Legal
Privacy policy
Last updated 5 September 2026
This policy explains what MyOnlineInvoice stores, why, who can see it, and how you can export or delete it. It applies to the website, the signed-in app, the public invoice pages your customers open, and the Android install of the same product.
Who we are
MyOnlineInvoice is invoicing software for tradespeople, freelancers and small firms. The controller of personal data for your workspace is the operator of this MyOnlineInvoice site (the account that published it). If you are a customer paying an invoice, the controller of your invoice details is usually the business that billed you — they use MyOnlineInvoice as their processor.
Questions: sign in and send a note from Settings → Support, or use the email on that business’s invoice.
What we collect
We collect only what the product needs to run:
- Account: name, email, password hash (we never store your password in plain text), sign-in provider if you use Google or X.
- Business profile: legal name, address, phone, tax IDs (VAT, EIN, ABN, GSTIN, TRN and similar), logo, invoice defaults.
- Books: customers, invoices, estimates, line items, payments recorded, expenses, time, projects, documents you upload, mileage, credit notes.
- Public invoice use: when a customer opens a pay link we log that the link was viewed and, if they pay, the payment reference the provider sends us — not their card number.
- Support: messages you send from Settings.
- Technical: IP address, browser type, and essential cookies so we can keep you signed in and stop abuse.
We do not scrape your contacts from your phone. We do not buy marketing lists. We do not require a date of birth except where a payment partner’s KYC asks you directly on their site.
What we do not collect
- Full payment card numbers or CVV — those stay with a PCI-compliant processor (for example SumUp, Square, or a bank’s Pay-by-Bank partner such as TrueLayer or Atoa). MyOnlineInvoice never stores PAN data.
- Your customer’s bank login. Open-banking payments happen on the bank’s or provider’s page.
- Advertising identifiers for resale.
- Special-category data (health, religion, union membership) unless you type it into a job note yourself. Please don’t.
Why we use it (legal bases)
- Contract — to create your account, host invoices, send the customer link, and provide the plan you chose.
- Legitimate interests — security, fraud prevention, product diagnostics, and improving the app without using your books for ads.
- Legal obligation — tax, accounting, and responding to a lawful request.
- Consent — optional analytics cookies, and marketing email if you tick it. You can withdraw it.
Who we share it with
We do not sell personal data. We share it only with processors who run the product:
- Hosting and content delivery (the platform that serves this site).
- Database hosting for your workspace.
- Authentication.
- Email delivery if you send invoices or magic links by email.
- Payment providers you connect in Settings — they receive amount, invoice number, and the minimum needed to take the payment.
- AI features (assistant, invoice-from-text, blog autopilot) send the prompt you type to xAI. Do not paste secrets or extra customer data you would not put on an invoice.
Team members you invite (owner, admin, staff, accountant) see what their role allows. Public invoice tokens show that invoice to whoever has the link — treat the link like a document.
International transfers
Servers and subprocessors may be in the UK, the EEA, the United States, or other countries. Where UK GDPR or EU GDPR requires a safeguard (adequacy, standard contractual clauses, or an equivalent), we rely on that. If you are in a country with its own privacy statute (for example Australia’s Privacy Act, Canada’s PIPEDA, California’s CCPA/CPRA, UAE PDPL), you still have the rights that law gives you against the business that billed you, and against us as operator of the app.
How long we keep it
- While the account is open, the books stay so you can file tax and chase payment.
- After you delete the account, we remove or irreversibly anonymise workspace data within 30 days, except records we must keep for tax, dispute, or legal hold.
- Backups roll off on a short cycle (typically within 90 days).
- Public invoice links stop working when you void or the token is rotated.
Many countries expect invoices to be kept for years (often six in the UK). Export before you delete if you still need the archive.
Your rights
Depending on where you live, you can usually:
- Access a copy of your data (export from Settings, or ask us).
- Correct it (edit the customer or invoice).
- Delete it (delete the record or the account), subject to legal keeps.
- Object to or restrict some processing.
- Port the data in a common format.
- Withdraw consent where we relied on it.
- Complain to a regulator — in the UK, the ICO (ico.org.uk); in the EU, your lead authority; elsewhere, your national privacy commissioner.
If you are a data subject of a MyOnlineInvoice user (for example you were invoiced), contact that business first. We will help them if they ask.
Children
MyOnlineInvoice is a business tool. It is not directed at children under 16. If we learn an account was created by a child, we will close it.
Security
Access to the app is behind a signed-in session. Data in transit uses HTTPS. Files you upload are stored with the workspace, not on a public guessable URL. No internet product is perfectly secure; you must still use a strong password and be careful who you invite and which invoice links you forward.
Cookies
Essential cookies keep you signed in and remember the active business. We do not run advertising pixels on the product. See the cookie policy for the list.
Changes
If we change this policy in a way that actually affects you, we will update the date above and, for material changes, notify signed-in owners by email or an in-app banner.