This policy explains how BillingNudge collects and uses information when you visit our website or use the invoice-reminder service. The service is intended for United States business users.
Information we collect
- Account data: email address, verified Google identifier if used, country, locale, time zone, sign-in and terms records.
- Business and invoice data: sender details, client names and email addresses, invoice numbers, amounts, currencies, dates, links, private notes, reminder wording, schedules, and delivery history.
- Billing data: subscription status and Stripe identifiers. Stripe collects payment-card and billing-address data; BillingNudge does not store full card numbers.
- Technical and safety data: IP address, request and security logs, device/browser details, webhook records, abuse reports, and error diagnostics.
- Analytics: a narrow set of product events identified by an internal account ID. We do not send invoice values, client details, message content, typed fields, or token-bearing URLs to analytics.
How we use information
We use data to authenticate users, generate approved schedules, deliver and track reminders, prevent duplicate sends, stop messages when required, provide billing and support, investigate abuse, secure and improve the service, and comply with law. We do not sell personal information or use client contact data for advertising.
Service providers
We use infrastructure and specialist providers to operate the service, including Railway for hosting, Resend for transactional email, Stripe for subscriptions, Google for optional sign-in, Sentry for error monitoring, and PostHog for limited analytics. Providers process data under their own terms and only for the functions we configure.
Retention and deletion
Account records remain while your account is active. A deletion request immediately stops sending and revokes sessions; the account and its operational records are scheduled for permanent deletion after a 30-day recovery window. Provider, security, backup, fraud, tax, or legal records may remain for a limited period where required. Backups age out on their normal schedule and are not restored except for disaster recovery.
Your choices
You can update sender settings, pause or cancel reminders, export account data, unlink Google when another sign-in method exists, and request deletion from Security & data settings. You may also contact privacy@billingnudge.com. We will verify requests before acting.
Cookies and analytics
Customer and administrator applications use essential security cookies. The public website’s initial analytics configuration is anonymous, in-memory, cookieless, has autocapture disabled, and does not use session replay. Product session replay is disabled.
Security
We use transport encryption, access controls, signed provider webhooks, rate limits, secret filtering, account-scoped queries, and monitoring. No online system is completely secure; report a suspected security issue to security@billingnudge.com.
Children and international use
BillingNudge is a business service and is not directed to children under 18. New business accounts are initially limited to the United States. Clients may be elsewhere, but BillingNudge does not provide local tax, collections, or legal compliance advice.
Changes and contact
We may update this policy and will post the effective date. Material changes will be communicated in the service when appropriate. Questions can be sent to privacy@billingnudge.com.