Skip to content
Gelhaus Solutions
Apps Services Security Contact
EN DE
Apps / GPlatform Billing / GPlatform Billing privacy notice

GPlatform Billing privacy notice

What a billing system holds about you, taken from its schema — starting with the thing it deliberately never holds.

Last updated 6 September 2026 Auf Deutsch lesen →

On this page

  1. No card data, ever
  2. Your organisation
  3. You
  4. Your sessions
  5. Payments
  6. Usage
  7. Who else touches it
  8. Why we may do this
  9. How long
  10. Your rights

This applies alongside the general terms of service and privacy policy. Where they differ on a point about GPlatform Billing specifically, this page wins.

No card data, ever

Start here, because it is the question this notice exists to answer.

We never hold your card. Stripe holds the instrument; this database holds an identifier for it and nothing that could be used to charge anybody. There is no card number here, no expiry, no security code, and no bank mandate. A copy of this database is not a way to take money from you.

The controller is Gelhaus Solutions, Eichenwald 3, 49624 Löningen, Germany, egelhaus@ennogelhaus.de.

Your organisation

Its name, the identifier it is known by, and its status.

Your billing address — country, postcode, city, street lines and where applicable the state. The country decides the tax rate, and the rest is what makes an invoice legal.

Your VAT identifier, its type, and its verification status. Its presence changes what you are charged rather than only what is printed on the invoice.

Identifiers linking you to your Stripe customer object and, where you have one, to your organisation in GPlatform Control. The Control link is made deliberately over the commercial API and is never inferred from a name matching.

You

Your email address, your display name, and a hash of your password. When you last signed in, how many sign-ins have failed, and whether the account is locked. Which organisations you belong to and in what role.

Invitations hold the address invited, the role offered, who sent it, who accepted it, when it expires and how many times it has been sent. The link itself is stored as a digest, so a dump of the table is not a set of working ways into other people's organisations.

Your sessions

A digest of the session token — whoever has the token is signed in, so the database keeps a hash and a copy of it cannot impersonate you.

The IP address and browser user agent the session was signed in from, so you can recognise your own sessions and end ones you do not.

There is deliberately no city. Drawing a town beside each session would mean a geolocation lookup, which would mean a third party learning every address every customer signs in from. The address itself is the fact we actually hold, and it is the one you can act on.

Payments

The raw Stripe event, exactly as it arrived, keyed by Stripe's own event id. Events arrive out of order and more than once, and the stored copy is both the deduplication key and the audit trail. This is the one place data arrives in a shape we did not choose, and it can contain what Stripe put in it about the payment.

Your subscriptions, what they are for, what they cost, and their commercial state.

A commercial trail of what happened to a subscription and why, which is append-only: there is no code anywhere that edits a row in it. It records attempts rather than only successes, because a grant that could not be written is the row that matters most.

Usage

One row per subscription item, meter and UTC day: what the meter said, how many readings the day was built from, and whether it was too thin to trust as complete.

These are numbers. They are not a record of what anybody did — the readings behind them stay on the instance that produced them.

Who else touches it

Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Dublin, Ireland, as the payment service provider. Stripe holds your payment instrument and acts as its own controller for that, on its own terms and its own privacy policy. Where a payment involves Stripe entities outside the EU, Stripe's own transfer mechanism applies.

IONOS SE (Germany) for outgoing email, and hosting on servers rented from IONOS and Contabo GmbH (Germany) and our own hardware in Germany.

That is the whole list. There is no analytics service, no error-reporting service, no telemetry exporter, no advertising network and no AI provider in this application. GPlatform Control is reached over mTLS on the local network and never through the public internet.

Why we may do this

Taking payment and providing what was paid for is performance of a contract, Art. 6(1)(b) GDPR.

Invoicing, accounting and tax records are a legal obligation, Art. 6(1)(c).

Fraud prevention, securing accounts, and reconciling what Stripe, this side and GPlatform Control each believe are legitimate interests under Art. 6(1)(f).

How long

Invoices and the accounting records behind them are kept ten years, because Sec. 147 AO and Sec. 14b UStG require it. Deleting your account does not and cannot reach them.

Account, organisation and membership records are kept while the relationship runs and afterwards as the record of it. Sessions expire and are removed. Usage rows are kept as the billing record. Raw Stripe events are kept as the audit trail of what was processed and may be pruned once they are no longer needed for it; the commercial trail deliberately survives that pruning, which is why it stores an event id rather than a reference.

Your rights

Access, rectification, erasure, restriction, portability and objection, as in the general privacy policy, subject to the retention above. An informal email is enough.

You may complain to a supervisory authority; the competent one here is Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover.

Gelhaus Solutions

Self-hosted applications, and the platform that hosts them for the people who would rather not.

Site

  • Apps
  • Security
  • Writing
  • Contact
  • Sitemap

GHub

  • GAnalytics
  • contribution-checker
  • GAdvisory
  • GeGroups
  • GControl

Legal

  • Impressum
  • Privacy
  • Terms
  • Data processing
  • Withdrawal
  • Report content

Elsewhere

  • egelhaus@ennogelhaus.de
  • @egelhaus
  • @egelhaus
© 2026 Enno Gelhaus Built and shipped in Germany