Privacy Policy
Last updated 25 August 2026
This policy explains what personal data Invoita collects, why, who we share it with, and the rights you have. It covers https://invoita.com and the Invoita application.
1. Two different roles
We are the controller of data about you as an Invoita user — your name, email, password hash and billing records.
For the data you put into Invoita about your own clients, you are the controller and we are your processor. We only handle that data to run the service for you, and we do not sell it, mine it, or use it to build any profile.
2. What we collect
- Account data — name, email address and a hashed password. If you sign in with Google we receive your name, email and profile picture from Google.
- Business data — your business name, address, tax number, logo and invoice settings.
- Client and document data — the clients, invoices, quotes, contracts, expenses and time entries you create, including any personal data about your clients that you enter.
- Billing data — your plan, subscription status and Stripe customer reference. Card numbers go directly to Stripe and never reach our servers.
- Technical data — IP address, browser type and timestamps in server logs, plus error reports, used for security, debugging and abuse prevention.
- Delivery data — whether an invoice email was sent and, where enabled, whether it was opened, so you can see if a client has seen an invoice.
We do not run advertising trackers, and we do not sell personal data to anyone.
3. Why we use it, and our legal basis
- To provide the service — creating and sending your documents, generating PDFs, and keeping your account working. Basis: performance of a contract.
- To take payment — managing subscriptions and invoices for the service itself. Basis: performance of a contract.
- To keep the service safe — rate limiting, fraud and abuse prevention, error monitoring and backups. Basis: our legitimate interest in a secure service.
- To contact you — service notices such as verification, password reset and important changes. Basis: performance of a contract. Marketing email, if we ever send any, would be on consent you can withdraw.
- To meet legal duties — keeping accounting and tax records. Basis: legal obligation.
4. Who we share it with
We share data only with providers that help us run Invoita, and only as far as each needs. Several are optional and receive nothing unless you connect them.
| Provider | Purpose |
|---|---|
| Stripe | Subscription billing and invoice card payments |
| Resend | Transactional and invoice email delivery |
| Optional sign-in and optional Gmail sending | |
| OpenAI | Optional AI drafting of invoice content |
| Plaid | Optional bank account connection and reconciliation |
| Twilio | Optional SMS and WhatsApp delivery |
| GoCardless | Optional direct debit collection |
| Wise | Optional bank transfer details on invoices |
| PayPal | Optional invoice payment collection |
| Xero and QuickBooks | Optional accounting synchronisation |
| Sentry | Application error monitoring |
| Cloudflare | DNS, CDN and denial-of-service protection |
| OVHcloud | Server hosting and database storage |
We may also disclose data where the law requires it, or to establish or defend legal claims. If Invoita is ever sold or merged, data may transfer to the acquirer under this policy.
5. AI features
If you use AI drafting, the text you supply is sent to OpenAI to generate a draft and returned to you. We do not permit that content to be used to train third-party models. AI output can be wrong — always check a draft before sending it to a client.
6. International transfers
Some providers listed above operate outside your country. Where data leaves the UK or EEA we rely on an adequacy decision or on Standard Contractual Clauses with appropriate safeguards.
7. How long we keep it
- Account and document data: for as long as your account is open.
- After deletion: removed or irreversibly anonymised within a reasonable period, except where we must retain records by law.
- Billing records: retained for the period tax law requires, typically six years.
- Server logs: retained for a short rolling window for security and debugging.
8. Security
Passwords are hashed with bcrypt and never stored in readable form. Stored third-party credentials are encrypted at rest. Traffic is served over TLS, and optional two-factor authentication is available on your account. No system is perfectly secure, but we work to protect your data and will tell you and the relevant regulator about a qualifying breach without undue delay.
9. Your rights
Depending on where you live you may have the right to access, correct, delete, restrict or object to our use of your personal data, to receive it in a portable format, and to withdraw consent. You can exercise most of these directly in your account settings, or by emailing [email protected]. You also have the right to complain to your data-protection authority.
If your data is in Invoita because one of our customers invoiced you, please contact that business first — they control that record.
10. Children
Invoita is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children.
11. Cookies
We use a small number of strictly necessary cookies. See our Cookie Policy.
12. Changes
We will post any update here and change the date at the top. If a change is material we will notify you by email or in the product.
Questions about this policy? Email [email protected].