Privacy

What we hold, and what you can do about it.

No lawyer language where a plain sentence works. This describes the product as it actually behaves, not a template someone filled in.

Last updated
September 11, 2026
Effective
September 11, 2026
Contents
  1. 01Who we are
  2. 02What we collect
  3. 03Why we have it
  4. 04Your clients’ information
  5. 05The free invoice generator
  6. 06Cookies and analytics
  7. 07Who else handles it
  8. 08How long we keep it
  9. 09Your choices
  10. 10Security
  11. 11Changes to this page
01

Who we are

Invoframe is an invoicing tool. You design an invoice document and the email it travels in, send them together, and follow the invoice until it is paid. The service is operated from invoframe.com.

This page explains what we hold, why we hold it, and what you can do about it. It describes the product as it actually works today. If something here stops matching the product, the page is wrong and we want to hear about it.

02

What we collect

Everything below is either something you typed, something the product has to store to work, or a delivery record for mail we sent for you. We do not buy data about you, and we do not build advertising profiles.

Your account
Your email address, and your name once you set it. If you sign in with Google we receive your name, email address, and profile picture from Google. There is no password, so we never hold one.
Your workspace
Company name, contact email, address, tax ID, and a logo if you upload one. These are the details printed on your invoices.
Your work
Clients, catalogue items, invoices and their line items, payments you record, and the templates, fields, and groups you build.
Mail we sent for you
For each invoice, reminder, or receipt sent from your workspace: the recipient, the subject, the delivery status, and a copy of the message as it was sent, so you can see exactly what your client received. If the message is opened, we record that it was opened.
Activity
A log of actions taken in your workspace (an invoice created, a payment recorded, a teammate removed) so the workspace has a history you can read.
Technical
Ordinary server logs from our host, which include IP addresses and are kept briefly. We use an IP address in memory to rate limit our public pages so they cannot be abused.
03

Why we have it

To run the service you asked for. Your account details identify you and let you sign in. Your workspace and your work are the product: without them there is no invoice to render and nothing to track.

To send mail on your behalf. When you send an invoice, we deliver it from our sending domain under your name, with replies pointed at your own inbox.

To keep the service working and honest: preventing abuse of the public pages, diagnosing failures, and keeping a record of what was sent in case a client says they never received it.

04

Your clients’ information

When you add a client or send an invoice, you are giving us information about somebody else. That information belongs to your relationship with them, not to us. You decide what to collect and what to send; we store it and deliver it on your instruction, and we do not contact your clients for our own reasons.

You are responsible for having a proper reason to hold your clients’ details and for telling them how you use them. If one of your clients asks you to remove their information, you can delete the client record and their invoices from your workspace, or ask us and we will do it.

05

The free invoice generator

The invoice generator at /invoice-generator works without an account. What you type is sent to our server so it can draw the PDF, and it is not saved: the file is built, handed back to your browser, and the details are gone. No account is created and no record is kept.

That changes only if you choose to send the invoice by email. Sending requires verifying your email address with a one time code, which creates your account, and at that point the details you typed become your workspace, your client record, and your invoice, exactly as if you had typed them inside the product.

06

Cookies and analytics

We set a cookie to keep you signed in. Without it the product cannot tell one request from another, so it cannot be turned off while you are using your account. Your theme choice is kept in your browser and never leaves it.

We use Google Analytics to count visits and see which pages people use, so we know whether the site is working. A Google Ads tag is also present on the site from an earlier advertising campaign. If you would rather not be measured, any standard tracker blocker stops both, and the product itself keeps working normally.

07

Who else handles it

We keep this list short on purpose. Each of these does one job, and we do not sell or rent your information to anyone.

Vercel
Hosts the site and runs the application.
Neon
Hosts the database where your workspace is stored.
Resend
Delivers the email we send for you, and reports back whether it arrived, bounced, or was opened.
Google
Sign in with Google, if you choose it, plus the analytics and advertising tags described above.
08

How long we keep it

Your workspace and everything in it stays until you delete it. Deleting your workspace in Settings removes the workspace and the records attached to it: clients, invoices, line items, payments, templates, the activity log, and the sending log.

If you join a team and your own solo workspace is closed as part of that move, we keep a marker of it rather than erasing it outright, so the change can be reversed if it was a mistake. Ask us and we will remove that too.

Server logs at our host roll off on their own after a short period. Mail already delivered to your client is in their inbox and is no longer ours to delete.

09

Your choices

You can read and change almost everything yourself: your name in your profile, your company details in Settings, and any client or invoice from the page it lives on.

You can delete your workspace at any time from Settings, which is immediate and cannot be undone. If you want a copy of your data before you go, or you want us to delete something we have not given you a button for, write to us and we will handle it. We do not charge for any of this, and we will not ask you why.

Depending on where you live you may have formal rights to access, correct, export, or erase what we hold about you, and to object to some of it. Ask and we will do it, whether or not the law where you are requires it.

10

Security

There is no password to steal: signing in uses a one time code sent to your email, or your Google account. Traffic to the site is encrypted, and your workspace is separated from every other workspace at the database level so one account cannot read another.

No service can promise perfect security, and we will not pretend otherwise. If something happens that affects your data, we will tell you what happened rather than quietly hoping you do not notice.

11

Changes to this page

When the product changes in a way that changes this page, we update the page and move the date at the top. If a change matters to you, for example a new company handling your data, we will say so directly rather than leaving you to spot the edit.

Questions about any of this, or a request about your own data, go to our contact page or straight to support@invoframe.com. A person reads it. See also the terms of service.