Privacy Policy
Last updated: January 2025
1. Introduction & Data Controller
Invoicemonk ("we," "us," or "our") is committed to protecting your privacy and /ensuring the security of your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information wh/en you use our platform and services.
Data Controller: For the purposes of the G/eneral Data Protection Regulation (GDPR) and other applicable data protection laws, Invoicemonk is the data controller responsible for your personal data.
Data Protection Officer (DPO)
Email: dpo@invoicemonk.com
For privacy-related inquiries, you may contact our DPO at any time.
This policy applies to all users of Invoicemonk services worldwide, with specific provisions for users in the European Union/European Economic Area (EU/EEA), United Kingdom, California (USA), Brazil, Nigeria, Australia, and Canada.
2. Information We Collect
2.1 Information You Provide Directly
- Account Information: Name, email address, password, phone number
- Business Information: Company name, business address, tax id/entification numbers (TIN, VAT, GST), business registration details
- Financial Data: Invoice details, exp/ense records, paym/ent information, bank account details for payouts
- Cli/ent Data: Information about your cli/ents that you store in our system
- Communications: Messages you s/end to us, support tickets, feedback
2.2 Information Collected Automatically
- Device Information: IP address, browser type, operating system, device id/entifiers
- Usage Data: Pages visited, features used, time sp/ent on the platform, click patterns
- Log Data: Access times, error logs, referring URLs
- Cookies & Similar Technologies: See our Cookie Policy for details
2.3 Information from Third Parties
- Paym/ent Processors: Transaction confirmations from Stripe, Paystack, and other paym/ent providers
- Auth/entication Providers: If you sign in via Google or other OAuth providers
- Business Partners: Information from integrations you authorize
3. Legal Basis for Processing (GDPR Article 6)
We process your personal data only wh/en we have a valid legal basis to do so. The legal bases we rely on include:
Contract Performance (Art. 6(1)(b))
Processing necessary to provide our services to you, including creating invoices, managing exp/enses, processing paym/ents, and maintaining your account.
Legitimate Interests (Art. 6(1)(f))
Processing for our legitimate business interests, such as improving our services, analytics, fraud prev/ention, and security, where these interests are not overridd/en by your rights and freedoms.
Legal Obligation (Art. 6(1)(c))
Processing required to comply with applicable laws, including tax regulations, accounting requirem/ents, and responding to legal requests.
Cons/ent (Art. 6(1)(a))
Processing based on your explicit cons/ent, such as marketing communications. You may withdraw cons/ent at any time without affecting the lawfulness of processing based on cons/ent before its withdrawal.
4. How We Use Your Information
We use your personal data for the following purposes:
4.1 Service Delivery
- Creating and managing your account
- G/enerating invoices, estimates, and receipts
- Processing paym/ents and refunds
- Managing exp/ense tracking and reporting
- Providing customer support
4.2 Service Improvem/ent
- Analyzing usage patterns to improve features
- Conducting research and developm/ent
- Testing new features and functionality
4.3 Communications
- S/ending transactional emails (invoices, receipts, account updates)
- Providing technical notices and security alerts
- S/ending marketing communications (with your cons/ent)
- Responding to inquiries and support requests
4.4 Legal & Compliance
- Complying with tax and accounting regulations
- Prev/enting fraud and unauthorized access
- Enforcing our terms of service
- Responding to legal requests and court orders
6. Data Sharing & Third Parties
We do not sell your personal data. We may share your information with the following categories of recipi/ents:
6.1 Service Providers
- Paym/ent Processors: Stripe, Paystack (for paym/ent processing)
- Cloud Infrastructure: Secure cloud hosting providers
- Email Services: Transactional email delivery
- Analytics: Usage analytics (anonymized where possible)
All service providers are contractually bound to protect your data and may only use it for the specific purposes we authorize.
6.2 Legal Requirem/ents
We may disclose your information wh/en required by law, court order, or governm/ent request, or wh/en necessary to protect our rights, safety, or property.
6.3 Business Transfers
In the ev/ent of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you of any such change.
7. International Data Transfers
Invoicemonk operates globally, and your data may be transferred to and processed in countries outside your country of resid/ence, including countries that may not have the same data protection laws as your jurisdiction.
7.1 Transfer Mechanisms
Wh/en transferring data from the EU/EEA or UK to countries without adequate data protection, we implem/ent appropriate safeguards including:
- Standard Contractual Clauses (SCCs): EU-approved contractual terms
- Adequacy Decisions: Transfers to countries deemed adequate by the European Commission
- Binding Corporate Rules: Where applicable
7.2 Data Storage Locations
Your data is primarily stored in secure data c/enters located in the United States and European Union. We /ensure all data c/enters meet industry security standards.
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
| Data Type | Ret/ention Period | Reason |
|---|---|---|
| Account Information | Duration of account + 30 days | Service provision |
| Financial Records | 7 years after creation | Tax/legal compliance |
| Usage Logs | 12 months | Security & analytics |
| Support Communications | 3 years | Quality assurance |
| Marketing Prefer/ences | Until cons/ent withdrawn | Cons/ent-based |
Upon account deletion, we will delete or anonymize your personal data within 30 days, except where ret/ention is required by law.
9. Your Privacy Rights
Dep/ending on your location, you may have the following rights regarding your personal data:
9.1 Rights for EU/EEA and UK Resid/ents (GDPR)
- Right of Access (Art. 15): Request a copy of your personal data
- Right to Rectification (Art. 16): Correct inaccurate personal data
- Right to Erasure (Art. 17): Request deletion of your personal data ("right to be forgott/en")
- Right to Restrict Processing (Art. 18): Limit how we use your data
- Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format
- Right to Object (Art. 21): Object to processing based on legitimate interests
- Rights Related to Automated Decision-Making (Art. 22): Not be subject to decisions based solely on automated processing
Supervisory Authority: You have the right to lodge a complaint with your local data protection authority. For the UK, this is the Information Commissioner's Office (ICO). For the EU, contact your national DPA.
9.2 Rights for California Resid/ents (CCPA/CPRA)
- Right to Know: What personal information we collect and how we use it
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: We do not sell personal information
- Right to Non-Discrimination: Equal service regardless of privacy choices
- Right to Correct: Request correction of inaccurate personal information
- Right to Limit Use of S/ensitive Personal Information: Where applicable
9.3 Rights for Brazilian Resid/ents (LGPD)
- Confirmation of the exist/ence of processing
- Access to data
- Correction of incomplete, inaccurate, or outdated data
- Anonymization, blocking, or deletion of unnecessary data
- Data portability
- Deletion of data processed with cons/ent
- Information about sharing with third parties
- Revocation of cons/ent
9.4 Rights for Nigerian Resid/ents (NDPR)
- Right to information about data processing
- Right to access personal data
- Right to rectification of inaccurate data
- Right to withdraw cons/ent
- Right to object to processing
- Right to data portability
9.5 Rights for Australian Resid/ents (Privacy Act)
- Right to access personal information
- Right to correction of personal information
- Right to complain about privacy breaches
- Right to opt-out of direct marketing
9.6 Exercising Your Rights
To exercise any of these rights, please contact us at privacy@invoicemonk.com. We will respond to your request within 30 days (or sooner if required by applicable law). We may need to verify your id/entity before processing your request.
10. Children's Privacy
Invoicemonk is not int/ended for use by individuals under the age of 18. We do not knowingly collect personal information from childr/en. If you are a par/ent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@invoicemonk.com, and we will delete such information from our systems.
11. Data Security
We implem/ent compreh/ensive security measures to protect your personal data:
11.1 Technical Measures
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
- Secure auth/entication with password hashing (bcrypt)
- Regular security audits and p/enetration testing
- Automated threat detection and monitoring
- Firewall and intrusion detection systems
11.2 Organizational Measures
- Employee training on data protection
- Access controls and least-privilege principles
- Incid/ent response procedures
- Regular policy reviews and updates
11.3 Data Breach Notification
In the ev/ent of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours as required by GDPR. If the breach is likely to result in a high risk to your rights, we will also notify you directly.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. Wh/en we make material changes, we will:
- Update the "Last updated" date at the top of this policy
- Notify you via email (for registered users)
- Display a promin/ent notice on our platform
- Where required by law, obtain your cons/ent to the changes
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
G/eneral Privacy Inquiries: privacy@invoicemonk.com
Data Protection Officer: dpo@invoicemonk.com
Mailing Address: Invoicemonk Legal Departm/ent, [Address to be updated]
We are committed to working with you to resolve any privacy concerns. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.