Invoice
Scarica l'app

Legal

Privacy policy

Last updated 7 September 2026. This document is published in English only; the English text is the binding version.

1. Who we are

Invoice Global makes invoicing software for small businesses and self-employed people. This policy covers three things we run:

  • This website, invoiceglobal.app — the marketing pages and these legal documents.
  • The mobile app, Invoice Global for iOS and Android.
  • The web app, app.invoiceglobal.app — the same product in a browser.

They are deliberately separated below, because they do not collect the same things and are not built on the same services. The website carries no account and no product data at all.

Invoice Global is operated from Germany, and is the controller of the data described below for the purposes of the GDPR. For anything in this policy — questions, requests, complaints — write to support@invoiceglobal.app.

2. The short version

We sell software. We do not sell data, we run no advertising, and we do not share your information with advertisers or data brokers. The invoices, clients and figures you put into the app are yours; we process them to run the service and for nothing else.

SurfaceAnalyticsWhat that means
invoiceglobal.app
(this website)
Umami, self-hostedNo cookies, no account, no cross-site tracking, no consent banner needed. We cannot identify you from it.
Mobile app and
app.invoiceglobal.app
Google Analytics for FirebaseTied to your account so we can see which features are used and where sign-up breaks. Crash reports go to Sentry.

3. What you give us

This applies to the app, not to this website.

Your account

An email address and password, or a Sign in with Apple or Google identifier. You can also use the app anonymously — no email at all — until you decide to add one. We generate a random identifier for your device and store it on the device itself; it is not derived from your hardware and it does not follow you to other apps.

Your business profile

Business name, address, phone, fax, email, website, logo, signature image, tax name, default tax rate, tax note, payment terms and cancellation policy — and, if you choose to print them on invoices, bank details (account holder, IBAN, BIC, bank name). All of this is optional and exists to be printed on your documents.

The work you record

Clients and their contact details, products with barcodes, units and stock counts, services and rates, invoices, estimates, receipts, appointments, saved document styles, and the images you attach.

Much of this is personal data belonging to your clients rather than to you. For that data you are the controller and we are your processor: you decide what to enter and what to do with it, and you are responsible for having a lawful basis to hold it. We process it only to provide the app to you.

4. What we collect automatically

On this website

We use Umami, an open-source analytics tool we host ourselves rather than a third-party service. It records, per page view: the page address, the referring address, browser, operating system, device type, screen size, browser language and country.

It sets no cookies and reads nothing from your browser storage. Repeat visits within a day are grouped under an identifier derived by one-way hash from your IP address, your browser and the site — it cannot be reversed, it changes daily, and it is not shared across sites. Your IP address is not stored. Because none of this identifies you, there is no cookie banner to click.

In the app and the web app

  • Google Analytics for Firebase — which screens are opened and which actions are taken (creating an appointment, emailing or printing a document, sorting reports, signing in, changing settings), together with your Firebase account identifier so we can tell one session from another. Google also derives the usual device and approximate-location data described in its own documentation.
  • Sentry — crash and error reports: the error, a stack trace, the app version, the device model and OS, and your account identifier and email address so we can tell whether a crash hit one person or everyone.
  • Firebase App Check — an attestation from Apple's App Attest, Google's Play Integrity or, on the web, reCAPTCHA, proving the request came from a real installation of our app rather than a script. This keeps other people out of your data.
  • RevenueCat — if you subscribe, your purchase and its status, linked to your account identifier.
  • Our API — when you upload a logo, signature or product photo, our server logs the request. Log entries are operational (timestamps, errors, rate limiting) and are not used to build a profile.

We do not put your email address, your clients' details, or any figure from your invoices into analytics events.

5. Device permissions

Every one of these is optional. The app works without them, and declining one only disables the feature it belongs to.

PermissionWhy
CameraPhotograph a logo or product, and scan barcodes. The camera library also declares a microphone permission on Android; the app never records audio.
PhotosPick an existing image for your logo, signature or products.
ContactsImport a client instead of typing them out. Your contact list is read on the device and never uploaded — only the single contact you pick becomes a client record.
NotificationsAppointment reminders. These are scheduled on the device itself; there is no push server, and we hold no push token for you.

6. Cookies and local storage

This website sets no cookies. It stores one thing in your browser: your light or dark theme choice, so the page does not flip back on your next visit. That never leaves your browser.

The app and web app store your session so you are not signed out constantly, the theme, and the last document template you used. On mobile the device identifier sits in the operating system's secure storage (Keychain or Keystore).

7. Who else processes it

We keep this list short on purpose. Each of these is a processor acting on our instructions under a data processing agreement.

ProcessorWhat forSurface
Google (Firebase)Sign-in, the database holding your documents, analytics, abuse preventionApp
Cloudflare (R2)Storage for logos, signatures and product imagesApp
RailwayHosting for our upload and account APIApp
Expo (EAS)Hosting for the web app and over-the-air app updatesApp
SentryCrash and error reportingApp
RevenueCatSubscription statusApp
Apple, GoogleApp distribution, sign-in, and payment. We never see your card details — the store bills you and tells us only whether a subscription is active.App
VercelHosting for this websiteWebsite

Umami is not on this list because we host it ourselves — the website's analytics data goes to our own server and to no one else.

8. Where it is stored

Your account and everything you record in the app — invoices, estimates, clients, products, appointments — live in Google Cloud's eur3 multi-region, which is data centres in Belgium and the Netherlands. That data is replicated between them and does not leave the European Union.

The rest is not all in the EU. Images are stored by Cloudflare, which distributes them across its own network. Several of the processors in the table above are US companies or move data to the United States. Where that happens the transfer relies on the European Commission's standard contractual clauses, or on the EU–US Data Privacy Framework where the processor is certified under it.

9. How long we keep it

  • Your account and documents — until you delete them. Deleting your account from within the app removes your account and the documents, clients, products and appointments under it.
  • Analytics — website statistics are aggregated and hold nothing that identifies you. In-app analytics follow Google's retention setting for our project.
  • Crash reports — kept for Sentry's standard retention period and then deleted.
  • Server logs — short-lived and operational.
  • Purchase records — kept as long as tax and accounting law requires, which in Germany is up to ten years.

Under Article 6(1) GDPR we rely on:

  • Performance of a contract — your account, your documents, storing your images, and your subscription. Without these there is no product.
  • Legitimate interests — keeping the service secure and working, preventing abuse, understanding which features are used, and fixing crashes.
  • Legal obligation — keeping records of purchases for tax purposes.
  • Consent — for camera, photo, contacts and notification access, which you grant on the device and can withdraw in your system settings at any time.

11. Your rights

If you are in the EU or UK you have the right to access your data, correct it, delete it, restrict or object to how we process it, receive it in a portable form, and withdraw any consent you have given. These rights are yours regardless of where you are; we apply them to everyone.

The fastest route for most of them is the app itself: your data is editable in place, and Settings has an account deletion that removes everything. For anything else, write to support@invoiceglobal.app and we will respond within one month.

You also have the right to complain to a supervisory authority — in Germany, your state's data protection commissioner.

12. Children

This is a business tool. It is not directed at children and we do not knowingly collect data from anyone under 16. If you believe a child has given us data, write to us and we will delete it.

13. Security

Traffic is encrypted in transit. Your documents sit behind security rules that scope every read and write to your own account, and every request to our API carries both a sign-in token and an App Check attestation. Uploaded images are stored under unguessable names and served through short-lived signed links.

No system is perfect. If we ever suffer a breach that puts your rights at risk, we will tell you and the relevant authority as the GDPR requires.

14. Changes

When we change this policy we update the date at the top. If a change materially affects how we handle your data, we will say so in the app rather than relying on you to re-read this page.

15. Contact

Questions, requests, or anything in here that reads wrong to you: support@invoiceglobal.app.