Privacy Policy
Last Updated: January 28, 2026
1. Company Information
This privacy policy applies to the Billbora marketing website (billbora.com) operated by:
Immeka Pty Ltd
ABN: 15 639 304 073
ACN: 639 304 073
Email: privacy@billbora.com
Important: This policy covers only the marketing website. If you use the Billbora application (app.billbora.com), separate privacy terms apply and will be presented when you create an account.
2. Information We Collect
We collect information you provide directly to us and information automatically collected when you use our marketing website.
2.1 Information You Provide
| Data Type | When Collected | What We Collect |
|---|---|---|
| Contact Forms | When you submit an inquiry | Name, email address, company name, message content |
| Newsletter Subscriptions | When you subscribe to updates | Email address, name (optional) |
| Founding Customer Program | When you apply for the program | Business name, ABN, email address, contact name, business type |
2.2 Information Collected Automatically
| Data Type | Description |
|---|---|
| Analytics Data | Page views, clicks, session duration, navigation paths (via Google Analytics 4) |
| Technical Data | IP address, browser type, device information, operating system, referring URLs |
| Cookies | See Section 5 for detailed cookie information |
3. How We Use Your Information
We use the information we collect to:
- Respond to your inquiries and provide support
- Process Founding Customer Program applications
- Send you product updates, marketing communications, and newsletters (with your consent)
- Analyse website usage and improve our marketing website
- Comply with legal obligations and protect our rights
Legal Basis for Processing (GDPR)
| Legal Basis | Purpose |
|---|---|
| Consent | Analytics cookies, marketing communications, newsletter subscriptions |
| Legitimate Interest | Website functionality, security, fraud prevention, website improvement |
| Contract Performance | Processing inquiries and Founding Customer Program applications |
4. Data Sharing and Third-Party Services
We share your information with the following third-party services. We do not sell your personal data.
4.1 Google Analytics 4
We use Google Analytics 4 to analyse website usage. Google Analytics collects information about your use of our website, including IP address (anonymised), pages visited, and time spent on pages.
- Data Controller: Google LLC
- Privacy Policy: https://policies.google.com/privacy
- Opt-out: Install the Google Analytics Opt-out Browser Add-on
4.2 Google Tag Manager
We use Google Tag Manager to manage tracking tags on our website. GTM itself does not collect personal data but facilitates the deployment of analytics tags.
4.3 Firebase Hosting (Google Cloud)
Our website is hosted on Firebase Hosting, a service provided by Google. Firebase may collect technical data such as IP addresses and request logs for security and performance purposes.
- Data Processor: Google LLC
- Privacy Policy: https://firebase.google.com/support/privacy
- Data Location: Google Cloud infrastructure (multi-region)
4.4 Amazon Web Services (AWS) - Email Processing
Contact form submissions are processed through Amazon Simple Email Service (AWS SES). AWS processes email data on our behalf to deliver your messages to us.
- Data Processor: Amazon Web Services, Inc.
- Privacy Policy: https://aws.amazon.com/privacy/
- Data Location: AWS Sydney region (ap-southeast-2)
4.5 Brevo - Newsletter and Marketing Emails
When you subscribe to our newsletter or receive marketing communications, your information is processed by Brevo (formerly Sendinblue).
- Data Processor: Brevo SAS
- Privacy Policy: https://www.brevo.com/legal/privacypolicy/
- Data Location: European Union (France/Germany)
- Data Collected: Email address, name (if provided), email engagement metrics (opens, clicks)
- GDPR Compliance: Brevo is GDPR-compliant and certified under EU data protection standards
You can unsubscribe from marketing emails at any time by clicking the "unsubscribe" link in any email or by contacting us at privacy@billbora.com.
4.6 Billbora Application
If you sign up for the Billbora application (app.billbora.com), your data will be processed under separate terms. The application collects and processes additional business data necessary for invoicing, payment processing, and related services. Application-specific privacy terms will be presented during account creation.
5. Cookies and Tracking Technologies
We use cookies to enhance your experience and analyse site usage. You can manage your cookie preferences at any time by clicking "Cookie Settings" in the website footer.
Essential Cookies (Always Active)
| Cookie | Purpose | Duration |
|---|---|---|
cc_cookie | Stores your cookie consent preferences | 6 months |
Analytics Cookies (Requires Consent)
| Cookie | Purpose | Duration |
|---|---|---|
_ga | Google Analytics unique visitor ID | 2 years |
_ga_[ID] | Google Analytics 4 session tracking | 2 years |
_gid | Google Analytics session ID | 24 hours |
_gat | Google Analytics request throttling | 1 minute |
For comprehensive information about our cookie practices, please see our Cookie Policy.
6. Data Retention
| Data Type | Retention Period |
|---|---|
| Contact Form Data | Until service relationship established, or 2 years from submission, whichever comes first |
| Newsletter Subscriptions | Until you unsubscribe |
| Founding Customer Program Applications | Duration of program participation plus 7 years for tax/legal compliance |
| Analytics Data | 14 months (Google Analytics 4 setting) |
| Cookie Consent Data | 6 months |
7. Your Privacy Rights
7.1 Australian Privacy Rights
As an Australian company, we comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). You have the right to:
- Access your personal information we hold
- Correct inaccurate or out-of-date information
- Complain if you believe we have breached the Privacy Act
To exercise these rights: Contact us at privacy@billbora.com
If you're not satisfied with our response:
You may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
- Website: https://www.oaic.gov.au/
- Phone: 1300 363 992
- Post: GPO Box 5218, Sydney NSW 2001
We will respond to complaints within 30 days and work with the OAIC to resolve any concerns.
7.2 GDPR Rights (EU/EEA/UK Visitors)
If you are located in the European Union, European Economic Area, or United Kingdom, you have additional rights under GDPR:
| Right | Description |
|---|---|
| Access | Request a copy of your personal data |
| Rectification | Correct inaccurate or incomplete data |
| Erasure | Request deletion of your data ("right to be forgotten") |
| Restrict Processing | Limit how we use your data |
| Data Portability | Receive your data in a machine-readable format |
| Object | Object to processing based on legitimate interest |
| Withdraw Consent | Withdraw consent for analytics cookies and marketing |
Response time: Within 30 days of your request
Supervisory Authority: You may lodge a complaint with your local data protection authority
7.3 CCPA Rights (California Residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act:
| Right | Description |
|---|---|
| Know | Request disclosure of personal data collected about you |
| Delete | Request deletion of your personal data |
| Opt-Out | We do not sell your personal data |
| Non-Discrimination | We will not discriminate against you for exercising your rights |
Response time: Within 45 days of your request
7.4 Exercising Your Rights
To exercise any of these rights, please contact us at:
- Email: privacy@billbora.com
- Subject line: Privacy Rights Request - [Your Right]
We will respond within 10 business days to acknowledge your request. We may need to verify your identity before processing your request.
8. International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence:
| Service | Data Location | Safeguards |
|---|---|---|
| Google Analytics | United States | Standard Contractual Clauses, Google Consent Mode v2 |
| Firebase Hosting | Multi-region (Google Cloud) | Standard Contractual Clauses |
| AWS SES | Sydney, Australia (ap-southeast-2) | Data remains in Australia |
| Brevo | European Union (France/Germany) | GDPR-compliant, EU data residency |
We ensure appropriate safeguards are in place for international transfers, including Standard Contractual Clauses (SCCs) where applicable.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data:
| Security Measure | Implementation |
|---|---|
| Encryption in Transit | TLS 1.3 for all website connections |
| Hosting Security | Firebase Hosting with Google Cloud security infrastructure |
| Access Controls | Limited access to personal data on a need-to-know basis |
| Vendor Security | All third-party services selected for strong security practices |
| Email Security | DKIM, SPF, and DMARC configured for email authentication |
10. Children's Privacy
Our website is not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us at privacy@billbora.com and we will delete it promptly.
11. Do Not Track
We respect Do Not Track (DNT) browser signals. If your browser sends a DNT signal, we will not set analytics cookies unless you explicitly consent via our cookie banner.
12. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of changes by:
- Posting the updated policy on this page with a new "Last Updated" date
- For material changes, displaying a prominent notice on our website
- For newsletter subscribers, sending an email notification of significant changes
We encourage you to review this policy periodically.
13. Contact Us
If you have questions about this privacy policy or our privacy practices:
| Contact Method | Details |
|---|---|
| privacy@billbora.com | |
| Company | Immeka Pty Ltd |
| ABN | 15 639 304 073 |
We aim to respond to all privacy inquiries within 10 business days.
14. Regulatory Authorities
If you are not satisfied with our response to your privacy concerns, you have the right to lodge a complaint with the relevant authority:
| Region | Authority | Contact |
|---|---|---|
| Australia | Office of the Australian Information Commissioner (OAIC) | https://www.oaic.gov.au/ |
| European Union | Your local Data Protection Authority | https://edpb.europa.eu/ |
| United Kingdom | Information Commissioner's Office (ICO) | https://ico.org.uk/ |
| California | California Attorney General | https://oag.ca.gov/ |
This Privacy Policy applies to the Billbora marketing website (billbora.com) only. The Billbora application (app.billbora.com) operates under separate terms.