Legal

Privacy Policy

How we collect, use, and protect your information. Last updated: March 2026.

1. Introduction

InvoiceStream (“we”, “our”, or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at invoicestream.ai and all associated services.

By accessing or using InvoiceStream, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of our services.

2. Information We Collect

Account Information: When you register, we collect your name, email address, and password. For business accounts, we may also collect your company name, address, and VAT/tax ID.

Financial Data: We store invoice data, expense records, client information, and payment transaction details that you input into our platform. This data belongs to you and is processed solely on your behalf.

Usage Data: We automatically collect information about how you interact with InvoiceStream, including pages visited, features used, timestamps, and browser/device information.

Payment Information: Payment processing is handled by third-party providers (Razorpay, Stripe, PayPal). We do not store your full card details on our servers.

AI/OCR Data: When you use our AI receipt scanning feature, uploaded images are sent to our AI vision API for processing. Extracted data is stored in your account. Images are not retained by our AI provider after processing.

3. How We Use Your Information

We use your information to:

  • Provide, operate, and improve the InvoiceStream platform
  • Process payments and manage your subscription
  • Send transactional emails (invoices, payment receipts, account notifications)
  • Respond to support requests and customer service inquiries
  • Analyse usage patterns to improve user experience
  • Comply with legal obligations and enforce our Terms of Service
  • Prevent fraud and ensure platform security

4. Data Sharing and Disclosure

We do not sell, trade, or rent your personal data to third parties. We may share information with:

Service Providers: Supabase (database hosting), AI Provider (OCR processing), Razorpay/Stripe/PayPal (payment processing), and Vercel (hosting). Each provider is contractually bound to protect your data.

Legal Requirements: We may disclose your information if required by law, court order, or to protect the rights, property, or safety of InvoiceStream, our users, or the public.

Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. You will be notified before your data is subject to a different privacy policy.

5. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we will delete or anonymise your personal data within 30 days, except where retention is required by law (e.g., financial records required for tax purposes, which may be retained for up to 7 years).

You may request deletion of your data at any time by contacting us at privacy@invoicestream.ai.

6. Data Security

We implement industry-standard security measures including:

  • Encryption in transit via TLS/HTTPS on all connections
  • Data at rest encrypted by our database provider (Supabase/PostgreSQL)
  • Row-Level Security (RLS) ensuring data isolation between accounts
  • Regular security reviews and vulnerability assessments

Despite these measures, no transmission over the internet is 100% secure. We cannot guarantee absolute security of your data.

7. Cookies

We use cookies and similar tracking technologies to maintain sessions, remember your preferences, and analyse usage. See our Cookie Policy for full details.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data (“right to be forgotten”)
  • Portability: Request your data in a machine-readable format
  • Objection: Object to certain types of data processing

To exercise any of these rights, email privacy@invoicestream.ai. We will respond within 30 days.

9. Children's Privacy

InvoiceStream is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with information, please contact us immediately.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by posting a prominent notice in the app. Your continued use of InvoiceStream after changes constitutes acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy or your data, contact our Data Protection Officer at:

InvoiceStream — Privacy Team

Email: privacy@invoicestream.ai

General: support@invoicestream.ai

Website: invoicestream.ai