Skip to content
PayBlah — Get paid. Skip the blah.
How It Works Features Industries Integrations Pricing FAQ
Reminder Sequences Product Demo Message Templates For Accountants Customer Stories System Status
Sign in Start Your Free TrialFree trial
Sign in Start Your Free TrialFree trial

Legal

Privacy policy

How we handle data for visitors, accounts, and the people you invoice. Product-readiness draft.

Start free trial

On this page

Who we are Scope Roles (controller & processor) Data we collect Debtor & invoice data How we use data Lawful bases Sharing International transfers Retention Your rights Security Cookies Children Territory notes Changes Contact
Draft for product readiness — not legal advice. Have qualified counsel review this policy before public launch in each territory (United States, United Kingdom, Ireland, Australia, and any others you serve). Last updated: 26 July 2026 (draft). Open owner/counsel decisions are collected in section 18 — not as unfinished mid-sentence brackets for reviewers.

1. Who we are

PayBlah is accounts-receivable (AR) software that helps small and mid-size businesses send polite overdue-invoice reminders by email and SMS — in the customer’s own business name — and stop when a payment, reply, or dispute arrives. PayBlah is not a debt-collection agency. We do not buy debt, we do not contact people as a third-party collector, and the PayBlah customer remains the creditor at every step.

In this policy, “PayBlah,” “we,” “us,” and “our” mean the legal entity that operates the service (trading as PayBlah). PayBlah is operated by PayBlah. Primary contact: Richard Brennan (hello@payblah.com).

Contact for privacy matters is set out in section 17. Registered office details will be published in the footer when confirmed; until then use the email contacts below.

2. Scope

This privacy policy describes how personal data is handled when you:

  • Visit our marketing website (including forms, cookie banners, and related pages);
  • Create or use a PayBlah customer account (the SaaS application);
  • Are contacted through PayBlah on behalf of a PayBlah customer (for example, as the recipient of an invoice reminder or as a visitor to a debtor portal link); or
  • Otherwise interact with us by email at the addresses listed below.

This policy is designed to satisfy common transparency expectations under privacy and data-protection laws that may apply in the United States, the United Kingdom, Ireland, and Australia. It is not a claim of settled compliance in any jurisdiction. Local requirements differ; counsel should map this draft to each territory before go-live.

Related documents (also drafts until counsel-approved):

  • Terms of Service Refunds & Cancellation
  • Cookie Policy
  • GDPR & Data Protection
  • Data Processing Addendum
  • Sub-Processors
  • Acceptable Use
  • Security overview

3. Roles: controller and processor

Who is responsible for personal data depends on the context:

3.1 PayBlah as controller

We act as a controller (or equivalent) for:

  • Website visitor data (pages viewed, cookie consent choices, marketing form submissions);
  • Customer account and billing-related data needed to operate your subscription (account holder name, work email, organization name, plan, seats, authentication records, support tickets);
  • Our own business records (security logs, abuse reports, commercial correspondence with you).

3.2 PayBlah as processor

We act as a processor (or service provider / equivalent) for personal data that our customers upload or sync into PayBlah about the businesses and contacts they invoice — including invoice details, contact names, emails, phone numbers, reminder history, portal activity, and related notes. In that capacity:

  • The PayBlah customer remains the controller (creditor) of that data;
  • We process it only to provide the service, on documented instructions, and as described in our data processing addendum (when executed);
  • We do not market to those contacts, sell their data, or use it to build advertising profiles.

If you are a person who received a reminder or opened a portal link from a business that uses PayBlah, that business is primarily responsible for how your data was collected and why you were contacted. You may still contact us (see section 17); we will route requests appropriately and assist the customer as required by law and our DPA.

4. Data we collect

We collect only what is needed to run the website and the product. Categories below are illustrative of the product design; exact fields may evolve. We do not invent or require government ID numbers, biometric data, or similar special categories for standard use of PayBlah.

4.1 Website and marketing

  • Technical data: IP address, browser type, device type, approximate location derived from IP (if used by infrastructure or analytics), pages visited, referrer, and timestamps.
  • Cookie and similar technologies: essential cookies for site operation and consent storage; optional analytics cookies only if you accept them. See Cookie Policy.
  • Contact and form data: name, email, organization, message content, and any other fields you choose to submit (for example via About Us Vs Collection Agency Contact).
  • Consent records: cookie preference choices and related timestamps stored locally and/or server-side as needed to honor them.

4.2 Customer accounts (controller data)

  • Identity and account: name, work email, password (stored hashed — never in plain text), organization/business name, role (for example Admin or Standard), and optional two-factor authentication factors and recovery codes.
  • Subscription and commercial: plan selection, seat usage, invoice/payment status for your PayBlah subscription, and related billing metadata processed by our payment provider Stripe. Card details are handled by the payment provider; PayBlah is designed so we do not store full card numbers.
  • Configuration: reminder sequences, tone settings, quiet hours, sending domain/SMTP settings (where your plan includes them), approval preferences, and integration connection status.
  • Support and communications: tickets, emails you send us, and audit of platform support access when you request help.
  • Security and usage logs: sign-in events, API key use, rate-limit events, and product audit trails for actions taken in your account.

4.3 Customer content you connect or import

Depending on how you use PayBlah, we process data you provide through:

  • Accounting integrations (for example Xero, QuickBooks Online, Sage) — invoice and contact fields your system exposes under the connection you authorize;
  • Spreadsheet/CSV import;
  • Manual entry and in-app notes;
  • API and webhooks you configure.

That content may include business and contact personal data described in section 5. You are responsible for having a lawful basis and appropriate notices for importing and instructing reminders about those contacts.

4.4 Data we do not intentionally collect for product features

  • We do not offer AI-driven messaging features; reminder wording is template-based, not model-generated.
  • We do not hold customer funds; payment links (where available on your plan) go through an established payment provider to you. Card details are not meant to be seen by PayBlah or by you through PayBlah.
  • We do not require consumer credit files, public case records, or similar third-party enrichment products.

5. Debtor and invoice data (processor context)

When customers use PayBlah, the product processes data about the businesses and people they invoice. Product surfaces may use the label “debtor” (for example “debtor portal”); in ordinary copy we usually say “customer” for those contacts. Typical categories include:

  • Contact name, business name, email address, phone number (for SMS where enabled);
  • Invoice identifiers, amounts, currencies, due dates, aging status, and payment status as synced or imported;
  • Reminder history, channel used (email/SMS), delivery-related metadata, and template/tone chosen;
  • Portal access via high-entropy links, views of invoice details, promise-to-pay inputs (where plan includes them), and payment-link outcomes reported by the payment provider;
  • Opt-out and consent register entries (email unsubscribe, SMS STOP handling where texting is enabled);
  • Dispute, reply, and pause events that stop a chase for that invoice;
  • Append-only activity timeline entries associated with invoices and account actions.

Messages go out in the PayBlah customer’s name, not as PayBlah collecting in its own right. Safety features that protect recipients — including auto-pause on payment, reply, or dispute; Firm/Final approval settings; kill switch; opt-out handling; audit trail; and consent register — are available on every plan, including trials. They are not sold as paid upgrades.

PayBlah is designed for B2B invoices only, not consumer debt. Customers must not use the service to chase consumer debts or to harass anyone. See our Acceptable Use policy.

6. How we use personal data

6.1 As controller

  • Operate, secure, and improve the website and SaaS application;
  • Create and manage accounts, authentication, and seats;
  • Bill subscriptions and provide receipts/invoices for PayBlah fees;
  • Respond to support, security, and privacy requests;
  • Send service communications (for example security notices, material product or terms changes);
  • Send product updates or marketing where permitted and where you have not opted out optional product emails and marketing only with a lawful basis and unsubscribe where required (Open decision P-MKT for channel list by territory);
  • Detect, prevent, and investigate abuse, fraud, and security incidents;
  • Comply with law and defend legal claims where applicable.

6.2 As processor (on customer instructions)

  • Sync or import receivables data and keep it current according to product design;
  • Schedule and send invoice reminders by email and, on eligible plans, SMS;
  • Host debtor portal pages and related payment or promise flows;
  • Apply safety rails (pauses, approvals, opt-outs, audit);
  • Provide reports, exports, API/webhook delivery, and support that necessarily accesses tenant data under controls;
  • Delete or return data when the customer instructs or the subscription ends, subject to retention and legal holds.

We do not sell personal data. We do not use customer debtor data to advertise third-party products to those contacts.

7. Lawful bases (where GDPR/UK GDPR or similar applies)

Where the EU General Data Protection Regulation (GDPR), UK GDPR, or comparable frameworks apply, we rely on the following bases as appropriate. This section is designed to satisfy transparency expectations; it is not a determination that a particular basis always applies to every processing activity.

Context Examples Typical lawful basis
Account & service delivery Creating your account, providing the SaaS, billing your subscription Contract performance; legitimate interests in operating a secure B2B service
Website essential operation Security, load balancing, cookie consent storage Legitimate interests; legal obligation where applicable; consent for non-essential cookies
Optional analytics / marketing Optional analytics cookies; product news you request Consent where required; otherwise legitimate interests with opt-out where allowed
Security & abuse prevention Logs, rate limits, fraud/abuse investigation Legitimate interests; legal obligation where applicable
Customer content about invoice contacts Reminders, portal, consent register (processor role) Processing under customer instructions; customer is responsible for its own lawful basis (often legitimate interests or contract with its client, depending on facts)

For US state privacy laws (for example where a “sale” or “share” definition might apply), PayBlah is designed so that we do not sell personal information and do not share it for cross-context behavioral advertising. Any US state notice addendum or “Do Not Sell/Share” tooling is Open decision P-US if required for launch markets.

For Australia, we intend to handle personal information in a manner designed to satisfy the Australian Privacy Principles as they apply to our role. APP entity status and any APP-specific notices are Open decision P-AU.

8. Sharing

We share personal data only as needed to run the service:

  • Sub-processors / service providers who host infrastructure, send email or SMS, process payments for your PayBlah subscription or for payment links, provide error monitoring, or similar. Vendor names are not listed here until selected; we commit to publishing them on Sub-Processors with notice before launch.
  • Integration partners you connect (accounting platforms you authorize) — data flows under your connection and their terms.
  • Payment providers — Stripe for subscription billing and, where you enable payment links, for payor transactions to you. PayBlah does not hold those funds and does not store full card numbers.
  • Professional advisors (lawyers, accountants, insurers) under confidentiality where needed.
  • Authorities when required by law or to protect rights, safety, and security — without product messaging that pressures invoice recipients with consequence language.
  • Business transfers — if we explore a merger, acquisition, or asset sale, personal data may be transferred under appropriate safeguards, with notice to account holders where practicable and required.

Platform support access to tenant data is reason-gated, time-boxed, and audited, and is designed to fail closed until dual-control requirements are met — consistent with our Security overview. Support does not casually browse accounts.

9. International transfers

PayBlah is intended for customers and invoice contacts in territories including the United States, United Kingdom, Ireland, and Australia. Infrastructure and sub-processors may process data in countries other than where you or your contacts are located.

Primary hosting region(s) and any customer choice of region are Open decision P-REGION and will be published when infrastructure is finalized (see also Sub-processors).

Where personal data is transferred internationally and a transfer mechanism is required (for example under GDPR/UK GDPR), we will use an appropriate mechanism such as standard contractual clauses or another lawful transfer tool available at the time, together with supplementary measures where needed. Transfer language here is intentionally generic until hosting and sub-processor selections are final.

Customers remain responsible for assessing whether their use of PayBlah (including messaging contacts in other countries) is appropriate for their industry and local rules.

10. Retention

We keep personal data only as long as needed for the purposes above, including legal, accounting, and security requirements. We do not invent day-counts here. Retention periods below are categories; exact windows are Open decision P-RET for owner/counsel before launch:

  • Website logs and analytics — short operational windows; analytics only if consented.
  • Customer account data — while the account is active, then a wind-down period unless law requires longer.
  • Customer content / tenant data (processor) — for the life of instructions/subscription, then delete or return per the DPA; backups cycle out after a residual window.
  • Consent, opt-out, and audit records — long enough to honor suppressions and demonstrate compliance.
  • Security logs — security and incident investigation needs.
  • Billing records (including Stripe metadata) — tax and accounting retention by territory.

Deletion requests from account holders are honored according to law and technical constraints (for example, immutable audit segments may be retained in minimized form where necessary). Owner accounts are designed so users are archived rather than silently erased in ways that break audit integrity — details appear in product documentation and the DPA.

11. Your rights

Depending on where you live and your relationship to PayBlah, you may have rights to:

  • Access personal data we hold about you;
  • Correct inaccurate data;
  • Delete data (subject to legal exceptions);
  • Restrict or object to certain processing;
  • Data portability (where applicable);
  • Withdraw consent where processing is consent-based (for example optional cookies);
  • Lodge a complaint with a supervisory authority (for example in the UK, Ireland/EEA, or other competent body), or contact a relevant US state privacy regulator where applicable.

11.1 If you are a PayBlah customer (account holder)

Email hello@payblah.com from your account email, or use Contact (topic: Privacy & data). We may need to verify your identity before acting.

11.2 If you received a reminder or used a portal link

Start with the business that contacted you — they are the controller of that relationship. You can also email us; we will help route the request and pause processing where appropriate while the customer instructs us. Opt-out mechanisms in messages (email unsubscribe; SMS STOP where SMS is used) are honored in product design on every plan.

11.3 Response timing

We aim to respond within the timeframes required by applicable law. A stricter public internal SLA (if any) is Open decision P-SLA — we do not invent fixed marketing SLAs beyond legal requirements.

12. Security

Security measures are described in plain language on our Security page. Summarized — and limited to claims made there — PayBlah is designed with:

  • Database-per-tenant isolation: operational data for a customer lives in its own database with its own database user, so isolation is structural rather than only a shared-table filter.
  • Sealed secrets: API keys are stored hashed; tenant database passwords, OAuth tokens, and webhook secrets are sealed at rest — readable by the system, not by people casually.
  • Hardened sign-in: password hashing, CSRF protection on browser forms, and optional TOTP two-factor authentication (2FA) with recovery codes for customer accounts and platform admins.
  • Portal link design: high-entropy bearer tokens with rate limiting; failure responses designed so tokens cannot be enumerated by probing.
  • API and webhooks: bearer-key API (no session-cookie auth for API), scoped keys, rate limits; outbound webhooks signed with timestamp windows.
  • Support access: reason-gated, time-boxed, audited sessions that fail closed until dual-control requirements are met.
  • Roles and audit: Admin vs Standard roles; append-only timeline per invoice; owner accounts protected from casual deletion/demotion; users archived rather than erased in ways that destroy accountability.

We do not list third-party audit certifications on this site. No security practice is perfect; please report suspected vulnerabilities to security@payblah.com as described on the Security page.

13. Cookies

We use essential cookies to run this site and remember cookie preferences. Optional analytics cookies run only if you accept them. Details, category descriptions, and preference controls are in our Cookie Policy, including cookie preferences.

14. Children

PayBlah is a B2B service. It is not directed at children, and we do not knowingly collect personal data from children. If you believe we have received such data, contact hello@payblah.com and we will take appropriate steps.

15. Territory notes (US, UK, Ireland, Australia)

PayBlah is built for multi-territory B2B use. Honest notes:

  • United States: Federal and state privacy rules may apply depending on your size, data types, and states of residence of individuals. SMS programs may require US 10DLC registration for application-to-person messaging — product and carrier rules apply separately from this policy.
  • United Kingdom: UK GDPR and the Data Protection Act 2018 may apply. UK SMS sender registration requirements differ from the US; follow product guidance for sending.
  • Ireland / EEA: GDPR and ePrivacy rules may apply to website cookies and electronic communications. Ireland may also involve ComReg-related considerations for certain SMS use.
  • Australia: The Privacy Act 1988 (Cth) and Australian Privacy Principles may apply. SMS may involve ACMA-related rules for commercial messaging.

This policy is designed to satisfy cross-cutting transparency themes; it does not assert that PayBlah is “compliant with” every local statute out of the box. Customers are responsible for their own collection notices, messaging consent, and industry rules when instructing reminders.

16. Changes

We may update this policy as the product, vendors, or laws change. Material changes will be signaled by updating the “Last updated” date and, where appropriate, by notice in-app or by email to account holders. Draft target for material changes: at least 14 days’ notice to paid account holders where practicable (aligned with Terms Open decision L-NOTICE).

17. Contact

For privacy questions, requests, or complaints:

  • Privacy & general: hello@payblah.com
  • Support: support@payblah.com
  • Security reports: security@payblah.com
  • Web form: Contact (topic: Privacy & data)

Formal legal notices: email hello@payblah.com with subject “Legal notice” addressed to Richard Brennan, PayBlah (hello@payblah.com).

Privacy contact: Richard Brennan — hello@payblah.com or use the GDPR Data Request form. A formal DPO / EU representative is not separately appointed as of this draft (Open decision P-DPO if counsel requires one).

18. Open decisions (owner / counsel)

IDDecisionWho
L-ENTITYPayBlah · primary contact Richard Brennan · hello@payblah.comSet
P-REGIONPrimary data residency region(s); customer region choice if anyOwner
P-RETExact retention windows (logs, post-cancel account, delete/return, backups, consent, security, billing)Owner + counsel
P-MKTMarketing channels and opt-in model by territoryOwner + counsel
P-USUS state privacy addendum / DNS tooling if neededCounsel
P-AUAPP entity status and AU-specific noticesCounsel
P-DPOAppoint DPO / EU or UK representative, or confirm not requiredCounsel
P-SLAWhether to publish a privacy-request response SLAOwner

Draft website policies for product readiness — have qualified counsel review before public launch in each territory. Not legal advice.

PayBlah

Get paid. Skip the blah. Automated overdue-invoice chasing for small and mid-size B2B businesses.

Not a debt-collection agency. You remain the creditor.

Company identity

Trading as PayBlah

Legal name: PayBlah

Contact: Richard Brennan

hello@payblah.com

B2B invoice-reminder software. Not a debt-collection agency. You remain the creditor.

Product

How It Works Industries Features Pricing Security Start Your Free Trial

Resources

FAQ News & Updates Guides & Resources Knowledge Base Help & Support Sub-Processors Customer Sign In

Legal

Privacy Policy Terms of Service Cookie Policy GDPR & Data Protection Data Processing Addendum Acceptable Use

Company

Contact Affiliate Program hello@payblah.com security@payblah.com Cookie Preferences
© 2026 PayBlah. All rights reserved. Privacy Data Request Terms Refunds Cookies GDPR DPA

Draft website policies for product readiness — have qualified counsel review before public launch in each territory. Security summary describes the product’s design; confirm territory-specific compliance with counsel.

We use cookies

Essential cookies run this site; optional analytics cookies help us understand usage. See our Cookie Policy and Privacy Policy.