Your invoices contain sensitive business information, so we keep data collection to the minimum needed to run InvoiceGen. This policy explains what we collect, why, and the choices you have.
1. Who we are
InvoiceGen (“we”, “us”) operates InvoiceGen at https://invoice-generator1718.vercel.app. For personal data about you as an account holder, we are the data controller. For personal data about your own customers that you enter on invoices, you are the controller and we act as your processor, handling it only to provide the service to you.
2. Data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Email address, name, password hash, sign-in provider (Google / GitHub) | You, or the provider you sign in with |
| Business profile | Business name, address, logo, default currency and tax rate | You |
| Invoice & client data | Client names, addresses, emails, line items, amounts, notes, signature images | You |
| Billing data | Plan, billing period, payment status. Card details are handled by Stripe and never reach our servers. | You and our payment processor |
| Technical data | IP address, browser type, timestamps and error logs kept by our hosting providers | Automatically |
If you use the free invoice builder without an account, your draft stays in your browser’s local storage and is not sent to us unless you choose to save it to an account.
3. How we use your data and our legal bases
- To provide the service — create your account, store and render invoices, generate PDFs (performance of a contract).
- To run subscriptions — process payments, apply plan limits, send receipts (contract; legal obligation for tax records).
- To keep the service secure — detect abuse, prevent fraud, debug errors (legitimate interest).
- To communicate with you — service and security notices, replies to support requests (contract; legitimate interest). We do not send marketing email without your consent.
4. Who we share data with
We never sell your personal data. We share it only with service providers that help us run the product:
- Supabase — database, authentication and storage.
- Vercel — application hosting and delivery.
- Stripe — subscription payments (only if you buy a paid plan).
- Google / GitHub — only if you choose to sign in with them.
Each provider is bound by a data processing agreement. We may also disclose data if required by law or to protect our users’ rights and safety.
5. International transfers
Our providers may process data outside your country, including in the United States. Where data leaves the EEA or UK we rely on the European Commission’s Standard Contractual Clauses or an adequacy decision.
6. How long we keep data
- Account, profile, invoice and client data — for as long as your account exists.
- When you delete your account, this data is deleted from our live database immediately and from backups within 30 days.
- Billing records — up to 7 years where tax law requires it.
- Server logs — typically 30 days or less.
7. Your rights
Depending on where you live (for example under the GDPR, UK GDPR or CCPA/CPRA), you can access, correct, export, delete or restrict the use of your personal data, and object to processing based on legitimate interests. Most of this is self-service:
- Edit your details in Settings.
- Download all your data as JSON with Settings → Your data → Export.
- Delete your account and data with Settings → Your data → Delete account.
For anything else, email privacy@invoicegen.app. We answer within 30 days. You may also complain to your local data protection authority.
8. Security
Data is encrypted in transit (HTTPS) and at rest by our database provider. Row-level security ensures each account can only read its own invoices and clients, and passwords are stored only as salted hashes. No system is perfectly secure; if we learn of a breach affecting you, we will notify you and the relevant authorities as required by law.
9. Cookies and local storage
We use only strictly necessary cookies (to keep you signed in) and local storage (to save invoice drafts). There are no advertising or cross-site tracking cookies. See the Cookie Policy.
10. Children
InvoiceGen is a business tool and is not directed to children under 16. We do not knowingly collect their data.
11. Changes to this policy
We will post any changes on this page and update the date above. For material changes we will also notify signed-in users by email or in the dashboard before they take effect.
Questions about this document? Email privacy@invoicegen.app or use our contact form.