Cookie Policy
Last updated 25 August 2026
Invoita uses a small number of strictly necessary cookies and nothing else. There are no advertising cookies, and we do not sell or share cookie data.
What we use
- Session cookie — keeps you signed in as you move between pages. Without it you would have to log in on every request.
- CSRF token cookie — proves a form or sign-in request came from you and not from another site. This is a security control.
- Callback cookie — a short-lived cookie used during sign-in to return you to the right page afterwards.
- Theme preference — remembers whether you chose light or dark mode. Stored in your browser only.
These are all strictly necessary to deliver a service you asked for, so under UK and EU rules they do not require a consent banner.
What we do not use
- No advertising or retargeting cookies.
- No cross-site tracking, and no data brokers.
- No third-party analytics cookies at the time of writing. If we add analytics we will update this page first, and choose a privacy-preserving option or ask for consent where required.
Cookies set by others
If you pay through Stripe or sign in with Google, those providers may set their own cookies on their own pages under their own policies. Public invoice links do not set tracking cookies for your clients.
Controlling cookies
You can clear or block cookies in your browser settings. Blocking the session or CSRF cookies will stop you being able to sign in, because the application cannot keep you authenticated without them.
For the wider picture on personal data, see our Privacy Policy.
Questions about this policy? Email [email protected].