Privacy notice
Last updated 2026-08-26
This notice describes what Tallyloop does with personal data. It is written against what the software actually does; where a practice is absent it says so rather than staying silent.
Who is responsible
The controller is the operator of this service, identified in the imprint. Data-protection enquiries reach us at info@sp33c.tech, or through the support page.
What is collected, and why
Your account. Your name, email address and a password. The password is never stored: only a salted scrypt hash of it is kept, which cannot be reversed back into the password. Purpose: to create your workspace and sign you in. Lawful basis: performance of the contract (Art. 6(1)(b) GDPR).
The data you enter. Your company details, your customers (names, contact names, email addresses, phone numbers, billing and shipping addresses, VAT identifiers), your catalogue, your service assignments, your invoices, and your payment account details including IBAN or account numbers. Purpose: to run the billing you signed up for. Lawful basis: performance of the contract. Where that data describes your own customers, you are the controller for it and we process it on your behalf.
Nothing else. There is no analytics, no advertising, no profiling, no device fingerprinting, and no third-party tracking script on any page of this service.
Cookies
Two cookies, both first-party, neither used for tracking:
__billing_session— signs you in. Strictly necessary. Expires after 30 days.__billing_lang— remembers the language you picked. A preference. Expires after one year.
Because neither is used for tracking or advertising, no consent banner is shown for them.
Who else receives data
- Amazon Web Services — hosting, storage and content delivery. Your workspace data is stored in AWS in the
eu-central-1(Frankfurt) region. AWS acts as a processor. - Anthropic — only when you press Refresh on the AI insights page, and only if an API key is configured for this deployment. What is sent is a summary of your workspace: customer names together with revenue, margin, aging and subscription figures. It is not used to train models. If no key is configured, the insights page runs a local rule-based analysis instead and nothing leaves the service.
- Frankfurter API — published European Central Bank exchange rates. Only a date and currency codes are requested. No personal data and nothing about your workspace is sent.
No data is sold, and none is shared with data brokers or advertising networks.
How long it is kept
Your workspace data is kept for as long as the workspace exists. There is no automatic expiry — no retention timer is configured on the datastore, and this notice will not claim one that does not exist. Data is removed when you ask for the workspace to be deleted, as described below.
One exception is worth stating plainly: an invoice deliberately freezes a copy of the customer and company details as they were when it was issued, so that a document you already sent cannot change afterwards. Editing or deleting a customer record therefore does not alter invoices already issued to them.
Tracking
Tallyloop does not track you. No advertising identifier is collected, the iOS app contains no App Tracking Transparency prompt because it has nothing to ask about, and no data is shared with data brokers or used to build a profile across other companies' apps or websites.
Your rights, and how to use them
Under the GDPR you have the right of access, rectification, erasure, restriction, data portability, and to object to processing. You may also lodge a complaint with a supervisory authority.
- Rectification — you can correct your company details, customers, catalogue and payment accounts yourself, at any time, from within the app.
- Access and export — email info@sp33c.tech and we will return your workspace data in a machine-readable form.
- Erasure — email info@sp33c.tech. Deletion means the workspace and its records are removed, not that sign-in is merely disabled.
- Withdrawing consent — where processing rests on consent rather than the contract, it can be withdrawn at any time by the same address, with effect for the future.
Security
Traffic is served over HTTPS. Passwords are hashed with scrypt and a per-user salt. Session cookies are signed, HttpOnly, Secure in production, and SameSite=Lax. Data at rest is stored in AWS with encryption managed by that service.
Changes
When this notice changes, the date at the top changes with it. Material changes will be summarised here.