Legal

Privacy Policy

Last updated:  ·  Effective Date: March 1, 2025

Agency Billing Hub ("ABH", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our website at agencybillinghub.com and our software-as-a-service platform (collectively, the "Service").

1. Information We Collect

1.1 Information You Provide to Us

Account Information. When you create an account, we collect:

  • Full name
  • Email address
  • Password (stored as a cryptographic hash — never in plaintext)
  • Agency or business name
  • Phone number (optional)
  • Business address (optional)
  • Website URL (optional)
  • Social media handles (X/Twitter, LinkedIn, Instagram) (optional)

Payment Information. We use Polar as our payment processor. Payment card details and billing addresses are collected and stored by Polar, not by us. We receive only:

  • Subscription plan type and status
  • Payment status and renewal dates
  • Transaction IDs
  • Polar customer and subscription identifiers

Customer Data. When you use the Service, you input business data including client names and contact details, project and task information, time tracking entries, invoice data, team member information, notes, and file attachments. You own this data; we process it only to provide the Service.

Support Communications. If you contact our support team, we collect the content of your messages and any attachments you provide.

Contact Form. If you submit our public contact form, we collect your name, email, message, and any optional information you choose to provide (e.g., budget range).

1.2 Information Collected Automatically

Usage Data. We automatically collect analytics data about how you use the Service, including pages visited, features used, session duration, and referring URLs. This data is collected via Google Analytics only after you give explicit cookie consent (see Section 7).

Technical Data. Our server infrastructure may log IP addresses, browser type, device type, and operating system for security and operational purposes. These logs are not used for marketing and are retained for a limited period.

2. How We Use Your Information

We use the information we collect to:

  • Provide and maintain the Service — create and manage your account, process payments, enable core features (time tracking, invoicing, reporting), and store your Customer Data.
  • Communicate with you — send transactional emails (account verification, password resets, payment confirmations), service notifications, weekly automated reports (if enabled), and respond to support requests.
  • Send marketing communications — we may send onboarding or promotional emails only with your consent. You may opt out at any time via the unsubscribe link in any marketing email or by contacting us.
  • Improve the Service — analyze usage patterns, identify bugs, develop new features, and conduct internal research.
  • Ensure security — detect and prevent unauthorized access, monitor for abuse, and comply with legal obligations.
  • Legal and compliance purposes — comply with applicable laws, respond to lawful requests, and protect our rights.

Legal bases for processing (GDPR): We process your personal data on the following legal grounds: performance of a contract (to provide the Service), legitimate interests (security and service improvement), legal obligation (compliance), and consent (analytics cookies, marketing emails).

3. How We Share Your Information

We do not sell, rent, or trade your personal information. We share data only in these circumstances:

3.1 Service Providers

We share information with trusted third-party providers who operate under data processing agreements:

  • Polar — payment processing and subscription management
  • Resend — transactional and automated email delivery
  • Hetzner — cloud hosting and data storage (servers in Germany, EU)
  • Cloudflare — CDN, DDoS protection, CAPTCHA (Turnstile). Cloudflare may process IP addresses and request metadata as part of providing these services.
  • Google Analytics — website and app analytics (only if you consent to analytics cookies; IP addresses are anonymized by default in Google Analytics 4)

3.2 Legal Requirements

We may disclose your information if required by law, court order, or government request, or to investigate fraud, security breaches, or illegal activity.

3.3 Business Transfers

If Agency Billing Hub is acquired or merged, your information may be transferred to the new owner. We will notify you of any change in ownership or control of your personal data.

3.4 With Your Consent

We may share your information with third parties if you give explicit written consent.

4. Data Storage & Security

4.1 Storage Location

Your data is stored on servers operated by Hetzner in Germany (European Union). This means your data is subject to GDPR protections and remains within the EEA.

File uploads (avatars, support attachments) are stored in Cloudflare R2 object storage, with data centres located in Europe.

4.2 Security Measures

We implement industry-standard security measures including:

  • Encryption of all data in transit (HTTPS/TLS)
  • Bcrypt password hashing — passwords are never stored in plaintext
  • JWT token invalidation on password change
  • Role-based access controls and multi-tenant data isolation
  • Magic-byte validation and re-encoding of all file uploads
  • Rate limiting on authentication endpoints
  • CAPTCHA protection on public forms (Cloudflare Turnstile)

4.3 Limitations

No method of transmission over the internet is 100% secure. We cannot guarantee absolute security but will notify you without undue delay if a data breach occurs that is likely to result in a risk to your rights and freedoms.

5. Data Retention

  • Active accounts — we retain your information for as long as your account is active or as needed to provide the Service.
  • Unverified accounts — accounts that are registered but never verified by email are automatically deleted after 72 hours.
  • After cancellation — your account and Customer Data are retained for 90 days to allow reactivation or data export. After 90 days, Customer Data may be permanently deleted.
  • Backups — backup copies may persist for up to 30 additional days after deletion from active systems.
  • Legal retention — some information (e.g., billing records) may be retained longer as required by applicable law or for legitimate legal purposes.
  • Anonymized data — aggregated, anonymized analytics data may be retained indefinitely.

6. Your Rights

6.1 Rights Under GDPR (EU & UK)

If you are located in the European Economic Area (EEA) or United Kingdom, you have the following rights under GDPR / UK GDPR:

  • Right of Access — request a copy of the personal data we hold about you. Use the "Download my data" button in Settings → Privacy & Data.
  • Right to Rectification — request correction of inaccurate or incomplete data via Settings or by contacting us.
  • Right to Erasure ("Right to be Forgotten") — request deletion of your personal data. Contact us at [email protected]. We will respond within 30 days.
  • Right to Restriction — request that we limit processing of your data in certain circumstances.
  • Right to Data Portability — receive your data in a structured, machine-readable format (JSON). Available via Settings → Privacy & Data → Download my data.
  • Right to Object — object to processing for marketing purposes. Unsubscribe from any marketing email or contact us directly.
  • Right to Withdraw Consent — withdraw analytics cookie consent at any time via the cookie settings in your browser.
  • Right to Lodge a Complaint — lodge a complaint with a supervisory authority. In the EU, contact your national data protection authority. In the UK, contact the ICO.

We respond to all GDPR rights requests within 30 days.

6.2 Rights Under CCPA (California Residents)

California residents have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know — request disclosure of the categories and specific pieces of personal information we collect, use, disclose, and sell (we do not sell personal information).
  • Right to Delete — request deletion of your personal information.
  • Right to Correct — request correction of inaccurate personal information.
  • Right to Opt-Out of Sale — we do not sell personal information.
  • Right to Non-Discrimination — we will not discriminate against you for exercising your privacy rights.
  • Right to Data Portability — receive your data in a portable format.

To exercise CCPA rights, contact us at [email protected]. We will respond within 45 days (extendable by a further 45 days with notice).

6.3 How to Exercise Your Rights

Email us at [email protected] with the subject line "Privacy Rights Request". We may need to verify your identity before processing your request. There is no charge for exercising your rights unless requests are manifestly unfounded or excessive.

7. Cookies & Tracking Technologies

We use cookies and similar technologies to operate the Service. When you first visit our website, a cookie consent banner is displayed. Analytics cookies are only set after you click "Accept".

For full details, see our Cookie Policy.

You can withdraw consent at any time by clearing cookies in your browser settings. Withdrawing analytics consent does not affect your use of the Service.

Google Analytics

We use Google Analytics 4 (GA4), which anonymizes IP addresses by default. GA is only loaded after you accept analytics cookies. We have also configured GA with anonymize_ip: true as an additional safeguard.

You can opt out globally via the Google Analytics Opt-out Browser Add-on.

8. Children's Privacy

The Service is not intended for individuals under 16 years of age. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, contact us at [email protected] and we will delete it promptly.

9. International Data Transfers

Your data is stored on servers in Germany (EU). If you access the Service from outside the EU, your information may be transferred to and processed in the EU. We ensure that all international transfers comply with applicable data protection laws, including the use of Standard Contractual Clauses (SCCs) where required.

For US users: by using the Service, you acknowledge that your data will be transferred to and processed in the EU, which may provide different levels of data protection than your home country.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you by email. Your continued use of the Service after the updated policy takes effect constitutes your acceptance of the changes.

We encourage you to review this policy periodically.

11. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Agency Billing Hub

Email: [email protected]

Website: agencybillinghub.com

We aim to respond to all privacy-related enquiries within 5 business days.