Who this applies to

This policy describes the InvoiceMint application you are using. It is a product policy, not legal advice for the invoices you send to your own clients.

Guest invoices

If you are not logged in, the invoice you type stays in local storage on that browser. Preview and PDF download run on your device. Guest invoice contents are not sent to the server to be saved.

Accounts

If you register, we store your name, email address, a password hash (Argon2id), and session records. If you opt in, we store the time you consented to product email. You can withdraw that consent in settings. Marketing email is allowed only for verified accounts that still have a consent timestamp and have not been deleted or disabled. This installation does not include a bulk mailer.

Saved invoices include the business and client details, line items, and notes you enter. A logo is used only in the browser that builds the PDF and is removed before the invoice is stored. Those fields are available to your account. They are not written into application logs or into URLs. Search text is not logged.

Payments for Pro

Pro is paid in Bitcoin. For each checkout we store a receive address, the satoshi amount, and, once the network confirms it, the transaction id. We also store the plan, interval, status, and period end. We do not store a Bitcoin private key, a card number, or a card security code. A donation address, when published, is separate and does not by itself start a subscription. The local development provider, used only outside production, confirms a plan without collecting a payment.

Support and errors

Contact messages and support tickets store the message you send. Please do not include a client’s bank login, a full card number, or a copy of someone else’s identity document. Browser error reports store a short message and the path, not the invoice you were editing.

Access by staff

Support and admin accounts can manage users, tickets, and site content. They do not get a browser of customer invoices. An administrator may open a single invoice only by invoice id, with a written reason, for no more than 60 minutes. Granting, viewing, and revoking that access are audit events.

Deletion

You can delete an invoice, which removes its contents. You can delete your account from settings. That removes invoice contents, template presets, and sessions, and replaces the account email with a non-routable address. Billing event rows for the subscription may be retained for the configured retention period (seven years unless the operator sets BILLING_RETENTION_YEARS) because they are limited to amount, currency, and date.

Legal and access requests are logged by an admin with a subject reference, a legal basis, and an outcome. The log is meant to record the category of the request, not a second copy of an invoice.

Cookies

The session cookie is essential. See the cookie policy.