Privacy Policy
Last updated: April 12, 2026
Data Controller
The data controller responsible for processing your personal data on this website is an individual based in Poland, operating under the name Invoicify.
Contact email: contact@invoicify.dev
For any data protection inquiries, please use the email address above. We respond to all requests within 30 days as required by GDPR.
What We Collect (and What We Don't)
All tool calculations, invoice generation, and PDF creation happen entirely in your browser. No personal data, invoice details, client information, or financial data is ever sent to our servers. We do not store your invoices, VAT calculations, or any data you enter into our tools.
The only data processing occurs through the third-party services listed below, and only with your explicit consent.
Legal Basis for Processing (GDPR Art. 6)
We process personal data under the following legal bases:
- Consent (Art. 6(1)(a)) — for analytics cookies (Google Analytics) and advertising cookies (Google AdSense). You grant consent through our cookie banner and can withdraw it at any time.
- Legitimate Interest (Art. 6(1)(f)) — for essential cookies required for the site to function (cookie preference storage) and for basic security measures (CSRF protection, bot detection).
Cookies and Tracking
We use the following third-party services, subject to your consent:
- Google Analytics 4 — anonymous usage analytics (page views, device type, country). Data is aggregated and cannot identify individual users. Analytics cookies are only set if you consent via the cookie banner.
- Google AdSense — advertising. Ad cookies are only set if you consent. You can manage your ad personalization preferences at any time.
Essential cookies (cookie consent preferences) are stored in your browser's localStorage and are required for the site to function. These do not track you across websites.
Cookie Categories
- Essential — cookie consent preferences (localStorage). Always active. Cannot be disabled.
- Analytics — Google Analytics 4. Only active with your consent. Used to understand how visitors use the site.
- Advertising — Google AdSense. Only active with your consent. Used to show relevant ads and measure performance.
Managing Your Preferences
You can change your cookie preferences at any time by clicking "Cookie Settings" in the footer of any page. By default, only essential cookies are active. No analytics or advertising scripts are loaded until you explicitly opt in.
Third-Party Services
- Google Fonts — we load Instrument Serif and Inter fonts from Google's CDN. Google may log your IP address when fonts are downloaded. Google Fonts privacy FAQ.
- VIES API — when you use the VAT Number Validator, requests are sent directly from your browser to the EU Commission's VIES service. We do not proxy, intercept, or log these requests.
- Flagcdn.com — country flag images are loaded from this CDN when using the Invoice Generator country selector.
International Data Transfers
Google Analytics and Google AdSense may transfer data to servers in the United States. These transfers are protected by the EU-US Data Privacy Framework and Standard Contractual Clauses (SCCs) as implemented by Google. For details, see Google's Privacy Policy.
Data Retention
We do not store any personal data on our servers. Google Analytics data is retained for 14 months, after which it is automatically deleted by Google. Cookie consent preferences are stored in your browser indefinitely until you clear your browser data or reset preferences.
Your Rights Under GDPR (Articles 15-22)
If you are located in the EU/EEA, you have the following rights regarding your personal data:
- Right of access (Art. 15) — request a copy of any personal data we process about you.
- Right to rectification (Art. 16) — request correction of inaccurate personal data.
- Right to erasure (Art. 17) — request deletion of your personal data ("right to be forgotten").
- Right to restrict processing (Art. 18) — request limitation of how we process your data.
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format.
- Right to object (Art. 21) — object to processing based on legitimate interests.
- Right to withdraw consent (Art. 7(3)) — withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Since we do not collect personal data beyond what is processed by Google Analytics (aggregated, non-identifying), these rights primarily apply to your cookie consent settings, which you can manage through our cookie banner at any time.
To exercise any of these rights, email us at contact@invoicify.dev. We will respond within 30 days.
Supervisory Authority
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. For Poland-based operations, the relevant authority is:
Urząd Ochrony Danych Osobowych (UODO)
ul. Stawki 2, 00-193 Warszawa, Poland
uodo.gov.pl
Children's Privacy
Our services are not directed to children under 16. We do not knowingly collect personal information from children.
Changes to This Policy
We may update this privacy policy from time to time. The "last updated" date at the top reflects the most recent revision. Material changes will be communicated by updating this page.