InvoiceLoop

Privacy Policy

Last updated: July 25, 2026

This Privacy Policy describes how InvoiceLoop("we", "us") handles information when you use our invoicing service at sendinvoiceloop.com and related domains (the "Service").

1. Who we are

InvoiceLoop is a multi-tenant invoicing product operated as a small independent software service. Contact for privacy questions: the operator email published on the account or support channel you used to reach us.

2. Information we collect

  • Account data: email address and a hashed password (we never store passwords in plain text).
  • Business and client data you enter: business profile, client names and contact details, invoice/quote/time-entry content, logos you upload, and notes you choose to store.
  • Technical data: IP address used for abuse throttling, basic server logs, and session cookies required to keep you signed in.
  • Payment data (Premium): purchases are processed by Freemius. We receive entitlement signals (plan status, Freemius user / license identifiers) — not full card numbers.

3. How we use information

  • Provide and secure the Service (auth, multi-tenant isolation, abuse prevention).
  • Send transactional email (activation, password reset, invoice delivery, reminders).
  • Apply Premium entitlements after a Freemius purchase.
  • Operate, debug, and improve the Service.

We do not sell your personal data.

4. Where data lives (data residency)

  • Application database: PostgreSQL hosted on Supabase in the US East (AWS us-east-1) region.
  • Application compute & CDN: AWS (Lambda + CloudFront), primary region us-east-1.
  • Logo uploads:private Amazon S3 bucket in the app's AWS region, served only through our application routes.
  • Email:transactional mail via our configured SMTP provider (messages may transit that provider's infrastructure).
  • Payments: Freemius (and its payment processors) for Premium checkout.

5. Cookies and sessions

We use a session cookie to keep you signed in after login. We do not use third-party advertising trackers in the app. A local theme preference may be stored in your browser.

6. Sharing

We share data only with infrastructure and service providers needed to run the Service (hosting, database, email, payment entitlement), or when required by law. Public invoice links you create are intentionally reachable by anyone who has the link.

7. Retention

We retain account and business data while your account is active. You may request deletion of your account and associated data by contacting us. Some records (e.g. security logs, payment entitlement receipts) may be retained longer where needed for security, legal, or accounting obligations.

8. Security

Passwords are hashed with a memory-hard algorithm (scrypt). Access to your data is scoped to your account. We apply transport security (HTTPS/HSTS) and other baseline controls; no method of transmission or storage is 100% secure.

9. Your choices

  • Update profile and client data in the app.
  • Rotate public invoice links from an invoice's detail page.
  • Request account deletion by contacting us.

10. Children

The Service is not directed to children under 13, and we do not knowingly collect their personal information.

11. Changes

We may update this policy. The "Last updated" date at the top will change when we do. Continued use of the Service after changes means you accept the revised policy.