Legal
Privacy Policy
Effective September 2, 2026
SaaSync, LLC, doing business as BillCadence (“SaaSync,” “BillCadence,” “we,” “us,” or “our”), has prepared this Privacy Policy to explain how we collect, use, disclose, and otherwise process personal information through the public BillCadence website at www.billcadence.com and other websites that link to this Privacy Policy (collectively, the “Website”), the BillCadence application, and related services (collectively, the “Services”).
This Privacy Policy applies when BillCadence determines the purposes and means of processing, such as for Website visitors, leads, Account and Authorized User administration, billing, security, analytics, and marketing. When we process personal information in Customer Data on behalf of a business Customer, the Customer generally determines why and how that information is processed. In that context, BillCadence generally acts as a processor or service provider and our Data Processing Addendumapplies. If your information was provided to BillCadence by one of our Customers, direct your request to that Customer where appropriate.
Capitalized terms not defined here have the meanings in the BillCadence Service Agreement.
1. Information we collect
1.1 Contact and professional information
We may collect your name, work email address, telephone number, job title, employer, company domain, company size, business address, and professional interests. This includes information submitted through a beta application, demo request, event registration, survey, referral, or other Website form.
1.2 Account and authentication information
We may collect usernames, authentication identifiers, hashed passwords where BillCadence manages credentials, single-sign-on information, multifactor-authentication status, Account roles, permissions, and administrative settings.
1.3 Company, subscription, and transaction information
We may collect the Customer's legal or business name, company profile, billing contacts, subscription plan, purchases, invoices from BillCadence, payment status, usage tier, renewal and cancellation information, and related transaction records. Payment-card details used to pay BillCadence are provided directly to our payment processor and are not intended to be transmitted through or stored by BillCadence.
1.4 Customer Data and Connected-Service information
To provide the Services, we may process information selected or supplied by a Customer or retrieved from a Connected Service such as QuickBooks Online, Xero, ChartMogul, or another accounting, billing, payment, commerce, customer-relationship, subscription-analytics, revenue- reporting, or communications system. Depending on the Customer's configuration, this may include customer and contact records, subscription terms, products, prices, quantities, discounts, service periods, invoices, invoice lines, credits, payments, billing schedules, transaction identifiers, status information, custom fields, and data needed to create, update, post, or initiate delivery of an invoice.
Customer Data may concern a Customer's personnel, clients, purchasers, subscribers, or other individuals. BillCadence processes that information on the Customer's behalf and under its instructions except where we are required to process it for security, legal compliance, or another purpose permitted by the applicable agreement and law.
BillCadence may use internal software, infrastructure, APIs, and data- processing functionality also used to provide SaaSync's core integration platform. For an enabled ChartMogul integration, these internal components may retrieve, transform, map, classify, and synchronize applicable Customer Data with the Customer's ChartMogul account and combine it with BillCadence configuration and metadata solely to improve the integration's accuracy and operation. SaaSync, LLC operates both BillCadence and those internal components; this internal use does not make SaaSync a third party to itself.
1.5 Communications and support information
We collect messages, feedback, support requests, call or meeting details, and attachments you provide. Support content may include information about an Account, Connected Service, invoice, or billing workflow.
1.6 Device, Website, and usage information
We and our providers may collect IP address, approximate location derived from IP address, browser and device type, operating system, language, referring page, pages viewed, links selected, timestamps, session and advertising identifiers, cookie identifiers, and interactions with the Website, Services, messages, and advertisements. Within the application, we may collect feature use, configuration, performance, error, security, and audit information.
1.7 Advertising and audience information
We may collect or derive advertising preferences, campaign source, advertisement interactions, conversion events, audience membership, company domain, and identifiers used for audience matching. We may normalize and hash contact information such as a work email address before providing it to an advertising partner. Hashed identifiers remain personal information when they can be used to recognize or target a person.
1.8 Consent, choice, and request records
We may record a consent or preference identifier, date and time, policy or consent version, country or region used for consent-policy selection, category-level choices, Global Privacy Control signals, unsubscribe status, privacy requests, and steps taken in response.
We use c15t and its Inth-hosted service, operated by Consent Management Inc., to select the applicable consent experience, present privacy controls, and maintain consent records. Inth may process the consent and preference information described above together with browser or device information, such as IP address and user-agent information, needed to select a regional policy, secure the service, and document the choice.
1.9 AI inputs and outputs
When an AI-assisted feature is used, we may process the information submitted to that feature, relevant Customer Data selected for the task, instructions and prompts, model responses, classifications, evaluations, and related technical metadata.
1.10 Deidentified and aggregated information
We may create aggregated or deidentified information that does not reasonably identify a Customer, Authorized User, Data Subject, or other person. We maintain safeguards designed to prevent reidentification and do not attempt to reidentify information treated as deidentified.
2. Sources of information
We may obtain personal information from:
- you when you visit the Website, communicate with us, or use the Services;
- the Customer organization and its Account administrators or Authorized Users;
- Connected Services selected or authorized by the Customer;
- cookies, pixels, tags, SDKs, logs, and similar technologies;
- analytics, advertising, attribution, consent-management, and marketing providers;
- referral partners, integration partners, events, and business partners;
- professional networks, company websites, public sources, and business-data providers; and
- affiliates, service providers, and parties involved in a corporate transaction.
We may combine information from these sources where permitted by law, but we do not combine Customer Data obtained from connected accounting or billing systems with advertising data for audience matching or targeted advertising.
3. How we use information
We may use personal information to:
- provide, configure, operate, maintain, secure, and support the Services;
- create and administer Accounts, permissions, subscriptions, billing, and payments;
- connect to Customer-selected systems and carry out configured instructions;
- organize subscription terms and changes and generate billing schedules, invoice information, alerts, reports, and other BillCadence Output;
- create draft or final invoices, update records, and initiate a Connected Service's invoice-delivery workflow;
- authenticate users, prevent fraud and abuse, enforce terms, and protect the Services and Customers;
- provide support and respond to messages, requests, and feedback;
- monitor performance, troubleshoot errors, maintain audit records, and improve functionality;
- understand Website and Service use and conduct research, analytics, testing, and product development;
- communicate service, security, legal, billing, and administrative information;
- send marketing communications and manage communication preferences;
- advertise, personalize marketing, create audiences, identify similar prospective customers, enrich business profiles, attribute conversions, and measure campaigns as described below;
- establish, exercise, and defend legal rights; comply with law; and respond to lawful requests; and
- evaluate or complete a financing, merger, acquisition, reorganization, sale, or other corporate transaction.
4. Advertising and audience matching
4.1 Advertising technologies and partners
BillCadence uses or may use Google properties, Meta properties, and similar analytics, advertising, attribution, and enrichment services. These services may use cookies, pixels, tags, APIs, server-side events, and similar technologies to collect or receive Website activity and advertising information from BillCadence and elsewhere online.
4.2 Matched and similar audiences
Where permitted, we may provide first-party lead, Account, and Authorized User information—such as a normalized and hashed email address, company domain, country, or similar business contact information—to Google, Meta, or another approved advertising partner. The partner may compare the identifier with information associated with its users to create a matched audience, deliver or suppress BillCadence advertising, create similar or lookalike audiences, personalize campaigns, measure performance, and attribute conversions. Advertising partners process information under their own terms and privacy policies and may act as processors, service providers, contractors, or independent businesses depending on the activity and law.
4.3 Advertising-data boundary
BillCadence may use information about its own leads, Website visitors, Customers, Account contacts, and Authorized Users for the advertising purposes described in this Policy. BillCadence does not use any information about our Customers' customers—including their identities, contact details, subscription information, invoices, payments, or other connected billing data—for advertising, audience matching, enrichment, lookalike modeling, or campaign attribution. We do not provide that information to Google or Meta for those purposes.
4.4 Sale, sharing, and targeted advertising
We do not sell personal information in exchange for money. Some privacy laws define disclosures to advertising partners for cross-context behavioral advertising as a “sale,” “sharing,” or targeted advertising even when no money is exchanged. Where applicable, you may opt out as described in Sections 8 and 9.
5. Artificial intelligence
5.1 AI service providers
BillCadence may use OpenAI and other disclosed AI service providers to deliver AI-assisted features. Relevant information may be transmitted to and processed by those providers as subprocessors. We configure our OpenAI business or API use so Customer content is not used to train or improve OpenAI's generalized models. Provider retention may nevertheless apply for abuse monitoring, security, or application functionality as described in our Data Processing Addendum and Subprocessor List.
5.2 Customer-specific AI
We may use models to process Customer Data to provide the Services and may maintain a customer-isolated model, embedding, configuration, or similar learned artifact. We treat a Customer-Specific AI Artifact as Customer Data, do not use it to benefit another customer except in aggregated or deidentified form, and apply the applicable retention and deletion terms.
5.3 Generalized BillCadence models
We do not use identifiable Customer Data to train or improve a generalized, shared, or cross-customer BillCadence model unless the Customer separately and affirmatively authorizes that processing in an Order or other written agreement identifying the data, purpose, and additional terms. Merely updating this Privacy Policy does not authorize training on previously collected Customer Data. We may use appropriately aggregated or deidentified information for product and model improvement subject to safeguards and a prohibition on reidentification.
6. How we disclose information
We may disclose personal information to:
- Customer and Account users. Account owners and administrators may access and manage Account and Authorized User information, permissions, Customer Data, and activity.
- Connected Services. We exchange Customer Data with systems the Customer selects and authorizes, including when creating or updating records or initiating invoice delivery.
- Service providers and subprocessors. Providers may support hosting, databases, authentication, security, monitoring, communications, support, payment processing, consent management, analytics, AI, and other business functions.
- Analytics and advertising partners. Google, Meta, and similar partners may receive Website activity, advertising information, and approved first-party identifiers for the purposes described in Section 4.
- Professional advisers. Lawyers, auditors, accountants, insurers, financial advisers, and other professional advisers may receive information where reasonably necessary.
- Authorities and legal recipients. We may disclose information when we believe disclosure is required or permitted by law, necessary to protect rights, safety, and security, or appropriate to investigate fraud, abuse, or violations.
- Corporate-transaction parties. We may disclose or transfer information in connection with diligence, financing, reorganization, merger, acquisition, sale, insolvency, or another corporate transaction.
- Affiliates and successors. We may disclose information to entities controlling, controlled by, or under common control with SaaSync and to successors, subject to applicable law.
- Other recipients at your direction or with consent. We disclose information when you or the Customer instructs us or when we obtain applicable consent.
7. Retention and deletion
7.1 Active Accounts
We generally retain Customer Data while the relevant Account or Service remains active and as needed to provide, secure, maintain, and support the Services. Specific operational records may have shorter periods described in the Data Processing Addendum or Security page.
7.2 Inactive Accounts
If an Account becomes inactive without an express deletion request, we may retain active operational Customer Data for up to 45 days to permit reactivation, export, and Account recovery. We then schedule the associated accounting and billing information for production deletion.
7.3 Express deletion
If an authorized Customer administrator expressly deletes the Account, we promptly queue associated operational Customer Data for deletion from production systems. Production deletion ordinarily completes within minutes. Residual copies may remain in encrypted backups for up to seven days and remain protected until deletion through the ordinary backup lifecycle.
7.4 Limited retained records
After operational deletion, we may retain limited Account, company, transaction, consent, suppression, security, and communication records for as long as reasonably necessary to satisfy tax, accounting, legal, fraud-prevention, security, dispute, compliance, and recordkeeping purposes. Access and use are limited to those purposes.
7.5 Suppression records
To prevent a deleted or reacquired identifier from being added back to marketing or an advertising audience, we may retain a minimal suppression record. It may contain a keyed hash of a normalized identifier, the type and date of the choice, applicable channels, and implementation status. We use suppression records only to honor choices and demonstrate compliance, not for advertising, enrichment, attribution, or analytics.
8. Your choices
8.1 Account information
You may update certain Account information through the Services or by contacting the Customer's Account administrator or BillCadence support.
8.2 Marketing communications
You may unsubscribe from marketing email using the link in the message or by contacting us. We may continue to send transactional, security, support, and other nonmarketing communications. An email unsubscribe does not necessarily opt you out of targeted advertising, which has separate controls.
8.3 Cookies and advertising choices
Before we activate advertising technologies, the Website will provide a cookie or privacy-preference control where required. For visitors in the EEA, United Kingdom, Switzerland, and Québec, we will not activate nonessential analytics or advertising technologies or use identifiers for matched-audience advertising unless the visitor makes a choice permitting that processing. Visitors may later change or withdraw their choices through the Website preference control.
When applicable advertising technologies are active and an opt-out model is permitted, you may use the Website's “Your Privacy Choices” or “Do Not Sell or Share My Personal Information” control to opt out of applicable sale, sharing, and targeted advertising on that browser or device. Clearing cookies, changing browsers, or changing devices may require you to renew a browser-level choice. You may also use controls offered directly by Google, Meta, and other advertising providers.
8.4 Global Privacy Control
Before we activate applicable advertising technologies, we will configure the Website to treat a recognized Global Privacy Control signal, where required by law, as a request to opt out of sale, sharing, and targeted or cross-context behavioral advertising for the browser or device sending the signal. We do not respond to generic “Do Not Track” signals, which do not provide a uniform legal or technical standard.
9. Privacy rights
Depending on your location and the circumstances, you may have rights to request access, confirmation, correction, deletion, portability, or restriction of personal information; object to processing; withdraw consent; opt out of sale, sharing, targeted advertising, or certain profiling; appeal a decision; or complain to a regulator.
Submit a request to
. We may need to verify your identity and authority. Applicable rights are subject to legal limitations and exceptions. We will not unlawfully discriminate against you for exercising an applicable right.
If the request concerns Customer Data that we process for a Customer, we may direct you to that Customer or notify it of the request. The Customer is generally responsible for responding, and we will provide assistance as required by our agreement and applicable law.
10. International processing
SaaSync is established in the United States. We and our service providers may process information in the United States and other countries whose laws may differ from those where you live. Where applicable law requires a transfer safeguard, we use an appropriate mechanism, which may include an adequacy decision, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another legally recognized safeguard. Customer Data transfer terms are addressed in theBillCadence Data Processing Addendum.
11. Regional disclosures
11.1 EEA, United Kingdom, and Switzerland
When European data-protection law applies to processing for which BillCadence is controller, we rely on one or more of the following legal bases: performance of or steps toward a contract; compliance with legal obligations; our legitimate interests or those of another party where not overridden by your rights; and consent. We generally rely on consent for nonessential cookies, matched-audience advertising, and personalized advertising where required. You may withdraw consent at any time without affecting earlier lawful processing.
Our legitimate interests may include securing and improving the Services, understanding business use, communicating with business contacts, preventing fraud, enforcing agreements, and marketing in contexts where consent is not required. You may object to direct marketing at any time. You may complain to the data-protection authority where you live or work or where you believe a violation occurred.
11.2 United States
Certain US state privacy laws require disclosure of categories collected, purposes, recipient categories, and retention criteria. The categories in Section 1 may include identifiers; professional and employment-related information; commercial information; Internet and electronic-network activity; approximate geolocation; account credentials; inferences; and other information that identifies, relates to, or can reasonably be linked with a person or household. We collect and disclose these categories for the business and commercial purposes in Sections 3 through 6 and retain them under Section 7.
We do not knowingly sell or share the personal information of people under 16. We do not sell personal information for money. Advertising disclosures described in Section 4 may constitute sale, sharing, or targeted advertising under some state laws. Applicable residents may exercise the rights described in Sections 8 and 9, including an appeal where provided by law.
11.3 California direct-marketing disclosure
California Civil Code sections 1798.83–1798.84 may permit California residents with an established business relationship to request information about certain disclosures to third parties for their own direct-marketing purposes. Submit a request using the contact information below.
11.4 Canada and Québec
Canadian residents may request access or correction and may withdraw consent subject to legal and contractual restrictions. For Québec visitors, we require a choice permitting nonessential analytics and advertising technologies before activating them. Withdrawal does not affect processing that occurred before withdrawal.
11.5 Australia
Australian residents may contact us to request access or correction or to raise a privacy complaint. We will respond under applicable law. You may also contact the Office of the Australian Information Commissioner.
12. Security
We maintain administrative, technical, and organizational safeguards designed to protect personal information based on its nature and the risks presented. No transmission or storage method is completely secure, and we cannot guarantee absolute security. Additional information is provided in the BillCadence Security page and Data Processing Addendum.
13. Children
The Website and Services are intended for business users and are not directed to children under 16. We do not knowingly collect personal information from children under 16 or knowingly sell or share their personal information for advertising. Contact us if you believe a child provided personal information to BillCadence.
14. Changes to this Privacy Policy
We may make non-material changes to this Privacy Policy by posting the revised version and updating the “last updated” date. Those changes take effect when posted unless we state otherwise. For material changes, we will provide at least 30 days' advance notice by email, an in-application notice, or another reasonable method where practicable and legally permitted. A shorter period may apply when a change is required to address an urgent legal, regulatory, security, safety, or abuse concern.
Advance notice alone does not authorize a new use when applicable law requires consent, a new notice at collection, or another action. In those circumstances, we will provide the required notice or obtain the required authorization before beginning the new Processing. A policy update will not retroactively authorize a materially different use of previously collected personal information where another legal basis is required.
15. Contact us
For privacy questions, requests, or complaints, email
. Legal notices concerning the Service Agreement should be sent to
. Support requests may be sent to support@billcadence.com.