Legal
Privacy Policy
Last updated: 15 March 2026
1. Who we are
AutoInvoice (โweโ, โusโ, โourโ) is an automated invoicing service operated from Ireland. We are the data controller for personal data collected through this service. If you have questions about this policy, contact us at privacy@autoinvoice.ie.
2. What data we collect
We collect the following categories of data:
- Account data: name, email address, and password (managed by Clerk).
- Business data: business name, VAT number (optional, entered by you).
- Client data: your clients' names, email addresses, and service details โ entered by you.
- Invoice data: invoice records, line items, amounts, and status.
- Billing data: subscription plan and status. Payment card details are handled directly by Stripe and never stored by us.
- Usage data: pages visited, actions taken, and device/browser information (via analytics tools).
3. How we use your data
We use your data to:
- Provide and operate the AutoInvoice service.
- Generate and send invoices on your behalf to your clients.
- Process subscription payments via Stripe.
- Send transactional emails (invoice confirmations, payment receipts).
- Improve the service through anonymised usage analytics.
- Comply with our legal obligations.
4. Legal basis (GDPR)
We process your data on the following legal bases under GDPR:
- Contract: to provide the service you signed up for.
- Legitimate interests: to improve the service, prevent fraud, and ensure security.
- Legal obligation: where required by Irish or EU law.
5. Data sharing
We do not sell your data. We share data only with trusted service providers who process it on our behalf:
- Clerk โ authentication and user management (EU data residency available).
- Supabase โ database and file storage (EU region).
- Stripe โ payment processing (PCI DSS compliant).
- Resend โ transactional email delivery.
- PostHog โ product analytics (EU Cloud, GDPR compliant).
6. Data retention
We retain your data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or tax purposes (e.g., invoice records may be retained for 7 years under Irish tax law).
7. Your rights
Under GDPR, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data.
- Request erasure of your data ("right to be forgotten").
- Restrict or object to processing.
- Portability โ receive your data in a machine-readable format.
- Lodge a complaint with the Data Protection Commission (DPC) at dataprotection.ie.
To exercise any of these rights, email privacy@autoinvoice.ie.
8. Cookies
We use essential cookies to keep you logged in and functional cookies for analytics. You will be asked for consent when you first visit the site. You can withdraw consent at any time via the cookie settings in the footer.
9. Changes to this policy
We may update this policy from time to time. We will notify you of material changes by email or via a notice on the site. Continued use of the service after changes constitutes acceptance of the updated policy.