1. Information We Collect
When you use InvoiceMo, we collect:
- Account information: Your name, email address, and profile photo from Google or Facebook OAuth.
- Shop information: Shop name, slug, payment methods, and logo you provide during onboarding.
- Invoice data: Customer names, contact numbers, addresses, items, prices, and payment status of invoices you create.
- Payment proof files: Images uploaded by your buyers as proof of payment. These are stored in Supabase Storage.
- Usage analytics: Page views and feature interactions via PostHog (anonymized).
2. Libre Plan — No Storage
If you use the free Libre plan, no invoice data is written to our database. Your invoice is rendered server-side and returned as a PNG. We do not log or retain any invoice contents from Libre sessions.
3. How We Use Your Information
We use your data to:
- Provide and improve the InvoiceMo service
- Generate invoice PDFs and shareable pages
- Send transactional emails (invoice receipts, payment notifications)
- Manage your subscription
- Prevent fraud and enforce our Terms of Service
We do not sell your data to third parties. We do not use your invoice data for advertising.
4. Data Sharing
We share data only with trusted service providers necessary to operate the Service:
- Supabase — Database, authentication, and file storage (servers in Singapore/US)
- Vercel — Web hosting and serverless functions
- Resend — Transactional email delivery
- Anthropic (Claude API) — AI theme generation (only your theme prompt is sent, not invoice data)
5. Public Invoice Pages
Shareable invoice links (e.g. invoicemo.app/yourshop/inv/abc123) are publicly accessible to anyone with the link. The link contains a cryptographically random 12-character ID that is not guessable. Do not share sensitive personal information in invoice notes beyond what is necessary.
6. Data Retention
Your data is retained for as long as your account is active. If you delete your account, your data will be permanently deleted within 30 days. Cancelled subscribers’ data is retained for 90 days before deletion.
7. Your Rights
Under the Philippine Data Privacy Act (Republic Act 10173), you have the right to:
- Access and obtain a copy of your personal data
- Correct inaccurate data
- Request deletion of your data
- Object to processing of your data
To exercise these rights, email us at privacy@invoicemo.app.
8. Security
All data is encrypted in transit (TLS) and at rest. We use Supabase Row-Level Security to ensure your data is never accessible to other users.
9. Cookies
We use cookies strictly for authentication (Supabase session) and basic analytics (PostHog). We do not use advertising cookies or third-party tracking pixels.
10. Children
The Service is not intended for users under 18. We do not knowingly collect data from minors.
11. Changes to This Policy
We may update this Privacy Policy. Material changes will be communicated via email to active subscribers at least 14 days in advance.
12. Contact
For privacy concerns, contact our Data Protection Officer at privacy@invoicemo.app.