Privacy
Last updated 10 August 2026
What we store about you
Your email address and sign-in identity (handled by Clerk), your business details as you enter them, your plan status, and an encrypted copy of the restricted Stripe key you provide. The key is encrypted with AES-256-GCM before it is written to our database and is never logged or returned by our API.
What we store about your customers
For each payment we sync from your Stripe account: the customer email, name where available, amount, currency, description, and date. When a customer generates an invoice, we also store the company details they enter — including a VAT or tax identifier — so those details prefill next time.
In data-protection terms, you are the controller of this data and BillHog is a processor acting on your instructions.
Portal verification
When a customer requests an invoice, we email a six-digit code to the address they enter. Codes are stored only as a keyed hash, expire after ten minutes, and are limited to five attempts. A verified session lasts thirty minutes and grants access only to payments made with that exact email address.
Analytics and error tracking
We use PostHog for product analytics on the owner-facing dashboard only, with autocapture and session recording disabled. The customer portal loads no analytics at all. Errors are reported to Sentry with request bodies, cookies, headers, email addresses, and credentials stripped before transmission.
Subprocessors
Vercel (hosting and file storage), Neon (database), Clerk (authentication), Resend (transactional email), Polar (payments and merchant of record), PostHog (analytics), and Sentry (error tracking).
Deletion
Disconnecting your Stripe account deletes the stored key, synced payments, and saved customer details. Issued invoices are retained as financial records. To have everything erased, contact us and we'll remove it.