Privacy Policy
Last updated: May 22, 2026 · Effective immediately upon use of the Service
This Privacy Policy describes how Invoice Sync ("we", "us", or "our") collects, uses, and protects information when you use the Invoice Sync mobile app, web app, and related services (the "Service"). We designed the Service to collect the minimum data necessary to function.
1. Information We Collect
| Category | Examples | Source |
| Account & device data | Device ID (random UUID generated on first launch), platform, app version | Generated locally on your device |
| POS connection data | Merchant ID, merchant name, OAuth access and refresh tokens, region | Returned by Clover, Square, or Shopify after you authorize |
| Invoice content | Invoice images you submit, extracted line items (name, quantity, cost, flavor, notes), vendor name, invoice number | You, when you scan or upload an invoice |
| Inventory data | Your existing POS inventory items, fetched to enable SKU matching | Read from your connected POS via authorized API calls |
| Usage data | Number of scans per month, subscription tier, billing period | Recorded server-side to enforce plan limits |
| Conversation data (AI agent only) | Customer messages sent to the optional embeddable AI agent | Visitors to the merchant's website, if the merchant enables the AI agent feature |
We do not collect: real names, email addresses (unless you contact support), phone numbers, payment card numbers (handled by Clover, Apple, or Stripe), browsing history, advertising identifiers, contacts, location, or biometric data.
2. How We Use Information
- To extract line items from invoice images using AI
- To match scanned items against your existing POS inventory
- To sync inventory updates to your connected POS
- To enforce subscription plan limits (scan counts per month)
- To refresh expired OAuth tokens so the Service continues to work
- To respond to your support requests
- To operate the optional embeddable AI agent if you enable it
3. Third-Party AI Processing
Invoice images and inventory data are transmitted to the following AI providers strictly to perform the requested task:
- OpenAI — invoice image OCR and line-item extraction. We use OpenAI's vision models via Replit's AI integrations. OpenAI's API terms state that data sent via the API is not used to train their models.
- Anthropic (Claude) — only if you enable the AI customer agent feature, customer chat messages are sent to Anthropic's Claude model along with your live inventory data so the agent can answer product questions. Anthropic's API terms also prohibit use of API data for training.
4. How We Store Information
- On your device: Scan history, invoice images you take, batch queues, Clover configuration, and your device ID are stored locally in AsyncStorage / device file system. Clearing the app's storage deletes this data.
- On our servers (PostgreSQL): OAuth tokens for connected POS platforms, merchant IDs, AI-agent enablement flag, device ID with scan count and current billing period, and conversation records used by integration features.
- Encryption: All data in transit is encrypted via TLS. OAuth tokens are stored in a managed PostgreSQL database with restricted access.
5. Data Retention
- OAuth tokens are kept until you disconnect the platform from Settings or until you uninstall and request deletion.
- Scan history on your device is retained until you delete it or uninstall the app.
- Server-side usage counters reset automatically each calendar month.
- Backups are retained for up to 30 days.
6. How We Share Information
We do not sell or rent your data to anyone. We share information only with:
- Your connected POS platforms (Clover, Square, Shopify) — to read inventory and create or update items, as you direct.
- AI providers (OpenAI, Anthropic) — to process invoice images and answer customer chat queries, as described above.
- Infrastructure providers (Replit, our PostgreSQL host) — to host the application and database.
- Payment processors (Clover, Apple) — when you purchase a subscription. We do not see your full card number.
- Legal authorities — only when required by valid legal process.
7. Your Rights
You may at any time:
- Disconnect any POS platform from the Settings tab — this immediately deletes the associated OAuth tokens from our servers.
- Delete local scan history from the History tab.
- Uninstall the app to remove all local data.
- Request deletion of all server-side data tied to your device by emailing support@invoicesync.live. We will complete deletion within 30 days.
- Request a copy of the data we hold about your device by emailing the same address.
If you are in the EU/UK, you have rights under GDPR including access, correction, deletion, and portability. If you are in California, you have rights under the CCPA. Email us to exercise any of these rights.
8. Children's Privacy
The Service is intended for use by businesses and is not directed at children under 16. We do not knowingly collect data from children.
9. International Data Transfers
Data is processed in the United States. If you access the Service from outside the US, you consent to your data being transferred to and processed in the US, subject to safeguards required by applicable law.
10. Security
We use industry-standard practices including TLS encryption in transit, access controls on the database, secret management for API keys, and least-privilege OAuth scopes. No system is perfectly secure; please report suspected vulnerabilities to support@invoicesync.live.
11. Changes to This Policy
We may update this Policy. Material changes will be announced via in-app notice or email at least 14 days before they take effect.
12. Contact
Privacy questions or data requests: support@invoicesync.live.
Terms of Service · Home