Last updated

Privacy policy

Last updated: 20 September 2026

The German version is authoritative.

This notice explains how Emilio Ybarra (“tobbli”, “we”) processes personal data when you use tobbli.com, app.tobbli.com, or the related services. The German version is authoritative. Workspace content about your own clients is also covered by the data processing agreement.

1. Controller

The controller for processing on the tobbli sites and for your user account is:

Emilio Ybarra

Meller Straße 17

49143 Bissendorf

Germany

Email: privacy@tobbli.com

Further contact details are in the imprint.

For personal data you store as a workspace owner about your own clients, teammates, or documents, you are usually the controller. tobbli is the processor. Details are in the DPA.

2. Purposes and legal bases

  • Providing the account, sign-in, and workspace — Art. 6(1)(b) GDPR (contract).
  • Billing tobbli Pro through Stripe — Art. 6(1)(b) and (c) GDPR (contract and tax duties).
  • Operations, security, abuse and rate limits — Art. 6(1)(f) GDPR.
  • Answering support and privacy requests — Art. 6(1)(b) or (f) GDPR.
  • Strictly necessary cookies and similar storage (language, appearance, session) — section 25(2) TDDDG.
  • Error reports to Sentry when a DSN is set — Art. 6(1)(f) GDPR.
  • Workspace content (invoices, clients, receipts, portal, hosted links) — on your instructions, Art. 28 GDPR; you determine the legal basis toward third parties.

3. Data we process

Depending on how you use tobbli, this may include:

  • Marketing visitors: IP address and ordinary hosting logs, language, colour mode.
  • Account owners: name, email, password (hashed by the auth service), business profile, bank details/IBAN, tax IDs, logo and avatar.
  • Studio teammates: invite email, name, time entries.
  • Portal users: invite email, login, uploads, name and email when accepting a quote.
  • Hosted document views (/d/…): first-view time and the technical data needed to serve the page. No account is required.
  • Support: name, email, topic, and message. The site form currently only opens your mail app (mailto). Once you send the message, it reaches us by email.
  • Billing: Stripe customer and subscription IDs, payment status, period end.

In the workspace you may also store third-party data: clients, invoices, quotes, credit notes, payments, projects, time, expenses, receipts, attachments, boards, catalog, automations, webhooks, and e-invoice XML (ZUGFeRD / XRechnung). We process that content as a processor.

4. Recipients and processors

We use service providers that process data on our behalf or as independent controllers. The region of each service is the region actually configured. If processing happens outside the EU/EEA, we rely on standard contractual clauses or an adequacy decision.

  • Netlify, Inc., 512 2nd Street, Suite 200, San Francisco, CA 94107, USA — hosting of tobbli.com and app.tobbli.com. Netlify privacy.
  • Supabase — authentication, PostgreSQL, and file storage (attachments, receipts, avatars, portal uploads).
  • Stripe — checkout and customer portal for tobbli Pro; optional payment links on hosted invoices when that feature is on. Stripe privacy.
  • Transactional email over SMTP. The vendor in use (for example Resend, SendGrid, or Postmark) follows the technical configuration.
  • Sentry (Functional Software, Inc.) when error reporting is enabled. Sentry privacy.

Fonts (Inter, Plus Jakarta Sans) are served from our own hosting (Nuxt Fonts). We do not currently run a marketing analytics script or an advertising cookie banner.

5. Cookies and local storage

We only use storage that is needed to run the service:

  • `tobbli-web-locale` — marketing-site language.
  • Colour-mode cookie on the marketing site.
  • `folio-locale` — app language.
  • Authentication session cookies (Supabase).
  • Stripe cookies on Stripe-hosted checkout and payment pages.
  • localStorage in the app for the offline/demo workspace copy until cloud access exists.

A consent banner is not required for that today. If we later add analytics or marketing cookies, we will ask for consent first and update this notice.

6. Hosted documents, portal, and team

A hosted link (/d/…) can be opened by anyone who has the token. The first view can be shown to the workspace owner. Accepting a quote through the link sends a name and email.

Portal and studio invites create accounts with the invited email address. The workspace owner decides whom to invite and which documents to share.

7. Retention

  • Account and workspace data: until the account is deleted, then for a short technical period in backups (point-in-time recovery, typically at least several days).
  • Cancelling Pro ends the subscription; it does not delete the workspace.
  • tobbli’s own invoices to you: for German tax retention, usually 8 or 10 years.
  • Support email: as long as needed to handle the request and follow-up.
  • Server logs and error reports: according to each vendor, typically days to a few months.

8. Your rights

You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with a supervisory authority. For Lower Saxony that is the Landesbeauftragte für den Datenschutz Niedersachsen; you may also contact the Federal Commissioner for Data Protection and Freedom of Information.

Write to privacy@tobbli.com. Include the account email and whether you want an export, a deletion, or a clarification.

In the app you can export the workspace as a ZIP and delete the account (settings). Account deletion removes files under your prefix and the auth user. Demo accounts cannot be deleted. Cancelling Pro is not deletion.

9. Required data

We cannot create an account without an email and password. We cannot create or send documents without the details a document needs. The marketing site can be used without an account.

10. Changes

We update this notice when services, purposes, or the law change. The date at the top of this page is the current version.