Legal

Privacy Policy

How BillFi collects, uses, stores and protects personal data belonging to our customers (ISPs) and their subscribers.

Effective January 1, 2026

This page is maintained by BillFi to answer common questions about how BillFi operates. It is app-owner editable content, not an independent certification or legal advice. Where you need something formal, contact privacy@billfi.net.

1. Who we are

BillFi provides billing, RADIUS, captive-portal and network automation software to internet service providers ("Customers"). In this policy, "we", "us" and "our" refer to BillFi. "You" refers to a Customer, a Customer's employee, or a subscriber of a Customer whose data flows through BillFi.

Where a Customer processes their subscribers' data through BillFi, the Customer is the data controller and BillFi acts as a data processor under a separate Data Processing Addendum (DPA).

2. What we collect

The categories of personal data we may process include:

  • Customer account data: name, email, phone, company name, billing address, role.
  • Subscriber data (on behalf of Customers): name, address, ID/KYC details where the Customer's jurisdiction requires it, contact number, plan, invoice history, payment status.
  • Network & session data: RADIUS authentication records, session start/stop, framed IP, NAS identifier, upload/download counters.
  • Payment metadata: transaction IDs, gateway references, amounts, currency, timestamps. We do not store card PANs — those live with our PCI-compliant gateway partners.
  • Usage & telemetry: pages viewed inside the admin app, feature usage, error logs, IP address of the admin session.

3. How we use it

  • Provide, secure and improve the BillFi service.
  • Authenticate subscribers and reconcile payments on our Customer's behalf.
  • Send transactional email/SMS (invoice reminders, receipts, system alerts).
  • Respond to support requests, incidents and abuse reports.
  • Meet legal, tax and regulator obligations.

We do not sell personal data. We do not use subscriber data to train third-party AI models.

5. Who we share data with

BillFi uses vetted sub-processors to operate the service — cloud hosting, email/SMS delivery, error tracking and payment gateways selected by the Customer. A current list is available on request and in the DPA.

We disclose data to law enforcement or regulators only when we have a valid legal basis, and where practical we notify the affected Customer first.

6. Retention

Customer account data is retained for the life of the subscription and up to 90 days after cancellation, unless a longer period is required by law. Subscriber data retention is controlled by the Customer — deletion requests from a Customer are honoured within 30 days.

Backup snapshots are kept encrypted and cycled on a 35-day rolling schedule.

7. Security

Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). We enforce role-based access, per-action audit logs and require 2FA for BillFi staff with production access. See our Security & DPA page for details on platform controls.

8. Your rights

Depending on your jurisdiction, you may have the right to access, correct, delete, restrict or port personal data we hold about you, and to object to certain processing. If you are a subscriber of one of our Customers, please contact your ISP first — they act as the controller of your data.

For requests we can act on directly, email privacy@billfi.net. We respond within 30 days.

9. International transfers

BillFi operates infrastructure in multiple regions. Where personal data is transferred out of the EEA/UK, we rely on Standard Contractual Clauses and supplementary safeguards appropriate to the destination.

10. Children

BillFi is a B2B service intended for internet service providers. We do not knowingly collect data from children under 16. If you believe we have, contact us and we will delete it.

11. Changes to this policy

We update this page when the service or our practices change. The "Effective" date at the top reflects the latest revision. Material changes are communicated to Customer admins by email.

12. Contact

Privacy questions: privacy@billfi.net. For a signed DPA or a sub-processor list, request it via the same address.