1. Who is responsible
Pedro Silva, trading as Plainworks, is the data controller for account administration, billing, website operation, security, support, and our own service analytics. Contact: pedro@duetally.com.
A DueTally user controls the invoices, client records, messages, and payment links they create. For personal data in that content, the user is normally the controller and we process the data on their behalf. Questions about the underlying invoice or commercial relationship should usually go to the business identified on the payment page. We remain a controller for processing we perform for security, legal compliance, and administration of DueTally itself.
2. Data we collect
Account and identity
- Email address, name, Google/Firebase user identifier, account identifier, authentication provider, session and login-token records.
- Business name, business address, notification and reply-to addresses, initials, invoice settings, plan, and preferences.
Customer content
- Client names, companies, email addresses, billing addresses, notes, preferences, and known public payer-wallet addresses.
- Invoice, payment-request, and payment-link details, including line items, descriptions, amounts, currency, tax, discounts, dates, messages, and status.
- Public receiving-wallet addresses, selected assets and networks, transaction hashes, public sender and recipient addresses, amounts, confirmations, matching decisions, and payment activity.
Billing
Stripe gives us customer and subscription identifiers, plan and subscription status, renewal dates, and webhook event data. Stripe collects payment-card and payment-method details directly; DueTally does not store full card numbers or security codes.
Usage, device, and security
- Page routes and selected product events, account and pseudonymous user identifiers, plan, feature type, network, and coarse amount buckets.
- IP addresses received with web requests. For abuse prevention, DueTally stores keyed hashes of rate-limit identifiers for short rolling windows rather than retaining the raw IP in its rate-limit table.
- Browser/device information, timestamps, request and diagnostic metadata, and error or performance traces. Our application is configured not to send default personal information to Sentry.
Support
Your contact email, message, current app path, browser user-agent, account identifiers, and related correspondence when you use the feedback form or contact us.
3. Where data comes from
We receive personal data:
- directly from you, including through account, settings, feedback, and payment-claim forms;
- from a DueTally user who adds a client, payer, invoice recipient, or wallet address;
- from Google/Firebase when you choose Google authentication;
- from Stripe about subscription and billing events;
- from public blockchains, block explorers, and node/RPC providers; and
- automatically from your browser, device, and interaction with the service.
4. Why we use data and our legal bases
- Provide and administer DueTally: create accounts and sessions, deliver requested features, send transactional messages, provide support, manage plans, and process subscriptions. Legal basis: contract or steps requested before contract.
- Process customer content: host and use client, invoice, wallet, and payer data according to the user’s instructions. Legal basis: the user’s instructions under our data-processing terms; the user determines its own legal basis.
- Monitor and match payments: read public-chain data, associate transactions with configured wallets and amounts, and surface status or review suggestions. Legal basis: contract and our legitimate interest in providing and improving the requested receivables workflow.
- Secure and protect the service: authenticate users, rate-limit requests, detect abuse, debug faults, preserve integrity, and enforce our Terms. Legal basis: contract and legitimate interests in network security, fraud prevention, and protecting users and DueTally.
- Operational product measurement: record narrowly defined, server-side service events without customer names, email addresses, invoice descriptions, wallet addresses, transaction hashes, or public payment-link tokens. Legal basis: legitimate interests in understanding reliability and feature operation.
- Optional browser analytics: use PostHog to record page routes and permitted product events only after you choose “Allow analytics.” Legal basis: consent. You can withdraw it at any time below.
- Billing, accounting, and compliance: maintain transaction records, respond to lawful requests, establish or defend claims, and comply with tax and other laws. Legal basis: legal obligation and legitimate interests in legal compliance and claims.
- Communicate: respond to questions and send service, security, billing, and policy notices. Legal basis: contract, legal obligation, and legitimate interests in administering the service.
We do not use personal data for third-party behavioural advertising, and we do not sell personal data. DueTally does not make decisions producing legal or similarly significant effects solely by automated means. Payment matching suggestions can be reviewed and corrected by the account user.
5. Public payment and blockchain data
Published invoices, payment requests, and payment links are available to anyone who receives their hard-to-guess URL. They may show the issuing business, client or invoice information, amount, memo, network, token, and public receiving address. Recipients can forward a link. Users should avoid placing unnecessary confidential or sensitive information on public pages.
Public blockchains are operated by independent networks, not DueTally. Wallet addresses, transaction hashes, amounts, and other on-chain information may be permanently public and replicated worldwide. We cannot alter, erase, or control data recorded on a blockchain. Deleting it from DueTally does not remove it from the chain, node providers, explorers, wallets, or other third parties.
6. Who receives data
We disclose data only as needed for the purposes above:
- Google Firebase: Google sign-in and identity-token verification.
- Stripe: checkout, subscription billing, customer portal, and billing webhooks.
- Cloudflare: transactional email delivery and related internet/security services.
- PostHog: narrow server-side operational events and, with consent, browser product analytics. Browser session recording and automatic element capture are disabled.
- Sentry: error and performance diagnostics when configured.
- Hosting, database, backup, and infrastructure providers: storage and operation of the web app, worker, database, logs, and backups.
- Blockchain infrastructure providers, including Alchemy where configured: public transaction, log, receipt, and confirmation queries.
- The account user and payment-page recipients: content the user chooses to publish, email, export, or share.
- Professional advisers, authorities, or transaction counterparties: where reasonably necessary for legal compliance, claims, safety, or a genuine financing, reorganisation, or transfer of DueTally, subject to appropriate confidentiality and legal safeguards.
Providers may process limited metadata of their own under their privacy notices when you interact directly with them. We do not give providers permission to use Customer Data for their own advertising.
7. International transfers
DueTally is operated from the EEA and is available worldwide. Some providers or their support teams may process data outside the EEA, including in the United States. Where required, we rely on an adequacy decision, the EU–US Data Privacy Framework for a participating recipient, European Commission Standard Contractual Clauses, supplementary safeguards, or another lawful transfer mechanism. You may ask us for information about the safeguard applicable to a transfer.
8. Retention
We retain data only as long as needed for the stated purpose, using these criteria:
- Account and Customer Data: while the account is open and afterwards only as reasonably needed to complete deletion, resolve disputes, enforce agreements, or meet law. A paid-plan cancellation does not delete account history.
- Sessions: expire after 30 days. Email sign-in links expire after 15 minutes, although limited token records may remain until routine cleanup or account deletion for integrity and abuse investigation.
- Rate-limit records: keyed identifier hashes are deleted as their short rate-limit windows roll forward; configured windows range from minutes to one hour.
- Billing, tax, and accounting records: normally 10 years where Portuguese fiscal law requires that period.
- Support, security, and diagnostic data: for the period reasonably needed to answer the request, investigate an incident, maintain security, or establish and defend claims.
- Analytics: according to the configured PostHog retention and only while needed for product measurement. Browser collection stops when you withdraw consent.
- Backups: protected from ordinary use and deleted or overwritten through the regular backup lifecycle. If restoration is required, deletion instructions are re-applied where appropriate.
We may retain a minimal record longer when required by law, necessary for legal claims, or needed to document a privacy request. Public blockchain data remains subject to the limits described above.
9. Cookies and browser storage
DueTally uses an HTTP-only duetally_session cookie to keep signed-in users authenticated for up to 30 days. Security and authentication providers may also use storage strictly needed to complete sign-in. These are necessary to provide the service and do not require analytics consent.
We store your analytics choice in local storage for 180 days so we can honour it. If you allow browser analytics, PostHog may store identifiers in cookies or local storage and receive the current route, product events, device/browser metadata, and network information. Public payment tokens are removed from analytics URLs. We disable PostHog automatic element capture and session recording. Refusing analytics does not reduce service functionality.
You can also clear site data in your browser. Clearing the preference will cause DueTally to ask again. Browser controls may block storage, but blocking the necessary session cookie will prevent sign-in.
10. Your rights
Depending on applicable law and our role, you may have rights to access, correct, erase, restrict, or object to processing; receive portable data; withdraw consent; and complain to a supervisory authority. Withdrawing consent does not affect processing already performed lawfully. Where we rely on legitimate interests, you may object based on your particular situation.
Email pedro@duetally.com to exercise a right or close your account. We may verify your identity and ask for information needed to locate the data. We normally respond within one month under the GDPR, subject to lawful extensions. We do not charge unless a request is manifestly unfounded or excessive and the law allows a fee.
If data was supplied and controlled by a DueTally user—for example, a business that invoiced you—contact that business first. We will assist the business with a valid request. You may also contact us and we will route or address the request as appropriate without disclosing another user’s confidential information.
In Portugal, you can complain to the Comissão Nacional de Proteção de Dados (CNPD). You may instead contact the data-protection authority where you live or work or where an alleged infringement occurred.
11. Security
We use technical and organisational measures designed for the risk, including transport encryption, HTTP-only session cookies, restricted access, secret management, rate limiting, data minimisation for analytics and diagnostics, logging, dependency maintenance, and backup/recovery procedures. No internet service is completely secure. Please report suspected compromise to pedro@duetally.com and never send us private keys or seed phrases.
12. Children
DueTally is for people who have reached the age of legal majority and can enter a contract. It is not directed to children, and we do not knowingly create accounts for them. Contact us if you believe a child has provided account data without proper authority.
13. Changes
We may update this Policy as DueTally, our providers, or legal requirements change. We will post the new version and update its date. We will provide reasonable advance notice by email or in the service when a change materially affects how we use personal data or your choices.
14. Legal information and contact
DueTally is operated by Pedro Silva, trading as Plainworks.
Avenida Infante Santo 58
1350 Lisbon, Portugal
pedro@duetally.com