InvoiceGen is designed so that you can meet your GDPR obligations to your own customers.
1. Controller and processor roles
We are the controller for your account data. For your customers’ data on invoices, you are the controller and we are your processor. Our Terms and Privacy Policy form our data processing terms; a signed DPA is available on request from privacy@invoicegen.app.
2. Data subject rights, built in
- Access & portability (Art. 15, 20) — one-click JSON export in Settings.
- Rectification (Art. 16) — edit profile, clients and invoices at any time.
- Erasure (Art. 17) — delete individual clients/invoices, or your whole account, instantly.
- Restriction & objection (Art. 18, 21) — on request by email.
3. Data minimisation
We collect only what is needed to produce invoices. No advertising trackers, no selling of data, and the free builder works without an account — drafts stay in your browser.
4. Security measures
- TLS encryption in transit and encryption at rest.
- Row-level security isolating each account’s data at the database level.
- Role-based admin access, with admin actions limited to account and plan management.
- Hashed passwords and optional sign-in with Google or GitHub.
5. Sub-processors
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication |
| Vercel | Hosting |
| Stripe | Payments (paid plans only) |
6. Breach notification
If a personal-data breach affects your account we will notify you without undue delay, and supervisory authorities within 72 hours where Article 33 requires it.
Questions about this document? Email privacy@invoicegen.app or use our contact form.