Privacy Policy

What we collect, why, how long we keep it, and the choices you have. Written from how InvoiceHelix actually handles data, not from a template.

1. Who this policy covers

This Privacy Policy explains how Digital Web Team LLC (“we,” “us”) collects, uses, and protects information through InvoiceHelix (invoicehelix.com and the associated application, the “Service”). It applies to you if you sign up for an account, use our marketing site, or join our waitlist.

InvoiceHelix is currently offered only to businesses billing US addresses; see our Terms of Service for details.

2. Information we collect

Account information. Your business name, email address, and password (handled by our authentication provider, Supabase; we never see your password in plain text).

Invoice and client data, deliberately minimal. To send a reminder, we store only what we call the “Core Four” for each invoice: the client’s name, the client’s email address, the invoice amount, and the due date. We do not store your client’s phone number, credit card number, or Social Security number, and we never ask for or retain your own SSN.

Payment information. Handled entirely by our payment processor, Stripe. We receive a payment token, not your card number. InvoiceHelix never sees or stores your full card details.

Email content. The body of reminder emails we send on your behalf, and the body of replies your clients send back, so our system (and, for reply analysis, AI models, see Section 4) can determine what’s happening with an invoice. See Section 6 for how long we keep this.

Waitlist signups. If you join our waitlist (for example, because you’re outside the US), we collect your email address and self-declared or IP-detected country, solely to notify you if and when the Service becomes available to you.

Usage and log data. Basic technical logs (request logs, error logs) needed to operate and secure the Service.

3. How we use your information

We use the information above to: provide and operate the Service (sending reminders, processing replies, tracking invoice status); process payments and manage your subscription; secure the Service and prevent abuse; comply with legal obligations; and improve the product.

We do not sell your personal information or your clients’ contact information to third parties, and we do not use your invoice or client data for advertising.

4. AI processing

Some parts of the Service, drafting reminder-email content and analyzing the sentiment of a client’s reply (for example, detecting a payment promise so a sequence can auto-pause), are performed with the assistance of third-party AI providers, including Anthropic and Google. The relevant email content is sent to these providers’ APIs for processing under their respective API data-use terms; as of this writing, both providers’ standard API terms state that API inputs are not used to train their general-purpose models absent separate agreement. We rely on that contractual commitment rather than independently verifying it, which is a reasonable practice for a company this size but worth knowing.

5. How we send your emails

Reminder emails are sent through our email delivery provider, Postmark, using SPF, DKIM, and DMARC authentication so your reminders reliably reach your clients’ inboxes and aren’t spoofable by others. Reminder emails are classified as transactional or relationship messages tied to an existing business obligation, so they include an accurate “From” and footer disclosure (“Sent on behalf of {Business Name} via InvoiceHelix”) but are not required to carry a marketing-style unsubscribe link, consistent with the CAN-SPAM Act’s transactional-message exception.

6. How long we keep your data

We keep data only as long as it’s useful or legally required, then delete it on a schedule:

DataRetention
Invoice PDFs (if uploaded)Purged after 90 days
Inbound reply email bodiesPurged after 1 year (a record that a reply occurred stays in our audit log)
Audit log entriesRetained 7 years, for US recordkeeping and compliance purposes
Account and invoice recordsRetained while your account is active

If you delete your account, we cascade-delete your invoices, email messages, and inbound replies; anonymize your audit log entries (removing the link to your account, but keeping the entries themselves for the 7-year compliance window); and purge your stored files from our cloud storage.

7. Your rights

Access and export. You can request or directly download a complete export of your account data (invoices, email history, and audit log) at any time from your account settings. We aim to make this available within 30 days of a request, consistent with GDPR’s right-of-access timeline, even though the Service is currently US-only.

Deletion. You can delete your account at any time; see Section 6 for what happens to your data when you do.

Waitlist opt-out. If you’re on our waitlist, you can unsubscribe or ask us to delete your waitlist entry at any time.

If you’re located in the EU or UK and believe GDPR gives you rights beyond what’s described here, contact us at the address in Section 13 and we’ll work with you directly, even though the Service isn’t currently marketed to non-US businesses.

8. Cookies and analytics

We use Google Analytics 4 (“GA4”) to understand aggregate traffic on invoicehelix.com: which pages get visited, and how people move between the guides and pricing. GA4 sets first-party and Google-set cookies and collects information like your IP address, device and browser type, and pages viewed; that data is processed by Google under Google’s Privacy Policy.

We configure GA4 with Google Signals and ads personalization turned off, and with IP addresses truncated where Google’s tooling supports it. We do not use GA4 (or any other tool) to build individual visitor profiles, to retarget visitors with ads, or to sell or share data with data brokers.

If you’re a California resident, or would simply rather not be counted, the control below turns analytics tracking off in this browser. The same control is linked from the footer of every page.

Checking this browser’s setting…

This setting lives in this browser only. Clearing site data resets it.

9. Data security

Application data is stored in Supabase with row-level security policies that restrict each account to its own data. All traffic to the Service is encrypted in transit (HTTPS). We never store raw payment card data; Stripe handles that entirely. Webhooks from our providers are verified (Postmark via Basic Auth over HTTPS plus IP allowlisting; Stripe via signed webhook verification) before we act on them.

10. Children’s privacy

InvoiceHelix is a business tool intended for use by adults acting on behalf of a business. It is not directed at children, and we do not knowingly collect information from anyone under 18.

11. International users

The Service is currently offered only to businesses billing US addresses. If you’re outside the US, you may join our waitlist (Section 2), and this policy’s data handling still applies to that waitlist entry.

12. Changes to this policy

We may update this Privacy Policy from time to time. We’ll notify you of material changes via email or an in-app notice before they take effect.

13. Contact us

Questions about this policy, or to make a data access, export, or deletion request: privacy@invoicehelix.com