Skip to content

Legal · Privacy

Privacy Policy

A clear record of what Invoise collects, why we need it, who receives it, and how you stay in control.

01

Clear notice before checkout information is captured or shared.

02

Affirmative consent from an OTP-verified session.

03

Hosted, PCI DSS-compliant payment processing with encrypted transit.

01

Who we are and scope

Invoise is operated by Kappa Alpha Ventures Private Limited ("Invoise", "we", "us" or "our"), an Indian private limited company with GSTIN 29AAHCK7889F1ZS. Our registered office and support channel appear on the Contact Details page.

This Privacy Policy applies when you visit invoise.app, create or use an Invoise account, prepare or share documents, make a purchase, or contact us. If you enter another person's information, you are responsible for having authority to do so and for giving any notice required by law.

02

Information we collect

  • Account information: name, email address, OTP verification status, organization, and sign-in records.
  • Business records: business and client details, addresses, tax identifiers, invoice and estimate content, payment status, and branding you choose to add.
  • Checkout information: plan, billing name and contact details, billing address, tax details, payment status, and payment-provider references.
  • Technical information:browser and device details, IP-derived security signals, timestamps, diagnostic events, and fraud or abuse-prevention data.
  • Communications: support, privacy, billing, grievance, and refund correspondence.

We do not intentionally collect or store full card numbers, CVVs, UPI PINs, internet-banking passwords, or payment OTPs. Those credentials are entered directly in the payment provider's controlled checkout.

03

How we use information

  • Provide, authenticate, secure, support, and improve Invoise.
  • Create and manage requested invoices, estimates, PDFs, share links, email deliveries, reports, and related records.
  • Process purchases, confirm payment outcomes, provide billing support, and issue refunds or credit documentation when required.
  • Prevent fraud and abuse, investigate incidents, maintain audit records, and enforce our agreements.
  • Meet accounting, tax, regulatory, and other legal obligations.
  • Send service notices and respond to requests. We do not sell or rent personal information.

We process personal data with your consent where consent is required, for specified legitimate uses permitted by law, and where processing is necessary to provide a service you request or meet a legal obligation.

05

Payment security and PCI DSS

Payments are completed through a hosted checkout supplied by a payment provider such as Razorpay. Sensitive payment credentials are entered into and processed within the provider's environment, not on Invoise servers.

Our payment integration is designed to comply with applicable Payment Card Industry Data Security Standard (PCI DSS) responsibilities. Checkout traffic is encrypted in transit using HTTPS/TLS; access to processor keys and payment records is restricted; and raw cardholder data is not routed through or stored by Invoise. We use payment providers that represent that their checkout environments are PCI DSS compliant.

Security is a shared responsibility. The payment provider secures its checkout and processing environment; Invoise remains responsible for securing our integration, credentials, systems, and the personal information returned to us.

06

Sharing and international transfers

We share information only as reasonably needed with:

  • Hosting, authentication, storage, email, security, analytics, customer-support, and payment providers acting for the service.
  • A client or recipient when you direct Invoise to send or share a document with them.
  • Government, regulatory, judicial, or law-enforcement authorities where disclosure is legally required.
  • Professional advisers or a successor organization in a legitimate corporate transaction, subject to appropriate confidentiality.

Providers receive only the information reasonably required for their function and must protect it under applicable law and contractual safeguards. Some providers may process information outside India; in those cases we use safeguards required by applicable Indian law and comply with any transfer restrictions notified by the Government of India.

07

Retention and deletion

We keep personal information only as long as reasonably necessary for the purposes in this policy, including security, dispute resolution, tax and accounting records, legal obligations, and enforcement of agreements. Invoice and payment records may need to be retained after an account closes when law or a legitimate audit requirement demands it.

When information is no longer required, we delete or anonymize it through a reasonable process. Protected backup copies may remain for a limited period until the backup cycle replaces them.

08

Your rights, choices, and grievances

Subject to applicable law, you may request access to a summary of personal data we process and the parties with whom it has been shared; correction, completion, updating, or erasure; withdrawal of consent; or grievance redressal. You may also nominate another person to exercise applicable rights in the event of death or incapacity.

Send a request to hello@invoise.app. We may verify your identity and may retain information where law requires it. We will acknowledge and resolve grievances within the period required by applicable law. If a grievance remains unresolved, you may use any escalation available under applicable data-protection law.

09

Security and incidents

We use controls appropriate to the nature of the information, including encryption in transit, access controls, least-privilege credentials, tenant isolation, logging, backups, and provider security reviews. No internet service can guarantee absolute security.

If a personal-data breach requires notice, we will take reasonable steps to contain it and notify affected individuals and the relevant authority in the form and timeframe required by applicable law.

10

Children, policy changes, and law

Invoise is a business service and is not directed to children. We do not knowingly create accounts for children or process their personal data for targeted advertising.

We may update this policy when the service, our providers, or the law changes. Material updates will be posted here with a new effective date and communicated through the service where required.

This policy is governed by applicable Indian law, including the Digital Personal Data Protection Act, 2023 and rules in force for the relevant processing.

Document record

Effective date
23 July 2026
Operated by
Kappa Alpha Ventures Private Limited