Privacy
Website privacy notice
This notice explains the limited information Billit processes when someone visits billit.online. It applies to website analytics, not business records stored inside the Billit product.
Effective: 24 July 2026
Information collected
For basic security and website analytics, Billit may record a randomly generated visit ID, visit time, page or route, referrer, user-agent, device category, browser, operating system and approximate browser language.
The server receives an IP address as part of the web request. The analytics database stores only a keyed, one-way HMAC pseudonym of that address—not the raw IP address. The pseudonym helps rate-limit abuse and estimate unique visits without exposing the original address in the website or public JavaScript.
Optional GPS location
On a mobile device, Billit may show an optional location prompt. The browser Geolocation API is called only after the visitor selects Allow Location. The browser then shows its own permission control. If granted, a single latitude, longitude and accuracy reading is recorded for that visit.
Location is not collected in the background, movement is not tracked, and the website continues to work if the visitor selects Not Now, denies browser permission or if location is unavailable. Billit does not use precise website location for advertising or share it with third parties.
Why the information is used
The information is used to operate and protect the website, prevent automated abuse, understand which pages and device types are useful, and—only where optional permission is granted—understand broad regional interest and improve local services.
Retention
Precise GPS coordinates and accuracy are removed after 30 days. The remaining website visit record is deleted after 90 days. Short-lived rate-limit counters are removed after two days. Scheduled cleanup runs daily, and these periods can be shortened by the site operator.
Access and protection
Visitor records are not public. Access is limited to authorised Billit personnel who need the information for website operations, security or aggregate analytics. Database credentials and pseudonymisation keys are held in server environment variables, and no public endpoint is provided for reading visitor records.
Your choices and contact
Location sharing is optional. You can decline the Billit prompt or use your browser settings to deny or revoke location permission. Clearing the current browser session may reset the local prompt state, but location is never requested without another visible choice.
For access, deletion or other privacy questions, use the Support option inside Billit and include “Privacy request” in the message. You may also reach Billit through the official founder profile.