Privacy Policy

Last updated: August 12, 2026

1. Introduction

This Privacy Policy explains what we collect and why. It applies to the invoicemaster.org website and the Invoice Master app. We follow GDPR and other applicable laws.

For account, billing, support, and website data, the controller is Enrique Moreno Tent (sole proprietor), operating Invoice Master, Trachauerstraße 5, 01139 Dresden, Germany. Email: support@invoicemaster.org.

For personal data customers add to their workspaces, the customer generally acts as controller and Invoice Master acts as processor under the Data Processing Agreement.

2. Data we collect

  • Account data — name, email, password hash, company details, billing info.
  • Workspace content — invoices, quotes, contacts, items, and files you upload.
  • Support data — messages you send to our support channels (e.g., chat or email).
  • Technical data — IP address, device, browser, and basic event logs.

3. Why we use your data

  • Provide and secure the service (contract).
  • Billing, taxes, and account notices (contract and legal duty).
  • Fraud prevention and service integrity (legitimate interests).
  • Product analytics and experience improvements in the app (consent where required).
  • Pricing currency personalization on the website (consent).
  • Support and troubleshooting (contract and legitimate interests).

4. Service providers

We use these providers to run, secure, monitor, and support the service:

  • Supabase (primary project region in Germany; other locations under its DPA) — database, file storage, authentication, scheduled jobs, and database backups.
  • Render (backend service region in Germany; other locations under its DPA) — backend hosting and API request processing.
  • Netlify (global delivery network) — browser-application and website hosting, deployments, and connection metadata.
  • Stripe (EU and US) — Invoice Master subscriptions and customer-enabled invoice payments.
  • Resend (Ireland for email dispatch; US for account data and provider records) — transactional email delivery and delivery records.
  • Zoho Mail (EU and provider locations) — support and account email.
  • Sentry (US and provider locations) — server and Android error monitoring and consent-based browser monitoring.
  • Unlayer (US and provider locations) — the optional custom email-template editor.
  • Crisp (EU storage and global relay locations) — optional support chat in the Web and Portal applications.
  • Hotjar (EU and provider locations) — optional, consent-based website and product-usage analysis.

Providers that process Customer personal data on a Customer's behalf are also covered by the DPA. Consent controls described below still apply to optional Hotjar, Crisp, Sentry browser monitoring, and currency-personalization features.

We also use the following providers for data for which Invoice Master generally acts as controller:

  • Googleoptional Google sign-in and delivery of a Google profile image when the user chooses that sign-in method.
  • Google Analyticsoptional, consent-based public-website analytics.
  • ipapi.cooptional, consent-based pricing-currency estimation from the visitor’s IP address.

Opening an external destination such as Google Maps or Discord sends the information included in that request directly to that provider.

5. Cookies and consent

We show a consent banner where optional third-party services are used. We only run Google Analytics, Hotjar, and ipapi.co after you accept optional services.

  • Essential — login, security, and load balancing.
  • Analytics (consent) — Google Analytics and Hotjar.
  • Support — Crisp chat may set cookies when you open chat.
  • Monitoring (consent in the browser) — Sentry browser monitoring. Server and Android crash monitoring operate as necessary security and reliability controls.
  • Currency personalization (consent) — ipapi.co may receive your IP address when we estimate local pricing currency.

6. Sharing

We do not sell personal data. We share data with our providers listed above only to deliver the service.

7. Security

We use TLS encryption in transit, provider and application permissions, and restricted access to production Customer data and configuration. The staff login that controls Netlify deployments uses multi‑factor authentication. This does not mean every provider or Customer login currently requires multi‑factor authentication. Never share your password or verification codes with anyone.

8. Retention and deletion

  • We keep account data while your account is active.
  • Cancellation does not delete data. Use the export before deletion guide to download records you need before deleting the account.
  • After you confirm account deletion, we delete your sign-in account and remove most active workspace records from the primary application database. Uploaded files and some technical or workspace records may remain in active systems.
  • Billing records, security logs, provider backups, transactional email records, and data held by service providers may also remain under applicable retention settings or where retention is legally required.

9. Your rights

  • Access your personal data and ask us to correct or delete it.
  • Ask us to restrict certain processing or object to it where these rights apply.
  • Receive personal data you provided in a structured, commonly used, machine-readable format where data portability applies.
  • Withdraw consent for optional third-party services at any time in the banner or by contacting support.
  • Complain to your local data protection authority.

10. International transfers

Some providers process data outside the EEA. Where required, we use the applicable provider DPA, Standard Contractual Clauses approved by the European Commission, or another approved transfer mechanism.

11. Contact and updates

Questions: support@invoicemaster.org. We update this page as needed and change the date above.