TTimastra CollectOpen workspace →
PRIVACY POLICY

Your receivables data stays accountable

This policy explains what Timastra Collect processes, why it is needed, how long it is retained, and how people can exercise their privacy rights.

Effective September 2, 2026 · Version 2026-09-02 · Pilot service

Version and acknowledgement

Version 2026-09-02, effective September 2, 2026. Timastra Collect records the organization owner's acknowledgement version, account identity, email, and timestamp. A billing contact name and email are used to administer subscriptions and provider-hosted billing.

Roles and scope

Your organization controls the customer, invoice, obligation, payment, communication, and team data it enters or connects. Timastra Collect processes that data to provide the service. Timastra Collect separately controls account, subscription, support, security, and product-usage information needed to operate and improve the service.

Data we process

We process authenticated user identifiers, names and email addresses; organization settings and membership; customer contact details; receivable and cash-planning records; collection notes and communications; support requests; audit and security events; and optional accounting-connection identifiers and encrypted credentials when an integration is enabled.

When a visitor intentionally starts a trial, Timastra Collect uses a 90-day first-party cookie and retains only a one-way hash of its random value, an allowlisted acquisition source, and qualification and conversion times. This measures aggregate visitor-to-trial conversion without storing an IP address, browser description, advertising identifier, email, organization ID, or financial value in the acquisition record. Ordinary page views and sign-in actions are not counted.

Do not submit passwords, card data, bank-login credentials, government identifiers, health information, or unrelated sensitive personal information.

Purposes and disclosure

Data is used to authenticate users, calculate forecasts, coordinate collections, produce reports, provide support, secure and troubleshoot the service, meet legal obligations, and measure aggregate product performance. We do not sell personal data or use customer financial records for advertising. Access is limited to authorized organization members and authorized service operators with a support, security, or legal need.

Hosting and subprocessors

Timastra Collect runs on a dedicated virtual private server selected and administered by the service operator. The deployed infrastructure provider processes network traffic and stores the application database, uploaded documents, and encrypted recovery archives in the operator-selected region. Stripe, Resend, and Brankas process billing, transactional-email, or consented bank-statement data only after the related service is configured and used. The current subprocessor and data-location disclosure identifies purposes, data categories, conditional use, location limits, and provider source material. The operator must replace the deployment-specific infrastructure placeholder there before commercial use.

Retention and deletion

Business records remain while the organization account is active so forecasts, corrections, and audit history stay explainable. Operational events and the data-minimal acquisition session are normally retained for no more than 90 days; transient authorization and replay records expire sooner. Verified organization deletion removes live tenant data and leaves only a non-personal deletion receipt. Encrypted recovery copies expire under the documented backup-retention schedule.

Your rights

Depending on your relationship and applicable law, you may request information, access, correction, objection, restriction, erasure, portability, or complaint handling. Submit a Privacy request through Help & legal. Timastra Collect verifies identity, coordinates requests involving customer-controlled data with the relevant organization, and provides the appropriate supervisory-authority details for the applicable jurisdiction.

Privacy incidents and contact

Report suspected exposure as an urgent Security concern in Help & legal. Timastra Collect investigates, contains, preserves evidence, and coordinates notices to customers, affected people, and regulators within the deadlines required by applicable law.