Skip to content
Invoicr

Legal

Privacy policy

Last updated 01 Jul 2026

In short

  • If you use Invoicr without an account, your invoice content is not sent to us — the PDF is rendered in your browser.
  • A share link is the only way anonymous invoice data reaches our servers, and only when you create one.
  • With an account we store your business, clients and invoices so we can show you a history. You can export or delete all of it.
  • We do not sell personal data and we do not run advertising trackers.

This summary is for orientation. The sections below are the operative text.

Who we are

Invoicr is operated by Invoicr Labs. You can reach us at hello@subhajitdas.in for any privacy question, including a request to access or delete your data.

Using Invoicr without an account

The builder, the live preview, the PDF download and the CSV/JSON exports all run in your browser. Your invoice content — party names, addresses, tax registration numbers, line items and amounts — is held in your browser and in its local storage so your work survives a closed tab. It is not transmitted to us.

Two deliberate actions change that. Creating a “save for later” share link uploads that invoice so the link can work. Using the server PDF endpoint (for example from the API) sends the invoice for rendering; it is not retained afterwards.

What we collect when you have an account

  • Your email address, used to sign you in and to send transactional email you have asked for.
  • Your business profile: name, address, tax registrations, bank details and branding defaults.
  • Your clients and invoices, including line items and computed totals, so we can show a history and produce documents.
  • Subscription and purchase records, so we know what you are entitled to. Card details are handled by Stripe and never reach us.
  • Basic operational logs — request paths, timestamps, error traces — retained for a short period to diagnose faults.

Payments

When we charge you, Stripe processes it and we store only the identifiers needed to reconcile your subscription or purchase.

When your client pays one of your invoices, the payment goes through your own Stripe or Razorpay account. We record the amount, currency, status and provider reference so the invoice can be marked paid. We never hold your client’s card or UPI details, and we take no cut.

Email

Transactional email — sign-in links, invoice delivery, payment reminders — is sent through Resend. We do not send marketing email to addresses collected for sign-in.

Cookies

We set a session cookie when you sign in. That is the only cookie required for the product to work. We do not use advertising or cross-site tracking cookies. Anonymous use of the builder sets no cookies at all.

Where data is stored

Account data is stored in Postgres via Supabase, protected by row-level security so a query can only ever reach rows belonging to a business you are a member of. Anonymous drafts are stored against an unguessable token and expire after 90 days.

Retention

  • Anonymous drafts: 90 days from the last save, then deleted.
  • Account data: kept while your account exists. Deleting your workspace removes your business, clients, invoices and line items.
  • Billing records: retained as long as tax law requires us to keep them.

Your rights

You can export everything at any time as CSV or JSON — on every tier, including free. You can request access, correction, deletion or portability by emailing us, and we will respond within 30 days.

If you are in the UK or EU, our lawful basis is contract performance for the service itself, legitimate interests for security and fault diagnosis, and consent where you have specifically asked for something.

Children

Invoicr is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16.

Changes

If we change this policy materially we will update the date at the top and, for account holders, say so by email. We will not retroactively reduce the protections that applied to data we already hold.