Accounts receivable All products [https://timastra.com/products] / Timastra Collect [https://timastra.com/products/collect] / Privacy Timastra Collect: Privacy Updated October 4, 2026 Read or download the October 4, 2026 legal documents [https://timastra.com/legal/releases/2026-10-04/index.html]. The dated archive preserves this release; your order or acceptance record identifies the documents that apply to you. Overview [https://timastra.com/products/collect]Privacy [https://timastra.com/legal/releases/2026-10-04/documents/products-collect-privacy.html]Terms [https://timastra.com/legal/releases/2026-10-04/documents/products-collect-terms.html]Support [https://timastra.com/products/collect/support]Account & data deletion [https://timastra.com/legal/releases/2026-10-04/documents/products-collect-delete-account.html]Billing & refunds [https://timastra.com/legal/releases/2026-10-04/documents/products-collect-billing.html] On this page Scope [#privacy-scope] Who controls your data [#privacy-roles] Information the product handles [#privacy-information] Purpose [#privacy-purpose] Providers, permissions and sharing [#privacy-providers] Retention and deletion [#privacy-retention] Your requests [#privacy-requests] Scope This privacy information is specific to Timastra Collect, which Timastra LLC provides and is responsible for. The website and account privacy policy [https://timastra.com/legal/releases/2026-10-04/documents/privacy.html] separately covers visits to timastra.com, central sign-in, hosted purchase information and correspondence with Timastra LLC. Who controls your data For workspace data that a customer uploads or connects, the customer is the controller and Timastra LLC processes that data on the customer's instructions. Timastra LLC is responsible for the account, billing and support information it needs to run the service. Our data processing agreement [https://timastra.com/legal/releases/2026-10-04/documents/dpa.html], which forms part of the service agreement, and our sub-processor list [https://timastra.com/legal/releases/2026-10-04/documents/subprocessors.html] describe how we process that data; email support@timastra.com [mailto:support@timastra.com?subject=Timastra%20Collect%3A%20DPA%20and%20sub-processor%20request] for a countersigned copy. Information the product handles Member identities, email addresses, roles, organization and billing contacts Customer contact details, invoices, balances, payment history, obligations, promises and disputes Uploaded documents, reminders, replies, communication preferences, forecasts and audit events Connection metadata and authorized financial or mailbox data when optional integrations are enabled Purpose Organize receivables, forecast cash availability, prioritize collection work, communicate about invoices, reconcile payments, and administer workspace access. Providers, permissions and sharing Collect supports organization sign-in, subscription billing and email delivery. Invoice checkout for your customers is available only in sandbox testing; live invoice payments are not offered. Bank balances come from CSV import, with no live bank-feed connection. Optional accounting and mailbox connections require explicit authorization and are confirmed for each workspace before use. The data each connection can access is shown before it is enabled. Timastra Collect runs on a server Timastra rents from netcup in Singapore, behind Cloudflare. Service email is sent through Resend from its Tokyo region, subscriptions are billed through Paddle, and encrypted backups are stored in Cloudflare R2. The sub-processor list [https://timastra.com/legal/releases/2026-10-04/documents/subprocessors.html] names each provider, its purpose and location. Optional connections are identified before use. Retention and deletion Retention depends on the record type, workspace agreement and applicable obligations. Financial and communication records may need different handling. Disconnecting a service does not by itself erase imported financial records. Before uploading workspace data, request the applicable processing and retention schedule. It must identify the export or return window when service ends, the live-data removal date, the expiry of each backup, recovery and operator copy, and any retained category's purpose, authority and review or expiry date. A backup rotation or subscription cancellation alone does not establish those deadlines. The customer chooses return or deletion at the end of the service, subject to documented legal retention obligations; recovery must reconcile completed deletion requests before records are used again. Closing a whole workspace is different from removing a member or deleting a customer's personal information. Workspace export and deletion are available through the service process. Identify the organization and requested scope so support can review financial records, connected services and backups together. Hosted data is backed up daily to encrypted storage. The standard managed rotation selects 14 daily, 4 weekly and 3 monthly copies. Protected release snapshots, legacy backups, provider recovery history and operator copies have separate schedules; rotation alone is not a guaranteed expiry date. Your deletion response identifies affected copies, documented holds and expected expiry. Recovery must reconcile completed deletion requests before reopening access. Your requests For access, correction, deletion or questions about processing, email support@timastra.com [mailto:support@timastra.com?subject=Timastra%20Collect%3A%20Privacy%20request]. Identify the relevant organization if applicable. We answer within one month, extendable where the law allows. Available rights and exceptions depend on the circumstances and applicable law; see the legal bases [https://timastra.com/legal/releases/2026-10-04/documents/privacy.html#legal-bases], international transfers [https://timastra.com/legal/releases/2026-10-04/documents/privacy.html#international-transfers] and your rights [https://timastra.com/legal/releases/2026-10-04/documents/privacy.html#your-rights] sections of the website privacy policy. Request account or data deletion [https://timastra.com/legal/releases/2026-10-04/documents/products-collect-delete-account.html]