Legal
Privacy Policy
Last updated September 16, 2026
Draft for legal review. This document is awaiting review by counsel and may change before it is final.
1. Who we are
Invoicevisor is cloud-based invoicing, estimating, and business-management software for small businesses, contractors, and freelancers. It is operated by Codevisor LLC, a limited liability company organised under the laws of the State of Texas, United States (“Codevisor”, “we”, “us”, “our”).
This Privacy Policy explains what personal information we collect through invoicevisor.com and the Invoicevisor application (the “Service”), why we collect it, who we share it with, how long we keep it, and what choices you have.
The Service is offered to businesses in the United States and Canada. We do not market or offer the Service in the European Economic Area, the United Kingdom, or Switzerland. If you access the Service from outside the US or Canada, you do so on your own initiative and are responsible for compliance with your local law.
By using the Service you agree to this Policy. If you do not agree, please do not use the Service.
2. Two roles: when we decide, and when you decide
Invoicevisor handles two distinct kinds of information, and our responsibility differs for each.
a) Information about you, our account holder. Your name, email address, phone number, login credentials, security settings, subscription records, support correspondence, and logs of your use of the Service. We determine how this is used, and this Policy governs it.
b) Information you enter about your own clients and business. Client records, invoices, estimates, receipts, appointments, and everything else you create in the Service. This is your data. We store and process it on your behalf, on your instructions, solely to provide the Service to you. We do not sell it, we do not mine it for advertising, and we do not use it to build profiles of you or anyone else.
You are responsible for collecting your clients’ information lawfully and for giving them any notice their law requires. If one of your clients asks us about their information, we will refer them to you — see Section 10.5.
3. What we collect
3.1 Account and profile
- First and last name
- Email address — your login identifier, and where we send verification and service messages
- Phone number, where you provide one or enrol it for SMS-based multi-factor authentication
- A salted cryptographic hash of your password. We never store your password in readable form and cannot recover it for you.
- Your role in the account (administrator or standard user) and whether the account is active
- If you use “Sign in with Google”: the unique account identifier Google returns, plus the email address and name on that Google account. We request identity information only. We do not request or receive access to your Gmail, Drive, Calendar, or any other Google service data.
3.2 Security and authentication
- Email-verification and password-reset tokens
- Multi-factor authentication data: authenticator-app secrets (stored encrypted), enrolled phone numbers, one-time codes delivered by SMS or email, and recovery codes
- Passkey / WebAuthn credentials — public keys and credential identifiers registered by your device. A passkey’s private key never leaves your device and is never transmitted to us.
- “Trusted device” records, so you are not challenged for a second factor on every sign-in from a device you have already verified
- Session and refresh-token records that keep you signed in, and which you can revoke
3.3 Business profile
Business name, contact details, address, tax or registration identifiers, logo and branding you upload for use on documents, default currency, tax settings, document numbering preferences, and the payment options you choose to display on your invoices.
3.4 Content you create (“Your Data”)
Operational data you enter or upload, which will often include personal information about third parties:
- Clients and contacts — names, email addresses, phone numbers, billing and shipping addresses, notes, and attached files
- Documents — invoices, estimates, and credit notes, with line items, prices, discounts, taxes, totals, terms, and the client name and address recorded on each document
- Payments — amounts, dates, methods, and reference notes recorded against invoices
- Catalogue — products and services you sell, with SKUs, descriptions, and default prices
- Expenses and receipts — expense records, categories, amounts, and receipt images or PDFs
- Mileage — vehicles, trips, distances, dates, and purposes
- Appointments — dates, times, related clients, and notes
- Recurring templates — schedules for automatically issued invoices
- Email templates — the wording you configure for documents and reminders sent to your clients
3.5 Subscription and billing
Your Invoicevisor subscription is billed through Stripe. Stripe collects your payment card or bank details directly. Invoicevisor never receives, stores, or has access to your full card number, CVC, or bank credentials. We retain only:
- your Stripe customer identifier
- your plan, billing interval, user count, subscription status, trial end date, and renewal date
- subscription invoice, payment, and refund records
- any promotional code applied to your account
Stripe processes this information as an independent controller under its own privacy policy.
3.6 Online payments from your clients (Stripe Connect)
If you enable online card payments, you onboard your own Stripe connected account through the Service. During onboarding, Stripe collects the identity, business, and bank information it needs to verify you and pay you out — collected by Stripe, under Stripe’s terms, directly from you. We receive only your connected account identifier and status flags such as whether charges and payouts are enabled, plus records of checkout, refund, and dispute events on your invoices so we can show them to you.
Funds from your clients settle directly to your Stripe account. Invoicevisor never holds, transmits, or takes custody of your money or your clients’ money.
If you display a Venmo handle on your invoices, we store only the handle you enter. It is rendered as a payment link or QR code for your client. We are not involved in any resulting transaction and receive no information about it.
3.7 People who view or pay an invoice you send
When you send a document, the recipient can open it through a secure link without creating an account. For those visitors we process a limited amount of information — the link identifier, the date and time of access, IP address, and browser user-agent — to deliver the document, protect against abuse of the link, and record delivery and payment status for you. We do not create accounts for, market to, or build profiles of your clients.
3.8 Communications with us
Correspondence you send to our support address, including your email address, the content of your message, and any attachments or screenshots.
Messages you send through the contact form on invoicevisor.com: your name, email address, subject, and message. To keep automated spam out of the form, it uses Cloudflare Turnstile, which processes technical information about your browser and connection, such as your IP address, to tell people apart from bots.
3.9 Technical, usage, and security logs
Collected automatically:
- IP address and browser user-agent
- Date and time of access, and the pages, screens, and API endpoints requested
- Authentication events — successful and failed sign-ins, MFA challenges, password changes, and device-trust decisions
- An audit trail of significant actions in your account: who did what, to which record, and when — kept for security, accountability, and dispute resolution
- Diagnostic and error information, and aggregate performance metrics
3.10 Cookies and similar technologies
We currently use cookies only for strictly necessary purposes: keeping you signed in (session and refresh tokens), remembering a trusted device, protecting against cross-site request forgery, and routing requests correctly. These cannot be switched off without breaking the Service, and they do not track you across other websites.
We do not currently use third-party analytics, advertising, or cross-site tracking cookies on the Service. If that changes, we will update this Policy, give notice, and where required obtain your consent before setting non-essential cookies.
3.11 Mobile app permissions
The Invoicevisor iOS and Android apps ask for device permissions only when you use a feature that needs them, and you can withdraw any permission in your device settings.
- Camera and photos — used only when you scan or attach a receipt, or add a logo. Location metadata embedded in photos is removed on your device before upload.
- Location — used only while the app is open and you are tracking a mileage trip, to record the route and distance of that trip. We do not track your location at any other time.
- Contacts — used only to read the single contact you choose when adding a client. We do not upload your address book.
- Face ID, Touch ID, or fingerprint — used to unlock the app. Biometric matching is performed by your device’s operating system; biometric data never leaves your device and is never received by us.
- Push notifications — if you allow them, we store a device token so we can notify you about payments, reminders, and account activity.
If you use “Sign in with Apple”, we receive the unique account identifier Apple returns and the name and email address Apple shares, which may be a private relay address.
3.12 What we do not collect
We do not intentionally collect sensitive personal information such as health or biometric data, precise geolocation other than the mileage-trip tracking you start yourself (Section 3.11), government identification numbers, racial or ethnic origin, religious beliefs, or information about a person’s sex life or sexual orientation, and you should not upload such information into the Service. We do not buy personal information from data brokers. We do not knowingly collect information from anyone under 18.
4. How we use information
We use personal information to:
- create, administer, and secure your account
- deliver the Service — storing your records, generating documents and PDFs, calculating totals, and sending the invoices, estimates, and reminders you instruct us to send
- verify your email address and authenticate you, including multi-factor authentication
- extract data from receipts you upload (see Section 5)
- take payment for your subscription and manage renewals, plan changes, and refunds
- enable the online payment methods you choose to offer your clients
- provide customer support, which may require our staff to access your account records to reproduce and resolve an issue
- detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms — including rate limiting and anomaly detection
- maintain audit logs and records of account activity
- monitor performance, diagnose faults, and improve and develop the Service
- send you service and transactional messages: verification, security alerts, billing notices, and material changes to the Service
- send product news and marketing, where you have not opted out
- comply with tax, accounting, and other legal obligations, and respond to lawful requests
- establish, exercise, or defend legal claims
We will not use your information for a materially different purpose without telling you first.
5. Automated processing of receipts
Receipt scanning is optional. When you upload a receipt, the image or PDF is sent to Amazon Textract, an automated document-analysis service operated by Amazon Web Services, which returns machine-readable text and field values — merchant, date, total, tax — that we use to pre-fill an expense record.
- This is automated text extraction, not automated decision-making that produces legal or similarly significant effects about any person. Every extracted value is shown to you for review, and nothing is saved until you accept it.
- Extracted values are machine-generated suggestions and may be wrong. You are responsible for checking them.
- Scanning is subject to a per-plan monthly allowance. When the allowance is used up, scanning stops until your next billing cycle. There are no overage charges.
We do not use Your Data — your records, documents, receipts, or client information — to train artificial intelligence or machine learning models, whether ours or anyone else’s.
6. Who we share information with
We do not sell personal information. We do not share personal information for cross-context behavioural advertising or targeted advertising. We have never done either.
We disclose information only as follows.
6.1 Service providers
Each vendor below is bound by contract to process information only on our instructions, to protect it appropriately, and not to use it for its own purposes.
| Provider | What it does for us | Data involved | Where processed |
|---|---|---|---|
| Amazon Web Services | Application hosting, database, and file storage for all Service data | All Service data, including Your Data and uploaded files | United States (us-east-1) |
| Amazon SES (AWS) | Sending transactional email — verification, password reset, security alerts, and the invoices, estimates, and reminders you send your clients | Sender and recipient email addresses, message content, attachments | United States |
| Amazon SNS (AWS) | Sending SMS one-time codes for multi-factor authentication | Phone number, verification code | United States |
| Amazon Textract (AWS) | Automated data extraction from receipts you upload | Receipt images and extracted text | United States |
| Amazon SNS (AWS), Apple Push Notification service, Firebase Cloud Messaging (Google) | Delivering push notifications to the mobile apps, only if you allow them | Device token, notification content | United States / global |
| Cloudflare | Turnstile bot protection on the invoicevisor.com contact form | IP address, browser and device signals | United States / global |
| Stripe | Subscription billing; and, if you enable it, processing of card payments from your clients into your own connected account | Billing contact and subscription records; payment method data held by Stripe; connected-account status | United States / global |
| “Sign in with Google” identity verification, only if you choose to use it | Google account identifier, email address, name | United States / global | |
| Apple | “Sign in with Apple” identity verification, only if you choose to use it | Apple account identifier, email address (which may be a private relay address), name | United States / global |
We keep this list current. If we add a provider that materially changes how your information is handled, we will update this Policy.
6.2 Recipients of documents you send
When you send an invoice, estimate, or reminder through the Service, we deliver it to the recipient you specify. That is done on your instruction. You are responsible for the accuracy of the recipient address and for your right to contact that person.
6.3 Other users in your account
Invoicevisor accounts support multiple users. Other users — particularly administrators — can see the records in the account and may be able to see your name, email address, role, and your actions in the audit trail. If you were invited into an account created by someone else, that account owner controls the account and its data.
6.4 Legal and safety
We may disclose information where we believe in good faith it is necessary to comply with a law, regulation, subpoena, court order, or other binding legal process; to enforce our Terms; to investigate suspected fraud, security incidents, or abuse; or to protect the rights, property, or safety of Codevisor, our users, or the public. Where we are legally permitted to do so, we will make reasonable efforts to notify you before responding to a legal request for your information.
6.5 Business transfers
If we are involved in a merger, acquisition, financing, reorganisation, or sale of assets, information may be transferred as part of that transaction. We will require the recipient to honour the commitments in this Policy, and we will notify you of any change of ownership and of any material change in how your information is handled.
6.6 Aggregated and de-identified information
We may create aggregated or de-identified statistics that cannot reasonably be used to identify any individual — for example, average invoice volume per plan, or feature adoption rates — and use them to operate, improve, and report on our business. We will not attempt to re-identify such information, and we will maintain it in de-identified form.
7. Where your information is processed
The Service is hosted in the United States, in the AWS us-east-1 region. Our service providers are located in the United States.
If you are in Canada: your information, including information about your clients, is stored and processed in the United States. While it is there, it is subject to United States law and may be accessible to United States courts, law enforcement, and national security authorities under lawful process. We use contractual and technical measures to protect it, but you should be aware of this before using the Service, and you should consider it when telling your own clients how their information is handled.
8. How long we keep information
| Information | Retention |
|---|---|
| Your account and Your Data, while the account is open | For as long as the account remains active |
| Your account and Your Data, after cancellation or deactivation | 90 days, then permanently deleted. You can reactivate and recover everything during that window; after it, recovery is not possible |
| Individual records you delete in the app | Removed from your view immediately and purged from our active systems within 30 days |
| Encrypted database backups | 7 days, after which they are overwritten. Deleted data may persist in a backup until that backup expires |
| Subscription billing, invoicing, and tax records | 7 years, as required for US tax and accounting purposes |
| Security and audit logs | 12 months, longer where retained for an active investigation or legal claim |
| Email delivery logs | 90 days |
| Support correspondence | 24 months from last contact |
| Marketing contact details | Until you unsubscribe. We then keep a minimal suppression record indefinitely so that we do not contact you again |
We may retain information longer where necessary to establish, exercise, or defend legal claims, or where subject to a legal hold.
9. How we protect information
We maintain administrative, technical, and physical safeguards designed to protect personal information, including:
- encryption in transit using TLS, and encryption at rest for our database and file storage
- passwords stored only as salted cryptographic hashes, never in recoverable form
- encryption of sensitive stored secrets, such as authenticator-app seeds
- multi-factor authentication support: authenticator apps, SMS, email codes, and passkeys
- strict logical separation of each account’s data, enforced at the data-access layer so that one account cannot read another’s records
- role-based access control within your account
- rate limiting and abuse detection on authentication and other sensitive endpoints
- audit logging of significant actions
- least-privilege access for our personnel, granted only where needed to operate or support the Service
- regular patching and dependency updates
No system is perfectly secure and we cannot guarantee absolute security. You are responsible for keeping your password confidential, for enabling multi-factor authentication, and for the actions of users you invite into your account. If you believe your account has been compromised, contact us immediately at support@codevisor.com.
Breach notification. If a security breach compromises your personal information, we will notify you and any regulator as required by applicable law, including the breach-notification statutes of the US states where affected users reside and, for Canadian users, the requirements of PIPEDA where the breach poses a real risk of significant harm. We will do so without unreasonable delay.
10. Your rights and choices
10.1 Available to everyone
Whatever your location, you can:
- Access and correct most of your information directly in the Service, in your profile and business settings
- Export your business records using the Service’s export tools
- Delete individual records, or close your account entirely
- Opt out of marketing using the unsubscribe link in any marketing email
- Ask us for a copy of the personal information we hold about you, or ask us to correct or delete it, by contacting support@codevisor.com
10.2 If you are in California
Under the California Consumer Privacy Act as amended, you have the right to know what personal information we collect, use, and disclose; to delete it; to correct it; to opt out of its sale or sharing; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights.
We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is no opt-out for you to exercise. In the preceding twelve months we collected the categories of information described in Section 3, used them for the purposes in Section 4, and disclosed them for business purposes to the service providers in Section 6.1. You may exercise your rights at support@codevisor.com, and you may use an authorised agent if you give them written permission and we can verify it.
10.3 If you are in another US state with a privacy law
Residents of states including Texas, Virginia, Colorado, Connecticut, Utah, Oregon, and Montana have comparable rights of access, correction, deletion, portability, and opt-out of targeted advertising and sale. We honour these requests regardless of whether we currently meet a given statute’s applicability thresholds, and we do not engage in targeted advertising, sale of personal information, or profiling with legal effects. Contact support@codevisor.com.
10.4 If you are in Canada
Under PIPEDA and comparable provincial law you have the right to access the personal information we hold about you, to challenge its accuracy and have it corrected, and to withdraw consent, subject to legal and contractual restrictions. You may also complain to the Office of the Privacy Commissioner of Canada. We would appreciate the opportunity to address your concern first.
10.5 How we handle requests
Email support@codevisor.com. We will verify your identity before acting — usually by confirming control of the email address on the account. We respond within 45 days, and will tell you if we need a permitted extension. There is no charge unless a request is manifestly unfounded, repetitive, or excessive.
We may decline a request where the law permits — for example where fulfilling it would compromise another person’s privacy or security, conflict with a record we are legally required to keep, or interfere with a legal claim. We will explain our reasons.
If your request concerns information held inside a customer’s Invoicevisor account — for instance, if you received an invoice from a business that uses Invoicevisor — we hold that information on that business’s behalf and are not permitted to change or delete it on our own initiative. Please contact the business directly. If you contact us, we will refer you to them where we can identify them, and we will assist them in responding.
11. Children
The Service is a business tool for people aged 18 or over. It is not directed at children, and we do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it and close the account. If you believe a child has given us information, contact support@codevisor.com.
12. Marketing communications
We will send you service and transactional messages — email verification, security alerts, billing notices, and important changes to the Service — for as long as you have an account. These are part of the Service and cannot be turned off separately, though you may close your account.
Marketing emails are separate. Every marketing email includes an unsubscribe link that works with one click and takes effect within ten business days, as required by the CAN-SPAM Act. You can also unsubscribe by contacting us. Opting out of marketing does not stop service messages.
Marketing emails include our physical postal address as US law requires. See Section 15.
13. Third-party links and services
Our website and the Service may link to third-party sites and services — including Stripe, Google, Apple, and Venmo — that we do not control. This Policy does not apply to them. Read their privacy policies before providing them with information.
14. Changes to this Policy
We may update this Policy. When we do, we will revise the “Last updated” date at the top. If a change is material — a new purpose for using your information, a new category of recipient, the introduction of tracking technologies, or a change of ownership — we will notify you by email or in the Service at least 30 days before it takes effect, and we will obtain your consent where the law requires it. Continuing to use the Service after a change takes effect means you accept the updated Policy. Prior versions are available on request.
15. Contact us
Codevisor LLC
Williamson County, Texas, United States
Email: support@codevisor.com