Legal

Privacy Policy

Last updated: March 5, 2026

Agent Billy is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights.

1. Information We Collect

We collect information you provide directly to us, such as when you create an account, connect your Stripe account, or contact us for support. This includes: name, email address, organization name, and billing information. We also collect usage data and log files generated when you use the Service, including IP addresses, browser type, pages visited, and actions taken within the Service. We do not store your Stripe API keys in any database — they are encrypted and stored in Azure Key Vault.

2. How We Use Your Information

We use the information we collect to: (a) provide, maintain, and improve the Service; (b) process transactions and send related information such as purchase confirmations and invoices; (c) send technical notices, updates, and support messages; (d) respond to your comments and questions; (e) monitor and analyze trends and usage; (f) detect, investigate, and prevent fraudulent or unauthorized activity; (g) comply with legal obligations.

3. Information Sharing

We do not sell, rent, or share your personal information with third parties for marketing purposes. We may share your information with: (a) service providers who perform services on our behalf, such as cloud hosting (Microsoft Azure) and payment processing (Stripe); (b) professional advisors such as lawyers and accountants; (c) law enforcement or government agencies when required by law; (d) a buyer or successor in the event of a merger, acquisition, or similar transaction. All service providers are contractually required to use your information only as necessary to provide services to us.

4. Data Storage and Security

Your data is stored in Microsoft Azure data centers in the United States and European Union. We implement industry-standard security measures including: encryption at rest and in transit (TLS 1.3), Azure Key Vault for API key storage, network segmentation and per-customer container isolation, access controls and audit logging, and regular security reviews. While we implement these measures, no security system is impenetrable. We cannot guarantee the security of your information.

5. Stripe Data

When you connect your Stripe account, we retrieve billing data (charges, customers, subscriptions, invoices) via the Stripe API and store it in your isolated container database. This data is used solely to power the Agent Billy dashboard and is never shared with other customers or used for any purpose other than providing the Service. We sync this data periodically and retain it while your subscription is active. Upon cancellation, all Stripe data is deleted within 30 days.

6. Cookies and Tracking

We use strictly necessary cookies to maintain your session and authentication state. We do not use advertising cookies or cross-site tracking technologies. We may use analytics tools to understand how the Service is used. Analytics data is aggregated and not linked to individual users.

7. Your Rights

Depending on your location, you may have rights including: (a) access to the personal information we hold about you; (b) correction of inaccurate or incomplete information; (c) deletion of your personal information; (d) restriction of processing; (e) data portability; (f) objection to certain types of processing. To exercise these rights, contact us at privacy@agentbilly.ai. We will respond within 30 days.

8. Data Retention

We retain your account information for as long as your account is active or as needed to provide the Service. After you cancel, we retain your data for 30 days in case you wish to reactivate, after which it is permanently deleted. Audit logs are retained for 90 days for active subscribers and deleted upon cancellation after the 30-day grace period.

9. International Data Transfers

If you are located outside the United States, your information may be transferred to and processed in the United States. We implement appropriate safeguards for international transfers in accordance with applicable data protection laws, including Standard Contractual Clauses where required by EU data protection law.

10. Children's Privacy

The Service is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will promptly delete it.

11. Changes to this Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a prominent notice in the Service at least 14 days before changes take effect. We encourage you to review this policy periodically.

12. Contact

If you have questions about this Privacy Policy or our privacy practices, contact us at privacy@agentbilly.ai. For security-related disclosures, contact security@agentbilly.ai.