Agency Billing Hub ("ABH", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our website at agencybillinghub.com and our software-as-a-service platform (collectively, the "Service").
Account Information. When you create an account, we collect:
Payment Information. We use Polar as our payment processor. Payment card details and billing addresses are collected and stored by Polar, not by us. We receive only:
Customer Data. When you use the Service, you input business data including client names and contact details, project and task information, time tracking entries, invoice data, team member information, notes, and file attachments. You own this data; we process it only to provide the Service.
Support Communications. If you contact our support team, we collect the content of your messages and any attachments you provide.
Contact Form. If you submit our public contact form, we collect your name, email, message, and any optional information you choose to provide (e.g., budget range).
Usage Data. We automatically collect analytics data about how you use the Service, including pages visited, features used, session duration, and referring URLs. This data is collected via Google Analytics only after you give explicit cookie consent (see Section 7).
Technical Data. Our server infrastructure may log IP addresses, browser type, device type, and operating system for security and operational purposes. These logs are not used for marketing and are retained for a limited period.
We use the information we collect to:
Legal bases for processing (GDPR): We process your personal data on the following legal grounds: performance of a contract (to provide the Service), legitimate interests (security and service improvement), legal obligation (compliance), and consent (analytics cookies, marketing emails).
Your data is stored on servers operated by Hetzner in Germany (European Union). This means your data is subject to GDPR protections and remains within the EEA.
File uploads (avatars, support attachments) are stored in Cloudflare R2 object storage, with data centres located in Europe.
We implement industry-standard security measures including:
No method of transmission over the internet is 100% secure. We cannot guarantee absolute security but will notify you without undue delay if a data breach occurs that is likely to result in a risk to your rights and freedoms.
If you are located in the European Economic Area (EEA) or United Kingdom, you have the following rights under GDPR / UK GDPR:
We respond to all GDPR rights requests within 30 days.
California residents have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
To exercise CCPA rights, contact us at [email protected]. We will respond within 45 days (extendable by a further 45 days with notice).
Email us at [email protected] with the subject line "Privacy Rights Request". We may need to verify your identity before processing your request. There is no charge for exercising your rights unless requests are manifestly unfounded or excessive.
The Service is not intended for individuals under 16 years of age. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, contact us at [email protected] and we will delete it promptly.
Your data is stored on servers in Germany (EU). If you access the Service from outside the EU, your information may be transferred to and processed in the EU. We ensure that all international transfers comply with applicable data protection laws, including the use of Standard Contractual Clauses (SCCs) where required.
For US users: by using the Service, you acknowledge that your data will be transferred to and processed in the EU, which may provide different levels of data protection than your home country.
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you by email. Your continued use of the Service after the updated policy takes effect constitutes your acceptance of the changes.
We encourage you to review this policy periodically.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
We aim to respond to all privacy-related enquiries within 5 business days.