Privacy Policy

How Invoiceo handles personal data: what we collect and why, who sees it, how long we keep it, and what you can do about it.

Last updated

In short

  • We collect what is needed to run your account and your invoices, and nothing for advertising. We do not sell your data and use no ad or analytics trackers.
  • The free invoice maker on the home page keeps nothing on our server. Your details are remembered only in your own browser.
  • Your business records belong to you. Only the people in your business can see them.
  • You can ask to see, correct, export or delete your data at any time. We reply within 30 days.
  • We name a point of contact for privacy complaints, and explain your rights in India, the UK and EU, the USA, Canada and the UAE.

This summary is a help, not a substitute for the full text below.

1. Who we are, and who is responsible for what

Invoiceo is an online invoicing and bookkeeping tool for small businesses. In this policy “we” means Invoiceo.

There are two different roles, and it helps to know which one applies:

  • For your own account (your name, email, password, how you use the service) we decide why and how the data is used. We are the “controller” (in India, the “data fiduciary”).
  • For your customers’ and suppliers’ details that you type into your business records, you decide why they are used and we only store and process them for you. You are the controller and we are your “processor”. If you are a customer of one of our users and have a question about your data, please ask that business first.

You can always reach us about privacy at support@invoiceo.app.

2. What we collect

We collect only what the service needs to work. Here is everything, and the reason for each.

WhatExamplesWhy we need it
Account detailsYour name, email address, a password (kept only as a salted hash, never in readable form)To create your account, let you log in, and send you account emails such as a password reset.
Business profileBusiness name, address, tax number (GSTIN, EIN, VAT, TRN or GST/HST number), phone, email, logo, invoice settings, and optionally bank and UPI detailsTo print on your invoices and to work out the right tax.
Your business recordsCustomers and suppliers, products, invoices, quotations, delivery challans, payments, expenses, purchases, stock movementsTo run the service for you: show your records, make documents and reports.
Team detailsNames and emails of people you invite, and their roleTo give them the access you chose.
Activity and audit logsWhich signed-in user did what (for example issued an invoice) and whenSo you can see who changed what, and so records stay trustworthy.
Messages to usWhat you write on the contact form or in an email, and your email addressTo answer you.
Technical dataYour IP address and browser details in short-lived server logs; a short-lived counter of your IP address in memory to limit abuseTo keep the service secure and available, and to stop automated abuse.

We do not ask for, and you should not enter, sensitive personal data such as health information, government ID numbers (other than tax numbers that appear on invoices), or card details. We do not take card payments on the service today.

3. The free invoice maker on our home page

The invoice maker on the home page works without an account, and we built it to keep nothing. What you type is sent to our server for one reason only: to turn it into a PDF or an Excel file. It is not saved in a database, not written to logs, and not emailed to anyone, and the response is marked so that browsers and proxies do not cache it.

  • Remembered in your browser only. To save you typing, your business details and an unfinished invoice are kept in your browser’s local storage on your own device. We cannot see them. You can remove them with “Forget my details” or by clearing your browser’s site data.
  • Customer phone and email boxes are used only to write the WhatsApp or email message you choose to send. They are never printed on the invoice or sent to us.
  • “Save this invoice to my account” is your choice. It keeps the invoice in your browser (for up to 30 days) until you have an account. Nothing reaches our server until you sign up and the invoice is imported into your account as a draft, along with the customer on it. If you never sign up, it stays only on your device.
  • PDFs and Excel files made here carry a small “Made with Invoiceo” line. Invoices made inside an account do not.

4. Cookies and similar storage

We use only what is strictly necessary to make the service work. We do not use advertising cookies, analytics or tracking scripts, and we do not share data with ad networks. Because of that we do not show a cookie banner.

NameWhat it doesHow long
Session cookie (authjs.session-token)Keeps you signed in. Signed, http-only and sent only to us.Up to 14 days
CSRF and callback cookies (authjs.*)Protect the sign-in form from forged requests and send you back to the right page.Session or a few hours
active_businessRemembers which of your businesses is open. It only selects among businesses you already belong to; it never grants access.Persistent, until you log out or switch
Browser storage: themeRemembers light or dark mode.Until you clear it
Browser storage: invoice makerRemembers your business details and an unfinished invoice on the home page (see above).Until you clear it

5. How we use your data, and why we are allowed to

We use personal data only for the purposes below. Where the law asks for a legal basis, this is it:

  • To provide the service you asked for (account, invoices, reports, reminders you switch on). Basis: performing our contract with you.
  • To keep the service safe and working: security, abuse prevention, fixing faults, backups. Basis: our legitimate interest in running a secure service.
  • To meet legal duties, such as keeping records or answering lawful requests. Basis: legal obligation.
  • To answer your messages and requests. Basis: legitimate interest, and your request.
  • Anything optional (for example if we ever send news or product updates) only with your consent, which you can withdraw at any time. We send no marketing email today.

We do not sell your personal data. We do not use your business records to train AI models, and we do not make decisions about you by automated means that have legal or similarly significant effects.

6. Emails we send, and emails we send for you

Account emails (password reset, team invitations, security notices) are sent by us because the service needs them.

Payment reminders. If a business switches on reminders, Invoiceo emails that business’s customers about unpaid invoices on the business’s behalf. The business is the sender and is responsible for having a genuine reason to write to its customers. Every reminder contains an unsubscribe link. Once a customer uses it, no further reminders are sent to that customer record, and the business is told that the customer opted out.

7. Who we share data with

Inside a business, records are visible only to the people who are members of it, with the role the owner gave them. Every request is checked against business membership on our server.

Outside that, we share personal data only with:

  • Service providers that help us run the service under contract and only on our instructions: hosting and database providers, and an email delivery provider. They may not use the data for their own purposes. We will tell you who they are if you ask.
  • Authorities, when a valid legal request or a legal duty requires it. We tell you first where the law allows.
  • A successor if the business is sold or merged, in which case this policy continues to apply to your data until you are told otherwise.

We do not sell personal data, and we do not share it for advertising. The India e-invoice feature prepares the file for the government’s e-invoice portal; today it does not send anything to that portal on your behalf, so those details go there only if you upload them yourself.

8. Where your data is processed

Our servers and providers may be in a different country from you, so your data can cross borders. When it does, we use the safeguards the law of your country expects, such as contractual protections with our providers. India’s Digital Personal Data Protection Act, 2023 allows transfers except to countries the government restricts; UK and EU law asks for approved safeguards. Ask us if you want details for your country.

9. How long we keep data

  • Account and business records: for as long as your account is open. Issued invoices are never silently changed or deleted: they are cancelled with a reason, so your books stay complete.
  • After you close your account: we delete or anonymise your data within 90 days, except what we must keep to meet a legal duty or to defend a legal claim. Copies in backups are removed when the backups expire.
  • Tax records are your duty too. Tax laws in your country may require you to keep invoices for several years. Export what you need before you close the account.
  • Messages to us: for as long as needed to answer and follow up, then deleted.
  • Security and server logs: kept for a short period (weeks, not years).

10. How we protect your data

  • Passwords are stored only as salted hashes (bcrypt). We cannot read them, and nobody at Invoiceo will ever ask you for one.
  • Connections use HTTPS, and our site tells browsers to insist on it (HSTS).
  • Sessions use signed, http-only cookies. Password-reset links work once and expire after one hour.
  • Every request is checked on the server against your account and business membership. One business can never see another’s records.
  • Sign-in, sign-up, password reset and the free invoice maker are rate-limited to slow down abuse. Important actions are written to an audit log.
  • The site sends security headers (a content security policy, no framing, no content-type sniffing) to limit what a hostile page or script can do.

No system is perfectly secure, and we do not claim ours is. If we learn of a breach that affects your personal data, we will tell you and the authorities as the law requires. To report a security problem, please see how to reach us securely.

11. Your rights

Whichever country you are in, you can ask us to tell you what we hold about you, correct it, export it, or delete it, and you can object to how we use it. Write to support@invoiceo.app from the email address on your account. We may need to check it is really you. We reply within 30 days (the law gives us longer in a few cases, and we will say so). It is free unless a request is plainly excessive.

India

Under the Digital Personal Data Protection Act, 2023 you may ask for a summary of the personal data we process and who we share it with, ask us to correct, complete or update it, ask us to erase it when it is no longer needed, withdraw consent you gave, nominate someone to exercise your rights if you die or cannot, and have your grievance answered. See “Grievance and contact” below. If you are unhappy with our answer you can complain to the Data Protection Board of India.

United Kingdom and European Economic Area

You have the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent. You can complain to the UK Information Commissioner’s Office or to your local EU data protection authority.

United States

Depending on your state (for example California, Virginia or Colorado), you may have the right to know what we hold, to correct or delete it, to get a copy, and to opt out of the sale or sharing of personal information or of targeted advertising. We do not sell or share personal information and we do not do targeted advertising, so there is nothing to opt out of. We will not treat you differently for asking. California residents: we reply within 45 days, extended by up to 45 more if we tell you why.

Canada

Under PIPEDA and provincial laws you may ask to see your personal information, challenge its accuracy, and withdraw consent. You can complain to the Office of the Privacy Commissioner of Canada or your provincial regulator.

United Arab Emirates

Under the federal Personal Data Protection Law you may ask for access, correction, erasure, restriction and portability, and object to processing. You can complain to the UAE Data Office.

12. Children

Invoiceo is for businesses and is not meant for anyone under 18. We do not knowingly collect personal data from children. If you think a child has given us data, write to us and we will delete it.

13. Grievance and contact

Grievance Officer: our privacy team. Email support@invoiceo.app. We acknowledge complaints within 2 working days and aim to resolve them within 30 days.

Or use the contact page and choose “Privacy request”.

14. Changes to this policy

When we change this policy we change the date at the top and add a line to the list below. If a change matters (for example a new purpose for your data), we tell account holders by email or in the app before it starts, and ask for consent where the law requires it.

15. What changed

  • 11 October 2026. Full rewrite: added what we collect and why, the free invoice maker, cookies, retention, regional rights and the grievance contact.

Questions about this page? Contact us. See also our Terms of Service and About us.