Privacy Policy
Last updated: 9 September 2026 · Version 1.1
Who to contact
EUInvoice operates this service and decides how the personal data described below is handled. For anything in this policy — a question, a correction, a request to see or delete your data, or a complaint — write to [email protected]. That address reaches a person, and it is the single route for every right described further down.
What we hold
- Your account: email address, a hash of your password, and an optional display name you choose. We never store the password itself.
- Your sign-in sessions: a hash of the session token. The token itself is only ever in your cookie.
- Passkeys, if you register one: the public key, a label you choose, and when it was last used. A passkey's private key never leaves your device.
- Your organisation: legal name, VAT identifier, postal address, IBAN and account-holder name.
- Your contacts: legal name, VAT identifier and address of the businesses you invoice.
- Your documents: invoice and credit-note contents, including a frozen snapshot of the buyer's details as they were when the document was issued, and a recipient email address where you chose to send one.
- Records around those documents: delivery attempts, acceptance or dispute, payment records and reminders.
- Server logs: your IP address, the user-agent string your browser or tool sends, which page or action you requested, whether it succeeded and how long it took. We do not log the contents of what you send, and links that carry a private access code are recorded without that code.
- How you found us: when you create an account we record, as a daily count only, which broad channel you arrived from — a search engine, another site, a campaign link, or directly. We keep the count, never the referring address, and it is never attached to your account.
- Feedback you send us: the message text and when you sent it. From inside the application it is stored against your account. The form on our home page needs no account, and there we hold only the message, the time, and the email address you give us if you would like a reply. It is attached to no account. Your IP address reaches the server log and the anti-abuse check described below, the same as any other page view.
Cookies
We set one cookie: a session cookie, created only after you sign in.
It is first-party, HttpOnly (so no script can read it), SameSite=Lax,
and it expires after 30 days. It is strictly necessary — without it you cannot stay signed in.
Our public pages — this one and the home page — also use
a third-party analytics provider to measure how many people visit and
where they arrive from. It sets _ga and _ga_<id> cookies,
which last up to two years and are read by that provider as well as by us. We use it
only to understand traffic in aggregate; we do not use it to advertise to you, and we do
not link it to your account. Signed-in pages of the application carry no analytics of
any kind.
You can refuse it: block third-party scripts, enable Do Not Track or a content blocker, or install the analytics provider's opt-out browser add-on. Doing so does not affect anything in the application.
Besides that cookie, the application stores one temporary value in your browser's session storage while you are signing up, holding the broad channel you arrived from. It is not a cookie, it is not sent to any third party, it is deleted the moment your account is created, and your browser discards it when you close the tab.
Who else sees your data
- The European Commission (VIES). When you ask us to look up a VAT identifier, we send that identifier to the EU's VAT Information Exchange System to check it. This happens only when you initiate a lookup — never automatically while you type, validate or issue a document.
- Our network provider. Traffic reaches us through a network provider that sits in front of our servers. It terminates the encrypted connection and therefore processes your requests in transit.
- An anti-abuse check on sign-up, sign-in and the feedback form. Those three places run a check that distinguishes a person from an automated script, provided by the same network provider described above. It receives your IP address and basic information about your browser and how it behaves on the page, and it tells us only whether the attempt looks automated. It runs in those three places and nowhere else, and it is not used to recognise you or to build a profile. On the home page it loads with the page, so it is present before you decide to write anything.
- Our mail provider. Mail for our domain is handled by this provider, so anything you email to our support address is processed there.
- Our email-delivery provider. When you create an account, we send an account-verification email through this provider, which processes the email address of every new account for that purpose. It accepts and routes this mail through its EU region, so it stays within the EU.
- Our analytics provider. Visits to our public pages are measured by this provider, which receives the page you viewed, your approximate location derived from your IP address, and your browser details. This happens on the public pages only, never inside the application.
- Our hosting provider, which operates the server this runs on.
One thing worth stating positively, because it is a choice rather than an accident: reading a PDF you upload happens entirely on our own servers — no third-party OCR or document-analysis service is involved. The one email the application sends automatically is an account-verification message when you sign up, delivered through our email-delivery provider, which processes that message on our behalf and routes it through its EU region. We do not use it to track you: it is a one-time message with no tracking pixel and no analytics of any kind.
Why we are allowed to hold it
- Running your account and signing you in — to perform the contract you entered into by creating an account.
- Creating, issuing and storing your documents — to perform that same contract; and, once a document is issued, to meet the record-keeping obligations that tax law places on invoices.
- Checking a VAT identifier against VIES — to perform the contract, at your request. We do it only when you ask.
- Server logs and backups — our legitimate interest in keeping the service running, diagnosing faults and not losing your data. Both are kept for a fixed number of days and then deleted.
- Analytics on our public pages — our legitimate interest in knowing whether anyone is finding the site. It runs on the public pages only and never on a page where you are signed in.
- Counting which channel new accounts arrive from — our legitimate interest in knowing which of our own pages and links work. It is a running total per day with no identifier in it, so it cannot be traced back to you.
- Reading the feedback you send us — our legitimate interest in knowing what people need from the product, so we can decide what to build next. It is not used for anything else. Sent from inside the application it is linked to your account and deleted when you close it; sent from our home page it is linked to no account at all, and the email address you optionally leave is used to reply to you and for nothing else — no newsletter, no list.
How long we keep it
- Share and claim links expire after 30 days. After that the link stops working and the recipient can no longer open the document through it.
- The email-verification link expires after 24 hours, and can only be used once. After that it stops working and, if you still need to verify, you can request a new one.
- Issued invoices are permanent by design. Once a document is issued it cannot be edited or deleted — a correction is made by issuing a credit note. This is what makes the stored document a reliable legal original, and it is also required by tax law.
- Backups are kept for 7 days and then deleted, so data you remove may persist in a backup for up to that long.
- Server logs are kept for 7 days and then deleted automatically, so nothing from them lingers beyond that window.
- Feedback sent without an account is kept until we have acted on it — it is a note about what to build, not a record we need afterwards — and deleted sooner if you ask. Because it is tied to no account, closing an account does not reach it and there is no self-service button for it: write to us and say which message was yours.
- Your account and its documents are kept for as long as the account exists. Issued invoices are kept beyond that where tax law requires it — retention periods for invoices are set by the law of the country you are established in, commonly between seven and ten years, and we keep them for at least as long as that law requires of you.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or send it to another provider. Write to [email protected] and we will respond within one month.
Separately, and stated on its own for that reason: where we rely on our own legitimate interest rather than a contract with you — feedback you send us is one such case — you can object to that use. Write to [email protected]; we will stop unless we have a compelling reason not to, in which case we will tell you what it is.
One limit, stated plainly rather than buried: we cannot delete an invoice you have already issued. Issued documents are immutable and are subject to statutory retention, so a deletion request against them will be refused on that basis. Drafts, contacts, saved templates and passkeys you can delete yourself at any time. Your profile page also has a button to download everything the account holds, and a button to close the account — closing removes your sign-in, your address book, your saved templates, any draft you have not issued and any feedback you have sent from inside the application, and keeps the issued invoices and the businesses named on them for as long as the retention above requires. Feedback sent from our home page is not attached to any account, so neither the download nor the closure can find it — ask us by email and we will delete it.
If you think we have handled your data wrongly, tell us first at [email protected] and we will try to put it right. You also have the right to complain to a data protection supervisory authority — the one in the EU or EEA country where you live, where you work, or where you believe the problem occurred. You do not need our agreement to do that.
Changes
Version 1.1, published 9 September 2026, is the one you are reading. It changes one thing from version 1.0: it sets out what happens to feedback sent from our home page without an account, which we did not offer before. Nothing else about what we hold, why, or for how long has changed.
If this policy changes materially we will update the date above and raise the version number, and any superseded version will be available on request.