1. Who we are
InvoiceKit (invoicekitpro.com) is operated by Nishit Sharma, a sole proprietor trading as Nexflow AI Labs, Bengaluru, Karnataka, India ("we", "us"). This policy covers the website, the InvoiceKit app, hosted invoice pages, and emails the service sends.
2. Your data and your clients' data
InvoiceKit handles two kinds of personal data, and our role differs for each:
- Your account data — your sign-in details and the business details you enter about yourself. We decide how this is processed, so we are the data fiduciary (India's Digital Personal Data Protection Act, 2023) or controller (UAE Federal Decree-Law No. 45 of 2021) for it.
- Your clients' data — names, emails, addresses and tax numbers of the people and businesses you invoice. You decide what to enter and why; we process it only to provide InvoiceKit to you, on your instructions. For this data you are responsible for having a lawful basis and for telling your clients how you use it, and we act as your processor.
3. What we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account | Email address; a password (stored only as a salted hash by our authentication provider); or, if you use Google sign-in, your name, email and profile picture link from Google | You, or Google with your permission |
| Business profile | Legal and trading name, addresses, phone, billing email, GSTIN, PAN, UAE TRN, LUT ARN, bank account number, IFSC, SWIFT, IBAN, UPI ID, logo and signature images, invoice preferences | You |
| Client records | Client names, contact emails, addresses, state and country, tax numbers, and whether they deduct TDS | You |
| Financial records | Invoices, line items, amounts, exchange rates, payments you record, and expenses | You |
| Activity | When an invoice was sent, first viewed by the recipient, reminded or receipted | Generated by the service |
| Technical | IP address, browser type and request times in our hosting and database providers' logs | Your browser, automatically |
We don't ask for or knowingly collect sensitive data such as health information. Please don't put it in invoice descriptions or notes.
4. How we use it
- To create and secure your account and sign you in.
- To produce your invoices, work out tax, number them, host invoice links, and build your ledgers, summaries and exports.
- To send the emails you ask for — invoices, reminders and receipts to your clients — and account emails to you, such as sign-in links and password resets, when email sending is switched on.
- To keep the service working and secure: diagnosing errors, preventing abuse, and enforcing our terms.
- To tell you about material changes to the service, pricing or this policy.
- To meet legal obligations, such as responding to lawful requests from authorities.
We rely on your consent, given when you create an account, and on the processing being necessary to provide the service you asked for. You can withdraw consent at any time by deleting your account (section 12); processing already done before withdrawal stays lawful.
5. What we don't do
- We don't sell or rent personal data.
- We don't show ads or share data with advertisers.
- We don't use third-party analytics or tracking scripts. We count visits ourselves (see section 9).
- We don't use your invoices, clients or financial records to train AI models.
- We only email your clients about invoices you've sent them: the invoice when you choose to email it, receipts you send, and payment reminders. Automatic reminders are on by default for each sent invoice, and you can switch them off per invoice.
6. Services that process data
These providers process data on our behalf, only as needed for the purpose listed:
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Supabase | Database, authentication, file storage (logos and signatures), server functions | All account, profile, client and financial data | Mumbai, India (AWS ap-south-1) |
| Vercel | Hosting the website and app | IP address and request logs | Global edge network; company based in the US |
| Resend | Sending emails, once email sending is switched on | Recipient email, message content, your business name and reply-to address | United States |
| Razorpay | Taking Pro subscription payments, if you choose Pro | Your name, email, phone if given, and the payment details you enter on Razorpay's checkout (we never see or store card or bank numbers) | India |
| Sign in with Google, if you choose it; web fonts | Sign-in: the account details listed in section 3. Fonts: your IP address when your browser loads them | Global | |
| jsDelivr | Delivering the open-source Supabase JavaScript library to your browser | IP address | Global |
| ExchangeRate-API (open.er-api.com) | Daily exchange rates, fetched by your browser | IP address only — no account or invoice data is sent | Global |
If we add or replace a provider that handles your account or client data, we'll update this table at least 14 days before the change takes effect.
7. Where data is stored
Your account, business, client and financial data is stored in India. Some providers above process limited data — mainly IP addresses and, when emails are sent, the email content — in other countries including the United States. We only use providers bound by contractual data-protection terms, and we don't transfer data to any country the Government of India restricts under the DPDP Act.
8. Invoice links
Every sent invoice has a link containing a long random token. Anyone who has the link can view and download that one invoice, including the business and bank details printed on it, without signing in. The link doesn't give access to anything else in your account. Invoice pages are marked so search engines don't index them. When a link is opened for the first time by someone other than you, we record the time so you can see the invoice was viewed; we don't record who opened it.
9. Cookies and browser storage
We don't use advertising or analytics cookies. InvoiceKit stores your sign-in session in your browser's local storage so you stay signed in; it's removed when you sign out. The website's home page reads that entry only to show "Open your book" instead of "Sign in".
To understand how people find and use InvoiceKit, our own servers count page views and clicks on sign-up buttons. We store a random visitor ID in your browser's local storage, the page, the referring site and campaign tags, the type of device, and the approximate country, region and city our hosting provider derives from your IP address. We don't store your IP address with these records, don't share them with anyone, and delete them after 24 months. If your browser sends "Do Not Track", none of this is recorded.
10. How long we keep it
- While your account is open, we keep your data so the service works — including sent invoices, which stay unchanged so your records match what clients received.
- When you ask us to delete your account, we delete your account and all its data from our live systems within 30 days of the request, and confirm by email when it's done. Copies in our providers' backups expire on their normal backup cycle and are never restored into the service.
- Technical logs are kept by our providers for their standard periods, generally under 30 days.
Indian GST law generally requires businesses to keep invoice records for 72 months from the due date of the annual return for the year they relate to. That duty is yours as the business, not ours: export your invoices (CSV, HTML or PDF) before you delete your account.
11. Security
- All traffic uses HTTPS.
- Database row-level security means each account can only read and write its own records.
- Sent invoices can't be altered, and invoice numbers are assigned on the server.
- Email-sending credentials are held server-side and never reach your browser.
No system is perfectly secure. If a personal data breach affects you, we'll tell you without undue delay — what happened, what data was involved, what we're doing, and what you can do — and report it to the Data Protection Board of India within 72 hours of becoming aware of it, as the DPDP Rules require.
12. Your rights
You can ask us to:
- Access — a summary of the personal data we hold about you and how we use it, and the providers we've shared it with.
- Correct or complete — most of your data can be edited in Settings; sent invoices are locked, so corrections to them are made by issuing a new document.
- Erase — delete your account and its data (section 10).
- Withdraw consent — by deleting your account.
- Nominate someone to exercise these rights if you die or become unable to.
- Get a copy of your records — the app's exports give you this at any time.
Email the contact in section 15 from your account email. We'll acknowledge your request within 7 days and complete it within 30 days. If you're not satisfied with our answer, you can complain to the Data Protection Board of India or, in the UAE, the UAE Data Office.
If you're a client who received an invoice through InvoiceKit, the business that sent it controls your data. Contact them first; if you can't reach them, contact us and we'll pass your request on within 7 days.
13. Children
InvoiceKit is a business tool for people aged 18 and over. We don't knowingly process children's data. If you think a child has created an account, contact us and we'll delete it.
14. Changes to this policy
For material changes, we'll email account holders and show a notice in the app at least 30 days before the change takes effect. Minor clarifications take effect when posted. The effective date at the top always shows the current version.
15. Contact and grievances
Nishit Sharma, Nexflow AI Labs, Bengaluru, Karnataka, India
Email: nishit@nexflow.co.in
This contact also acts as our grievance officer for privacy complaints. We'll acknowledge a grievance within 7 days and resolve it within 30 days.