Your data
Privacy Policy
What we collect, why, who else touches it, and the things that never reach us at all.
1Who is responsible for this data
Alderbill is operated by [[LEGAL ENTITY NAME]] (“we”, “us”). This policy covers alderbill.com, the workspaces on it, and the invoice links we serve to your customers.
For questions about anything below, write to [[PRIVACY CONTACT EMAIL]].
2The short version
- We collect what is needed to run an invoicing product, and we do not sell it.
- We never see a card number or a bank account number. Those go to Stripe’s own pages.
- There is no advertising, no tracking pixel and no analytics.
- The customer records in a workspace belong to that business. We hold them on its behalf, not for our own purposes.
3What we collect about account holders
If you hold an Alderbill account, we hold:
- Your account. Your name, email address and sign-in credentials. Credentials are held by our authentication provider — we never store your password.
- Your request for access. Your business name, the address you asked for, anything you wrote to us, and the decision we reached with its reason. Kept as the record of why an account exists.
- Your business profile. The details you want printed on invoices: trading name, email, phone, website, address, tax identifier.
- Your settings. Currency, payment terms, invoice numbering, tax and fee configuration.
- Your Stripe connection. Your Stripe account identifier and whether Stripe says it can take card payments. Nothing about your legal, tax or bank details is stored here — you enter those on Stripe’s own pages and they never reach us.
- An audit record of actions that move money or change who can reach what: who did it, to which record, and when.
4What we hold on behalf of a business
When a business uses Alderbill, it enters information about its own customers: names, email addresses, phone numbers, postal addresses, tax identifiers, notes, and the invoices themselves. If a business asks a customer to approve an invoice before paying, we store the name they typed, the exact sentence they agreed to, and the time.
The business decides what to collect and why; we only hold it. In data-protection terms it is the controller and we are its processor. If you are a customer of a business that uses Alderbill and you want your details corrected or removed, ask that business — they can do it themselves, and they are the ones who know why they hold it. If you cannot reach them, write to us and we will try to help.
One thing we deliberately do not record against an approval is an IP address. We could only get one from the browser, which means whoever is signing would choose what it said. A field that looks like evidence and is actually self-reported is worse than no field.
5Signing in with Google
If you choose to sign in with Google, Google shows you what you are agreeing to share and we receive only this:
- your name;
- your email address, and whether Google has verified it;
- your profile picture;
- your Google account identifier.
We use it for one thing: to create your Alderbill account and to recognise you when you come back. It appears in the product as your name and email, so you can tell which account you are in.
Alderbill’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we do not use Google user data for advertising, we do not sell it, we do not transfer it to anyone except the providers in section 8 who process it to run the service for us, and no human reads it except where you have asked us for support, where it is needed for security, or where the law requires it.
We do not request access to your Gmail, Drive, Calendar, Contacts or anything else in your Google account. You can disconnect Alderbill at any time from your Google account’s permissions page; doing so stops you signing in that way and does not by itself delete your Alderbill account.
6What never reaches us
Three things worth stating plainly, because they are the ones people worry about:
- Card numbers. Payment happens on Stripe’s hosted page. What comes back to us is the card brand and the last four digits, so an invoice can say which card paid it. The full number, the expiry and the security code never touch this system.
- Bank details. A business enters those with Stripe during onboarding. We store an account identifier and a yes-or-no on whether card payments work.
- Passwords. Held by our authentication provider, never by us.
7Cookies
Alderbill sets the cookies needed to keep you signed in and to keep the session secure. That is the whole list. There are no advertising cookies, no analytics, no third-party trackers, and consequently no consent banner to dismiss.
Blocking these cookies will stop you being able to sign in. A customer opening an invoice link does not need to be signed in and is not given a session cookie for it.
8Who else processes this data
We use a small number of providers to run the service. Each processes data on our instructions, under its own agreement with us.
- Clerk — accounts, sign-in and session security. Holds your name, email and credentials.
- Convex — the database. Holds workspaces, invoices, customer records, payment records and the audit log.
- Stripe — payment processing and the connected accounts businesses are paid into. Holds cardholder and bank data that we never see.
- Vercel — hosting and content delivery. Processes requests to the site.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We may disclose data where the law requires it, or to establish or defend a legal claim — and if a business we host is ever the subject of such a request, we will tell them unless we are forbidden to.
If Alderbill is ever sold or merged, this data may transfer with it. You would be told before that happened.
9Where it is held
Alderbill operates in the United States and its data is processed there. Our providers may process or back up data in other countries under their own safeguards. If you are outside the United States, using Alderbill means your data is handled there.
10How long we keep it
Invoices, credit notes, payment records and the audit log are financial records. We keep them for as long as the workspace exists and for a period afterwards, because a business, its customer or a tax authority may need to establish what was charged and paid years later.
Customer records are archived rather than deleted when a business removes them, so that an invoice can always name who it was sent to.
Account and access-request records are kept while the account exists. Ask us to close a workspace and we will delete what we are not required to keep, and tell you what is left and why.
11How it is protected
Every piece of business data in the database is tied to the workspace it belongs to, and every query that reaches business data is forced through that check by the way the code is structured rather than by anyone remembering to add it. Screens are private because of where they sit in the application, not because a path was added to a list.
Invoice links carry a long random token rather than a sequential number, so they cannot be guessed by counting, and a business can reissue a link if one gets out. Traffic is encrypted in transit.
No system is perfectly secure, and we would rather say that than imply otherwise.
12Your rights
Depending on where you live, you may have the right to know what we hold about you, to get a copy, to correct it, to have it deleted, and to not be discriminated against for asking. Where we rely on your consent — as with Google sign-in — you can withdraw it.
Write to [[PRIVACY CONTACT EMAIL]]. We will verify who you are before acting, because doing what a request says without checking would itself be the privacy problem. We do not charge for this.
If you are asking about details a business entered about you as its customer, section 4 explains why that business is the right first contact.
13Children
Alderbill is a tool for businesses and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us information, write to us and we will remove it.
14Changes to this policy
We may update this policy. The date at the top says when the wording last changed. If a change materially affects how we handle your data, we will tell account holders rather than relying on you to re-read the page.
15Reaching a person
Write to [[PRIVACY CONTACT EMAIL]] and a person will read it. For anything else, the terms of service has our general address.
[[LEGAL ENTITY NAME]], [[REGISTERED POSTAL ADDRESS]]