Skip to content

Legal · Privacy

Privacy Policy

A clear record of what Invoise collects, why we need it, who receives it, and how you stay in control.

Effective 22 August 202612 sections · about 9 min
  • Clear notice before checkout information is captured or shared.
  • Affirmative consent from an OTP-verified session.
  • Optional AI review shares a minimized invoice summary only when you request it.
  • Hosted, PCI DSS-compliant payment processing with encrypted transit.

01

Who we are and scope

Invoise is operated by Kappa Alpha Ventures Private Limited ("Invoise", "we", "us" or "our"), an Indian private limited company with GSTIN 29AAHCK7889F1ZS. Our registered office and support channel appear on the Contact Details page.

This Privacy Policy applies when you visit invoise.app, create or use an Invoise account, prepare or share documents, make a purchase, or contact us. If you enter another person's information, you are responsible for having authority to do so and for giving any notice required by law.

02

Information we collect

  • Account information: name, email address, OTP verification status, organization, and sign-in records.
  • Business records: business and client details, addresses, tax identifiers, invoice and estimate content, payment status, and branding you choose to add.
  • Checkout information: plan, billing name and contact details, billing address, tax details, payment status, and payment-provider references.
  • Technical information:browser and device details, IP-derived security signals, timestamps, diagnostic events, and fraud or abuse-prevention data.
  • Communications: support, privacy, billing, grievance, and refund correspondence.
  • Public tool inputs: the words you type into our public HSN and SAC code finders, used only to look up a matching code. We do not store this text.

We do not intentionally collect or store full card numbers, CVVs, UPI PINs, internet-banking passwords, or payment OTPs. Those credentials are entered directly in the payment provider's controlled checkout.

03

How we use information

  • Provide, authenticate, secure, support, and improve Invoise.
  • Create and manage requested invoices, estimates, PDFs, share links, email deliveries, reports, and related records.
  • Process purchases, confirm payment outcomes, provide billing support, and issue refunds or credit documentation when required.
  • Prevent fraud and abuse, investigate incidents, maintain audit records, and enforce our agreements.
  • Meet accounting, tax, regulatory, and other legal obligations.
  • Send service notices and respond to requests. We do not sell or rent personal information.

We process personal data with your consent where consent is required, for specified legitimate uses permitted by law, and where processing is necessary to provide a service you request or meet a legal obligation.

04

Optional AI-assisted invoice review

Pro users may choose an AI-assisted review of an invoice draft. The feature does not run until you select Review invoice. It provides advisory suggestions only: it does not edit the invoice, determine tax or legal compliance, or control whether the invoice can be finalized.

To provide the review, Invoise sends DeepSeek a minimized, structured invoice summary containing dates, currency, tax treatment and jurisdiction, country and state codes, presence indicators, line-item descriptions and classifications, up to three candidate codes with their official descriptions, how the current code was selected, or the bounded reason a qualifying pure-agent disbursement has no code, quantities, rates, taxes, and totals. We exclude party names, full tax identifiers, email addresses, phone numbers, postal-address text, payment details, notes, footer, branding, and media.

Line-item descriptions are written by account users and may still contain personal, confidential, or sensitive information. Do not use AI review for an invoice whose descriptions contain information you are not authorized to provide to an AI service. You can avoid this processing by not selecting Review invoice; the normal invoice and finalization features remain available.

Invoise engages DeepSeek as an AI infrastructure provider under terms between Invoise and DeepSeek. You do not separately accept DeepSeek's terms. DeepSeek processes the minimized input to return the requested review. This may involve processing or storage outside India, including in the People's Republic of China, and its current public materials describe using inputs to operate, secure, develop, and improve its services. For information about the provider's current practices, see DeepSeek's Open Platform Terms and Privacy Policy.

06

Payment security and PCI DSS

Payments are completed through a hosted checkout supplied by a payment provider such as Razorpay. Sensitive payment credentials are entered into and processed within the provider's environment, not on Invoise servers.

Our payment integration is designed to comply with applicable Payment Card Industry Data Security Standard (PCI DSS) responsibilities. Checkout traffic is encrypted in transit using HTTPS/TLS; access to processor keys and payment records is restricted; and raw cardholder data is not routed through or stored by Invoise. We use payment providers that represent that their checkout environments are PCI DSS compliant.

Security is a shared responsibility. The payment provider secures its checkout and processing environment; Invoise remains responsible for securing our integration, credentials, systems, and the personal information returned to us.

07

Sharing and international transfers

We share information only as reasonably needed with:

  • Hosting, authentication, storage, email, security, customer-support, and payment providers acting for the service, and Google Analytics 4 for traffic on our marketing pages (see Cookies and analytics).
  • A client or recipient when you direct Invoise to send or share a document with them.
  • Government, regulatory, judicial, or law-enforcement authorities where disclosure is legally required.
  • Professional advisers or a successor organization in a legitimate corporate transaction, subject to appropriate confidentiality.

Providers receive only the information reasonably required for their function and must protect it under applicable law and contractual safeguards. Some providers may process information outside India; in those cases we use safeguards required by applicable Indian law and comply with any transfer restrictions notified by the Government of India.

08

Cookies and analytics

We use cookies and browser storage for three things: keeping the free lookup tools usable for everyone, remembering a display preference, and understanding which marketing pages are read. None of it is used for advertising.

  • Rate-limiting cookie (invoise_gst_demo): set after you pass the bot check on the free HSN, SAC, or GSTIN lookup tools. It lets our servers tell repeat visits apart so the free tools stay usable for everyone, carries no name or contact detail, cannot be read by any script, and expires after 30 days.
  • Theme preference: stored in your browser only, never sent to us, so the site opens in the light or dark mode you last chose. It stays until you clear your browser's site data.
  • Google Analytics 4: measures visits to our marketing and legal pages only. It never runs on the signed-in product, an invoice share link, or any page that could contain your business data. It sets cookies (typically _ga and a second cookie named for our tracking ID) for up to two years, though some browsers cap this considerably shorter — Chrome, for one, to 400 days. We send Google the page you visited and standard technical details. We do not send anything you type into a search box or form field.

Three more providers set their own cookies where you use the part of the service they support. Cloudflare Turnstile runs a bot check on the code finders and the contact form; most visitors never see a puzzle. Razorpay sets checkout cookies while you complete a payment inside the product, described further in Payment security and PCI DSS. Supabase, our authentication provider, sets the cookie that keeps you signed in once you have an account. We do not control what these providers set; see their own policies for detail.

Your browser lets you block or delete cookies, usually from its privacy or site-data settings. Blocking analytics will not stop the free lookup tools, checkout, or sign-in from working. To opt out of Google Analytics specifically, Google publishes a browser opt-out add-on.

09

Retention and deletion

We keep personal information only as long as reasonably necessary for the purposes in this policy, including security, dispute resolution, tax and accounting records, legal obligations, and enforcement of agreements. Invoice and payment records may need to be retained after an account closes when law or a legitimate audit requirement demands it.

When information is no longer required, we delete or anonymize it through a reasonable process. Protected backup copies may remain for a limited period until the backup cycle replaces them.

The steps for account users and WhatsApp recipients are published in our Data Deletion Instructions. When a WhatsApp recipient asks us to delete their data, we retain only a keyed, non-reversible identifier where needed to keep their recipient-wide opt-out effective. It is not used to contact or identify them.

10

Your rights, choices, and grievances

Subject to applicable law, you may request access to a summary of personal data we process and the parties with whom it has been shared; correction, completion, updating, or erasure; withdrawal of consent; or grievance redressal. You may also nominate another person to exercise applicable rights in the event of death or incapacity.

Send a request to hello@invoise.app. We may verify your identity and may retain information where law requires it. We will acknowledge and resolve grievances within the period required by applicable law. If a grievance remains unresolved, you may use any escalation available under applicable data-protection law.

11

Security and incidents

We use controls appropriate to the nature of the information, including encryption in transit, access controls, least-privilege credentials, tenant isolation, logging, backups, and provider security reviews. No internet service can guarantee absolute security.

If a personal-data breach requires notice, we will take reasonable steps to contain it and notify affected individuals and the relevant authority in the form and timeframe required by applicable law.

12

Children, policy changes, and law

Invoise is a business service and is not directed to children. We do not knowingly create accounts for children or process their personal data for targeted advertising.

We may update this policy when the service, our providers, or the law changes. Material updates will be posted here with a new effective date and communicated through the service where required.

This policy is governed by applicable Indian law, including the Digital Personal Data Protection Act, 2023 and rules in force for the relevant processing.

Operated by Kappa Alpha Ventures Private Limited · hello@invoise.app