01
Who we are and scope
Invoise is operated by Kappa Alpha Ventures Private Limited ("Invoise", "we", "us" or "our"), an Indian private limited company with GSTIN 29AAHCK7889F1ZS. Our registered office and support channel appear on the Contact Details page.
This Privacy Policy applies when you visit invoise.app, create or use an Invoise account, prepare or share documents, make a purchase, or contact us. If you enter another person's information, you are responsible for having authority to do so and for giving any notice required by law.
02
Information we collect
- Account information: name, email address, OTP verification status, organization, and sign-in records.
- Business records: business and client details, addresses, tax identifiers, invoice and estimate content, payment status, and branding you choose to add.
- Checkout information: plan, billing name and contact details, billing address, tax details, payment status, and payment-provider references.
- Technical information:browser and device details, IP-derived security signals, timestamps, diagnostic events, and fraud or abuse-prevention data.
- Communications: support, privacy, billing, grievance, and refund correspondence.
We do not intentionally collect or store full card numbers, CVVs, UPI PINs, internet-banking passwords, or payment OTPs. Those credentials are entered directly in the payment provider's controlled checkout.
03
How we use information
- Provide, authenticate, secure, support, and improve Invoise.
- Create and manage requested invoices, estimates, PDFs, share links, email deliveries, reports, and related records.
- Process purchases, confirm payment outcomes, provide billing support, and issue refunds or credit documentation when required.
- Prevent fraud and abuse, investigate incidents, maintain audit records, and enforce our agreements.
- Meet accounting, tax, regulatory, and other legal obligations.
- Send service notices and respond to requests. We do not sell or rent personal information.
We process personal data with your consent where consent is required, for specified legitimate uses permitted by law, and where processing is necessary to provide a service you request or meet a legal obligation.
04
Clear, OTP-verified checkout consent
Before checkout details are captured by Invoise or shared with Razorpay or another payment provider, we display a clear notice that identifies the information involved, the receiving provider, and the purpose of the handoff. You must affirmatively agree from an OTP-verified account or session before that capture or sharing takes place.
OTP verification confirms control of the email address or phone number used for the session. It does not authorize unrelated or optional uses. Where processing relies on consent, you may withdraw it by using the relevant product control or emailing us. Withdrawal does not affect lawful processing already completed or information we must retain for payment completion, fraud prevention, disputes, statutory records, or legal compliance.
05
Payment security and PCI DSS
Payments are completed through a hosted checkout supplied by a payment provider such as Razorpay. Sensitive payment credentials are entered into and processed within the provider's environment, not on Invoise servers.
Our payment integration is designed to comply with applicable Payment Card Industry Data Security Standard (PCI DSS) responsibilities. Checkout traffic is encrypted in transit using HTTPS/TLS; access to processor keys and payment records is restricted; and raw cardholder data is not routed through or stored by Invoise. We use payment providers that represent that their checkout environments are PCI DSS compliant.
Security is a shared responsibility. The payment provider secures its checkout and processing environment; Invoise remains responsible for securing our integration, credentials, systems, and the personal information returned to us.
07
Retention and deletion
We keep personal information only as long as reasonably necessary for the purposes in this policy, including security, dispute resolution, tax and accounting records, legal obligations, and enforcement of agreements. Invoice and payment records may need to be retained after an account closes when law or a legitimate audit requirement demands it.
When information is no longer required, we delete or anonymize it through a reasonable process. Protected backup copies may remain for a limited period until the backup cycle replaces them.
08
Your rights, choices, and grievances
Subject to applicable law, you may request access to a summary of personal data we process and the parties with whom it has been shared; correction, completion, updating, or erasure; withdrawal of consent; or grievance redressal. You may also nominate another person to exercise applicable rights in the event of death or incapacity.
Send a request to hello@invoise.app. We may verify your identity and may retain information where law requires it. We will acknowledge and resolve grievances within the period required by applicable law. If a grievance remains unresolved, you may use any escalation available under applicable data-protection law.
09
Security and incidents
We use controls appropriate to the nature of the information, including encryption in transit, access controls, least-privilege credentials, tenant isolation, logging, backups, and provider security reviews. No internet service can guarantee absolute security.
If a personal-data breach requires notice, we will take reasonable steps to contain it and notify affected individuals and the relevant authority in the form and timeframe required by applicable law.
10
Children, policy changes, and law
Invoise is a business service and is not directed to children. We do not knowingly create accounts for children or process their personal data for targeted advertising.
We may update this policy when the service, our providers, or the law changes. Material updates will be posted here with a new effective date and communicated through the service where required.
This policy is governed by applicable Indian law, including the Digital Personal Data Protection Act, 2023 and rules in force for the relevant processing.
Document record
- 23 July 2026
- Kappa Alpha Ventures Private Limited