Privacy Policy
Effective Date: August 6, 2025
Last Updated: August 6, 2025
1. Introduction
Invoice My Clients LLC ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our financial technology software-as-a-service platform (the "Service").
By using our Service, you consent to the data practices described in this policy.
2. Information We Collect
2.1 Personal Information
We may collect the following types of personal information:
- Identity Information: Full name, date of birth, Social Security number, government-issued ID numbers
- Contact Information: Email address, phone number, mailing address
- Financial Information: Bank account details, credit/debit card information, transaction history, credit scores, income information
- Professional Information: Employment details, business information, tax identification numbers
- Verification Information: Documentation for identity verification, Know Your Customer (KYC) requirements
2.2 Technical Information
- Device information (IP address, browser type, operating system)
- Usage data (pages visited, features used, time spent)
- Cookies and tracking technologies
- Log files and analytics data
2.3 Third-Party Information
We may receive information about you from:
- Credit bureaus and reporting agencies
- Financial institutions
- Identity verification services
- Public records
- Business partners and affiliates
3. How We Use Your Information
We use your information to:
- Provide Services: Process transactions, maintain accounts, deliver requested services
- Compliance: Meet regulatory requirements, prevent fraud, conduct KYC/AML checks
- Communication: Send service notifications, updates, and customer support
- Improvement: Analyze usage patterns, develop new features, enhance security
- Marketing: Send promotional materials (with your consent where required)
- Legal: Comply with legal obligations, resolve disputes, enforce agreements
Session replay on our marketing website
On our public marketing pages (www.invoicemyclients.com) we use PostHog to capture anonymized session replays: how visitors scroll, click, and move through pages. Recordings mask everything you type, and areas that display typed content (such as the invoice builder and its preview) are excluded from capture entirely. Replay honors the same consent choice as our analytics: in regions requiring consent it records nothing until you accept the cookie banner, and declining stops recording. We use these recordings solely to improve the website. We do not use session replay inside the Invoice My Clients application. See the PostHog privacy documentation for how PostHog processes this data.
Visit and form activity notifications
Our marketing website also sends us first-party notifications about aggregate visitor activity: when a visit ends we may receive a short summary of it (which pages were viewed and for how long), and we are notified when a contact or newsletter form is started or completed and when an invoice template is downloaded. These notifications reach us as text messages through Twilio, a communications provider. They never contain anything you type into a form: no names, email addresses, or message contents, only the type of event and the pages or template involved.
4. Legal Basis for Processing (GDPR)
For users in the European Union, we process your data based on:
- Contract Performance: To provide services you've requested
- Legal Obligation: To comply with financial regulations
- Legitimate Interest: For fraud prevention, security, and service improvement
- Consent: For marketing communications (where required)
5. Information Sharing and Disclosure
We may share your information with:
5.1 Service Providers
Third-party vendors who perform services on our behalf:
- Payment processors
- Cloud hosting providers
- Identity verification services
- Customer support platforms
- Analytics providers
5.2 Financial Partners
- Banks and financial institutions
- Credit reporting agencies
- Regulatory bodies and government agencies
5.3 Legal Requirements
When required by law or to:
- Comply with legal process or government requests
- Protect our rights and property
- Prevent fraud or security threats
- Protect user safety
5.4 Business Transfers
In connection with mergers, acquisitions, or asset sales
5.5 Mobile and SMS Information
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All of the sharing categories described above exclude text messaging originator opt-in data and consent; that information will not be shared with any third parties. Phone numbers you give us for SMS are used only to send the messages you asked for, and we do not sell, rent, or trade them.
6. Data Security
We implement industry-standard security measures including:
- Encryption of data in transit and at rest
- Multi-factor authentication
- Regular security audits and penetration testing
- Access controls and employee training
- Card data is handled by Stripe, a PCI DSS Level 1 service provider; our infrastructure runs on AWS, which maintains SOC 2 and other independent certifications
7. Data Retention
We retain your information for as long as:
- Your account is active
- Required to provide services
- Necessary for legal, regulatory, or compliance purposes
- Required by applicable law (typically 7 years for financial records)
8. Your Rights and Choices
8.1 Access and Updates
You can access and update your personal information through your account settings or by contacting us.
8.2 Marketing Communications
You may opt out of promotional emails by following unsubscribe instructions or contacting us.
8.3 GDPR Rights (EU Users)
You have the right to:
- Request access to your personal data
- Correct inaccurate information
- Request deletion (subject to legal requirements)
- Object to processing
- Request data portability
- Withdraw consent
8.4 CCPA Rights (California Users)
You have the right to:
- Know what personal information is collected
- Delete personal information (subject to exceptions)
- Opt-out of sale of personal information
- Non-discrimination for exercising your rights
9. Cookies and Tracking
We use cookies and similar technologies to:
- Maintain your session and preferences
- Analyze usage and improve our services
- Provide personalized experiences
- Ensure security
You can manage cookie preferences through your browser settings.
10. International Data Transfers
If you're located outside the United States, your information may be transferred to and processed in the US. We ensure appropriate safeguards are in place, including:
- Standard contractual clauses
- Adequacy decisions
- Binding corporate rules
11. Children's Privacy
Our Service is not intended for individuals under 18. We do not knowingly collect personal information from children under 18. If we become aware of such collection, we will delete the information promptly.
12. Third-Party Links
Our Service may contain links to third-party websites. We are not responsible for their privacy practices. We encourage you to review their privacy policies.
13. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes by:
- Posting the updated policy on our website
- Sending email notifications to registered users
- Providing in-app notifications
14. Contact Information
For questions about this Privacy Policy or to exercise your rights, contact us:
Data Protection Officer (if applicable):