Privacy policy
How this application processes personal data, under Articles 13 and 14 GDPR.
Controller
What this application stores
Your account. Your email address, and your password — stored only as a scrypt hash, never in a form that can be read back or recovered. Links sent for address verification and password resets are stored hashed too, expire, and can be used once.
It keeps a customer book and the invoices issued from it. For each customer that means the name, and where you enter them: postal address, email address and VAT identification number. For each invoice it means the line items, the amounts, the dates, and — once the invoice is issued — a frozen copy of the customer’s name, address and VAT ID as they stood at that moment.
That frozen copy is deliberate. German record-keeping rules (GoBD) require an issued invoice to remain unaltered, so it cannot be updated afterwards even if the customer’s details change.
What it does not do
No tracking cookies. Signing in sets two cookies: one holding your session, and one protecting the forms against cross-site request forgery. Both are strictly necessary to operate the service you asked for, so under § 25 Abs. 2 TTDSG no consent banner is required. Nothing is stored for advertising, profiling or statistics, and signing out ends the session.
No analytics or tracking. No visitor statistics, no profiling, no advertising identifiers.
No third-party requests from your browser. Fonts are downloaded when the application is built and served from this same server, so your IP address is never transmitted to a font provider. There are no embedded maps, videos, social buttons or external scripts.
Legal basis and purpose
Customer and invoice data is processed to prepare and perform a contract — Art. 6(1)(b) GDPR. Once an invoice is issued, it is additionally processed to comply with a legal obligation — Art. 6(1)(c) GDPR, in conjunction with the invoicing requirements of § 14 UStG and the retention requirements below.
Retention
Issued invoices and their underlying records are retained for ten years (§ 147 AO, § 257 HGB). The period runs from the end of the calendar year in which the invoice was issued.
A draft invoice carries no invoice number and no retention obligation; it can be deleted at any time. An issued invoice cannot — which is why the application itself refuses to delete or alter one.
Recipients and processors
Data is not sold, and it is not shared for advertising. It may be disclosed to a tax advisor or to the tax authorities where the law requires it.
Email. When email delivery is configured, messages are sent through Resend, an email provider acting as a processor: account verification and password-reset messages to you, and — when you choose to email an invoice rather than download it — the invoice as a PDF to the recipient address you enter. An emailed invoice PDF contains that invoice’s personal data (both parties’ names and addresses), which is therefore transmitted to Resend and to the recipient. Resend is a US company; the operator selects its EU data region and records the transfer basis. Where email is not configured, no message is sent to any third party — verification links are written to the server log, and invoices can still be downloaded and printed.
To complete before going live: if this application is hosted by a third party, that provider is a processor under Art. 28 GDPR and must be named here, with a data processing agreement in place.
If you use INVOICER to invoice your own customers, the operator processes that data on your behalf — see the data processing agreement.
Your rights
You may request access to your data (Art. 15), correction of inaccurate data (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), portability (Art. 20), and you may object to processing (Art. 21). To exercise any of these, contact the controller above.
One honest limit: where data forms part of an issued invoice, erasure can be refused until the ten-year retention period expires — Art. 17(3)(b) GDPR, since keeping it is a legal obligation. Correction requests are handled the same way: the customer record is updated, while the invoice already issued keeps what it stated at the time.
You also have the right to complain to a supervisory authority. In Germany that is the data protection authority of the federal state in which the controller is established.

