Privacy Policy

Last updated: August 2026

This Privacy Policy describes how InvoiceSpec processes personal data when you use our website and API. It is written for developers and operators who use the service, as well as for the individuals whose data may appear in invoices processed through the platform.

1. Data controller

InvoiceSpec is the data controller for personal data collected through the website and API. For data subject requests or questions about this policy, please contact us at support@invoicespec.com.

2. What personal data we collect

  • Account data: email address, authentication credentials managed by Supabase Auth, and dashboard activity.
  • Billing data: subscription status, credit balance, and transaction records processed by Stripe. We do not store complete payment card numbers — Stripe handles those directly.
  • API usage data: request timestamps, endpoint, operation code, credit consumption, HTTP status, request ID, and authenticated API key identifier. This is stored in api_logs for operational and billing purposes.
  • Invoice content: data you submit to the API for generation or validation, including seller/buyer names, addresses, identifiers, line items, and totals. We process this data to produce the requested document and then retain it only as described below.
  • Technical data: IP address, browser type, and request headers via Vercel and our hosting infrastructure, used for security, rate limiting, and debugging.

3. How we use personal data

  • To provide the invoice generation and validation service.
  • To authenticate users, manage API keys, and enforce access controls.
  • To meter usage, enforce rate limits, and manage credits.
  • To process payments and maintain billing records.
  • To operate, secure, and improve the platform, including debugging and fraud prevention.
  • To communicate service updates, billing issues, or security notices when necessary.

5. Data retention

  • Invoice content: we do not persist submitted invoice data after the request completes. Generation input is processed in memory and the output is returned to the caller. Temporary data may appear in logs for a short period for debugging purposes.
  • Account and billing data: retained as long as the account is active, and for the period required by applicable tax and accounting laws after closure.
  • API logs: retained for billing and operational analysis, then deleted according to the account plan retention window.
  • Technical logs: retained for up to 30 days for security and debugging purposes.

6. Subprocessors and third parties

We use carefully selected service providers to operate the platform. Personal data may be shared with:

  • Supabase — database, authentication, and vault secrets.
  • Stripe — payment processing and subscription management.
  • Vercel — web hosting and edge network.
  • Coolify on Oracle Cloud — backend API hosting.

We do not sell personal data. Subprocessors are contractually bound to process data only on our behalf and in compliance with applicable data protection law.

7. Cookies and tracking

We use only cookies that are strictly necessary for authentication and security. We do not use advertising or third-party analytics cookies by default. Any additional cookies are disclosed through the consent banner and are only set after you provide consent.

8. Security

We use TLS for data in transit, hashed API key storage with a pepper, role-based database access, and isolated secrets in Supabase Vault. Access to production infrastructure is limited and audited. Despite these measures, no system is completely secure, and users are responsible for safeguarding their own API keys.

9. Your rights under the GDPR

Depending on your location, you may have the right to access, correct, delete, or restrict processing of your personal data, as well as the right to data portability and to object to processing. To exercise these rights, contact us at support@invoicespec.com. We will respond within the timeframe required by applicable law.

10. International transfers

Our infrastructure is hosted in the EU (Germany region for Render/Coolify and Supabase Frankfurt). Stripe and Vercel may process data in additional regions under their own standard contractual clauses and data processing agreements. We take steps to ensure that any international transfer of personal data is protected by appropriate safeguards.

11. Children

The service is not directed to individuals under 18, and we do not knowingly collect personal data from children.

12. Changes to this policy

We may update this policy as the service or legal requirements change. Material changes will be communicated through the dashboard or by email. Continued use of the service after the effective date constitutes acceptance of the updated policy.

13. Contact

For privacy-related questions or data subject requests, contact us at: support@invoicespec.com

Need help? Visit the documentation or contact us.