Privacy Policy
Last updated: March 2026
1. Introduction
SuprInvoices (“we”, “us”, “our”) operates suprinvoices.com.
This Privacy Policy explains how we collect, use, store, and protect your information when you use our invoicing platform.
By using our platform, you agree to this Privacy Policy.
2. Data Controller
SuprInvoices is the data controller responsible for processing your personal data.
For privacy inquiries, contact: work.aniketmohite@gmail.com
3. Information We Collect
A. Account Information
When you sign up, we collect:
- Name
- Email address
- Authentication data (via Google or magic link)
- Account creation timestamp
B. Business & Invoice Data
When you use the platform, we store:
- Business profiles (name, address, logo, tax ID)
- Client information (name, email, address)
- Invoice data (line items, amounts, dates, status)
- Payment records and payment method details
- Bank details and UPI IDs stored for invoice rendering
- Items/products catalog
C. Billing Information
Platform subscription payments are processed by Polar.
We do not store full credit card details.
We may store:
- Subscription status
- Plan type
- Transaction ID
- Billing email
- Payment status
D. Usage & Log Data
We may automatically collect:
- IP address
- Device type
- Browser type
- Pages visited
- Timestamps
- Feature usage
- Error logs
This information helps us maintain service reliability and prevent abuse.
4. How We Use Information
We use collected data to:
- Provide and operate the invoicing platform
- Generate and render invoices and PDF exports
- Provide shareable invoice links for your clients
- Process subscription billing and manage plans
- Track payment status on invoices
- Improve platform performance and features
- Detect abuse, fraud, or infrastructure misuse
- Send essential account-related emails
- Comply with legal obligations
We do not sell your personal data.
We do not use your data for advertising purposes.
5. Legal Basis for Processing
Where applicable under data protection laws (including GDPR), we process data based on:
- Performance of a contract (providing the service)
- Legitimate interest (security, abuse prevention, product improvement)
- Legal compliance obligations
6. Data Storage & Security
Account and invoice data is stored securely in MongoDB Atlas with encryption at rest.
We implement reasonable technical and organizational safeguards to protect your data, including encrypted data transmission (HTTPS) and access controls.
However, no system is completely secure. Use of the service is at your own risk.
7. Data Retention
We retain:
- Account data while your account is active
- Invoice and business data while your account is active
- Shared invoice links remain accessible unless you revoke them or delete the invoice
- Usage data until deleted by you or your account is deleted
- Billing records as required by law
Upon account deletion, personal data is removed within a reasonable time unless retention is legally required.
8. Third-Party Services
We use third-party providers including:
- Vercel (hosting and infrastructure)
- MongoDB Atlas (database)
- Polar (subscription payment processing)
- Google (authentication)
- Resend (transactional email)
These providers process data under their own privacy policies.
We are not responsible for third-party privacy practices.
9. Cookies
We use cookies and similar technologies for:
- Authentication
- Session management
- Security
- Basic analytics
You may disable cookies in your browser, but parts of the service may not function properly.
10. International Data Transfers
Your data may be processed in countries outside your jurisdiction, depending on infrastructure providers.
By using the service, you consent to such transfers where permitted by law.
11. Your Rights
Depending on your location, you may have the right to:
- Access your data
- Correct inaccurate data
- Request deletion
- Restrict processing
- Export all your invoice and business data
- Revoke shared invoice links
- Withdraw consent
- Lodge a complaint with a supervisory authority
To exercise your rights, contact: work.aniketmohite@gmail.com
12. Children's Privacy
The service is not intended for individuals under 18.
We do not knowingly collect data from minors.
13. Changes
We may update this Privacy Policy from time to time. Updated versions will be posted on this page with a revised date. Continued use constitutes acceptance.
14. Contact
For privacy-related questions: work.aniketmohite@gmail.com