Our Data Collection Policy
We Never Collect User Data
InvoSpher is built on a core principle: WE NEVER COLLECT, STORE, OR USE YOUR PERSONAL DATA FOR ANY PURPOSE OTHER THAN PROVIDING THE SERVICE YOU REQUESTED.
We do not:
- Sell your data to third parties
- Use your data for marketing purposes
- Share your information with advertisers
- Mine your data for analytics or profiling
- Create profiles based on your usage
- Use cookies to track your behavior
Your information is strictly used to:
- Provide and maintain the InvoSpher service
- Process invoices you create
- Send you important service notifications
- Respond to your support requests
- Comply with legal requirements
Invoice Data
Your Data Belongs to You
All invoices, client information, and business data you create in InvoSpher belong entirely to you. We store this data solely to:
- Allow you to access your invoices
- Enable backups and recovery
- Provide service features you use
Data Export: You can export all your data at any time in standard formats (PDF, CSV). If you close your account, you have 90 days to download all your data before it's permanently deleted.
Data Retention
We retain your invoice data for as long as your account is active. After account deletion, your data is permanently removed from our servers within 30 days.
Account Information
What We Collect
To create your InvoSpher account, we collect only the minimum necessary information:
- Email address (for login and notifications)
- Password (encrypted)
- Name (optional)
- Subscription information
What We Don't Collect
We specifically do NOT collect:
- Your location or IP address (for profiling)
- Device information for tracking
- Browsing history
- Social media profiles or data
- Payment card details (handled by secure payment processors)
Security & Encryption
How We Protect Your Data
- SSL/TLS Encryption: All data in transit is encrypted with industry-standard SSL/TLS protocols
- AES-256 Encryption: All stored data is encrypted with military-grade encryption
- Secure Servers: We use trusted, secure cloud infrastructure
- Access Control: Only authorized personnel can access data, with multi-factor authentication
- Regular Audits: We conduct regular security audits and penetration testing
- GDPR Compliant: We follow all GDPR and international data protection standards
Your Security: Your password is never stored in plain text. We use industry-standard bcrypt hashing. Change your password regularly and never share it with anyone.
Your Privacy Rights
GDPR & Data Protection Rights
If you're in the EU or GDPR applies to you, you have the right to:
- Access: Request a copy of your personal data
- Correction: Update or correct your information
- Deletion: Request deletion of your data (right to be forgotten)
- Portability: Receive your data in a portable format
- Objection: Object to certain processing activities
- Withdrawal: Withdraw consent at any time
How to Exercise Your Rights
To exercise any of these rights, contact us at privacy@invospher.com with your request. We'll respond within 30 days.
Cookies & Tracking
Do We Use Cookies?
We use minimal cookies only for:
- Session Management: Keeping you logged in
- Security: CSRF protection
- Preferences: Remembering your settings
We do NOT use:
- Analytics cookies (no Google Analytics or similar)
- Advertising cookies
- Tracking pixels
- Third-party cookies
Cookie Control: You can disable cookies in your browser settings. Essential cookies cannot be disabled without losing functionality.
Changes to This Policy
We may update this privacy policy to reflect changes in our practices or legal requirements. We'll notify you of significant changes via email or through the app. Continued use of InvoSpher after changes means you accept the updated policy.