cooperating with Stripe on fraud or anti-money-laundering checks where required); and, for analytics cookies only, with your consent.
4. Who we share it with
- Stripe: payment processing, identity verification, and payouts (stripe.com/privacy).
- Resend: delivers transactional email (invoices, receipts, password resets) on our behalf (resend.com/legal/privacy-policy).
- Sentry: error monitoring, which can incidentally capture technical data in a crash report (sentry.io/privacy).
- Our hosting provider: stores the application, database, and backups.
- Google Analytics: marketing site only, and only if you accept our cookie banner (policies.google.com/privacy).
The full, current list of sub-processors we use to process data on your behalf as a processor is in our Data Processing Agreement. We don't sell personal data, and we don't share it with anyone for their own advertising purposes.
5. International transfers
Stripe and Google may process data outside the EU/EEA (for example, in the United States). Both rely on recognized transfer safeguards: Stripe under the EU-U.S. Data Privacy Framework and Standard Contractual Clauses (see Stripe's own Data Processing Agreement), and Google under its own equivalent mechanisms.
6. How long we keep it
We keep your data for as long as your account exists. After you delete your account, most data is permanently erased following the 30-day grace period described in-app. Invoice, payment, and other tax-relevant records may be kept longer where Dutch or EU bookkeeping law requires it, generally up to seven years for financial administration. Support emails are kept as long as reasonably needed to resolve and document the matter.
7. Your rights
Where we're the controller of your data (section 1), you can ask to access, correct, delete, or restrict it, ask for a portable copy, object to processing based on our legitimate interest, or withdraw cookie consent at any time. Two of these are already self-service: a full data export (Settings → Export → "Download everything") and account deletion (Settings → Danger zone). For anything else, email support@billebly.com. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or your own country's supervisory authority.
8. If you're a client of a Billebly merchant
If you received an invoice or payment link from a business using Billebly, that business, not Netonic, is the controller of the personal data on that invoice, and is who you should contact first about your rights over it (access, correction, deletion, and so on). We process that data on their behalf, as their processor, under our Data Processing Agreement with them. If your request is security-related, or the business is unreachable, email support@billebly.com and we'll help where we can.
9. Security
We use HTTPS everywhere, encrypt two-factor authentication secrets and recovery codes at rest, never let card data touch our servers, and rely on Sentry to catch and monitor errors. No system is completely secure, and we can't guarantee absolute security, but we take reasonable, industry-standard measures to protect your data.
10. Children
The Service is intended for businesses and professionals, not children. We don't knowingly collect personal data from anyone under 16.
11. Cookies
Google Analytics sets cookies on billebly.com to help us understand how the site is used, but only after you actively accept our cookie banner; nothing loads before that. The application (app.billebly.com) doesn't use analytics or marketing cookies at all. Full details, including how to change your mind at any time, are in our Cookie Policy.
12. Changes to this policy
If this policy changes in a meaningful way, we'll update the date at the top of this page and, where the change is significant, let you know by email or in-app.
13. Contact & complaints
Questions about this policy, or requests about your data, can be sent to support@billebly.com. You can also lodge a complaint with the Autoriteit Persoonsgegevens, the Dutch data protection authority, or your own country's equivalent.