InvoiceOne ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your data when you use the InvoiceOne web and mobile applications.
Compliance Notice: This privacy framework is designed in accordance with the Digital Personal Data Protection (DPDP) Act, 2023 (India) and other applicable Indian laws. You retain full ownership, portability, and control over your digital business records.
1. Data We Collect
To provide billing, invoicing, and tax accounting services, we collect the following categories of information:
Account Information: Your name, business email address, phone number, and password details for authentication.
Business & GST details: Your business/firm name, address, Goods and Services Tax Identification Number (GSTIN), business logo, and digital signature files.
Invoicing & Client Data: Invoices, estimates, purchase bills, item lists, tax rates (CGST, SGST, IGST), payment statuses, and contact information of your customers.
Device & Usage Logs: IP address, device type, operating system, and log metadata to secure sessions and audit system events.
2. Purpose Limitation & Data Processing
Under Section 4 of the DPDP Act, we only process your data for lawful, specific, and transparent purposes:
To generate compliant GST invoices and estimates.
To calculate tax breakdowns and structure billing templates.
To authenticate users, prevent unauthorized access, and manage active device sessions.
To deliver user-triggered backups and data portability features.
No Advertising / Selling: We do not sell, rent, or lease your business data, customer contacts, or financial figures to marketing agencies or third-party advertisers.
3. Data Storage & Security
All data is processed using transport-level encryption (SSL/TLS) and stored in secure Firebase Firestore databases. Backups are executed at regular intervals under tight security configurations. We restrict backend access only to automated processing scripts and verified compliance protocols.
4. Your Rights under the DPDP Act 2023
Under Indian legislation, you are the "Data Principal" and have complete authority over your personal and business data:
Right to Correction & Completion: You can edit and update any of your business credentials, billing configurations, and account profiles in the application settings.
Right to Portability: You can export all your invoices, customer lists, and account profiles in a structured, machine-readable JSON format directly from the "Privacy Settings" dashboard.
Right to Erasure (Withdraw Consent): You can withdraw consent and delete your account permanently. Doing so triggers a complete cleanup routine that wipes your profiles, invoices, and databases from our active storage.
5. Grievance Redressal & Contact
If you have any questions, compliance queries, or complaints regarding how we process your personal data under the DPDP Act, please contact our designated Grievance / Data Protection Officer:
Data Protection Officer: dpo@invoiceone.in Corporate Office: InvoiceOne, Bengaluru, India.