Privacy Policy
Last updated: August 2026
This Privacy Policy describes how InvoiceSpec processes personal data when you use our website and API. It is written for developers and operators who use the service, as well as for the individuals whose data may appear in invoices processed through the platform.
1. Data controller
InvoiceSpec is the data controller for personal data collected through the website and API. For data subject requests or questions about this policy, please contact us at support@invoicespec.com.
2. What personal data we collect
- Account data: email address, authentication credentials managed by Supabase Auth, and dashboard activity.
- Billing data: subscription status, credit balance, and transaction records processed by Stripe. We do not store complete payment card numbers — Stripe handles those directly.
- API usage data: request timestamps, endpoint, operation code, credit consumption, HTTP status, request ID, and authenticated API key identifier. This is stored in
api_logsfor operational and billing purposes. - Invoice content: data you submit to the API for generation or validation, including seller/buyer names, addresses, identifiers, line items, and totals. We process this data to produce the requested document and then retain it only as described below.
- Technical data: IP address, browser type, and request headers via Vercel and our hosting infrastructure, used for security, rate limiting, and debugging.
3. How we use personal data
- To provide the invoice generation and validation service.
- To authenticate users, manage API keys, and enforce access controls.
- To meter usage, enforce rate limits, and manage credits.
- To process payments and maintain billing records.
- To operate, secure, and improve the platform, including debugging and fraud prevention.
- To communicate service updates, billing issues, or security notices when necessary.
4. Legal basis for processing
We process personal data on the following legal grounds under the GDPR:
- Performance of a contract: providing the API service, billing, and account management.
- Legitimate interests: security, fraud prevention, platform stability, and debugging.
- Legal obligation: tax, accounting, and regulatory compliance.
- Consent: non-essential cookies and analytics, where required.
5. Data retention
- Invoice content: we do not persist submitted invoice data after the request completes. Generation input is processed in memory and the output is returned to the caller. Temporary data may appear in logs for a short period for debugging purposes.
- Account and billing data: retained as long as the account is active, and for the period required by applicable tax and accounting laws after closure.
- API logs: retained for billing and operational analysis, then deleted according to the account plan retention window.
- Technical logs: retained for up to 30 days for security and debugging purposes.
6. Subprocessors and third parties
We use carefully selected service providers to operate the platform. Personal data may be shared with:
- Supabase — database, authentication, and vault secrets.
- Stripe — payment processing and subscription management.
- Vercel — web hosting and edge network.
- Coolify on Oracle Cloud — backend API hosting.
We do not sell personal data. Subprocessors are contractually bound to process data only on our behalf and in compliance with applicable data protection law.
8. Security
We use TLS for data in transit, hashed API key storage with a pepper, role-based database access, and isolated secrets in Supabase Vault. Access to production infrastructure is limited and audited. Despite these measures, no system is completely secure, and users are responsible for safeguarding their own API keys.
9. Your rights under the GDPR
Depending on your location, you may have the right to access, correct, delete, or restrict processing of your personal data, as well as the right to data portability and to object to processing. To exercise these rights, contact us at support@invoicespec.com. We will respond within the timeframe required by applicable law.
10. International transfers
Our infrastructure is hosted in the EU (Germany region for Render/Coolify and Supabase Frankfurt). Stripe and Vercel may process data in additional regions under their own standard contractual clauses and data processing agreements. We take steps to ensure that any international transfer of personal data is protected by appropriate safeguards.
11. Children
The service is not directed to individuals under 18, and we do not knowingly collect personal data from children.
12. Changes to this policy
We may update this policy as the service or legal requirements change. Material changes will be communicated through the dashboard or by email. Continued use of the service after the effective date constitutes acceptance of the updated policy.
13. Contact
For privacy-related questions or data subject requests, contact us at: support@invoicespec.com
Need help? Visit the documentation or contact us.