Legal & privacy

Privacy should be readable before you trust the workflow.

This policy explains the data CloudInvoice is designed to process when an account owner uses the invoicing product. It is written for transparency, not as a substitute for the service operator’s final, jurisdiction-specific legal notice.

At a glance

CloudInvoice processes the information needed to run your workspace and invoice your clients.

Last updated: August 1, 2026. This policy applies to the CloudInvoice web application at the domain operated by the service provider.

1. Information we process

The data stays tied to the work you ask the product to do.

Account and session data

Examples: Name, email address, authentication records, session expiry, and technical session fields such as IP address or user agent when the authentication system records them.

Why: To create an account, authenticate a user, maintain a signed-in session, and protect the service from misuse.

Workspace and business data

Examples: Organization name, business contact details, address, logo reference, GSTIN, PAN, state code, invoice numbering preferences, and payment configuration references.

Why: To present and operate the workspace the account owner creates.

Client and invoice data

Examples: Client contact and billing details, GSTIN and state code when entered, invoice line items, notes, tax settings, due dates, totals, and payment status.

Why: To create, send, display, and track invoices on behalf of the workspace.

Payment and delivery data

Examples: Stripe payment identifiers, payment amount, currency, payment outcome, the date recorded, and invoice-delivery email address when email sending is configured.

Why: To associate a verified payment outcome with the correct invoice and deliver invoice communications.

2. How information moves

Limited to the services that deliver the product

Service providers

The deployment may use PostgreSQL for application records, a transactional email provider for invoice emails, cloud infrastructure for hosting, and object storage for enabled file features. Each provider should be configured by the operator with appropriate credentials and access controls.

Payment processing

When a client chooses card payment, Stripe Checkout receives the information needed to process that payment. CloudInvoice receives the outcome necessary to reconcile the invoice rather than the client’s full card number.

Legal and operational needs

Information may be disclosed when required by applicable law, to protect the service or people from harm, or as part of a legitimate business transfer. The operator should apply legal review before relying on any such disclosure.

CloudInvoice is not designed to sell client invoice data or turn it into an advertising audience. Its purpose is to provide invoicing and payment-tracking functionality to the workspace that supplied the data.

3. Access, retention, and control

A policy must match the actual operator’s practices.

Your practical controls

  • Workspace access: limit invitations and account access to people who need it.
  • Client records: review and correct the invoice and client details you enter before sharing an invoice link.
  • Payment links: treat a public invoice link as confidential because anyone who has it may see the invoice presentation it serves.
  • Privacy requests: the service operator must supply a monitored privacy contact and a process to verify and respond to requests before public launch.

4. Security and changes

Privacy depends on both product controls and responsible operation.

CloudInvoice uses application-level workspace scoping, opaque invoice links, hosted Stripe Checkout, and signature-verified Stripe webhooks as part of its product security model. Learn more in the Security overview. No system can promise absolute security, so account owners and service operators must also protect credentials, infrastructure access, and exported data.

The operator may update this policy when the product, vendors, or legal requirements change. A material update should include a new effective date and reasonable notice through the product or another appropriate channel. Continued use after an updated policy takes effect is subject to applicable law and any contract governing the account.

This policy should be read alongside the Terms of Service and Cookie Policy. Tax, accounting, and legal obligations remain the responsibility of each workspace owner.

Keep your invoice data organized—and intentional.

Create a workspace with the details your client experience actually needs, then keep access limited to the people you trust.

Get started