Privacy Policy
Last updated 23 July 2026
This policy explains what Invoice Forever collects, why, and what you can do about it. In plain terms: we store only what we need to run your account, we don't sell your data, and we don't show ads.
Who we are
Invoice Forever is operated by Thomas van der Bruggen Holding B.V., registered in the Netherlands under number 75464136. Thomas van der Bruggen Holding B.V. is the data controller for the personal data described below. For any privacy question or request, email hello@invoiceforever.com.
What we collect
- Account details — your email address and a securely hashed password, used to sign you in and keep your data separate from everyone else's.
- The data you enter — your invoices, clients, business details, saved items and settings. This is yours; we store it so the app works.
- Files you upload — such as a business logo, stored so it can appear on your invoices and PDFs.
What we don't do
- We don't sell or rent your personal data to anyone.
- We don't show advertising or run advertising trackers.
- We don't use your invoice content for anything other than providing the service.
- We don't use it to train machine-learning models.
Why we're allowed to hold it
The GDPR asks us to name a legal basis for each thing we do, so here they are.
- Performance of a contract — your account details and the data you enter. We can't run an invoicing service for you without storing your invoices.
- Legitimate interests — anonymous usage and error statistics, and preventing abuse of a free service. Our interest is keeping the product working and standing up; we've weighed it against your privacy by making the analytics cookieless and anonymous, so the effect on you is close to nothing. You can object at any time.
- Legal obligation — donation records we have to keep for accounting.
- Consent — only where we ask for it outright, such as subscribing to an update email. You can withdraw it whenever you like.
Data about your clients
When you invoice someone, you enter their details. That's their personal data and you decide what happens to it, which makes you its controller and us your processor. The terms governing that are set out in our data processing agreement, which applies automatically from the moment you create an account — you don't need to ask us for a copy or sign anything.
If you sign in with Google
Signing in with Google is optional — you can always use an email address and password instead. If you do use it, Google tells us your name, email address and profile picture so we can create and recognise your account. We don't receive your Google password and we ask for nothing else from your Google account.
Where your data lives
Access is restricted to your authenticated account. We don't run our own servers, so a handful of providers process data on our behalf: Convex for the database, DigitalOcean Spaces for uploaded files, Netlify for hosting, Resend for transactional email, and PostHog for anonymous statistics. Each one is listed with what it touches and where it runs on the subprocessors page, which we update before any change takes effect.
Leaving the EU
Your invoices, clients and uploaded files stay in the EU: the database is hosted in the European Union and files sit in Amsterdam.
Two providers are United States companies. Netlify serves the website itself, so it sees ordinary request information such as your IP address, and Resend sends service emails, so it handles your email address and their contents. Both operate under the European Commission's Standard Contractual Clauses, which is the approved mechanism for those transfers. We'd prefer EU providers for these too, and we'll move and say so if that becomes practical.
Cookies and analytics
There's no consent banner on this site, and that's not an oversight. The only cookie we set keeps you signed in. Our analytics don't use cookies at all: PostHog runs with its state in memory, so nothing is written to your device and no profile follows you between visits. We count page views and watch for errors and slow pages; session recording and automatic click tracking are off, and there are no third-party scripts, advertising pixels or embedded widgets anywhere. Even the fonts are served from our own site rather than fetched from Google.
Because all of that is either strictly necessary or stores nothing, there's nothing for you to consent to. The cookies page lists every single entry, all four of them, so you can check rather than take our word for it.
How long we keep it
We keep your data for as long as your account exists. Deleting your account removes your invoices, clients, saved items, expenses, business details and settings, and deletes the files you uploaded. It happens immediately and you don't need to ask us to do it.
Two honest caveats. Donation records are kept because accounting law requires it, but the details linking them to you, meaning your name, email and account, are erased, leaving an amount and a date attached to nobody. And backups age out on their normal rotation rather than being edited retroactively, so a deleted account can persist in a backup snapshot for a short period before expiring.
Children
Invoice Forever is a business tool and isn't directed at children. We don't knowingly collect data from anyone under 16. If you believe a child has created an account, email us and we'll remove it.
Your rights
You can access and edit your data at any time inside the app. Settings has an Export Data button that downloads everything as a single file, and a Delete account option that erases your account and its data straight away — you don't need to ask us. If you'd rather we did it, or you want a copy of anything else we hold, email hello@invoiceforever.com. Under the GDPR you also have the right to correct your data, to restrict or object to how we process it, and to have it sent to another provider. We'll honour those requests, and we won't charge you or make you explain why.
Complaining about us
If you think we've mishandled your data, please tell us first at hello@invoiceforever.com, because it's usually fixable in an afternoon. You also have the right to complain to a data protection authority regardless. Ours is the Autoriteit Persoonsgegevens in the Netherlands, and you can also go to the authority where you live or work.
Changes
If this policy changes in a meaningful way, we'll update the date above and note it in the changelog. Questions? Contact us.