Show HN: A source-available billing system I've spent 18 months building
billabear.com
billabear.com
I don't want to read the source code, I want to use the product. If there is a bug, I want you to fix it. If you don't fix it, why am I paying you / using it? Assuming I am a programmer (many users aren't) and make my own patch, and you don't merge it, I'm still screwed. Source only helps me if I'm the one running the code. So the fact that your SaaS is source available has no bearing on my use of it.
Personally, I would never reach for a tool or component or any piece of software if I have to run or operate it unless I can change the code.
Now, "source available" has another implication, however...
It's something we had to deal with in a previous job where we (as a small company) sold products to Global 500 companies. Either we agreed to this, or there would be no deal. Every time we released a new version to those clients, we would place the updated source code (along with documentation and tooling etc) in escrow.
What exactly is escrow for source code? Some party you paid to upload a tar.gz to an sftp server?
We also had to details on how to actually build the product from the source, though I think they mostly just trusted us on that as long as we supplied a separate document - and by trusted, there were penalties spelled out in the contract about that too. (We were in good shape releng-wise but I expect a lot of companies would have to clean up their act to actually comply with that part.)
Only in the case of source code, I give them the code, and they won't give it to you until I go out of business. They get paid for that, of course. In our case, we uploaded source code an escrow service's servers.
> We hereby irrevocably grant you an additional license to use the Software under the Apache License, Version 2.0 that is effective on the second anniversary of the date we make the Software available.
[1] https://github.com/billabear/billabear?tab=License-1-ov-file
>Source only helps me if I'm the one running the code
Many times I've gotten better support when I open a Github issue and send the link to support--usually I can get around all the canned troubleshooting steps and get to an engineer quicker.
>So the fact that your SaaS is source available has no bearing on my use of it
You can tell if the product is garbage before you pay for it (does this place review changes, do they have automated tests??)
imo it's still helpful although small. If you're looking to run it yourself, sometimes source available can quickly be ruled out--especially if your company reviews and tracks license terms and doesn't want the headache of something custom/complicated
Even large businesses that don't produce software as a product often have internal dev teams that customize third party software to their needs (at least in the particular vertical that I'm involved in).
It's immaterial in these cases whether the code is properly open source or not, but being able to go in yourself and fix minor bugs that are blocking you in hours/days rather than the weeks/months it might take the vendor to get back with a fix is practically a hard requirement for any dependencies that are core to your business.
In this case since it's more of a SaaS I don't know if I would make that choice, I'm not familiar with billing software however not being 3rd party dependent and knowing you could self-host later if needed sounds useful.
To some extend. Projects that are “open-source” but not MIT piss me off because they make my life harder.
I know that’s not strictly fair, but nonetheless true.
But it is weird that just MIT seems to be acceptable to him, I would think some BSD licenses variant would be OK as well. But maybe even an acknowledgement of the hard work of others is too much to ask for...
When the source is available, I need to carefully consider what the license is, and if it’s anything other than MIT I’ll have to go through a whole approval process to use the thing. Any experience with corporate means you know the thing cannot be used if you value your sanity.
I just fundamentally believe that making the source available should be the same as making it free/unencumbered. If you need the legal system to enforce your license for you something is going wrong.
Presuming the customer is a single person. Plenty of business software is sold as proprietary with some source available pieces -- where the business doesn't care about the license, but IT wants to maintain/adjust/integrate the customizable parts.
[0]: https://github.com/billabear/billabear/blob/main/LICENSE.md
As I understand it, nothing FSL does couldn't be expressed in a modified BSL but having it as its own license makes it less ambiguous by not allowing for much variation beyond which specific license it converts to upon expiration.
> How exactly does the two years work?
> The two year timeframe applies to each software version that is made available. Methods of making software available include pushing a Git commit, publishing a package to a repository, or mailing out a CD in a tin. For example, one could clone a repo, run git checkout `git rev-list -n 1 --before="2 years ago" master`, and—if LICENSE.md is FSL—use that version under MIT or Apache 2.0.
git checkout `git rev-list -n 1 --before='2 years ago' master`
and if the license is FSL, you're g2g.This is the first time I've seen FSL and it is quite nice. Surely "source available" is the wrong term to label the license with.
There's a new term coming very soon, "Fair Source." :)
See: https://fair.io
no, its just the correct term, we literally ask people who use the wrong license to change their terminology to "source available", lets not punish people who do it right from the get go
I'm saying that there ought to be a more descriptive term for this license to differentiate from the usual proprietary "source available" licenses. ezekg's comment gives an appropriately descriptive label, "Fair Source".
It can be a practical need, rather than a prestige grab. Some people can only sink time into developing their software if sales of that software pay their bills. The redistribution rights granted by an open-source license somewhat conflict with this, by allowing another party to appropriate their original work and use it to undercut them. (This is part of why a revenue model based on services, rather than sales, is often encouraged in open-source.)
Meanwhile, the author might very much want to offer customers other rights granted by open-source licenses, like the ability to inspect the code, or to have it audited, or to modify it, or to build it from source as an assurance of what instructions are being executed. This is a situation where "source available" makes sense.
Looking at it from the other direction, some potential customers will only accept software that grants the latter rights, but don't care about redistribution rights. "Source available" is a viable option for them as well.
I wonder if it would be helpful to have a new, clearly defined term for a class of licenses granting inspection & modification rights without redistribution rights, and explicitly protecting users from additional restrictions like fees for source access. That could help make licensing of this kind easy to identify and understand, and if that meant wider acceptance, perhaps more developers would be willing to release their source code to users.
(I do see "Fair Source" mentioned in another comment, but I haven't investigated to see if it aligns with what I'm describing.)
I even came across taxes that were only present in half a city, even—one side of a road but not the other, that kind of thing.
Much much later there were efforts to tax sales on the internet no matter where in the US, and for good reasons.
The Wayfair Decision in 2018
Seems like it was both enacted and neutered by Boomers and even older generations.
Concurring justices:
- Justice Anthony Kennedy - Silent Generation (born 1936)
- Justice Clarence Thomas - Baby Boomer Generation (born 1948)
- Justice Ruth Bader Ginsburg - Silent Generation (born 1933)
- Justice Samuel Alito - Baby Boomer Generation (born 1950)
- Justice Neil Gorsuch - Generation X (born 1967)
Appointing presidents:
- Ronald Reagan (Justice Anthony Kennedy) - Greatest Generation (born 1911)
- George H. W. Bush (Justice Clarence Thomas) - Greatest Generation (born 1924)
- Bill Clinton (Justice Ruth Bader Ginsburg) - Baby Boomer Generation (born 1946)
- George W. Bush (Justice Samuel Alito) - Baby Boomer Generation (born 1946)
- Donald Trump (Justice Neil Gorsuch) - Baby Boomer Generation (born 1946)
> George H. W. Bush (Justice Clarence Thomas)
> Bill Clinton (Justice Ruth Bader Ginsburg)
What's up with repeating the word "Justice" so much? Shouldn't you be writing "President of the United States Ronald Reagan, Leader of the Free World (Justice Anthony Kennedy)", etc?
I live in IL and haven't heard of that. Generally if something is a 'sale' it's taxed though. I miss the old days when anything purchased online was some gray area they couldn't figure out if they should tax or not.
>Chicago’s 9% amusement tax extends to all “amusements that are delivered electronically.” If you stay home and watch a movie, you pay the same tax rate as you would if seeing it in theaters.
https://www.illinoispolicy.org/this-christmas-your-gift-from...
You can get to a basic level of compliance fairly easily with state- and customer-based rates in select circumstances. But unless you dig deep, you will get things wrong, and you will only know about it when you get a potentially expensive audit years later.
Context: CTO of [Taxwire](https://taxwire.co), writing software for sales tax.
Is there a us sales tax software development documentation somewhere ?
We are looking to expand an open source accounting software into usa but without sales tax, it wont be usable for businesses I suppose.
I will fix that. It handles US State Sales Tax to some extent. So it has state tax rules and thresholds. So will only apply the tax if the threshold or there is a nexus. However, it doesn't have the polygon tax areas that would be needed for cities. For example, Illinois doesn't have SaaS tax but Chicago does. That is very high on my list of things to do. But you could work around that right now by doing it on a customer level. Where you set the tax rate for the customer.
But I will definitely improve that text on the tax page to explain how it hands the US tax issues.
Or for that matter, sales tax/ vat of countries ? I suppose there should be
I'm going to be adding integrations with tax jar to help make it easier for keeping tax rules up to date. Do a daily/weekly check for tax in each area and then save it.
For £80,000 a month with transactions each being £100.
* Stripe Billing is £400 a month or £4,800 a year. * Stripe Tax £800; a month or £9,600. * Payment Links is £320; a month or £3840 a year.
Total per month: £1,520. Total per year £18,240.
And that would be a small company.
Stripe Billing doesn't allow you to:
* Control the templates of your pdfs * Control the templates of your emails * Control how your emails are being sent * It makes having multiple subscription items a lot easier. * It allows you to define tax rates on a customer and product level * It allows you to define tax rates on a country and state level * Have multiple brands on the same account
Also, it's a lot cheaper than Stripe Billing even the cloud hosted version is. Stripe Tax is even more expensive.
There is an awkward mix of formal and informal sentences, and also some too literal translations here and there.
I would also recommend localizing the screenshots into Spanish (I’m assuming the product is localized).
We can read english quite well.
Disclaimer: I have a connection to one of these companies, just want to share some knowledge. I strive to be as neutral as possible.
Fun fact: I'm German and know the challenges with the UI. It's a love/hate relationship!
The problem with i18n (internationalization) is that many developers and product owners believe it’s only about implementing a library and letting Google Translate, DeepL, or even ChatGPT do the rest. As most of you already know, that approach doesn't work well for German speakers. My language will break/destroy your UI design.
The real issue with i18n is that it involves many stakeholders throughout the process. Here are the most important ones to start with:
Developers: These folks need to implement a library and want a good DX (Developer Experience). It means You should choose a library with an IDE extension (e.g., VS Code's Sherlock i18n, i18n Ally). - Libraries: Please use something that utilizes .json files. Formats like .po are cumbersome and will cause many issues. - Use tooling that supports an ecosystem around it, like lint rules, to save time and effort.
Translators: Ideally, your preferred solution includes a TMS (Translation Management System) or a CAT (Computer-Assisted Translation) tool.
Designers: If your designers can't see the translations in tools like Figma, your UI will break, and users will complain. Figma plugins like Parrot, Phrase, or Weblate can help (just search for 'i18n' in Figma's marketplace).
All the apps mentioned are just a few examples among many tools available.
Conclusion: The important stakeholders in this process are Developers, Translators, and Designers. i18n is an ongoing process, not a one-time task. If you start your app or project with i18n from the beginning, the annoying parts are manageable, and it won’t cost you all your nerves.
If you're willing and able to create PRs and I'm able to merge.
What industries is this being used in already?
I guess my main concern with using it as a SaaS would be that it's located outside the EU (which creates GDPR headaches despite what "GDPR compliant" services outside the EU will tell you) and whether this also means it can be adapted to comply with any given country's laws (e.g. in 2025 laws will come into effect in Germany and the EU that will place certain requirements on B2B "e-billing" such as using a specific XML format).
Well the UK is GDPR compliant it literally has the entire GDPR law as GDPR (UK). If there is an issue in the future I'll just move the company to Germany. The servers are currently in Germany. I will be implementing everything and anything to comply with EU laws.
With what company? All good if it's a EU company like Hertzner, but it can still give GDPR headaches if you are hosting on e.g. AWS in Frankfurt because Amazon is still a US company.
Yea, the EU really needs to fix the EU-US GDPR issues. It's not like the US will.
And how would the EU "fix" the issues posed by the US's disregard for privacy? They tried several times but Schrems keeps tearing it down by pointing out the basic fact that you don't get a pass for violating civil rights by being the US.
But the implication was that the EU could do something to make such a treaty work and other than repeal and replace GDPR I don't see any way as long as the US insists on playing secret police when it comes to foreign data subjects.
I’ve made software for the childcare industry, where the data concerns are greater than most other industries.
Nobody had any problem with AWS, or really any non-EU vendor, as long as they lived up to the GRPR agreements and could provide the usual agreements.
Only in Germany would you run into requirements to either host in Germany (at worst) or at least within EU (at best). Additionally, there’s a lot of German specific laws on top, that simply aren’t in the other EU countries, and the general population is also much more concerned about data privacy and residency than any other EU country.
It was a world of difference, and honestly enough for me that I would not enter the German market again if it meant needing to comply with any additional effort than the rest of the EU market.
A bit more of a rant: The hosting solutions in Germany are also quite atrocious once you get to a certain scale. Lack of proper managed services, tons of instability, insane maintenance policies, poor security support (eg no 2FA for many). Once you’ve gotten used to how AWS/GCP/Azure handles things, it’s hard to go back to that world.
Edit: Almost as response to my last point, AWS is setting up a unique EU sovereign cloud https://aws.amazon.com/blogs/aws/in-the-works-aws-european-s...
Well, Germany isn't the country that made Google Analytics illegal. Other countries do care.
> Nobody had any problem with AWS, or really any non-EU vendor, as long as they lived up to the GRPR agreements and could provide the usual agreements.
I was in charge of the tech for a massive man in the middle company in Germany where we integrated with lots of companies to provide data for other companies. Noone had an issue with AWS because they were all using it. It's consumers who care and consumers who will make reports and it's companies that will pay the fine.
The only way out is to not be a US company.
> With what company? All good if it's a EU company like Hertzner, but it can still give GDPR headaches if you are hosting on e.g. AWS in Frankfurt because Amazon is still a US company.
Says Hetzner (with only one r) in the first FAQ, "Is BillaBear GDPR Compliant?", on the homepage.
[ETA:] Could of course have been added after you asked here; I only checked it out just now. [/ETA]
(50%+ in php)
I read it like "without". I think you mean "with out-of-the-box"?