Privacy Policy

Back to InvoiceBasket

Last updated: September 12, 2026

This Privacy Policy explains what personal data InvoiceBasket ("we," "us") collects, why, how long we keep it, and what rights you have over it.

1. What we collect. Account and business profile details you give us when you sign up (name, email, phone, business address, country, tax/VAT number, home currency, bank details and logo if you add them) — used to run your account and appear on the invoices you create. Content you create or upload — clients, invoices, and, on higher-tier plans, receipts/documents you scan and the transactions and categories generated from them. We don't store your card details ourselves — subscription payments are handled entirely by Stripe, and if you use Get Paid (Stripe Connect), your own connected Stripe account handles your clients' card payments directly; we only store whether that account is connected and active. We also keep standard technical information needed to run a web application, such as your login session and basic server logs for security and troubleshooting. We don't currently use advertising or analytics tracking cookies on the app or website.

2. Why we process it. To provide the Service you've signed up for — creating your account, generating your invoices, running AI categorisation on documents you upload, showing your dashboard, processing your subscription payment, and enabling Stripe Connect if you use it. We also process a limited amount of data to keep the Service secure and working properly, and to meet our own legal obligations such as keeping records for tax and accounting purposes.

3. Who else sees your data. We use a small number of service providers to run InvoiceBasket, each only processing your data to help deliver the Service: Supabase (our database, file storage, and login/authentication provider), Stripe (payment processing, for both your subscription and your own Stripe Connect account if you use it), Anthropic (the AI provider whose models read and categorise the documents you upload), and Vercel (hosts the InvoiceBasket web application itself). We don't sell your data, and we don't share it with anyone else for their own marketing purposes. Some of these providers may process data outside the EU/UK (for example, in the United States); where that happens, they do so under appropriate safeguards, such as the EU Standard Contractual Clauses.

4. How long we keep it. For as long as your account is active. If your subscription lapses or you close your account, we keep your content for 90 days afterward (in case you want to reactivate), after which it may be permanently deleted. We may keep limited records for longer where legally required to, such as billing records for tax purposes.

5. Your rights. Depending on where you're based, you generally have the right to access the personal data we hold about you, ask us to correct or delete it, ask us to restrict or object to certain processing, and receive a copy of your data in a portable format. To exercise any of these, contact us using the details in section 8. You also have the right to complain to your local data protection authority — in Ireland, the Data Protection Commission; in the UK, the Information Commissioner's Office; elsewhere in the EU, your own national authority.

6. Security. We rely on our service providers' own security measures (encryption in transit, access controls, and similar industry-standard practices) to protect your data. No system is completely secure, and we can't guarantee absolute security of information transmitted to the Service.

7. Changes to this policy. We may update this Privacy Policy from time to time, particularly as the Service changes. Where a change is material, we'll give reasonable notice before it takes effect.

8. Contact. Questions about this policy, or requests relating to your personal data, can be sent to invoicebasketadmin@gmail.com.