Skip to content
InvoiceKit
How tax is decidedFeaturesPricingFAQ
Sign inStart free
Legal

Privacy policy

Effective 26 September 2026. This explains what InvoiceKit collects, why, who else handles it, how long it's kept, and how to get it corrected or deleted.

On this page
  1. Who we are
  2. Your data and your clients' data
  3. What we collect
  4. How we use it
  5. What we don't do
  6. Services that process data
  7. Where data is stored
  8. Invoice links
  9. Cookies and browser storage
  10. How long we keep it
  11. Security
  12. Your rights
  13. Children
  14. Changes to this policy
  15. Contact and grievances

1. Who we are

InvoiceKit (invoicekitpro.com) is operated by Nishit Sharma, a sole proprietor trading as Nexflow AI Labs, Bengaluru, Karnataka, India ("we", "us"). This policy covers the website, the InvoiceKit app, hosted invoice pages, and emails the service sends.

2. Your data and your clients' data

InvoiceKit handles two kinds of personal data, and our role differs for each:

  • Your account data — your sign-in details and the business details you enter about yourself. We decide how this is processed, so we are the data fiduciary (India's Digital Personal Data Protection Act, 2023) or controller (UAE Federal Decree-Law No. 45 of 2021) for it.
  • Your clients' data — names, emails, addresses and tax numbers of the people and businesses you invoice. You decide what to enter and why; we process it only to provide InvoiceKit to you, on your instructions. For this data you are responsible for having a lawful basis and for telling your clients how you use it, and we act as your processor.

3. What we collect

CategoryWhat it includesWhere it comes from
AccountEmail address; a password (stored only as a salted hash by our authentication provider); or, if you use Google sign-in, your name, email and profile picture link from GoogleYou, or Google with your permission
Business profileLegal and trading name, addresses, phone, billing email, GSTIN, PAN, UAE TRN, LUT ARN, bank account number, IFSC, SWIFT, IBAN, UPI ID, logo and signature images, invoice preferencesYou
Client recordsClient names, contact emails, addresses, state and country, tax numbers, and whether they deduct TDSYou
Financial recordsInvoices, line items, amounts, exchange rates, payments you record, and expensesYou
ActivityWhen an invoice was sent, first viewed by the recipient, reminded or receiptedGenerated by the service
TechnicalIP address, browser type and request times in our hosting and database providers' logsYour browser, automatically

We don't ask for or knowingly collect sensitive data such as health information. Please don't put it in invoice descriptions or notes.

4. How we use it

  • To create and secure your account and sign you in.
  • To produce your invoices, work out tax, number them, host invoice links, and build your ledgers, summaries and exports.
  • To send the emails you ask for — invoices, reminders and receipts to your clients — and account emails to you, such as sign-in links and password resets, when email sending is switched on.
  • To keep the service working and secure: diagnosing errors, preventing abuse, and enforcing our terms.
  • To tell you about material changes to the service, pricing or this policy.
  • To meet legal obligations, such as responding to lawful requests from authorities.

We rely on your consent, given when you create an account, and on the processing being necessary to provide the service you asked for. You can withdraw consent at any time by deleting your account (section 12); processing already done before withdrawal stays lawful.

5. What we don't do

  • We don't sell or rent personal data.
  • We don't show ads or share data with advertisers.
  • We don't use third-party analytics or tracking scripts. We count visits ourselves (see section 9).
  • We don't use your invoices, clients or financial records to train AI models.
  • We only email your clients about invoices you've sent them: the invoice when you choose to email it, receipts you send, and payment reminders. Automatic reminders are on by default for each sent invoice, and you can switch them off per invoice.

6. Services that process data

These providers process data on our behalf, only as needed for the purpose listed:

ProviderPurposeData involvedLocation
SupabaseDatabase, authentication, file storage (logos and signatures), server functionsAll account, profile, client and financial dataMumbai, India (AWS ap-south-1)
VercelHosting the website and appIP address and request logsGlobal edge network; company based in the US
ResendSending emails, once email sending is switched onRecipient email, message content, your business name and reply-to addressUnited States
RazorpayTaking Pro subscription payments, if you choose ProYour name, email, phone if given, and the payment details you enter on Razorpay's checkout (we never see or store card or bank numbers)India
GoogleSign in with Google, if you choose it; web fontsSign-in: the account details listed in section 3. Fonts: your IP address when your browser loads themGlobal
jsDelivrDelivering the open-source Supabase JavaScript library to your browserIP addressGlobal
ExchangeRate-API (open.er-api.com)Daily exchange rates, fetched by your browserIP address only — no account or invoice data is sentGlobal

If we add or replace a provider that handles your account or client data, we'll update this table at least 14 days before the change takes effect.

7. Where data is stored

Your account, business, client and financial data is stored in India. Some providers above process limited data — mainly IP addresses and, when emails are sent, the email content — in other countries including the United States. We only use providers bound by contractual data-protection terms, and we don't transfer data to any country the Government of India restricts under the DPDP Act.

8. Invoice links

Every sent invoice has a link containing a long random token. Anyone who has the link can view and download that one invoice, including the business and bank details printed on it, without signing in. The link doesn't give access to anything else in your account. Invoice pages are marked so search engines don't index them. When a link is opened for the first time by someone other than you, we record the time so you can see the invoice was viewed; we don't record who opened it.

9. Cookies and browser storage

We don't use advertising or analytics cookies. InvoiceKit stores your sign-in session in your browser's local storage so you stay signed in; it's removed when you sign out. The website's home page reads that entry only to show "Open your book" instead of "Sign in".

To understand how people find and use InvoiceKit, our own servers count page views and clicks on sign-up buttons. We store a random visitor ID in your browser's local storage, the page, the referring site and campaign tags, the type of device, and the approximate country, region and city our hosting provider derives from your IP address. We don't store your IP address with these records, don't share them with anyone, and delete them after 24 months. If your browser sends "Do Not Track", none of this is recorded.

10. How long we keep it

  • While your account is open, we keep your data so the service works — including sent invoices, which stay unchanged so your records match what clients received.
  • When you ask us to delete your account, we delete your account and all its data from our live systems within 30 days of the request, and confirm by email when it's done. Copies in our providers' backups expire on their normal backup cycle and are never restored into the service.
  • Technical logs are kept by our providers for their standard periods, generally under 30 days.

Indian GST law generally requires businesses to keep invoice records for 72 months from the due date of the annual return for the year they relate to. That duty is yours as the business, not ours: export your invoices (CSV, HTML or PDF) before you delete your account.

11. Security

  • All traffic uses HTTPS.
  • Database row-level security means each account can only read and write its own records.
  • Sent invoices can't be altered, and invoice numbers are assigned on the server.
  • Email-sending credentials are held server-side and never reach your browser.

No system is perfectly secure. If a personal data breach affects you, we'll tell you without undue delay — what happened, what data was involved, what we're doing, and what you can do — and report it to the Data Protection Board of India within 72 hours of becoming aware of it, as the DPDP Rules require.

12. Your rights

You can ask us to:

  • Access — a summary of the personal data we hold about you and how we use it, and the providers we've shared it with.
  • Correct or complete — most of your data can be edited in Settings; sent invoices are locked, so corrections to them are made by issuing a new document.
  • Erase — delete your account and its data (section 10).
  • Withdraw consent — by deleting your account.
  • Nominate someone to exercise these rights if you die or become unable to.
  • Get a copy of your records — the app's exports give you this at any time.

Email the contact in section 15 from your account email. We'll acknowledge your request within 7 days and complete it within 30 days. If you're not satisfied with our answer, you can complain to the Data Protection Board of India or, in the UAE, the UAE Data Office.

If you're a client who received an invoice through InvoiceKit, the business that sent it controls your data. Contact them first; if you can't reach them, contact us and we'll pass your request on within 7 days.

13. Children

InvoiceKit is a business tool for people aged 18 and over. We don't knowingly process children's data. If you think a child has created an account, contact us and we'll delete it.

14. Changes to this policy

For material changes, we'll email account holders and show a notice in the app at least 30 days before the change takes effect. Minor clarifications take effect when posted. The effective date at the top always shows the current version.

15. Contact and grievances

Nishit Sharma, Nexflow AI Labs, Bengaluru, Karnataka, India
Email: nishit@nexflow.co.in

This contact also acts as our grievance officer for privacy complaints. We'll acknowledge a grievance within 7 days and resolve it within 30 days.

InvoiceKit

GST, TDS and UAE VAT invoicing for freelancers and small studios. Made in Bengaluru by Nexflow AI Labs.

Product

  • How tax is decided
  • Features
  • Pricing
  • FAQ

Account

  • Create an account
  • Sign in
  • Sample book

Company

  • Privacy policy
  • Terms of service
  • Contact
  • Nexflow AI Labs
© 2026 Nexflow AI Labs, Bengaluru, IndiaInvoiceKit is a billing tool, not tax advice.