Legal

Privacy Policy

Last updated: 27 July 2026

This Privacy Policy explains how Invoyr Ltd(“Invoyr”, “we”, “us”) collects, uses, and protects your personal data when you use Invoyr and its related services (the “Service”). We are the data controller for the personal data described here. If you have any questions, contact us at support@invoyr.io.

1. Data we collect

  • Account data — your name, email address, and password (stored hashed).
  • Business & invoicing data — your organisation details, clients, invoices, estimates, expenses, and related records you enter.
  • Payment data — processed by our payment providers; we store transaction records and identifiers, not full card details.
  • Bank data — where you connect Open Banking, transaction and account information retrieved via our provider with your consent.
  • Usage & technical data — log data, device/browser information, and cookies necessary to run and secure the Service.

2. How we use your data

  • To provide, maintain, and secure the Service and your account.
  • To process invoices and payments and to send transactional emails (e.g. receipts, reminders).
  • To provide support and respond to your requests.
  • To send marketing emails only where you have opted in; you can unsubscribe at any time.
  • To comply with our legal obligations and prevent fraud or abuse.

3. Legal bases (UK GDPR / EU GDPR)

We rely on: performance of a contract (to provide the Service); legitimate interests (to secure and improve the Service); consent (for marketing email and Open Banking connections); and legal obligation (e.g. tax and accounting records).

4. Sharing & sub-processors

We share data only with providers that help us run the Service, under appropriate data-processing terms:

  • Supabase — database, authentication, and file storage.
  • Stripe and PayPal — payment processing.
  • Resend — transactional and (opt-in) marketing email delivery.
  • TrueLayer — Open Banking connectivity (only when you connect a bank).
  • Vercel — application hosting.

We do not sell your personal data.

5. International transfers

Some providers may process data outside the UK/EEA. Where they do, we rely on appropriate safeguards such as Standard Contractual Clauses or an adequacy decision.

6. Data retention

We keep personal data for as long as your account is active and as needed to provide the Service, then for any period required by law (e.g. financial records). You can request deletion as described below.

7. Your rights

Depending on your location, you may have the right to access, correct, delete, restrict, or port your data, to object to certain processing, and to withdraw consent. California residents (CCPA/CPRA) have rights to know, delete, correct, and opt out of “sale”/“sharing” of personal information — we do not sell or share personal information in that sense. To exercise any right, email support@invoyr.io. You may also lodge a complaint with your local data-protection authority (in the UK, the ICO).

8. Cookies

We use cookies that are strictly necessary to sign you in, keep the Service secure, and remember your preferences. We do not use third-party advertising cookies.

9. Security

We use industry-standard measures including encryption in transit, access controls, and row-level database isolation between organisations. No system is perfectly secure, but we work to protect your data and will notify you of any breach as required by law.

10. Children

The Service is not directed to anyone under 18, and we do not knowingly collect their data.

11. Changes

We may update this policy from time to time. We will post the updated version here and revise the “Last updated” date above.

12. Contact

Invoyr Ltd, 128 City Road, London, United Kingdom, EC1V 2NX. Email: support@invoyr.io.