rroi
TermsPrivacyDocs

Legal

Privacy Policy

This policy explains how roi handles personal information in its websites, dashboard, APIs, hosted invoices, and related services.

Effective July 22, 2026
This policy describes the current early-access product. roi does not currently use advertising pixels or behavioral analytics and will update this notice before making a materially different use of personal information.

1. Scope and our role

This Privacy Policy applies when roi determines why and how personal information is processed—for example, information about workspace users, website visitors, support contacts, and prospective customers. In those situations, roi acts as a controller or business.

Businesses also use roi to process information about their own customers, subscribers, invoice recipients, and end users (Customer Data). For Customer Data, the roi customer determines the purpose of processing and roi acts as its processor or service provider. If you are an individual whose information a roi customer submitted, contact that business first; we will assist it with requests as required by law and our agreement with it.

2. Information we process

CategoryExamplesPrimary purpose
Workspace identityName, business email, user and organization IDs, roles, permissions, and authentication/session data provided through WorkOS.Create and secure accounts, authenticate users, enforce permissions, and communicate about the Services.
Merchant and support informationBusiness and legal name, support email, business address, tax ID, country, branding, invoice settings, messages, and support history.Configure the service, produce invoices, support customers, and maintain business records.
Customer billing dataCustomer names, emails, external IDs, subscriptions, usage events and properties, invoices, credits, discounts, ledger entries, payment attempts, refunds, disputes, and webhook payloads.Perform the billing instructions of the roi customer and maintain an auditable billing record.
Payment and connection dataProcessor account and transaction references, tokenized payment-method references, card brand, last four digits, expiration date, billing name and address, and encrypted credentials supplied for processor or accounting connections.Connect third-party systems, display the selected payment method, orchestrate authorized charges and refunds, and reconcile records.
Technical and usage dataIP address, request path and method, timestamps, request IDs, response status, latency, browser or device headers, error details, and security events.Operate, secure, troubleshoot, rate-limit, and improve the Services.
Commercial informationPlan, order-form, invoice, payment status, product usage, and communications about a customer relationship with roi.Provide and administer the commercial relationship, bill for the Services, and plan capacity.

roi is designed not to receive or store full payment-card numbers or card security codes. Payment credentials are collected by the customer’s payment processor and roi receives processor-issued references. Do not send full card numbers, government ID numbers, health information, or other unnecessary sensitive data in usage properties, descriptions, webhook payloads, or support messages.

3. Sources of information

We receive personal information:

  • directly from workspace users, prospective customers, and support contacts;
  • from roi customers through the dashboard, API, SDK, imports, and MCP tools;
  • from identity providers such as WorkOS;
  • from payment processors, accounting systems, and other services a customer connects;
  • from merchant-configured webhooks and callbacks; and
  • automatically from browsers, servers, and network infrastructure when the Services are used.

4. How we use information

We use personal information to:

  • provide, operate, maintain, and support the Services;
  • authenticate users and enforce organization, role, and test/live boundaries;
  • execute customer instructions for metering, billing, invoicing, collection, refunds, disputes, webhooks, and accounting sync;
  • detect, prevent, and investigate fraud, abuse, security incidents, and service failures;
  • monitor performance, troubleshoot errors, and improve reliability and usability;
  • communicate about accounts, incidents, product changes, support, and commercial matters;
  • enforce agreements, protect rights, and comply with law; and
  • create aggregated or de-identified information that does not reasonably identify a person or customer.

Where European data-protection law applies and roi acts as controller, our legal bases are performance of a contract, steps requested before entering a contract, compliance with legal obligations, and legitimate interests such as securing and improving a B2B service. We rely on consent where law requires it. roi does not use personal information for automated decisions that produce legal or similarly significant effects about an individual.

5. How we disclose information

We may disclose information to:

  • Service providers and subprocessors that provide hosting, database, workflow orchestration, authentication, security, monitoring, communications, and support. Current infrastructure categories include WorkOS, Fly.io, Temporal Cloud, and the database provider used for a deployment.
  • Customer-directed services, such as payment processors, accounting systems, webhook destinations, and other connectors selected and configured by the roi customer.
  • Professional advisers and authorities when reasonably necessary for legal, security, audit, insurance, or compliance purposes, or to protect rights and safety.
  • Transaction participants in a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of the business, subject to appropriate confidentiality protections.

We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising, and we do not knowingly sell or share personal information of people under 16. The current marketing site contains no advertising pixels or behavioral analytics. If those practices change, we will update this policy and provide any required choices before beginning the new processing.

6. Cookies and similar technologies

The authenticated dashboard uses cookies that are necessary for WorkOS authentication, session security, OAuth connection state, and the user’s selected test or live environment. The public marketing site does not currently set analytics or advertising cookies. Hosting providers may process ordinary request logs, including IP addresses and browser headers, to deliver and protect the site.

Because the current site uses only necessary functionality and no targeted advertising, roi does not currently present a non-essential cookie banner or “Do Not Sell or Share” link. Browser Global Privacy Control signals do not change processing because there is no sale or advertising share to opt out of.

7. Retention

We retain workspace identity, merchant configuration, and commercial records while the account is active and afterward for as long as reasonably necessary to provide exports, resolve disputes, enforce agreements, meet legal obligations, and protect the Services. Billing, ledger, invoice, payment-attempt, refund, dispute, and audit records may be kept longer because their purpose is to provide a durable financial history and because tax, accounting, fraud-prevention, and legal requirements may apply.

Operational logs and transient security records are retained for shorter periods based on troubleshooting and security needs. Backups, when enabled, and third-party workflow histories may persist until their configured or provider-managed rotation completes. When deletion is required, we delete or de-identify information unless continued retention is permitted or required by law. We are establishing documented retention periods during early access; customers with a contractual retention requirement should contact us before placing regulated data in production.

8. Security

We use administrative, technical, and organizational safeguards designed for the nature of the data we process. Current controls include TLS in transit, encrypted storage for merchant-supplied connector secrets, hashed API-key storage, role and permission checks, database row-level security for dashboard reads, tenant-scoped queries, distinct test and live tenant containers, request authentication, and processor-hosted card capture.

No method of transmission or storage is completely secure. Customers are responsible for user access, API keys, connected systems, endpoint security, and sending only data appropriate for the Services. Report a suspected security incident promptly using the contact information below.

9. International processing

roi and its providers may process information in the United States and other countries where they operate. Those countries may have different data-protection laws. Where required, we use contractual or other legally recognized safeguards for restricted international transfers. Contact us to request information about safeguards applicable to a particular customer deployment.

10. Privacy rights

Depending on your location and our role, you may have rights to request access, correction, deletion, restriction, objection, or portability; to withdraw consent; and to appeal or complain to a data-protection authority. California residents may also have rights to know the categories, sources, purposes, and recipients of personal information, to correct or delete it, and not to receive discriminatory treatment for exercising a right. roi does not sell or share personal information as those terms are defined by the California Consumer Privacy Act.

Send a request to sales@billroi.com. We may need to verify your identity and authority. An authorized agent may submit a request, but we may require proof of authorization and identity. If your request concerns Customer Data, identify the roi customer that controls it; we may refer the request to that customer. Rights are subject to legal exceptions, including obligations to preserve financial and security records.

11. Children

The Services are a business product and are not directed to children. Account holders must be at least 18. We do not knowingly collect personal information directly from a child under 13. If you believe a child has provided information directly to roi, contact us so we can investigate and take appropriate action.

12. Changes to this policy

We may update this policy as the Services and legal requirements change. We will post the revised policy with a new effective date and provide additional notice of material changes where required. We will not use previously collected personal information for a materially different purpose without notice and any consent required by law.

13. Contact

Questions, rights requests, and security reports may be sent to sales@billroi.com.

© 2026 roi
TermsPrivacyContact