Privacy Policy
Version 2.0 · Effective July 30, 2026
This Privacy Policy explains how InvoToday, a business operated from British Columbia, Canada (“InvoToday”, “we”, “us”), collects, uses, discloses, and protects personal information in connection with our websites and the InvoToday service at app.invotoday.com (the “Service”).
1. Our two roles
We handle personal information in two distinct roles:
- As a controller (responsible organization) for information about visitors to our websites and about the people who register and administer accounts — names, work emails, login and billing records, support conversations, and usage data. This Policy governs that information.
- As a processor (service provider) for the business records our customers store in their workspaces — their own customers, vendors, employees, documents, ledgers, and files (“Customer Data”). We process Customer Data only on the customer’s instructions under our Data Processing Addendum. If your information appears in a customer’s workspace, that customer is the controller — contact them first; we will assist them in responding.
2. Information we collect
- Account information: name, email address, username, password (stored only as a one-way hash), preferred language, company name and country, and role within a workspace.
- Billing information: subscription plan, seat counts, invoices, and payment status. Card details are collected and stored by our payment processor, Stripe — we never see or store full card numbers.
- Usage and log data: IP address, browser and device information, pages and features used, API request metadata, and application logs and audit records.
- Communications: support requests, emails, and feedback you send us.
- Customer Data (as processor): whatever your workspace administrator and users submit, which may include personal data of their customers, vendors, and employees.
3. How we use information
- to provide, operate, secure, and support the Service (performance of a contract);
- to process payments, manage subscriptions and seats, and send transactional messages such as receipts, trial and renewal reminders, and security notices (contract / legitimate interests);
- to monitor, troubleshoot, and improve reliability, performance, and security, including fraud and abuse prevention (legitimate interests);
- to comply with legal obligations, including tax and accounting record-keeping; and
- with your consent where required, to send product news — you can opt out at any time.
We do not sell personal information, and we do not use Customer Data to train AI models. AI features run under an API key the customer supplies for their own AI-provider account, and content is sent to that provider only when a user invokes an AI feature.
4. Who we share information with
We share personal information only with:
- Infrastructure and service providers (subprocessors) who help us run the Service: Amazon Web Services (hosting and storage), Stripe (payments), our transactional email provider (message delivery), and Pydantic Logfire (error and performance telemetry). The current list, with locations, is in Annex C of our Data Processing Addendum.
- Integrations you enable, at your direction: for example Intuit QuickBooks Online, Malaysia’s MyInvois platform (LHDN), or the AI provider whose key you configure. Their own terms and privacy policies govern their handling.
- Authorities where required by law, court order, or to protect rights, safety, or the integrity of the Service; and
- A successor in a merger, acquisition, or sale of assets, subject to this Policy.
5. International transfers
Our infrastructure is hosted with Amazon Web Services, and subprocessors may process data in Canada, the United States, and other countries. Where data protected by the GDPR or similar laws is transferred internationally, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses as incorporated by our Data Processing Addendum.
6. Security
We maintain administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit (TLS), one-way password hashing, encrypted storage of integration credentials, per-tenant data isolation enforced at the database layer, role-based permissions, audit logging, and routine backups. Details are in our Security & Cyber Liability Statement. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Retention
- Account and billing records: for the life of the account and thereafter as required for tax, accounting, and legal purposes (typically 7 years for financial records).
- Customer Data: for the subscription term; after termination we make it exportable for at least 30 days, then delete it from production systems, with residual copies aging out of encrypted backups in the ordinary rotation cycle (up to 90 days).
- Logs and telemetry: for a rolling operational window, then deleted or anonymized.
8. Your rights
Depending on where you live — including under Canada’s PIPEDA, British Columbia’s PIPA, the EU/UK GDPR, and Malaysia’s PDPA — you may have rights to access, correct, export, or delete your personal information, to object to or restrict certain processing, to withdraw consent, and to complain to a supervisory authority (in Canada, the Office of the Privacy Commissioner; in BC, the OIPC). To exercise your rights, email sales@invotoday.com; we will respond within the time required by law and may need to verify your identity. If your data lives in a customer’s workspace, we will refer your request to that customer where the law requires them to handle it.
9. Cookies and similar technologies
The application uses only essential storage (session and preference data, such as your login token and language) needed for it to function. Our marketing website uses Google Tag Manager and analytics cookies to understand site traffic; you can control these through your browser settings and, where shown, a consent banner. We do not use cross-site advertising trackers in the application.
10. Children
The Service is for business use and is not directed to anyone under 18. We do not knowingly collect personal information from children; if you believe a child has provided us information, contact us and we will delete it.
11. Changes to this Policy
We may update this Policy from time to time. We will update the version number and effective date above and, for material changes, notify account owners through the Service or by email before the changes take effect.
12. Contact
InvoToday — British Columbia, Canada
Privacy contact: sales@invotoday.com
Website: www.invotoday.com