← Back to sign in

Privacy notice

Last updated 9 September 2026

Before publishing Replace every [SQUARE BRACKET] below with your real details, and have this checked by someone qualified. It describes the system accurately as built, but accuracy is not the same as legal sufficiency.

This notice explains what happens to personal data in this invoicing application. It is written to be read, not to be survived.

Who is responsible

The application is operated by [OPERATOR NAME], [COMPANY NUMBER / “a sole trader”], of [REGISTERED ADDRESS]. Questions, requests and complaints: [CONTACT EMAIL].

[If registered with the ICO: “We are registered with the Information Commissioner’s Office, registration number [ICO NUMBER].”]

Two different roles

This matters, because it decides who answers to whom:

What we hold, and why

DataWhere it comes fromWhy
Name, email address, profile picture, Google account identifier Google, when you sign in To identify you and decide what you may see. There is no password to store.
Which businesses you may open, and your role in each Set by an owner of that businessAccess control
Invoices, quotes, client names, addresses, emails, amounts, payments, notes Entered by users of the business To produce and keep the business’s invoices
A change history: who changed which record, when, and a copy of the record Created automatically as records change So a business can see what happened to its own invoices
A session cookieSet when you sign in To keep you signed in. See the cookie notice.

Our lawful bases

What we do not do

These are facts about the system, not promises of intent:

Who else is involved

WhoWhat they seeWhere
Google (sign-in) That you signed in to this application, and your basic profile. We receive your name, email and picture; we discard the access tokens immediately. Google Ireland / United States
[HOSTING PROVIDER — Amazon Web Services (Lightsail)] Holds the server and its disks. Data is stored in [REGION — London, eu-west-2]. United Kingdom
Exchange-rate provider (Frankfurter) Nothing about you. Rates are fetched by our server, not by your browser, so only a currency pair and a date are sent. Your address is never disclosed to them.

Personal data may also be disclosed where the law requires it.

Check before publishing Your web server (Caddy) may keep access logs containing IP addresses. The application itself records none, but if the server does, say so here and give the retention period.

How long it is kept

WhatHow long
Invoices and clientsUntil deleted by the business. Deleted invoices sit in a recycle bin until purged.
Nightly snapshots inside the database90 days
Nightly file backupsThe most recent 30
Sign-in sessions7 days, then expired and deleted
Change historyFor as long as the business keeps the record
User accountsUntil removed. [CONFIRM YOUR PERIOD.]

Because backups are taken nightly, deleted data can persist in a backup for up to 30 backup cycles before it ages out.

Your rights

You may ask us for a copy of your data, to correct it, to delete it, to restrict or object to how it is used, or to receive it in a portable form. Write to [CONTACT EMAIL] and we will respond within one month.

If the request concerns the contents of a business’s invoices, we will pass it to that business, because it is their decision, not ours.

You can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would rather you told us first.

Security

No system is perfectly secure, and we do not claim otherwise.

Changes

If this notice changes materially, we will tell the businesses using the application. The date at the top always reflects the current version.