Privacy Policy
Last updated: 21 May 2026 · InvoiceFlow ("we", "us")
1. Introduction
This Privacy Policy explains how InvoiceFlow collects, uses, stores, and protects personal data when you use our invoicing and business platform. We comply with India's Digital Personal Data Protection Act, 2023 (DPDP) and applicable laws. By using the service, you consent to this policy.
2. Data we collect
- Account data: name, email, phone, business details, GSTIN, PAN, bank identifiers, timezone.
- Client & invoice data: client names, emails, invoice line items, amounts, currencies, PDFs.
- Compliance documents: FIRC, contracts, tax files uploaded to the Vault (up to 50 MB per file).
- Payment records: amounts, platforms (Wise, Razorpay, etc.), FX rates, reference numbers.
- Usage & technical data: IP address, browser type, logs for security and debugging.
- AI prompts: text you submit for invoice or contract generation (processed via third-party AI APIs).
3. How we use data
We use your data to provide invoicing, analytics, compliance storage, billing, support, fraud prevention, and product improvement. We do not sell your personal data.
4. Third-party processors
- Clerk — authentication and session management.
- Razorpay — subscription payments (PCI-DSS compliant).
- Cloud hosting (e.g. AWS) — application and database hosting; primary region India where configured.
- Email provider (e.g. Resend) — transactional emails for invoices and reminders.
- AI providers (e.g. OpenAI) — processing prompts you submit; prompts may be sent outside India subject to provider terms.
5. Retention
Account and invoice data are retained while your account is active. After account deletion, we delete or anonymize data within 90 days except where law requires longer retention (e.g. tax records for 6–8 years).
6. Your rights (DPDP)
You may request access, correction, erasure, or grievance redressal by emailing support@invoiceflow.com. We will respond within 30 days.
7. Cross-border transfer
Some processors (Clerk, AI, email) may store data outside India. We use contractual safeguards and only share what is necessary to operate the service.
8. Security
We use TLS encryption in transit, access controls, and regular backups. No method is 100% secure; report issues to support@invoiceflow.com.
9. Grievance officer
Grievance Officer: InvoiceFlow Support
Email: support@invoiceflow.com
Response timeline: within 30 days of verified request.
10. Contact
Contact page · support@invoiceflow.com