Who we are
Tallyo is operated by Edson Oliveira, a sole trader based in the United Kingdom. This notice explains how Tallyo uses personal information when you visit the Tallyo website, create or use a Tallyo account, buy a Tallyo subscription, contact us, or interact with a business that uses Tallyo.
Business and service address87 Coles Green Road, NW2 7JH, London, UK
Contact [email protected]
Privacy requests [email protected]
Our different data-protection roles
Tallyo is the controller for account registration and security, Tallyo subscriptions, service administration, support and complaints, product security, the public website, and the AI Helper if it is enabled. This means we decide why and how that information is used.
When a business user enters information about their customers, contacts, invoices, quotes, credit notes, recurring documents or payment status, that business normally decides why the information is used. The business is the controller and Tallyo acts as its processor. Questions about a business's invoice or its use of your information should normally be sent to that business first. We assist the business with data-protection requests where required.
Stripe and other providers may act as our processor, as an independent controller, or both, depending on the activity. Their roles are described below.
Information we use
Account and security information
We use your email address, account identifier, email-confirmation state, sign-in and session information, optional authenticator-app MFA state, recovery events, security events and device/session controls. One-time recovery codes are shown to you, but Tallyo stores only protected hashes while they are needed.
Business profile and document information
A business user may enter their business name, address, contact details, tax identifier, logo, branding, payment instructions, notes and terms. They may also create customer records, saved products or services, invoices, quotes, credit notes and recurring schedules. Those records can include customer contact details, line items, dates, references, amounts, tax, discounts, notes, payment status, reminders and activity history.
Please do not enter information that Tallyo does not need. Tallyo is not designed for special-category information or regulated professional records.
Subscription and payment information
For a Tallyo subscription, we use limited Stripe identifiers and subscription, price, period, payment and entitlement status needed to provide and manage the service.
When a business connects its own Stripe account for customer card payments, that business is the merchant of record for direct charges. Tallyo receives limited identifiers, amount, currency, status, event time, invoice association, refund/dispute status and reconciliation information.
Card numbers, CVCs, Stripe identity documents and payout-bank credentials are entered directly into Stripe and are not stored by Tallyo. A business user may separately place their own payment instructions or manual payment notes on a document.
Communications and support
We use the information in support questions, complaints, privacy requests and related correspondence. Document email and reminder delivery can include the recipient's email address, the document PDF, business/customer details and delivery status.
If you separately enter an email address in the free invoice generator and tick the optional consent box, Tallyo uses that address to send the single introductory overview you requested. We do not copy the invoice sender or recipient address into this field. We record the consent wording and version, time, source, one-way address and connection fingerprints, send state and any withdrawal so we can honour the one-email limit and demonstrate your choice.
Website, service and security information
Our infrastructure providers may process request metadata such as IP address, approximate country, browser or device information, timestamps and request identifiers to deliver and protect the service, enforce access controls, diagnose errors and prevent abuse.
If you choose Accept analytics, Tallyo uses Google Analytics 4 to understand how people use the public website and selected account journeys. Google may process an analytics cookie identifier, a query-free page address, approximate location derived from the connection, browser/device information and the limited events listed in our Cookie Notice. We do not send names, email addresses, company details, customer records, invoice or quote contents, payment information, Stripe identifiers, free-text entries or internal user identifiers to Google Analytics.
Analytics is off unless you affirmatively accept it. Tallyo uses Google's basic consent approach, so the Google tag is not loaded and no analytics request is sent before acceptance. You can reject Analytics and still use Tallyo, or withdraw later using the persistent Cookie settings control. Tallyo does not enable Google Signals, advertising personalisation, enhanced conversions, user-provided data collection or advertising cookies.
AI Helper
The public AI Helper answers questions about public Tallyo product information. When a visitor submits a question that the reviewed browser guidance cannot answer directly, Tallyo sends the short question and reviewed public Tallyo information to OpenAI. The Helper is not designed to access account records or private business/customer data, and visitors must not enter that information.
Tallyo does not intentionally store a Helper conversation history. OpenAI's standard API abuse-monitoring logs may retain prompt and response content for up to 30 days unless a separately approved reduced-retention control applies. Cloudflare uses a short-lived, protected network-derived key to enforce the Helper rate limit.
Why we use personal information
We use information only where a lawful basis applies:
- Contract: to create and operate a user's Tallyo account, provide subscribed features, manage the subscription, deliver requested support, and take requested steps before a contract.
- Legal obligation: to keep Tallyo's own tax/accounting records, respond to binding legal requirements, and meet other specific duties that apply to us.
- Legitimate interests: to secure the service, prevent fraud and abuse, diagnose faults, provide operational support, maintain limited audit and payment-integrity evidence, and establish, exercise or defend legal claims. We use this basis only after considering necessity, the effect on people and appropriate safeguards.
- Consent: for optional Google Analytics measurement after you choose Accept analytics, and for the single introductory Tallyo overview email only when you enter an address and tick its separate consent box. You can withdraw Analytics consent using Cookie settings and withdraw the overview-email consent using the unsubscribe link in that email.
Business users are responsible for identifying their lawful basis for the customer and document information they enter. We process that information under their instructions and the applicable Data Processing Terms.
Who receives information
We use providers only for genuine service purposes:
- Supabase: database, authentication and server functions.
- Resend: service, document, reminder, security and separately requested one-time overview email delivery.
- Cloudflare: website/app delivery, access protection, Turnstile, request security and the AI rate limiter.
- Stripe: Tallyo subscription Billing, connected-account onboarding and customer payments, payment/refund/dispute processing, fraud prevention and regulatory compliance. Stripe's role depends on the activity.
- OpenAI: public product-question processing only if the AI Helper is enabled.
- Google Analytics: optional website and selected account-journey measurement only after affirmative Analytics consent. Advertising features and user-provided data collection are disabled.
- Google Workspace: Tallyo's official system for business, support and privacy email and restricted privacy-request records.
- GitHub: source-code administration and limited rollback hosting; it is not the primary store for Tallyo customer workspaces.
Providers may use their own subprocessors. We may also disclose information to professional advisers, regulators, courts, law enforcement or a buyer of the business where lawful and necessary.
We do not sell personal information.
Stripe's roles
Stripe generally processes payment data to provide payment services and also determines some processing for fraud prevention, security, legal and regulatory compliance.
For Tallyo subscriptions, Tallyo determines the subscription purpose. Stripe provides Checkout, payment, billing and portal services and carries out its own compliance and fraud functions.
For direct connected-account customer payments, the connected business is the merchant of record. Stripe provides the connected account, onboarding, payment, payout, refund, dispute, identity and regulatory services. Tallyo retains only the limited status and reconciliation information needed to operate the invoice workflow.
Stripe gives individuals its own privacy information for processing it controls.
International transfers
Some providers and their subprocessors process information outside the United Kingdom, including in the United States, the European Economic Area and other countries listed in their current subprocessor records.
Where UK information is transferred to a country without applicable UK adequacy regulations, the relevant provider terms use safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the European Commission Standard Contractual Clauses. A provider may use another lawful transfer mechanism for processing it controls. You may contact us for more information about the applicable safeguard.
Provider terms and locations can change. We review the relevant data-processing terms and subprocessor information as part of provider oversight.
How long we keep information
We keep active-account and workspace information while the account is active.
To close an account or request deletion, email [email protected]. We verify and review each request manually. We delete or anonymise information when it is no longer necessary, but may retain limited records where required for tax, accounting, fraud prevention, payment disputes, regulatory duties or legal claims. We do not promise a fixed closed-account deletion deadline.
Deleted active-database information may remain temporarily in Supabase daily backups for up to seven days under the current Pro-plan cycle. Other providers retain information under their documented cycles and legal obligations.
We keep Tallyo's own subscription and tax/accounting records for the period required by UK tax law. Routine operational records are kept for shorter periods based on their security, support or payment-integrity purpose. Ordinary support records are normally reviewed for deletion two years after closure, privacy-request records three years after closure, and material claims when the claim and any necessary legal-retention period end.
Your Analytics consent preference is stored for up to six months so the website can respect your choice. If you accept, Tallyo configures Google Analytics cookies with a maximum age of six months. Withdrawing consent stops future Analytics events from Tallyo and removes the Analytics cookies that Tallyo can identify on this domain. Google may retain previously received Analytics event data under the retention settings and legal obligations that apply to its service.
For the optional one-time overview email, Tallyo removes the plain email address from its request record after the send attempt. We keep the minimised consent, one-way address fingerprint, send and withdrawal evidence only while reasonably needed to demonstrate the request, prevent a duplicate overview and respect a withdrawal. We review that evidence at least annually and delete or anonymise it when it is no longer needed.
Tallyo does not intentionally retain AI Helper conversations. If the Helper is enabled, standard OpenAI API abuse-monitoring logs may retain content for up to 30 days. Stripe keeps information it controls for its legal, regulatory, fraud and financial obligations.
We review retention manually at launch and record any exception or legal hold. More information about the retention criteria is available on request.
Security
Tallyo uses confirmed accounts, optional authenticator-app MFA, one-time recovery controls, session revocation, tenant-isolated database rules, server-side checks, signed webhooks and access controls. Providers also apply their own security measures.
No system can remove every risk. Users should use a strong unique password, protect recovery codes and avoid entering unnecessary or sensitive information.
Your rights
Depending on the circumstances, UK data-protection law may give you rights to:
- be informed about processing;
- obtain access to your information;
- correct inaccurate or incomplete information;
- request erasure;
- restrict processing;
- object to processing based on legitimate interests;
- receive portable information where applicable;
- withdraw consent for future processing where consent is the basis; and
- complain to the Information Commissioner's Office.
Some rights have legal limits. We may need to confirm your identity and clarify your request.
If your request concerns an invoice, customer record or other information entered by a Tallyo business user, contact that business first because it is normally the controller. You may also contact us and we will route or assist with the request as required.
Send privacy requests to [email protected].
You can complain to the Information Commissioner's Office, but we would welcome the opportunity to address your concern first.
Changes to this notice
We will update this notice when our product, providers, legal duties or data uses materially change. We will show the effective date and, where appropriate, give account users advance notice.
