Privacy Policy
Effective: September 1, 2026
Privacy at a glance
SnapInvoice does not sell personal data or use your invoices to target ads. We use limited Google Ads conversion measurement on the public/free app as described below. You can use the invoice editor without an account. Account, cloud saving, payment, email delivery, portal, and Pro features require us to process the data described below.
Who is responsible for your data
SnapInvoice, the operator of snapinvoice.io, is the controller for account, subscription, service-security, support, and direct usage data. Contact us at support@snapinvoice.io.
When a SnapInvoice user enters a client's details or sends that client a document, the user normally decides why that client data is processed and is the controller. SnapInvoice acts as the user's processor for that customer content, except where we must process limited data for our own security, fraud-prevention, legal, or billing purposes. If you received an invoice or quote, contact the sender first for requests about its content; you may also contact us for assistance.
Data we process
- Account and identity: email address, authentication records, and, if you choose third-party sign-in, the account identifier, name, email address, and profile picture returned by that provider.
- Profile and customer content: business/contact details, clients, invoices, quotes, line items, payment records you enter, logos, signatures, stamps, notes, and saved settings.
- Document delivery: recipient address, subject, message, document snapshot and PDF, delivery/bounce/complaint status, portal access time and view count, quote responses, and limited reply-forwarding metadata.
- Subscription and transaction metadata: payment-customer, subscription, checkout, plan, status, and transaction identifiers. SnapInvoice does not receive or store full payment-card numbers.
- Security and free-plan usage: public IP address, timestamps, and the SHA-256 hash of a random first-party browser identifier. The un-hashed random value remains in your browser. The hash is pseudonymous personal data; it is not anonymous.
- Support and diagnostics: messages you send us and production error details such as error message, page path without query parameters, browser type, application version, and component stack.
- Advertising measurement: consent signals, IP-derived country group, browser/device information, page URL, ad-click identifiers, and a confirmed Pro-purchase event containing the plan value, currency, and a pseudonymous checkout-attempt ID. We do not send invoice, client, recipient, email, PDF, portal, or account-profile content for advertising measurement.
Why we process data and our legal bases
- Contract: to create and secure your account, save and export documents, provide subscriptions, send documents, operate portals, forward replies, and provide support you request.
- Legitimate interests: to enforce the free-plan allowance, prevent fraud and abuse, secure the service, preserve delivery and billing integrity, and diagnose reliability problems. We balance these interests against user privacy and use pseudonymisation and retention limits.
- Legal obligations: to keep required financial records, respond to lawful requests, handle disputes, and comply with tax, accounting, and consumer-protection rules.
- Consent: for optional advertising storage where prior consent is required and for any other optional feature that relies on consent. Where law permits an opt-out model, limited conversion measurement is based on our legitimate interest in understanding advertising effectiveness, subject to your Privacy settings and browser privacy signal. You may withdraw consent without affecting earlier lawful processing.
Cookies, browser storage, and device access
SnapInvoice's own application does not set authentication cookies. Optional advertising storage may be used for Google Ads conversion measurement, subject to the controls below. It also uses the following technologies that privacy law may regulate similarly to cookies:
- Local storage: keeps anonymous drafts and recent local documents, preferences, free-PDF count, pending checkout state, and authentication session tokens. It remains until the app removes it, you sign out where applicable, or you clear browser data.
- Session storage: keeps short-lived authentication and checkout intent, attempt identifiers, and one-session UI dismissals. Browsers normally remove it when the tab session ends.
- Free-usage browser identifier: a random ID is generated and stored locally when the app checks or reserves a free PDF download. Only its SHA-256 hash and your public IP are sent for quota enforcement, abuse prevention, and related internal audit. The current app does not derive this ID from device or browser characteristics.
- Advertising-measurement preference: your accept or decline choice is stored locally for up to six months so the app can respect it. You can change it at any time through Privacy settings in the app footer. A supported Global Privacy Control browser signal overrides an earlier acceptance and disables optional advertising storage.
On the public/free app, Google Ads Consent Mode starts with advertising storage, advertising user data, personalisation, and analytics storage denied. In the EEA, United Kingdom, Switzerland, Canada, and when location is unavailable, we ask for a choice before enabling optional advertising storage. If you decline, Google may still receive limited cookieless consent and conversion signals for aggregate measurement and modelling, but the tag is instructed not to use optional advertising storage. In selected opt-out jurisdictions (currently the United States, Australia, and New Zealand), measurement may start with optional storage enabled, subject to your local rights, stored choice, and browser privacy signal.
We disable advertising personalisation, remarketing, enhanced conversions, and Google Analytics in this implementation. Marketing measurement is not loaded on legal pages, authentication pages, the admin area, invoice or quote portals, or an ordinary Pro workspace. A one-time confirmed-purchase conversion may be sent after checkout according to the applicable consent state.
Third-party identity and checkout providers may use cookies or similar technology on their own domains when you choose those services. Their notices and controls apply in those third-party contexts.
Documents, email, portals, and uploaded assets
If you send a document through SnapInvoice, we process the recipient, message, PDF, and an immutable document snapshot to perform and evidence delivery. A portal URL is a bearer link: anyone who has an active, unrevoked link can view the document without signing in. Senders can review access activity and revoke the link.
Delivery PDFs are private and exposed only through short-lived download URLs. User logos, signature images, and stamps are stored at public asset URLs so they can render in PDFs, emails, and portals. They are not intended to be listed through the storage API, but anyone who obtains the exact asset URL can retrieve the file. Do not upload an asset you do not want document recipients to receive or that contains unnecessary sensitive information.
When a recipient replies to a supported delivery email, the response is forwarded to the document sender. We retain limited delivery and reliability metadata and do not intentionally store the reply body in the SnapInvoice application database.
Service providers and other recipients
We disclose data only as needed to operate the service, comply with law, protect rights and security, or complete a transaction you request. The categories of recipients we use are:
- Cloud infrastructure providers for hosting, authentication, databases, file storage, and server functions.
- Payment and billing providers for checkout, subscriptions, fraud prevention, payment processing, and billing records.
- Communication providers for transactional email, delivery events, and reply forwarding.
- Reliability and security providers for restricted production error monitoring and service protection.
- Identity providers when you voluntarily choose a third-party sign-in method. We request only basic authentication/profile data, not mailbox, drive, contacts, or calendar access.
- Google for restricted Google Ads conversion measurement on the public/free app and confirmed checkout return. Google processes the limited measurement data under its own terms and Google's Business Data Responsibility site.
We maintain current records of service providers and subprocessors and will provide relevant information on request where required for your data-protection assessment.
We do not sell personal data or use customer content for cross-context behavioural advertising. The limited Google Ads measurement described above is configured without ad personalisation or remarketing and can be controlled through Privacy settings.
International transfers
Providers may process data in the European Economic Area, the United States, and other countries where they or their subprocessors operate. Where required, transfers outside the EEA, United Kingdom, or Switzerland rely on an adequacy decision, Standard Contractual Clauses, the UK Addendum, or another lawful transfer mechanism, together with appropriate safeguards. Contact us to request more information.
Retention
- Anonymous drafts, history, settings, and session data stay in your browser until removed by the app or cleared by you.
- Account profiles, clients, invoices, quotes, and related content remain until you delete the document or account, subject to backups and records we must keep by law.
- Portal links expire based on the document due date and no later than 120 days after delivery creation. Private delivery PDFs are queued for removal 30 days after portal expiry. Delivery history and document snapshots remain with the related document until it or the account is deleted.
- Operational delivery and communication logs are normally kept for no more than 90 days.
- Free-plan quota, security, fraud-prevention, and billing-integrity records are normally kept for no more than 13 months. Short-lived abuse-detection associations are removed within 24 hours.
- Internal administrative audit records are kept for no more than 24 months.
- Support, dispute, tax, accounting, suppression, and payment records may be kept longer where reasonably necessary or legally required. Payment providers keep transaction data under their own legal obligations.
Account deletion removes account content and owned uploaded assets and starts cancellation of any active paid subscription. Limited fraud, security, financial, suppression, and backup records may remain for the periods above or as required by law.
Your privacy rights
Depending on where you live, you may request access, correction, deletion, restriction, or portability of personal data; object to processing based on legitimate interests; withdraw consent; and complain to your local data-protection authority. These rights can be subject to legal exceptions. You can edit common profile data and delete your account in Account settings, or email support@snapinvoice.io. We may need to verify your identity before fulfilling a request.
SnapInvoice does not use personal data for legally significant automated decisions or advertising profiles. Free-PDF access is automatically allowed or limited using account, browser-identifier, and IP counters; this has no legal or similarly significant effect.
Security and children
We use access controls, row-level database policies, encryption in transit, private delivery storage, short-lived links, restricted service credentials, and monitoring. No system is perfectly secure, so protect your password and portal links and contact us if you suspect misuse. SnapInvoice is intended for adults and businesses and is not directed to children under 16.
Changes and contact
We may update this Policy as the service or law changes. We will update the effective date and provide additional notice for material changes where required. Questions and privacy requests can be sent to support@snapinvoice.io.