This Privacy Policy describes how convoinvoice ("convoinvoice," "we," "us," "our") collects, uses, stores, and protects information when you use our invoicing service, website, and related applications (collectively, the "Service"). By using the Service, you agree to the practices described below.
1. Information we collect
We collect only what we need to operate the Service well. That includes:
- Account information — your name, email address, password (encrypted), and optionally business name, logo, and payment details.
- Invoice content — anything you type into convoinvoice: client names, descriptions of work, amounts, dates, and related metadata.
- Usage data — basic, anonymized telemetry about how the Service is used (pages visited, features triggered, error logs). We do not sell this data.
- Technical information — device type, browser, IP address (used briefly for security and abuse prevention), and standard server logs.
2. How we use information
We use your information to:
- Provide, maintain, and improve the Service.
- Process invoices, generate PDFs, and deliver them when you instruct us to.
- Send transactional emails (receipts, password resets, important account notices).
- Respond to support requests.
- Detect and prevent fraud, abuse, or security incidents.
- Comply with applicable legal obligations.
We do not use your invoice content to train AI models. The AI that drafts invoices runs on third-party large language model APIs configured with no-retention contracts; prompts are not retained for training by those providers.
3. Sharing and disclosure
We do not sell your personal information. We share information only with:
- Service providers who help us run convoinvoice (hosting, payment processing, email delivery, customer support tooling), bound by confidentiality and data-processing agreements.
- Legal authorities, where required by law, valid legal process, or to protect rights, safety, or property.
- Successors in the event of a merger, acquisition, or asset sale — and only with notice to you.
4. Data storage and security
Your data is encrypted in transit (TLS) and at rest (AES-256). We host on reputable cloud infrastructure in the EU and US. Access is restricted to a small number of authorized personnel.
No system is perfectly secure. If a breach occurs that materially affects your data, we will notify you within 72 hours of becoming aware of it.
5. Your rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you.
- Correct or update inaccurate information.
- Delete your account and associated data.
- Export your data in a portable format (CSV, JSON, PDF).
- Object to or restrict certain processing.
- Lodge a complaint with a data-protection authority.
To exercise any of these rights, email privacy@convoinvoice.demo. We respond within 30 days.
6. Cookies and tracking
We use a minimal set of first-party cookies necessary for authentication and preferences. We use one privacy-respecting analytics tool (no third-party advertising trackers). You can disable cookies in your browser, though some features may not work properly.
7. Children
convoinvoice is not intended for individuals under 16. We do not knowingly collect data from children. If you believe we have, contact us and we will delete it.
8. International transfers
If you access the Service from outside the country where our servers are located, your data may be transferred internationally. We rely on standard contractual clauses or equivalent safeguards where applicable.
9. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced by email or in-app notice at least 14 days before they take effect. Continued use of the Service after the effective date constitutes acceptance.
10. Contact
Questions, concerns, or requests? Email privacy@convoinvoice.demo, or use the contact form on our Contact page. We read every message.