Invoiceum Privacy Policy
Effective Date: August 3, 2026
Last Updated: August 3, 2026
Invoiceum respects your privacy and is committed to processing personal information transparently and responsibly.
This Privacy Policy explains how information is collected, used, stored and disclosed when you visit Invoiceum, create an account, generate or receive an invoice, submit information through an Invoiceum document, contact us or otherwise use our services.
1. Who We Are
In this Privacy Policy, “Invoiceum”, “we”, “us” and “our” refer to the operator of the Service. Privacy inquiries: privacy@invoiceum.com.
Operator legal details will be published in this section when available and updated following incorporation or a change of operator.
2. Scope of This Policy
This Privacy Policy applies to:
- the Invoiceum website;
- Invoiceum user accounts;
- invoices, statements and payment-confirmation pages;
- forms completed by invoice recipients or customers;
- document-generation and blockchain-monitoring features;
- customer support and abuse-reporting channels;
- related services that link to this Privacy Policy.
The policy does not apply to independent websites, wallets, exchanges, blockchain networks or other third-party services.
3. Our Roles
Invoiceum may process personal information in different roles.
Invoiceum generally acts as a data controller when processing information for:
- account creation and administration;
- subscription and billing management;
- security and fraud prevention;
- service communications;
- customer support;
- abuse reports;
- legal and regulatory compliance;
- operation and improvement of the Service.
When an account holder uses Invoiceum to collect or process information about their own customers, clients, payers or counterparties, the account holder generally determines why that information is collected.
In that context:
- the account holder generally acts as the controller of the customer information; and
- Invoiceum generally processes the information on the account holder’s instructions.
Where required, this processing will be governed by an Invoiceum Data Processing Addendum.
The actual legal roles may depend on applicable law and the circumstances of the processing.
4. Information We May Collect
The categories below describe information that Invoiceum may collect when the relevant feature is used. Invoiceum does not necessarily collect every category from every person.
4.1 Account information
We may collect:
- name;
- email address;
- company or trading name;
- business contact information;
- country or region;
- account preferences;
- profile or company logo;
- authentication and account-security information;
- subscription status.
Passwords should be stored only in a securely hashed form. Invoiceum does not have access to a user’s readable password.
4.2 Business and invoice information
Account holders may provide:
- personal or company name;
- business or billing address;
- email address and phone number;
- company registration number;
- tax or VAT number;
- descriptions of goods or services;
- prices, currencies and tax information;
- invoice terms and notes;
- cryptocurrency wallet addresses;
- supporting business records.
4.3 Customer, payer and counterparty information
An account holder may request information from a customer or payer, including:
- name;
- email address;
- phone number;
- address;
- company name;
- company registration information;
- tax or VAT number;
- country of residence or incorporation;
- payment wallet address;
- transaction hash;
- responses to custom fields created by the account holder.
This information is supplied by the relevant user or counterparty. Invoiceum does not independently verify it unless a feature expressly states that a particular verification has been performed.
Invoiceum should not be used to request private keys, seed phrases, passwords or other wallet-authentication credentials.
Government identification documents and special-category personal information are not collected unless Invoiceum introduces a feature specifically designed for that purpose and provides an additional privacy notice before collection.
4.4 Blockchain information
Invoiceum may retrieve and process information recorded on public blockchains, including:
- wallet addresses;
- transaction hashes;
- sender and recipient addresses;
- transaction date and time;
- token or cryptocurrency type;
- token contract address;
- transaction amount;
- network fees;
- confirmation status;
- related publicly visible transaction history.
Blockchain information is generally publicly accessible and may remain permanently available on the relevant blockchain.
4.5 Technical and security information
When you access the Service, we may automatically receive:
- IP address;
- browser and device type;
- operating system;
- approximate location derived from the IP address;
- access date and time;
- pages and features used;
- referring URL;
- session identifiers;
- login and security events;
- error and performance information.
We use this information to operate, secure and troubleshoot the Service.
4.6 Communications
We may retain information submitted through:
- customer-support requests;
- privacy requests;
- legal inquiries;
- fraud and abuse reports;
- email communications;
- feedback and surveys.
4.7 Billing information
If paid subscriptions are offered, billing may be handled by an independent payment provider.
Invoiceum may receive:
- subscriber name and billing address;
- subscription plan;
- payment status;
- transaction reference;
- invoice and tax information;
- limited payment-method details, such as card brand and last digits.
Invoiceum does not intend to receive or store complete payment-card numbers when payment is processed by an external payment provider.
5. Sources of Information
We may obtain information:
- directly from account holders;
- from customers or payers completing Invoiceum forms;
- from public blockchains;
- from publicly accessible registries and databases;
- from blockchain nodes and explorers;
- from infrastructure, security and payment providers;
- from persons submitting fraud or abuse reports;
- from competent authorities where legally permitted.
Information obtained from a public source is not necessarily accurate, complete or verified.
6. How We Use Information
Invoiceum may process information to:
- create and administer accounts;
- provide invoices, statements and other document tools;
- collect information requested by an account holder;
- match blockchain transactions with invoices;
- generate payment confirmations and transaction records;
- display publicly available blockchain information;
- operate subscriptions and billing;
- authenticate users and protect accounts;
- detect fraud, phishing, impersonation and abuse;
- respond to support and privacy requests;
- maintain, troubleshoot and improve the Service;
- enforce our Terms of Service and Acceptable Use Policy;
- comply with applicable legal obligations;
- establish, exercise or defend legal claims;
- protect users, Invoiceum and the public from harm.
Invoiceum does not use customer or invoice information for third-party behavioural advertising.
Invoiceum does not use private customer or invoice information to train public or third-party artificial-intelligence models unless an additional notice is provided and any legally required permission is obtained.
7. Legal Bases for Processing
Where the GDPR, UK GDPR or similar law applies, Invoiceum may rely on the following legal bases:
Contract
Processing may be necessary to:
- create and operate an account;
- provide requested Invoiceum features;
- generate documents;
- manage subscriptions;
- provide customer support.
Steps before entering into a contract
We may process information when a person joins a waiting list, requests access or asks questions about the Service.
Legitimate interests
We may process information for legitimate interests such as:
- securing the Service;
- preventing fraud and abuse;
- maintaining business records;
- improving performance and reliability;
- responding to user inquiries;
- protecting legal rights.
We consider the potential effect on the rights and interests of affected individuals before relying on this basis.
Consent
We may rely on consent for:
- optional marketing communications;
- non-essential cookies or analytics;
- other optional processing identified at the time consent is requested.
Consent may be withdrawn at any time.
Legal obligations
We may process or preserve information where necessary to comply with applicable law, court orders and other binding legal requirements.
8. Information Submitted by Account Holders
Account holders are responsible for determining whether they have a lawful basis to collect and process information about their customers, clients and counterparties.
Account holders must:
- request only information reasonably necessary for a legitimate purpose;
- provide any notices required by privacy law;
- obtain consent where consent is legally required;
- respect applicable access, correction and deletion rights;
- avoid collecting passwords, private keys, seed phrases or unnecessary sensitive information;
- use the information only for lawful purposes.
A person who receives an Invoiceum form should contact the account holder regarding why particular information has been requested.
Invoiceum may assist account holders in responding to lawful privacy requests where technically and legally required.
9. Public Documents and Sharing Links
Invoices and other documents may be shared through public, private or unlisted links, depending on the available feature and the account holder’s selected settings.
A document accessible through an unlisted link may be viewed by anyone who obtains that link.
Account holders are responsible for:
- selecting appropriate access settings;
- sharing links only with intended recipients;
- avoiding unnecessary personal information;
- revoking links when access is no longer required.
Invoiceum may use technical measures intended to discourage search-engine indexing of non-public documents, but cannot guarantee that information shared publicly or with third parties will remain confidential.
10. Blockchain Data and Deletion
Public blockchain records are maintained by decentralised networks outside Invoiceum’s control.
Invoiceum may remove a wallet address, transaction reference or associated description from its own systems where appropriate. However, Invoiceum cannot:
- delete or alter a blockchain transaction;
- remove information from independent blockchain explorers;
- prevent third parties from retaining publicly available blockchain data;
- reverse a cryptocurrency transaction.
Privacy rights relating to information copied into Invoiceum’s own systems remain subject to applicable law.
11. When We Disclose Information
Invoiceum does not sell or rent personal information.
Invoiceum does not proactively submit ordinary user invoices or transaction histories to tax authorities.
We may disclose information:
To service providers
We may use providers of:
- website and application hosting;
- database and file storage;
- content delivery and network infrastructure;
- email delivery;
- authentication and security;
- error monitoring;
- customer support;
- payment and subscription processing;
- blockchain nodes and data;
- professional legal and accounting services.
These providers may process information only for the services they provide to Invoiceum and subject to appropriate contractual obligations.
A current list of material service providers or subprocessors will be made available on request at privacy@invoiceum.com before the relevant production services are enabled.
At a user’s direction
We may disclose information when a user requests a document, sends an invoice, shares a link, enables an integration or otherwise directs us to disclose it.
For legal reasons
We may preserve or disclose information where we reasonably believe it is necessary to:
- comply with applicable law or valid legal process;
- respond to a binding court order, subpoena or lawful authority request;
- investigate or prevent fraud, phishing, money laundering, sanctions evasion or other illegal activity;
- protect the rights, property or safety of Invoiceum, its users or another person;
- establish, exercise or defend legal claims.
Where legally permitted and appropriate, Invoiceum may require a requesting authority to provide valid legal process.
Invoiceum may notify an affected user unless notification is prohibited by law or would create a material risk of harm, fraud or evidence destruction.
Business transactions
Information may be disclosed in connection with a merger, acquisition, financing, restructuring or sale of all or part of Invoiceum. Appropriate confidentiality and data-protection measures will be used.
12. International Data Transfers
Invoiceum and its service providers may process information in countries other than the country where the user is located.
Before production launch, Invoiceum will identify the principal hosting locations and material service providers.
Where personal information protected by European or UK data-protection law is transferred to a country without an applicable adequacy decision, Invoiceum will use an appropriate transfer mechanism where required, such as:
- Standard Contractual Clauses approved by the European Commission;
- the UK International Data Transfer Agreement or UK Addendum;
- another mechanism permitted by applicable law.
Information about applicable transfer safeguards may be requested at privacy@invoiceum.com.
13. Data Retention
Invoiceum retains personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy.
Unless a different period is disclosed or required by law, the intended retention framework is:
- waiting-list and pre-launch inquiries: up to 24 months after the last interaction;
- account information: while the account remains active;
- invoices and account content: while retained by the account holder;
- deleted account information and documents: removed from active systems within approximately 30 days;
- residual backup copies: deleted or overwritten within approximately 90 days;
- security and access logs: generally up to 12 months;
- support communications: generally up to 24 months;
- billing and tax records: for the period required by applicable accounting and tax law;
- fraud, abuse and suspended-account records: for as long as reasonably necessary to prevent repeated abuse, protect legal rights or comply with law.
Information may be retained longer where:
- preservation is required by law or valid legal process;
- a dispute or investigation is ongoing;
- retention is necessary to prevent fraud or repeated abuse;
- the information has been anonymised so that it no longer identifies an individual.
These periods may be adjusted before production launch to reflect the selected infrastructure and applicable legal requirements.
14. Cookies and Similar Technologies
Invoiceum may use strictly necessary technologies for:
- user authentication;
- account security;
- session management;
- load balancing;
- fraud prevention;
- remembering privacy, language or theme preferences.
Strictly necessary technologies cannot always be disabled without affecting the Service.
Invoiceum does not initially intend to use advertising cookies, cross-site behavioural tracking or advertising pixels.
If optional analytics or advertising technologies are introduced, this Privacy Policy and the Cookie Policy will be updated, and consent will be requested where required before those technologies are activated.
15. Marketing Communications
Invoiceum may send operational communications necessary to provide the Service.
Marketing messages will be sent only where legally permitted. Users can unsubscribe through the link in the message or by contacting Invoiceum.
Unsubscribing from marketing does not prevent receipt of essential security, billing or service messages.
16. Automated Processing
Invoiceum may automatically:
- associate a blockchain transaction with an invoice;
- calculate confirmation status;
- identify technical inconsistencies;
- flag activity for fraud or security review.
Unless expressly disclosed otherwise, Invoiceum does not make decisions based solely on automated processing that produce legal or similarly significant effects on an individual.
Where an account is restricted based on automated indicators, Invoiceum may provide a way to request human review where appropriate.
17. Security
Invoiceum uses reasonable and proportionate technical and organisational measures designed to protect information against:
- unauthorised access;
- loss or destruction;
- alteration;
- improper disclosure;
- misuse.
Access to production information should be limited to authorised persons who require it for legitimate operational purposes.
No online service can guarantee absolute security. Users are responsible for protecting their passwords, email accounts, devices and wallet credentials.
If a personal-data breach occurs, Invoiceum will investigate and provide notifications where required by applicable law.
18. Your Privacy Rights
Depending on applicable law, an individual may have the right to:
- request access to personal information;
- request correction of inaccurate information;
- request deletion;
- request restriction of processing;
- object to certain processing;
- receive portable information;
- withdraw consent;
- object to direct marketing;
- request review of certain automated decisions;
- lodge a complaint with a data-protection authority.
Requests may be submitted to privacy@invoiceum.com.
Invoiceum may need to verify the requester’s identity before fulfilling a request.
Where information was collected by an account holder about their customer, Invoiceum may direct the request to the relevant account holder or assist that account holder in responding.
Certain rights may be limited where information must be retained for legal, security, fraud-prevention or evidentiary purposes.
19. Children
Invoiceum is intended for business and professional use and is not directed to children.
Account holders must be at least 18 years old or the minimum legal age required to enter into a binding contract in their jurisdiction.
Invoiceum does not knowingly collect personal information directly from children.
20. Do Not Provide Wallet Secrets
Invoiceum will never request a wallet seed phrase or private key through an invoice, customer questionnaire, support message or account-verification process.
Users should not provide:
- seed phrases;
- private keys;
- wallet passwords;
- exchange passwords;
- two-factor authentication codes;
- recovery codes.
A request for such information should be reported immediately to abuse@invoiceum.com.
21. Changes to This Privacy Policy
Invoiceum may update this Privacy Policy as the Service, infrastructure or legal requirements change.
The “Last Updated” date will identify the latest version.
Material changes will be communicated through the Service, by email or through another appropriate notice where required.
If a new purpose materially differs from the purposes described here, Invoiceum will provide additional notice and obtain consent where legally required before beginning that processing.
22. Contact Us
Privacy inquiries and requests:
Email: privacy@invoiceum.com
General support: support@invoiceum.com
Abuse reports: abuse@invoiceum.com
Individuals may also have the right to complain to the data-protection authority in the country where they live or work.