Privacy Policy
Last updated: September 19, 2026
This Privacy Policy explains how Invoice24 handles information. It is a practical starting template, not legal advice. Review it with counsel for your jurisdiction and update processor names if they change.
1. Who we are
Invoice24 ("we", "us") provides a web invoice generator at invoice24.online (and related domains). This policy covers guest use and optional accounts.
2. Information we collect
Account data
If you sign up: email address, password (stored hashed) when using email sign-in, optional business name, plan/role, and account timestamps. Social sign-in (Google, Facebook, Apple, Samsung) may also provide a verified email, display name, and profile image from that provider.
Invoice and business data
Content you enter into invoices (sender/customer details, line items, notes, terms, logos, emails for send, and related fields). Guest drafts may stay in your browser storage; cloud drafts and history are stored when you use account features.
Technical data
Standard server and security logs (such as IP address, user agent, timestamps), session cookies needed to keep you signed in, and theme preference stored locally on your device.
Communications
If you contact support or request a password reset, we process the email and message content needed to respond.
3. How we use information
- Provide, secure, and improve the Service
- Create and manage accounts; authenticate sessions
- Save drafts, history, and business preferences you request
- Send invoices or password-reset messages when you ask
- Enforce Terms, prevent abuse, and comply with law
We do not sell your personal information. We do not use your invoice content to train public AI models.
4. Processors and subprocessors
We use trusted service providers to operate Invoice24. Depending on configuration, this may include:
- Hosting / app delivery (e.g. Vercel)
- Database (e.g. Neon Postgres)
- Transactional email (Microsoft 365 SMTP)
- Logo images (currently stored with your invoice data; object storage such as Vercel Blob may be used later)
- Authentication session handling (Auth.js)
Providers process data under their own terms and only as needed for the Service.
5. Cookies and local storage
We use essential session cookies for sign-in. The generator may store drafts and preferences in your browser (localStorage / sessionStorage) so guest mode works without an account. Theme preference is also stored locally. We do not currently rely on third-party advertising cookies.
6. Retention
Account and cloud invoice data are kept while your account is active and for a reasonable period afterward if needed for backups, disputes, or legal obligations. Guest local drafts remain on your device until you clear them. You may delete cloud invoices or request account deletion through available product controls or by contacting us.
7. Security
We use industry-standard measures such as hashed passwords, HTTPS, and access controls. No method of transmission or storage is 100% secure; use a strong unique password and keep your devices protected.
8. Your choices and rights
Depending on where you live, you may have rights to access, correct, export, or delete personal data, or to object to certain processing. Guest users can clear browser storage. Account users can manage many records in-product. Contact us to exercise additional rights.
9. International transfers
Your information may be processed in countries where we or our providers operate. Those countries may have different data-protection laws than your home country.
10. Children
Invoice24 is intended for business and adult users. We do not knowingly collect personal information from children under 16 (or the age required in your region).
11. Changes
We may update this policy from time to time. The "Last updated" date at the top will change. Continued use after updates means you accept the revised policy where permitted by law. Material changes may also be highlighted in-product or by email when appropriate.
12. Contact
Privacy questions: use the contact email published on Invoice24 and reference "Privacy Policy".
Related: Terms of Service.