Legal
Privacy Policy
This Policy explains how Invoibase (“we”, “us”) collects, uses, and protects personal data when you use our B2B crypto invoicing platform.
Effective date: August 21, 2026
1. Who We Are
Invoibase operates the Invoibase application. For privacy inquiries or data-subject requests, contact [email protected].
2. Data We Collect
- Account data: name, email, password hash (never plaintext passwords), OAuth profile identifiers, business branding fields.
- Invoice & client data: client names, emails, line items, amounts, due dates, and notes you enter.
- Payment metadata: network, transaction hashes, settlement wallet addresses, and gateway event identifiers. We do not store private keys.
- Security & telemetry: IP addresses for rate limiting and audit logs, session tokens, support tickets, and optional error monitoring events.
3. Security of Sensitive Fields
Authenticator (2FA) secrets are encrypted at rest using AES-256-GCM field-level encryption before storage in our database. Passwords are stored only as one-way hashes. Webhook signatures are verified with HMAC before payment state changes are applied.
Email addresses are stored to operate the service (login, invoices, receipts, support). We do not sell personal data.
4. How We Use Data
- Provide invoicing, authentication, and payment workflows.
- Send transactional emails (invoices, receipts, 2FA codes).
- Enforce security, abuse prevention, and legal compliance.
- Improve reliability via optional error monitoring (e.g., Sentry) with sanitized diagnostics.
5. GDPR / CCPA Notes
If you are in the EEA/UK, we process personal data under contract necessity, legitimate interests (security and product integrity), and consent where required (e.g., certain cookies or optional marketing). You may request access, correction, deletion, restriction, or portability of your personal data, and object to certain processing, subject to legal exceptions.
If you are a California resident, you may request to know, delete, or correct personal information we hold about you, and opt out of “sale” or “sharing” as defined by the CCPA/CPRA. Invoibase does not sell personal information for monetary consideration.
To exercise rights, email [email protected]. We may verify your identity before fulfilling a request.
6. Processors & International Transfers
We use subprocessors to operate the product, which may include hosting providers, email delivery (e.g., Resend), authentication (Google OAuth), blockchain RPC providers, and error monitoring (Sentry). Data may be processed in the United States or other countries with appropriate safeguards.
7. Retention
We retain account and invoice records for as long as your account is active and as needed for tax, fraud prevention, and legal obligations. You may request deletion; some records may be retained in anonymized or legally required form.
8. Children
Invoibase is a B2B service and is not directed to individuals under 16. We do not knowingly collect data from children.
9. Changes
We may update this Policy. The effective date above will change when material updates are posted.
Questions? Contact [email protected]