Privacy Policy
Invoicaty
Last updated: September 2026
1. Introduction
Invoicaty (“we”, “our”, or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use the Invoicaty mobile application.
By using Invoicaty, you agree to the terms of this Privacy Policy.
2. Information We Collect
a) Account Information
- Full name
- Email address
- Password (encrypted — we never store it in plain text)
b) Business Profile Information
- Business name
- Phone number
- Business type (freelancer, professional, influencer, etc.)
- Country and preferred currency
- Preferred language (Arabic / English)
- Brand color
- Business logo (image you upload)
- Bank account details (bank name, account number, IBAN) — used solely for generating invoice documents
c) Business Data You Create
- Invoices (client name, project, amounts, line items, notes)
- Expenses (vendor, category, amounts)
- Quotations (client, items, totals)
- Drafts (title, content, client)
- Customer records (name, email, phone)
d) Automatically Collected Information
- App usage data stored locally on your device (offline cache)
- No advertising identifiers, no location data, no microphone or camera access beyond logo upload
3. How We Use Your Information
We use the information you provide exclusively to:
- Create and manage your account
- Generate invoices, quotations, expense records, and drafts
- Sync your data across your devices
- Enable offline access to your data
- Send password reset emails when requested
- Improve the app experience
We do not sell, rent, or share your personal data with third parties for marketing purposes.
4. Where Your Data Lives & Who Processes It
Your data is stored in the European Union (Frankfurt, Germany) on Supabase infrastructure (SOC 2 Type II, ISO 27001). It is not stored in Kuwait; we disclose this cross-border storage openly.
To run the service we rely on these processors, each bound by its own privacy commitments and receiving only what its job requires:
- Supabase — database, authentication, file storage (EU).
- Vercel — hosting of the website and its API.
- Resend — transactional email (invoices, receipts, sign-in emails).
- Meta (WhatsApp Business) — WhatsApp messages you or your customers opted into.
- PDFShift — renders your invoice PDFs from HTML; nothing is retained after rendering.
- Your chosen payment gateway (UPayments, MyFatoorah, Tap, Hesabe or Payzah) — only if you connect one; it receives the invoice amount and the payer's details needed to take payment.
- Cloudflare Turnstile — bot protection on sign-up.
- Google Ads — conversion measurement on the marketing website only (sign-up happened / first invoice created). No invoice amounts, customer data or document contents are ever sent. The mobile app uses no advertising or analytics SDKs.
- Apple / Expo — mobile app distribution and updates.
None of these providers may use your data for their own purposes. We never sell or rent it, and no one at Invoicaty browses your invoices, amounts or customers as a matter of course.
5. How We Protect It
Security is enforced in the database and on the server, not only in the app:
- Isolation at the database level — row-level security on every table: another user, or a visitor, cannot read your rows even if the app had a bug.
- Encryption in transit — TLS on every connection, with HSTS.
- Encryption at rest — AES-256 on the database disks and backups.
- Extra encryption for secrets — your payment-gateway keys are encrypted at the application layer with a key held outside the database.
- Passwords — hashed, never stored; sign-in attempts are rate-limited.
- Verified identity on every request — the server checks who you are and what your role allows before reading or writing anything.
- Team access you control — members you invite see only what their role permits; you can remove them at any time.
- Signed integrations — payment and messaging callbacks are verified with the provider before anything changes.
- Automated checks — thousands of tests run before every release; dependencies are scanned for vulnerabilities weekly.
If a breach ever affects your data, we will notify you and the competent authority without undue delay and within 72 hours of becoming aware of it.
6. Data Retention
We retain your data for as long as your account is active. You may request deletion of your account and all associated data at any time by contacting us at support@invoicaty.com, and we complete it within 30 days.
Deleted records go to your trash bin, where you can restore them or empty the bin to delete them permanently. You can export all your data (CSV or a full backup) from Settings at any time.
7. Your Rights
You have the right to:
- Access — request a copy of your personal data
- Correction — update inaccurate or incomplete information (via the app's Settings screen)
- Deletion — request permanent deletion of your account and all data
- Portability — request an export of your data
To exercise any of these rights, contact us at support@invoicaty.com.
8. Kuwait Data Privacy Principles
We operate according to the principles of the Data Privacy Protection Regulation issued by Kuwait's Communication and Information Technology Regulatory Authority (CITRA): a written policy, purpose-bound collection, your control over your data, deletion on request, appropriate security, breach notification, and open disclosure that your data is stored outside Kuwait.
9. Children's Privacy
Invoicaty is not directed at children under the age of 13. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by updating the “Last updated” date at the top of this page. Continued use of the app after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have any questions or concerns about this Privacy Policy, please contact us:
Email: support@invoicaty.com
Website: https://invoicaty.com
Developer: Invoicaty — Kuwait
