Privacy Policy

Last updated: March 19, 2026

At InvoiceKit, we are committed to protecting your privacy and ensuring you have a positive experience on our platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our invoice generation service.

Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use our services.

1. Information We Collect

Account Information

When you create an account or subscribe to our Pro plan, we collect:

  • Email address
  • Name (full name or business name)
  • Password (encrypted and hashed using industry-standard algorithms)

Invoice Data

Invoice information you create (client names, amounts, line items, etc.) is stored locally in your browser's localStorage. This data is never transmitted to our servers and remains on your device.

No invoice data is stored on our backend systems.

Payment Information

When you subscribe to the Pro plan, payment information (credit card details) is processed securely through Stripe, our payment processor. InvoiceKit never directly receives or stores your credit card information.

Stripe handles all payment processing in compliance with PCI DSS (Payment Card Industry Data Security Standard).

Technical Data

When you use InvoiceKit, we do not collect analytics data, track user behavior, or monitor usage patterns. We do not use Google Analytics, Mixpanel, or similar analytics services.

We may receive basic server logs from our hosting provider (Netlify) for security and system performance purposes only.

2. How We Use Your Information

We use collected information for the following purposes:

  • Account Management: To create and maintain your account, authenticate your identity, and manage your Pro subscription.
  • Service Delivery: To provide invoice generation services and deliver your downloaded PDF invoices.
  • Communications: To send you welcome emails, password reset confirmations, and subscription-related notifications via EmailJS.
  • Payment Processing: To process your subscription payments through Stripe.
  • Security: To detect, investigate, and prevent fraudulent or unauthorized access to your account.

3. Cookies and Local Storage

Cookies

InvoiceKit uses one essential cookie:

ik_saves: This cookie tracks the number of free invoices you have downloaded in the current period. This helps us manage our free plan usage limits.

This cookie is set to expire after a reasonable period and contains no personally identifiable information. We do not use cookies for advertising, tracking, or any purposes other than providing our service.

Local Storage

InvoiceKit uses your browser's localStorage to store the following data on your device:

  • Invoice count (for free plan tracking)
  • Your email address (for account recovery)
  • Your name (for invoice customization)
  • Subscription status (Pro or Free)
  • Invoice data and templates you create

This data is stored locally and never sent to our servers. Clearing your browser's local storage will delete this data.

4. Payment Processing with Stripe

InvoiceKit uses Stripe to process subscription payments securely. When you subscribe to our Pro plan ($2.50/week or $49/year), your payment information is handled directly by Stripe.

What we do not do:

  • We never see or store your full credit card number
  • We never handle your raw payment card data
  • We only receive confirmation of successful transactions from Stripe

For details about how Stripe handles your payment information, please review Stripe's Privacy Policy.

5. Data Storage and Retention

Invoice Data (Local Storage)

Invoice data is stored only in your browser's localStorage. We do not store invoice data on our servers. You are responsible for backing up your invoice data. If you clear your browser data, your invoices will be deleted.

Account Information

Account information (email, name, hashed password) is retained as long as your account is active. You may request deletion of your account at any time by contacting us.

Upon account deletion, your data will be removed from our systems within 30 days, except where we are legally required to retain it.

Payment Records

Payment records are retained by Stripe for billing and tax compliance purposes. We retain subscription records for as long as necessary to comply with legal and tax obligations.

Cookie and Usage Data

The ik_saves cookie expires automatically. We do not retain long-term usage or analytics data.

6. Security

We take the security of your information seriously. Here are the measures we have implemented:

  • Password Security: Passwords are hashed using industry-standard algorithms and never stored in plain text.
  • HTTPS: All communication between your browser and InvoiceKit is encrypted using HTTPS/SSL.
  • Local Storage: Invoice data remains on your device and is never transmitted to our servers.
  • Stripe Integration: Payment processing is handled by PCI DSS-compliant Stripe.
  • No Third-Party Tracking: We do not use advertising networks, analytics providers, or other third parties that track your behavior.
  • Minimal Data Collection: We collect only the minimum data necessary to provide our service.

While we strive to protect your information, no security system is impenetrable. If you suspect unauthorized access to your account, please contact us immediately.

7. Third-Party Services

InvoiceKit integrates with the following third-party services:

We do not share your data with any other third parties. We do not sell your data to advertisers or data brokers.

8. Your Rights and Choices

Data Access and Portability

You have the right to access the personal information we hold about you. You may request a copy of your data by contacting us.

Account Deletion

You may delete your account at any time. When you delete your account, your email, name, and password hash will be removed from our systems within 30 days. Invoice data stored in your browser's localStorage will persist until you manually clear it.

Cookie Control

Most web browsers allow you to control cookies through your browser settings. You can disable or delete the ik_saves cookie, though this may affect your free invoice download tracking.

Marketing Communications

We only send transactional emails (welcome emails, password resets, subscription confirmations). We do not send marketing emails or newsletters. You can opt out of welcome emails by not creating an account.

9. GDPR and Regional Compliance

For EU/UK Residents (GDPR):

If you are located in the European Union or United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR):

  • Right to access your personal data
  • Right to rectify inaccurate data
  • Right to erase your data ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing

To exercise these rights, please contact us at the address provided in the Contact Information section below.

10. Children's Privacy

InvoiceKit is not intended for children under the age of 13 (or the applicable age of digital consent in your region). We do not knowingly collect personal information from children. If we become aware that we have collected information from a child without parental consent, we will delete that information immediately.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by updating the "Last updated" date at the top of this page and, if the changes are significant, by providing you with more prominent notice.

Your continued use of InvoiceKit after changes become effective constitutes your acceptance of the updated Privacy Policy.

12. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

InvoiceKit

Website: https://invoicekit.net

Response Time: We aim to respond to privacy inquiries within 7 business days.

For GDPR requests or data subject access requests (SARs), please include "GDPR Request" in your subject line.

Thank you for trusting InvoiceKit with your invoice generation needs. We are committed to maintaining your privacy and providing a transparent, secure service. Your data security and privacy are our top priorities.