BillBirdy Privacy Policy
Last updated: July 9, 2026
Who we are
BillBirdy (“BillBirdy,” “we,” “us”) operates the BillBirdy web application (billbirdy.com), the owner/accountant dashboard, and the vendor-approver portal (collectively, the “Service”).
BillBirdy is a business tool. When we process invoice and vendor data inside a customer’s account, we act as a service provider/processor on behalf of that customer, who remains responsible for the data they route through the Service.
Questions about this policy or your data: privacy@billbirdy.com.
What we collect
Account information. Name, email address, and password (hashed via our authentication provider — we never store plaintext passwords) for dashboard users. Portal approvers authenticate through a separate magic-link/token system tied to the client they’re invited to approve for, and provide only a name and email address.
Invoice and vendor data. Vendor bills sent to your BillBirdy inbound email address, including attached PDFs, extracted data (vendor names, amounts, line items, PO numbers, due dates), and the approval decisions (approve/reject/adjust) made on them. Invoices sometimes contain vendor bank details printed on the document; we don’t ask for or separately process these.
QuickBooks Online connection data. When you connect a QBO company, we store OAuth tokens (encrypted at rest) that let BillBirdy read and post bills on your behalf. Authentication happens entirely through Intuit’s own OAuth flow — we never see or store your Intuit password.
Usage and log data. Standard web/API request logs, and error diagnostics sent to our error-monitoring provider with personal data scrubbed before it leaves our systems.
Notifications and audit history. In-app and email notifications about invoices needing attention, and the audit trail of who approved, rejected, or adjusted each invoice and when.
How we use it
To operate the Service: ingesting, extracting, matching, classifying, and routing your vendor bills for approval, and posting approved bills to your connected QuickBooks Online company. To notify the right people when an invoice needs a decision and enforce your organization’s approval rules (quorum, per-approver limits, role permissions). To detect and prevent duplicate postings, fraud, and abuse (duplicate-invoice detection, posting-amount caps). To monitor and improve reliability, with personal data scrubbed from what reaches our monitoring tools. To communicate with you about the Service (transactional email, not marketing, unless you opt in).
We do not sell or share your personal information, including as “sell” and “share” are defined under the California Consumer Privacy Act (CCPA/CPRA), and we do not use it for cross-context behavioral advertising. We do not use your invoice or financial data to train AI models — our AI provider processes your documents solely to extract data for your own account (see Anthropic below).
We may use data that has been aggregated and de-identified — so it no longer identifies you, your business, or your vendors — to analyze and improve the Service.
Who we share it with (subprocessors)
Each provider receives only the data it needs for its function:
- Supabase — database hosting and user authentication.
- Railway — backend application hosting.
- Vercel — frontend application hosting.
- Anthropic — AI processing: invoice documents (PDFs) are sent to Anthropic’s Claude API to extract and classify invoice data (vendor name, amounts, line items, dates). Under Anthropic’s commercial API terms, API inputs and outputs are not used to train Anthropic’s models, and are deleted from Anthropic’s systems within approximately 30 days by default.
- Postmark — inbound email processing for invoice ingestion, and outbound transactional email (approval requests, notifications).
- Sentry — error and performance monitoring, with personal data scrubbed before transmission.
- Intuit / QuickBooks Online — the accounting platform you explicitly connect; data flows to QBO only for the bills and vendors your organization chooses to sync.
- Cloudflare — DNS and edge/security services in front of our domains, and object storage (Cloudflare R2), where original invoice PDF files are archived.
We may also disclose data if required by law, subpoena, or valid legal process, or to protect the rights, property, or safety of BillBirdy, our customers, or others. If BillBirdy is involved in a merger, acquisition, or sale of assets, customer data may transfer as part of that transaction; this policy would continue to apply and we’d notify affected customers.
Vendor and third-party data
Vendor bills often contain information about your vendors — business name, contact details, sometimes banking details printed on the invoice. This vendor data is provided to BillBirdy by you (our customer), not collected from your vendors directly, and we have no direct relationship with your vendors. We process it only on your behalf, as your service provider. You’re responsible for having the right to share vendor information with BillBirdy in your normal course of business.
Data retention and deletion
While your account is active, we retain invoice and approval records so your organization has a complete audit trail. When you disconnect a QuickBooks company, that company’s connection data, invoice history, and archived invoice PDFs are scheduled for permanent deletion 30 days after disconnection — the window exists so an accidental disconnect is recoverable. After deletion, data may persist briefly in routine backups that age out on their own schedule, and we may retain specific records where needed to resolve an active dispute or meet a legal obligation.
You can request earlier deletion of your account and associated data at privacy@billbirdy.com.
Security
Dashboard sessions use cryptographically verified, short-lived tokens. Portal-approver sessions use a separately revocable token system, so a removed approver loses access immediately. QuickBooks OAuth tokens are encrypted at rest. All traffic is encrypted in transit (HTTPS/TLS). Database row-level security restricts each organization’s data to that organization. Request-size limits, posting-amount caps, and duplicate detection provide additional safeguards on the financial path.
No system is perfectly secure and we can’t guarantee absolute security, but we take reasonable, industry-standard measures and will notify affected customers of any security incident affecting their data as required by law.
Cookies and local storage
BillBirdy uses browser storage (cookies, localStorage, and sessionStorage) for authentication session tokens and product preferences (e.g., setup-guide and product-tour state). We do not use third-party advertising or cross-site tracking cookies.
Your choices and rights
You can review, correct, or request deletion of your account information by contacting us. Depending on where you live, you may have statutory rights — for example, under the CCPA/CPRA (California) or GDPR (EU/UK): the right to know what we collect, to access and receive a copy of it, to correct it, to delete it, to data portability, and to not be discriminated against for exercising these rights. You may designate an authorized agent to submit requests for you; we’ll verify the request before acting on it. Contact privacy@billbirdy.com and we’ll address the specific request even where this section doesn’t enumerate a jurisdiction’s rights.
Because BillBirdy processes most personal data as a service provider on behalf of business customers, individuals whose data appears in a customer’s invoices (e.g., vendor contacts) should direct requests to that business; we’ll support our customer in fulfilling them.
Children’s privacy
BillBirdy is a business tool and is not directed at, or intended for use by, children. We do not knowingly collect information from anyone under 18.
International data
BillBirdy’s infrastructure is hosted in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States.
Changes to this policy
We’ll update the “Last updated” date above when this policy changes, and for material changes, we’ll notify active customers by email before they take effect.
Contact
privacy@billbirdy.com