Transparency

Privacy Policy

Last updated: September 2026

At InvoiceFlow, we are committed to transparent and privacy-conscious practices. This Privacy Policy outlines how our web application handles data, how browser local storage operates, and what technologies are utilized when you access our invoice generator and informational pages.

Summary for Busy Professionals: InvoiceFlow is designed so you can create, calculate, and download professional invoices without creating an account. The financial information you type into your invoice is processed in your own browser—not sent to a private server database.

1. Information We Collect

Information collection on InvoiceFlow depends directly on the actual technical implementation of the website and how you interact with our pages:

  • Information You Voluntarily Enter: When you use the invoice generator, you input details such as your business name, contact information, client details, line-item descriptions, quantities, rates, and bank instructions. In the current implementation, these inputs are handled entirely client-side inside your browser session.
  • Contact Inquiries: If you submit an inquiry through our contact page, the name, email address, subject, and message you provide are processed for the purpose of addressing your request. In deployments where an active mail server or API webhook is configured, that transmission is utilized solely to reply to your inquiry.
  • Technical & Log Information: Like virtually all web servers, standard web servers hosting static websites may log technical details such as IP addresses, browser types, referring pages, and access timestamps for security, uptime diagnostics, and system administration.
  • Information We Do Not Collect: Because InvoiceFlow does not require user registration or billing for basic generation, we do not collect account passwords, credit card numbers, or social security numbers.

2. Invoice Data Privacy & Browser LocalStorage

It is essential to understand how invoice information is handled technically under our privacy-first architecture:

  • Versioned Local Storage Architecture: When you work on an invoice or customize your invoice theme, InvoiceFlow uses your browser's native localStorage API under centralized, versioned namespaces (invoiceflow:v1:draft, invoiceflow:v1:preferences, and invoiceflow:v1:numbering). If you had drafts created under legacy pre-versioned keys, they are seamlessly migrated locally on your device without network requests.
  • Debounced Local Autosave: To prevent unexpected work loss from accidental tab closures or browser crashes, InvoiceFlow features an automated, debounced client-side autosave system. Every change is stored locally on your device with clear status feedback (“Saving...” and “Draft saved”).
  • Startup Draft Recovery: When opening InvoiceFlow, the application detects any existing local draft and prompts you via an accessible modal, offering the choice to restore your previous work or start a fresh, blank invoice.
  • Zero Server Transmission of Invoice Data: All invoice inputs—including your business name, logo, customer details, line items, banking numbers, and payment notes—remain strictly inside your browser's JavaScript memory and local storage. No invoice content is ever transmitted, indexed, or saved to a remote server or third-party database.
  • Portable JSON Backup & Import: Because no server copies exist, InvoiceFlow empowers you with true data portability. You can export your invoice at any time as a structured, human-readable .json file to store offline or transfer to another computer. When importing, strict schema validation and sanitization ensure safe, immediate restoration without risk of malicious code execution.
  • User-Initiated Local Data Erasure: You maintain complete autonomy over your local data. In addition to clearing your browser history or site cookies, InvoiceFlow provides a direct “Clear Saved Invoice Data” button within the generator, allowing you to instantly purge all stored drafts, numbering history, and design preferences.
  • Private / Incognito Browsing: If you use private or incognito browsing modes, browser local storage is strictly isolated to that private window and wiped completely upon closing.
  • User Responsibility for Backups: Because we operate zero centralized databases, you should always retain your own permanent copies by downloading your invoices as PDF files, exporting JSON backups, or printing them for your accounting records.

3. Cookies & Web Technologies

Our policy regarding cookies reflects our current technical architecture:

  • Essential & Functional Technologies: InvoiceFlow utilizes client-side storage technologies strictly to support core functionality, such as retaining your current invoice draft across page reloads and remembering your chosen currency or visual template layout.
  • Analytics & Advertising: In this current implementation, InvoiceFlow does not employ invasive user-profiling cookies, cross-site tracking beacons, or third-party data broker pixels. Should performance analytics or advertising networks be implemented in future deployment phases, this policy will be explicitly updated to identify the specific technologies and provide opt-out mechanisms.

4. Third-Party Services & Content Delivery Networks (CDNs)

To deliver fast loading speeds and reliable document generation, InvoiceFlow utilizes select public content delivery networks:

  • Google Fonts: We reference the Google Fonts CDN to deliver the Inter font family. Your browser connects directly to Google's servers to retrieve font files, which may process standard HTTP request headers.
  • html2pdf.js via CDNJS / Cloudflare: For client-side A4 PDF compilation, InvoiceFlow loads the open-source html2pdf.js bundle via the Cloudflare-backed CDNJS network. The library executes entirely inside your client browser to render your document.

We only reference third-party resources that are genuinely part of the technical stack, and we do not claim partnerships or commercial affiliations with these providers.

5. Data Retention

Data retention aligns directly with our technical architecture:

  • Local Invoice Drafts: Stored locally on your personal device until you overwrite them with a new draft, click "Clear Form", or clear your browser's site data.
  • Support Inquiries: In the event a backend contact channel is configured, support messages are retained only as long as necessary to answer your inquiry and fulfill legitimate administrative needs.

6. Your Privacy Rights

Depending on your location and applicable privacy regulations (such as the GDPR in Europe, CCPA/CPRA in California, or other regional standards), you may have rights regarding your personal data, including the right to inquire about data handling, request deletion, or restrict processing.

Because InvoiceFlow processes invoice documents client-side without collecting personally identifiable accounts on a central database, you exercise direct, autonomous control over your invoice information through your own browser settings.

7. Inquiries Regarding Privacy

If you have questions, concerns, or feedback regarding our privacy approach, please reach out through our contact page or email us directly at support@invoiceflow.com.

Disclaimer: This document is provided for informational transparency regarding InvoiceFlow's technical data handling and does not constitute formal legal counsel.