Privacy Policy
Invoice No. (invoiceno.com and app.invoiceno.com)
Version 1.0 · Last updated 20 June 2026 · Effective 20 June 2026
1. Who is responsible for your data
The controller responsible for your personal data is:
Vipplov Choudhary, sole proprietor c/o COCENTER, Koppoldstr. 1, 86551 Aichach, Germany
Privacy and data protection contact: privacy@invoiceno.com
We are a small business and are not required to appoint a Data Protection Officer. The contact above handles all privacy questions, data rights requests, and, for users in India, grievances. Our full legal notice is in our Impressum.
2. The two parts of Invoice No.
This policy covers two products that handle data very differently:
-
The Free Tools (invoiceno.com). Browser-based generators and calculators for invoices, quotes, receipts, credit notes, and similar documents. No account is needed. The content you enter is processed locally on your device and is not sent to or stored on our servers. This is described in section 3.
-
The Account Service (app.invoiceno.com). An optional account-based product. When you sign in, your data is stored on our servers so it is saved and syncs across your devices. This is described in section 4.
If you only use the Free Tools, sections 4 and 5 do not apply to you, except for the limited website data in section 3.
3. The Free Tools: data that stays on your device
When you use the Free Tools, the document content you enter (such as your business details, client names, line items, and amounts) is held in your browser and, where you choose, saved in your browser's local storage on your own device. We do not receive, transmit, or store this content on our servers, and we cannot see it.
Even so, visiting the website involves some limited processing:
- Server and security logs. Our hosting and network providers automatically process technical data such as your IP address, browser type, and the time of your request, to deliver the site and keep it secure. This is described in section 7.
- Approximate country detection. To show the right tax fields, the site may detect your country from your connection. The IP address itself is not stored by us; only the resulting country code may be saved as a preference in your browser.
- Cookies and similar technologies. See section 6. Analytics and advertising technologies run only where you have given consent.
4. The Account Service: data we store on our servers
When you create an account and use app.invoiceno.com, we store the following on our servers (primarily in our Supabase database):
- Account and sign-in data. Your email address and the authentication data needed to sign you in. We sign you in using a one-time link or code sent to your email ("magic link"), so we generally do not store a password.
- Your business profile. The details you save as your own identity on documents, such as your business name, address, logo, signature, default currency, and language or country preferences.
- Your clients. Details you save about your clients, such as their name, address, contact details, currency, and any tax identifiers you enter (for example a VAT ID, GSTIN, or ABN).
- Your projects and documents. Your projects and the documents you create or save (invoices, quotes, receipts, credit notes, and similar), including the information on them, such as descriptions, line items, amounts, dates, and payment status. This is your invoice and document history.
- Subscription and billing data. Your plan, subscription status, and a reference that links your account to your customer record at Stripe. Payments are processed by Stripe. We do not receive or store your full card number; that is handled by Stripe (see section 7).
- Usage and technical data. Log and device data processed by our hosting and network providers to run and secure the app, and limited records needed to operate features such as the trash and restore function.
We use this data to create and run your account, to store and sync your documents and clients across devices, to provide the dashboard and status tracking, to process your subscription and payments, to provide support, to keep the Service secure, and to meet our legal obligations. The legal grounds for each purpose are in section 8.
5. Personal data of your own clients
When you use the Account Service, you may enter personal data about other people, such as your clients and their contacts. For that data, you decide why and how it is used. Under the GDPR you are the controller of your clients' personal data, and we act as your processor, handling it on your behalf and on your instructions only to provide the Service to you. Under India's DPDP framework, a similar split applies, with you as the Data Fiduciary for your clients' data.
You are responsible for having a proper basis to enter your clients' personal data into the Service and for meeting your own obligations toward them. If you need a data processing agreement to document this relationship, contact us at privacy@invoiceno.com.
6. Cookies and similar technologies
We use cookies and similar browser storage for three purposes:
- Strictly necessary. Required to run the site and the app, including keeping you signed in and remembering your consent choices. These do not require consent.
- Analytics. To understand how the Service is used so we can improve it. These run only with your consent.
- Advertising. On the free site, to serve and measure ads through Google. These run only with your consent.
Where consent is required, we ask for it through our cookie consent banner, and you can change or withdraw your choice at any time using the cookie settings. In Germany and the EU, the storing of and access to information on your device is also governed by the applicable telecommunications and telemedia data protection rules, and we rely on your consent for any non-essential storage.
7. Providers and recipients of your data
We use a small number of trusted service providers ("processors") to run Invoice No. They process data on our behalf under contracts that require them to protect it. We do not sell your personal data.
The main providers are:
| Provider | What they do | Data involved |
|---|---|---|
| Supabase | Database, authentication, and storage for the Account Service | Account, profile, clients, projects, documents, and related data |
| Stripe | Payment processing for subscriptions | Billing and payment data, including card details handled directly by Stripe |
| Vercel | Website and app hosting and delivery | Technical and log data, including IP address |
| Vercel Analytics | Privacy-focused usage analytics | Aggregated usage and technical data |
| Google Analytics | Usage analytics (consent-based) | Usage and device data, online identifiers |
| Google AdSense | Advertising on the free site (consent-based) | Online identifiers and advertising data |
| Cloudflare | Network, content delivery, and security | Technical and log data, including IP address |
| Resend | Email delivery for sign-in (magic-link) and account emails | Email address and email delivery data |
Our Supabase database is hosted in the European Union (Frankfurt region), so your primary Account Service data is stored in the EU. Some of our processors are based outside the EU — including Resend for email delivery and our US-based analytics and advertising providers — so international transfers still apply to that data, with the safeguards described in section 10.
We may also disclose personal data where we are legally required to (for example, to comply with a lawful request from an authority), or to establish, exercise, or defend legal claims, or in connection with a reorganisation, merger, or sale of the business, in which case your data remains protected under this policy.
8. Legal bases for processing (GDPR)
Where the GDPR applies, we rely on the following legal bases:
- Performance of a contract (Article 6(1)(b)). Creating and running your account, storing and syncing your documents and clients, providing the dashboard, and processing your subscription and payments.
- Consent (Article 6(1)(a)). Analytics and advertising cookies and similar technologies. You can withdraw consent at any time, which does not affect processing carried out before withdrawal.
- Legitimate interests (Article 6(1)(f)). Keeping the Service secure, preventing abuse and fraud, maintaining and improving the Service, and essential logging. Where we rely on legitimate interests, we balance them against your rights, and you can object as described in section 11.
- Legal obligation (Article 6(1)(c)). Keeping records we are required to keep, for example tax and accounting records relating to payments.
9. How long we keep your data
We keep personal data only as long as we need it for the purposes above, or as the law requires.
- Account data, clients, projects, and documents. Kept while your account is active. When you delete a document, it goes to trash and can be restored for 30 days, after which it is permanently deleted. When you delete your account, your account data is deleted, subject to the legal retention below.
- Payment and accounting records. Records relating to your payments and our own accounting are kept for up to 10 years, as required by German tax and commercial law.
- Backups. Deleted data may remain in routine backups for a limited period before it is overwritten.
- Analytics and advertising data. Kept for the period set by the relevant provider and your consent settings.
10. International data transfers
Some of our providers are based in, or transfer data to, countries outside the European Economic Area, including the United States. Where this happens, we rely on appropriate safeguards required by the GDPR, in particular the European Commission's Standard Contractual Clauses, and, where a provider is certified, the EU-US Data Privacy Framework. You can request more detail about these safeguards at privacy@invoiceno.com.
For users in India, personal data may be processed outside India, subject to any restrictions set by the Indian government under the DPDP framework.
11. Your rights
You have rights over your personal data. To exercise any of them, contact us at privacy@invoiceno.com. We will respond within the time the applicable law requires. We may need to verify your identity before acting on a request. You can use the export and delete functions in the app to exercise some of these rights directly.
11.1 If you are in the EU, EEA, or UK (GDPR)
You have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected and incomplete data completed;
- have your data erased in certain circumstances;
- restrict or object to certain processing, including processing based on legitimate interests;
- receive your data in a portable, machine-readable format and have it transmitted to another provider where technically feasible;
- withdraw any consent you have given, at any time; and
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (we do not carry out such processing).
You also have the right to lodge a complaint with a data protection supervisory authority. Our competent authority is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Promenade 18, 91522 Ansbach, Germany. You may also complain to the authority in your own country.
11.2 If you are a California resident (CCPA/CPRA)
Subject to the limits in the law, you have the right to:
- know what categories of personal information we collect, the sources, the purposes, and the categories of recipients;
- access the specific pieces of personal information we hold about you;
- delete your personal information;
- correct inaccurate personal information;
- opt out of the sale or sharing of your personal information; and
- not receive discriminatory treatment for exercising your rights.
We do not sell your personal information for money. However, the advertising technologies on our free site may involve "sharing" your information for cross-context behavioral advertising, as that term is defined under California law. You can opt out of this by adjusting your cookie settings, declining advertising cookies, or using a recognised opt-out preference signal such as Global Privacy Control (GPC), which we honour. You may also use an authorised agent to make a request on your behalf.
11.3 If you are in India (DPDP Act, 2023)
As a Data Principal, you have the right to:
- access a summary of the personal data we process about you and how we process it;
- correct, complete, update, or erase your personal data;
- nominate another individual to exercise your rights in the event of your death or incapacity;
- withdraw your consent at any time, as easily as you gave it; and
- have your grievances addressed.
We act as a Data Fiduciary for your personal data. For any grievance, contact our grievance contact at privacy@invoiceno.com, and we will respond within the timeframe required under the DPDP Rules (within 90 days for grievance redressal). If your consent is withdrawn, we will stop the related processing and delete the data unless we are required to keep it by law.
12. Children
The Service is not directed at children and is intended for users aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it. Where the law requires verifiable parental consent for a minor's data, we do not process such data without it.
13. How we protect your data
We use reasonable technical and organisational measures to protect personal data, including encryption of data in transit, access controls, and the use of reputable infrastructure providers. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your data and to respond appropriately to any incident.
14. Data breaches
If a personal data breach occurs that is likely to create a risk to you, we will assess it and notify the competent authorities and affected individuals where and within the timeframes the law requires. This includes notifying the relevant supervisory authority under the GDPR and the Data Protection Board and affected individuals under India's DPDP framework, as applicable.
15. Automated decision-making and profiling
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. Advertising shown on the free site may involve profiling by Google based on cookies and identifiers; this happens only with your consent, and you can withdraw it through your cookie settings.
16. Changes to this policy
We may update this policy, for example to reflect changes to the Service, our providers, or the law. We keep a version number and a "last updated" date at the top of this page and keep prior versions on record. If we make a material change to how we handle your personal data, we will take reasonable steps to inform you, for example by email to account holders or a notice in the Service, before the change takes effect where the law requires.
17. Contact
For any question about this policy or your personal data, or to exercise your rights, contact:
Vipplov Choudhary, c/o COCENTER, Koppoldstr. 1, 86551 Aichach, Germany privacy@invoiceno.com
End of Privacy Policy.