Privacy Policy
Last updated: 28 August 2026
This policy explains how we handle personal data when you use BillBook Business. We have written it to meet the EU General Data Protection Regulation (GDPR / DSGVO). BillBook Business is local-first: by default your business records stay on your own device, and we deliberately collect as little as possible.
Who is responsible (Controller)
The controller for personal data processed through the Service is:
Shamrocks Games
Email: privacy@billbookbusiness.com
Full business details are in our Legal Notice (Impressum).
Local-first by default
Your invoices, receipts, cashbook entries, orders, stock and customer records are saved in the app’s storage on your own device. Unless you turn on optional cloud sync, none of it is sent to us or anyone else. Because the data lives on your device, clearing the app’s data or uninstalling it removes it — so please keep your own backups (you can export your data at any time).
What we process, why, and our legal basis
- Account data — if you sign in with Google or Facebook, we receive your name, email address and profile picture from that provider, and use them only to create and secure your account and to recognise you when you sign in again. We ask for the minimum each provider offers for that purpose — from Facebook, only your public profile and email address. We never post anything to your account, never access your friends, contacts, photos or any other part of your profile, and never use this data for advertising. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Your business records — if you enable cloud sync, the records you choose to sync are stored so you can back them up and use them across devices. Legal basis: contract (Art. 6(1)(b)).
- Subscription & billing data — paid plans bought on the web are handled by our Merchant of Record, Paddle, and plans bought inside the app are handled by the Google Play Store or Apple App Store (see below). These providers process your payment details as independent controllers; we receive only limited transaction and billing information needed to manage your subscription and meet our record-keeping and tax obligations. Legal basis: contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)).
- Smart features — only when you choose to use the Smart Helper or Snap-a-bill, the question you type with the relevant business figures, or the photo of a bill you scan, is sent securely to our AI processor to produce that single answer or reading. It is never used for advertising or to train models, and never sold. Legal basis: contract / your request (Art. 6(1)(b)).
- Technical & security data — our hosting provider processes basic request data (such as IP address and timestamps) to deliver the site securely and prevent abuse. Legal basis: legitimate interests in security and reliability (Art. 6(1)(f)).
Who processes data for us
We use a small number of carefully chosen service providers who process data on our behalf under data-processing agreements, or as independent providers where noted:
- Paddle (Paddle.com Market Ltd and its affiliates) — payments and subscription billing for web purchases, as our Merchant of Record. For this data Paddle acts as an independent controller in its own right; see Paddle’s Privacy Policy.
- Google Play & Apple App Store — if you subscribe through the Android or iOS app, Google or Apple is the merchant of record and processes your payment for that purchase; we receive only limited entitlement data (that a subscription is active) to unlock your plan. See Google’s and Apple’s privacy policies.
- Google — optional “Continue with Google” sign-in. Our use of information received from Google APIs follows the Limited Use requirements of the Google API Services User Data Policy.
- Meta Platforms — optional “Continue with Facebook” sign-in. We receive only your public profile and email address, and use them solely to create and secure your account, in line with the Meta Platform Terms and Developer Policies. See Meta’s Privacy Policy.
- Supabase — secure cloud database for optional cloud sync, with per-user Row-Level Security so only you can read or write your own data. This database is hosted in India (Mumbai region); Supabase Inc. is based in the United States and may access it remotely to operate and support the service.
- Cloudflare — website and app hosting, content delivery and security.
- Anthropic — the AI provider that powers the Smart Helper and Snap-a-bill when you use them. Data sent for these features is not used to train models.
We do not sell your data or your customers’ details, and we do not show third-party advertising.
International transfers
Some of these providers process data outside the European Economic Area. In particular, our cloud database is hosted in India (Mumbai region), and providers such as Paddle, Google, Apple, Cloudflare, Meta and Anthropic may process data in the United States. India is not covered by an EU adequacy decision, and the EU–US Data Privacy Framework covers only those US providers that are self-certified under it. Where an adequacy decision does not apply, we rely on appropriate safeguards — principally the EU Standard Contractual Clauses agreed with the provider — alongside the technical measures described in this policy, including encryption in transit and at rest and per-user Row-Level Security. You can ask us for more detail, including which safeguard applies to a specific provider, using the contact above.
Website analytics & cookies
On our website (billbookbusiness.com) we use our own privacy-friendly, first-party analytics to understand which pages and features genuinely help small businesses — for example how many people view a page or open the app. We do not use it to serve advertising, we do not sell or share this data, and we do not track you across other websites. We store a random, non-identifying visitor ID in your browser’s local storage and record events such as page views and button clicks, together with the marketing campaign that referred you (UTM parameters). No name, email, phone number or other directly identifying information is collected by this website analytics.
For visitors in the EU, EEA, UK and Switzerland we ask for your consent before any non-essential analytics or attribution storage runs: until you choose “Accept”, no analytics identifier is stored and no events are sent, and choosing “Decline” keeps it off. We also honour the Global Privacy Control and Do-Not-Track browser signals as a binding opt-out everywhere. You can change your choice at any time by clearing this site’s browser storage. Outside those regions this first-party measurement runs by default to help us improve the product, and you can still opt out using those browser signals. This is separate from the optional Google/Facebook sign-in inside the app described above.
What we deliberately do not do
BillBook is not a payments product: it does not connect to any bank, card processor or payment gateway from your device, and never stores card, bank-account or payment-token details — those are handled solely by our Merchant of Record, Paddle (for web purchases) or by the Google Play Store or Apple App Store (for purchases made inside the app), at checkout. Any QR code you display is your own bank-issued code. We never sell your data, and we do not profile you for advertising. BillBook is invoicing and billing software — not a marketplace or a place to buy or sell digital content.
How long we keep data
We keep account and synced data for as long as your account is active. You can delete your account and data from within the app at any time, or request deletion on the web — see Delete your account & data. After that we delete it from our active systems, except where we must keep limited billing records to meet legal and tax obligations.
Government and legal requests
We may occasionally receive a request from a court, regulator, tax authority or law-enforcement body asking us to disclose personal data. We treat every such request seriously, and we handle it as follows:
- We check that it is lawful. We review each request against the applicable law before we respond, and we require it to be properly issued, specific and directed to us. We do not grant informal or voluntary access to personal data.
- We challenge requests we believe are unlawful. Where a request appears overbroad, improperly issued, or contrary to the GDPR or German law, we push back on it and, where necessary and lawful, contest it.
- We disclose the minimum necessary. We provide only the specific data actually covered by the request, and nothing beyond it. Because BillBook is local-first, your invoices, customers, stock and cashbook records normally never leave your own device — so in most cases there is simply nothing for us to hand over.
- We keep a record. We document the requests we receive, the legal reasoning we applied, and what was disclosed.
- We tell you where we can. Unless we are legally prohibited from doing so, we will notify you if we are required to disclose your personal data, so that you have an opportunity to seek protection.
Your rights
Under the GDPR you have the right to access, correct, delete or port your data, to restrict or object to certain processing, and to withdraw any consent at any time. To exercise these rights, contact privacy@billbookbusiness.com. You also have the right to lodge a complaint with a data-protection supervisory authority — for us, the competent authority is the Hessian Commissioner for Data Protection and Freedom of Information (Der Hessische Beauftragte für Datenschutz und Informationsfreiheit).
Children
BillBook Business is intended for business owners and is not directed at children.
Changes to this policy
We may update this policy as the Service evolves; the date above reflects the current version.
Contact
Privacy questions or requests: privacy@billbookbusiness.com. General support: support@billbookbusiness.com.