Document version
Privacy Statement
How TimeToBill processes personal data, for what purpose, on what legal basis and for how long.
This English version is a translation provided for your convenience. In case of any discrepancy between the Dutch and English text, the Dutch Privacyverklaring prevails.
This privacy statement describes how STB Services (operating under the name TimeToBill) processes personal data. TimeToBill is a business software product: the service is offered exclusively to entrepreneurs, sole traders and legal entities with a Chamber of Commerce (KvK) number. This statement is tailored accordingly.
1. Who is TimeToBill?
TimeToBill is a trade name of STB Services, a sole proprietorship of Sebastiaan ten Broek.
- Registered address: Parallelweg 30, 5223 AL 's-Hertogenbosch, the Netherlands
- Chamber of Commerce (KvK): 30226252
- VAT: NL001685860B73
- Email: hello@timetobill.nl
For all privacy questions, use one of the contact channels in section 12.
2. What does this statement cover?
This statement applies to:
- The marketing and checkout website
timetobill.nl. - The customer portal
manage.timetobill.nl. - The backend infrastructure that supports billing, licence validation and support.
- Transactional email sent from
hello@timetobill.nl.
The TimeToBill desktop application on your own computer is deliberately kept outside this statement for one specific point: the time-registration and invoice data you process through that app travels directly between your computer and the external services you choose (Clockify, Toggl, WeFact), using your own API keys. That data does not pass through our servers. Section 8 explains this.
3. Our role(s)
We are controller for all data we need in order to serve you as a TimeToBill customer: account, company, billing, invoice, licence, support and security data. The processing of that data is discussed in sections 4 through 6.
We are processor (article 28 GDPR) for two specific, narrowly delineated situations:
- What you submit to us yourself in a support or complaint request (for example screenshots or log files you attach).
- The in-transit relay of WeFact API traffic for customers who use the optional IP-relay proxy.
The Data Processing Agreement applies to that processor role.
4. Which personal data do we process, and why?
| Category | Data | Purpose | Legal basis |
|---|---|---|---|
| Account | Email address, one-time magic-link tokens (hashed), portal session tokens (hashed), session cookie | Access to the customer portal and authentication. We do not hold passwords; access runs via a magic link. | Performance of the contract (art. 6(1)(b) GDPR) |
| Company data | Company name, KvK number, VAT number, billing address, country | Billing, VAT treatment and B2B verification | Performance of the contract + legal obligation (fiscal retention, art. 6(1)(b) and (c) GDPR) |
| Payment pointers | Mollie customer ID, payment ID, subscription ID and status | Collection, linking order to payment, refund handling. IBAN details and SEPA mandates are held by Mollie, not by us. | Performance of the contract |
| Our invoices | Invoice number, lines, totals, VAT | Billing and bookkeeping | Legal obligation (art. 52 of the Dutch General State Taxes Act, *Algemene wet inzake rijksbelastingen*) |
| Licence | Licence key, linked machine fingerprints, activation timestamps | Licence validation and enforcement of the machine limit (2 active machines) and offline grace period (7 days) | Performance of the contract |
| Support and complaints | Emails to hello@timetobill.nl, submissions via the complaint and privacy-request forms | Providing support, handling complaints, fulfilling your GDPR rights | Performance of the contract + legal obligation (art. 12 GDPR) |
| Transactional email | Send metadata (event type, status, SMTP message ID, hashed recipient) and an encrypted rendering of the email content | Delivery proof, duplication protection, troubleshooting failed deliveries | Performance of the contract |
| Technical logs | IP address, User-Agent, URL path, timestamp, HTTP status | Security (rate limiting, abuse detection) and troubleshooting | Legitimate interest (art. 6(1)(f) GDPR): security of the service |
| Website analytics | Hostname and page path; referring hostname and path; event type; destination URL without query or fragment for an outbound link or file download; browser, operating system and device type derived from User-Agent; country-, region- and city-level location derived from IP address; daily-changing visitor ID | Aggregate measurement of pageviews, outbound links, file downloads and form submissions to improve the website and its information | Legitimate interest (art. 6(1)(f) GDPR): privacy-friendly improvement of the website |
| Functional and strictly necessary cookies | Language-preference, session and CSRF cookies | Language selection, authentication and security of the customer portal | Performance of the contract + statutory exemption from the consent requirement (art. 11.7a of the Dutch Telecommunications Act, *Telecommunicatiewet*) |
For website analytics we use Plausible Community Edition, self-hosted on VPS infrastructure operated by STB Services. Analytics is active only on the public timetobill.nl website, not on the customer portal or internal operations environment. Query strings and URL fragments are removed from page, referrer, outbound-link and download URLs before transmission. Form values, names, email addresses, order data and payment amounts are not sent to Plausible. We do not use revenue tracking. The IP address and full User-Agent are processed only briefly to determine location/device data and a daily-changing visitor ID; we do not store these raw values and the daily salt is replaced after 24 hours.
We do not process special categories of personal data (art. 9 GDPR) or criminal-law data (art. 10 GDPR). We do not carry out profiling or automated decision-making with legal effect (art. 22 GDPR). We use no analytics or tracking cookies and no advertising pixels.
5. How long do we keep this data?
| Category | Retention period |
|---|---|
| Account (email address) | For as long as your account is active + 12 months after cancellation, then deleted or anonymised. Magic-link and session tokens disappear immediately on use or TTL expiry. |
| Company data | 7 years after end of contract (fiscal retention, art. 52 *Algemene wet inzake rijksbelastingen*) |
| Payment pointers | 7 years (linked to invoice data). The actual mandate and payment data at Mollie falls under Mollie's own retention period. |
| Our invoices | 7 years (fiscal retention) |
| Licence | For as long as the licence is active + 12 months |
| Support and complaints | 24 months after resolution. Files with legal impact (for example a chargeback, a complaint at the Dutch Data Protection Authority, or a civil dispute) 5 years. |
| Transactional email | Metadata 24 months; encrypted rendering of the email content 90 days |
| Technical logs | 30 days, then automatically deleted |
| Website analytics | Aggregate event and visit statistics are retained while the TimeToBill property remains active so trends can be compared over time. Raw IP addresses and full User-Agents are not stored; the salt for the daily-changing visitor ID is replaced every 24 hours. If the property is deleted, live statistics are removed and backup copies then expire through the normal rotation. |
| Backups | Unchanged rotation: 14 daily and 12 monthly snapshots. Older snapshots are overwritten by the rotation policy. |
6. With whom do we share personal data?
We engage subprocessors to operate the service. The full, always-current list with country of establishment and purpose is at /legal/subprocessors. At present these are: Mollie (payment processing, NL), Hetzner (VPS hosting, DE), WeFact (invoicing, NL), mijn.host (transactional email and DNS, NL) and pCloud (off-site backups, CH).
Our own infrastructure for identity, licence validation, edge protection, logging and self-hosted website analytics runs on our own servers at Hetzner and is operated by STB Services itself. Plausible Community Edition runs there as our own component; we do not use the hosted Plausible Analytics SaaS service. Plausible is therefore not a separate external subprocessor. No other party is involved. For security reasons we do not publicly name the other specific components.
We never sell personal data. We otherwise share data only where a statutory obligation compels us to do so (for example a demand from the Tax Authority or the judicial authorities) or to defend our rights.
7. Where is your data processed?
All processing takes place within the European Economic Area, with one exception: off-site backups at pCloud AG in Switzerland. That transfer falls under the European Commission's adequacy decision for Switzerland (art. 45 GDPR), so no additional transfer safeguards are required.
If a subprocessor is ever established in a country without an adequacy decision, we fall back on the Standard Contractual Clauses (SCCs) and announce the change according to the procedure on the subprocessors page.
8. External integrations: what we do not see
TimeToBill runs as a desktop application on your computer. The app retrieves time registrations from Clockify or Toggl Track and creates invoices in WeFact, each time with your own API keys. That traffic runs directly between your computer and the service in question. We do not see that data and do not store it.
Your application settings too (for example which projects you bundle, which rates you apply) are kept in a local .ttb file that you store yourself — locally or in cloud storage of your choice. We have no access to that file.
The active .ttb file is a standard local SQLite database and is not encrypted by TimeToBill. Where needed, use FileVault (macOS), BitLocker (Windows), or trusted encrypted storage. TimeToBill does not synchronise .ttb files between devices; if you keep the file in Dropbox, iCloud Drive, OneDrive, Google Drive, kDrive, pCloud, or another cloud folder, you rely on that cloud provider for synchronisation.
If you enable Remote Tagging, the desktop app may write a tag back to Clockify or Toggl Track on your behalf to mark billed time entries at the source. This feature is opt-in, uses your own API key and sends only the configured tag name (default Billed by TimeToBill), not invoice content.
Consequence: for the data that passes through the desktop app to Clockify, Toggl and WeFact, you are the controller. The relevant agreements (privacy statement or data processing agreement) are concluded by you directly with those services.
Exception: IP-relay proxy. TimeToBill offers an optional feature that routes WeFact API traffic through our VPS, so that you need to allowlist only one IP address in WeFact. If you enable this feature, we decrypt the HTTPS request, forward it directly to WeFact and re-encrypt it. We do not store that data. Only technical metadata (licence key, request path, status code) falls under the "Technical logs" row in section 5. For this feature we act as processor on your behalf; see the Data Processing Agreement.
9. Security
At a high level, without disclosing operational detail:
- Encryption in transit (TLS 1.2+) on all public endpoints.
- Encryption at rest for off-site backups.
- Production access is limited to STB Services; multi-factor authentication on all administrative accounts.
- Edge protection (rate limiting and abuse detection) on all public endpoints.
- The recovery procedure is tested at least annually.
10. Cookies
We set functional and strictly necessary cookies only for language preference, authentication and CSRF protection. The self-hosted website analytics sets no cookies and uses no browser storage to track visitors. The existing operation without a cookie-consent banner therefore remains unchanged. See the Cookie Statement for the complete list and explanation.
11. Your rights
Under the GDPR you have the following rights:
- Right of access (art. 15 GDPR).
- Right to rectification (art. 16 GDPR).
- Right to erasure (art. 17 GDPR), within the limits of the fiscal retention obligation for invoice data.
- Right to restriction of processing (art. 18 GDPR).
- Right to data portability (art. 20 GDPR).
- Right to object to processing based on legitimate interest (art. 21 GDPR).
- Right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens): autoriteitpersoonsgegevens.nl/klacht.
We respond within 30 days of receipt of your request. Where a request is complex we may extend that term by up to 60 days (art. 12(3) GDPR); you will be informed of any extension within the first 30 days.
12. Contact and complaints
- Privacy question or request: use the form at /legal/privacy-request or email hello@timetobill.nl.
- Complaint: use the form at /legal/complaint.
- Complaint to the supervisory authority: you may lodge a complaint directly with the Dutch Data Protection Authority at any time via autoriteitpersoonsgegevens.nl/klacht.
13. Data breaches
In the event of a (suspected) personal-data breach we document the incident internally within 24 hours. Where the GDPR requires it, we report the breach within 72 hours to the Dutch Data Protection Authority (art. 33 GDPR) and, in the event of high risk, without undue delay to you as the data subject (art. 34 GDPR). Where we act as processor on your behalf (see section 3), we inform you within 24 hours of detection with all information you need to fulfil your own notification obligation.
14. Changes to this statement
This statement follows semantic versioning:
- PATCH for editorial changes (spelling, clarification without substantive change).
- MINOR for additions or changes to retention periods.
- MAJOR for scope changes (role, rights, categories or new purposes).
Material changes are announced at least 30 days in advance by email to active customers and by publication on this page. Older versions remain permanently retrievable at /legal/privacy/<version>.
Changelog
| Version | Effective from | Change |
|---|---|---|
| 2.0.0 | 2026-09-04 | Added self-hosted, cookieless Plausible website analytics and documented data minimisation, retention and legal basis. |
| 1.0.0 | 2026-04-28 | First published version. |
STB Services — Parallelweg 30, 5223 AL 's-Hertogenbosch, the Netherlands — Chamber of Commerce (KvK) 30226252 — VAT NL001685860B73 — hello@timetobill.nl