Privacy Policy
Last updated: 2026-07-11
This Privacy Policy explains what InvoIQ (“we”, “us”), operated by Margin Defender, collects about you, how we use it, who we share it with, and the choices you have. It applies to the InvoIQ web service, related emails, and any mobile access to the same account. We've tried to write this in plain English rather than legalese — if anything is unclear, email us.
1. What we collect
- Account information: email address, password hash (we never store the password itself), display name, and authentication provider (email/password or Google sign-in).
- Invoice images and documents you upload, plus the structured data our extraction systems extracts from them (line items, unit costs, quantities, dates, vendor identifiers).
- Catalog and inventory data you upload or that we read from a connected POS (SKUs, UPCs, product names, costs, retail prices, margins, categories, stock levels).
- Third-party connection metadata: when you connect Square, Shopify, Clover, or another integration, we store the OAuth tokens or API credentials needed to make authorized calls on your behalf, plus the merchant/location identifiers the provider returns.
- Payment metadata: if you're on a paid plan, we store your Stripe customer ID, subscription status, and invoice history. We do not store your full card number, CVV, or bank account number — Stripe handles those directly.
- Usage analytics: which features you use, which jobs complete, and campaign attribution fields (such as UTM source and campaign), plus technical metadata (browser, approximate IP-derived location, timestamps, request IDs) for security, reliability, acquisition measurement, and product improvement. We do not store email addresses or Google ad-click identifiers in campaign attribution fields.
- Error and performance data: stack traces and request context when something fails, captured through our error-monitoring tool. We scrub obvious secrets from these reports.
- Communications: if you email us or use in-app support, we keep your message to respond and improve support quality.
2. How we use it
- To run the core invoice ingestion and pricing analysis you signed up for.
- To sync your catalog with connected POS systems and — only when you approve — push price updates back to them.
- To send transactional email (account verification, password reset, report delivery, billing receipts).
- To improve the product — including extraction accuracy, match quality, and feature design. This may involve limited, confidential human review of a small sample of invoices and AI outputs for quality assurance.
- To build aggregated, anonymized vendor-quality intelligence (for example, “this vendor's invoices frequently change cost on staple items”) that does not identify you or any individual customer.
- To detect and prevent abuse, fraud, and security incidents.
- To comply with legal, tax, and accounting obligations.
We do not use Your Content to train general-purpose AI models. When we send data to an AI provider (see below), we do so under terms that prohibit the provider from using your data to train their models.
3. Marketing email
We only send product updates and tips if you opt in at signup or later in settings. You can unsubscribe at any time using the link in any marketing email. Transactional emails (such as password reset, report delivery, and billing receipts) are part of the Service and aren't covered by that unsubscribe.
4. Where we store data
- Render hosts our application servers and Postgres database. This is where your account, catalog, extracted invoice data, and operational records live.
- Vercel hosts the web front-end and, via Vercel Blob, stores the original invoice images and PDFs you upload.
- All data is stored in the United States. We use encryption in transit (TLS) and rely on our providers' encryption at rest for storage-level protection.
5. Who we share data with
We don't sell your data. We share limited data with service providers who process it on our behalf under contract. The most important ones:
- Google (Vertex AI / Gemini): we send invoice images and related structured data to Google's Gemini models (via Google Cloud's Vertex AI) to perform extraction and classification. Google's enterprise Vertex AI terms state that your inputs and outputs are not used to train their foundation models.
- Stripe: if you're on a paid plan, your payment is processed by Stripe. Stripe receives the payment details you enter directly; we only receive non-sensitive identifiers (customer ID, subscription state, last-four of card).
- Render and Vercel: our hosting providers, as described above.
- Connected POS platforms (Square, Shopify, Clover, and others you opt in to): we exchange data with these systems within the OAuth scopes you grant. Their own privacy policies cover their handling of that data.
- Email delivery providers to send transactional and opted-in marketing email.
- Error monitoring and analytics tools (such as Sentry) to keep the Service reliable. These receive only the minimum context needed to diagnose problems.
- Google Ads measurement: our public and signup pages load Google's advertising measurement tag so we can understand whether a campaign produced a signup. Google may receive page, browser, device, and conversion-event information under its own privacy terms. We do not send invoice or catalog contents to Google Ads.
We may also disclose data if required by law, subpoena, or valid legal process; to protect our rights, our users, or the public; or in connection with a merger, acquisition, or asset sale (in which case we'll let affected users know).
6. Legal bases for processing (EU / UK)
If GDPR or UK GDPR applies to you, our legal bases for processing your personal data are:
- Performance of a contract — to deliver the Service you signed up for, including ingestion, extraction, sync with connected POS systems, and billing.
- Legitimate interests — to secure the Service, prevent fraud, improve product quality, and generate aggregated, anonymized benchmarks, in each case balanced against your rights.
- Consent — for opted-in marketing email and any processing for which we specifically ask your permission. You can withdraw consent at any time.
- Legal obligation — where we're required to retain records (for example, tax and accounting) or respond to lawful requests.
7. Your rights
You can:
- Access the personal data we hold about you.
- Correct inaccuracies in your account or catalog data.
- Export Your Content — invoices, extracted data, catalog — from in-app tools.
- Delete your account and associated data from settings, or by emailing us. We'll process verified deletion requests within 30 days, subject to records we must retain by law.
- Object to certain processing or restrict it in specific cases.
Depending on where you live, you may have additional rights under laws such as GDPR (EU/UK) or the CCPA/CPRA (California). We honor those rights regardless of where you live, to the extent practical. To exercise any right, email support@invoiq.site.
8. Data retention
We retain your data while your account is active. When you delete your account, we delete identifiable data within 30 days except where we're required to retain specific records (such as billing and tax history). Aggregated, anonymized data — which cannot reasonably be tied back to you — may be retained indefinitely for product improvement and benchmarking.
9. Security
We use encryption in transit, encryption at rest for sensitive fields, scoped access controls, audit logging, and least-privilege engineering practices. No system is perfectly secure; please use a strong unique password and enable any available additional factors. If we learn of a security incident that materially affects your data, we'll notify you without undue delay and as required by applicable law.
10. Cookies, local storage, and Do Not Track
We use a small number of cookies and browser local-storage entries to keep you signed in, remember preferences, preserve first-party campaign attribution, and keep the app working across page loads. Public and signup pages also use Google Ads measurement technology to report page and signup events. We do not put invoice contents, catalog contents, email addresses, or payment details into those campaign fields. Browser-level opt-out or blocking settings may prevent that measurement. We do not currently respond separately to Do Not Track or Global Privacy Control headers.
11. Children
The Service is not intended for anyone under 18. We don't knowingly collect data from children. If you believe a child has given us personal data, email us and we'll delete it.
12. Automated decision-making
Parts of the Service involve automated processing — for example, the extraction system that reads line items from an invoice image and the rules engine that suggests retail prices. These decisions are advisory: they surface recommendations in the app, and a human (you or someone on your team) approves anything that would change a live price in your POS, unless you have explicitly opted that category or item in to autonomous pricing. You can turn off autonomous pricing and request a human review of any automated decision by emailing support@invoiq.site.
13. International transfers
Our infrastructure is hosted in the United States. If you access the Service from outside the US, you understand that your data will be processed in the US and in any other country where our service providers operate. We apply appropriate safeguards where required by applicable law.
14. Changes to this Policy
If we make material changes we'll notify you by email or in-app notice and update the “Last updated” date at the top. Continued use after changes take effect means you accept the updated Policy.
15. Contact
Questions, requests, or privacy concerns? Email support@invoiq.site and we'll respond within a reasonable time. A human reads every message.