Privacy Policy

Effective Date: 1 January 2026  ·  Version 2.0  ·  Last Updated: March 2026
Our commitment to you: Invoice Plus is built for small businesses and their teams. We collect only the data needed to run the app, we never sell your data, and we give you full control over what you share. This policy explains clearly what we collect, why, and your rights — wherever you are in the world.

Operated by: Jeffrey Lyon  ·  ABN 14 642 051 653  ·  VIC, Australia  ·  jeffstechservice@gmail.com

This policy applies to users in:

🇦🇺AustraliaPrivacy Act 1988
🇬🇧United KingdomUK GDPR
🇪🇺EuropeGDPR
🇺🇸United StatesCCPA / State Laws
🇨🇦CanadaPIPEDA / CASL
🇳🇿New ZealandPrivacy Act 2020
🌍All OthersGeneral Policy

1. What Information We Collect

Information You Provide

Information Collected Automatically

Staff Activity Notifications

When staff are on shift, the following events are recorded and sent to the business owner's dashboard:

ℹ️ Staff members are informed at login that their shift activity may be monitored by their employer. Location tracking only occurs during active shifts and only if the Business plan is active and the device has granted location permission.

2. How We Use Your Information

PurposeData UsedLegal Basis
Providing the app and its featuresAll app dataContract performance
Cloud sync and backup across devicesBusiness data, invoices, clientsContract performance
Staff shift tracking and payrollStaff data, shift recordsLegitimate interest / Contract
GPS location tracking during shiftsGPS coordinatesConsent (explicit permission required)
Push notifications to staffDevice push tokenConsent
Improving the app and fixing bugsAnonymised crash dataLegitimate interest
Responding to support requestsContact informationLegitimate interest

We do not use your data for advertising, we do not sell your data to third parties, and we do not use your data to train AI models.

3. How We Store and Protect Your Data

Storage Location

Your data is stored in two places:

Security Measures

Data Retention

We retain your data for as long as your account is active. If you stop using the app and request deletion, we will delete your cloud data within 30 days. Local device data can be cleared by deleting the app.

4. Third-Party Services

ServicePurposeData SharedPrivacy Policy
SupabaseDatabase and cloud syncBusiness data, staff records, shift datasupabase.com/privacy
Expo (EAS)App delivery and push notificationsDevice push tokensexpo.dev/privacy
RevenueCatSubscription managementPurchase receipts, anonymous user IDrevenuecat.com/privacy
Apple App StoreiOS app distribution and paymentsPurchase receiptsapple.com/privacy
Google PlayAndroid app distribution and paymentsPurchase receiptspolicies.google.com/privacy
Google Sign InOptional account authenticationName, email address, Google user IDpolicies.google.com/privacy
Apple Sign InOptional account authenticationName, email address (or private relay), Apple user IDapple.com/privacy
StripeWeb subscription paymentsPayment details processed by Stripe — we never store card numbersstripe.com/privacy
OpenStreetMap / NominatimAddress geocoding for geofence zonesJob site addresses onlyosmfoundation.org

We do not share your data with any other third parties. Your financial data, client details and staff payroll information are never shared with external services.

5. Location Data

Location tracking is an optional feature available on the Business plan only. It is used to:

📍 Important: Location is only tracked during active shifts when the staff member has clocked on. Location tracking pauses during breaks and supply runs. Staff members are always informed when GPS tracking is active. Location data is never collected without explicit device permission.

GPS data is stored in our Supabase database and is only visible to the business owner. Location history older than 24 hours is not retained in the live dashboard.

6. Staff and Employee Data

If you are a business owner using Invoice Plus, you are responsible as a data controller for the personal data you collect about your staff through the app. This includes:

You must ensure your staff are informed that their data is being collected and processed through Invoice Plus, in accordance with applicable employment and privacy laws in your country.

If you are a staff member using the worker app, your employer (the business owner) controls your data. Please speak to your employer about how they handle your personal information.

7. Your Rights by Country

🇦🇺 Australia — Privacy Act 1988 (Cth) & Australian Privacy Principles

Under the Australian Privacy Act, you have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate or incomplete information
  • Complain about a breach of the Australian Privacy Principles
  • Know how we collect, use and disclose your information

We comply with the 13 Australian Privacy Principles (APPs). If you have a privacy complaint, contact us first. Unresolved complaints can be lodged with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

For businesses using the staff management features, we note that the collection and use of employee data must comply with applicable provisions of the Fair Work Act 2009 and relevant state workplace laws.

🇬🇧 United Kingdom — UK GDPR & Data Protection Act 2018

Under UK GDPR, you have the right to:

  • Access — Request a copy of your personal data
  • Rectification — Request correction of inaccurate data
  • Erasure — Request deletion of your data ("right to be forgotten")
  • Restriction — Request we limit how we process your data
  • Portability — Receive your data in a portable format
  • Object — Object to processing based on legitimate interests
  • Withdraw consent — Where processing is based on consent (e.g. location tracking)

Our lawful bases for processing are: contract performance, legitimate interests, and consent (for location tracking and push notifications).

Unresolved complaints can be lodged with the Information Commissioner's Office (ICO) at ico.org.uk.

🇪🇺 European Union — General Data Protection Regulation (GDPR)

Under GDPR, you have the same rights as listed for UK users above. As a controller established outside the EU processing EU residents' data, we comply with GDPR requirements including:

  • Providing clear information about data processing (this policy)
  • Limiting data collection to what is necessary (data minimisation)
  • Ensuring data security through appropriate technical measures
  • Responding to data subject requests within 30 days

International data transfers to Supabase (US-based) are covered by Standard Contractual Clauses. Complaints can be lodged with your national Data Protection Authority (DPA).

🇺🇸 United States — CCPA (California) & Other State Laws

For California residents under the California Consumer Privacy Act (CCPA) and CPRA:

  • Right to Know — What personal information we collect, use, disclose and sell (we do not sell data)
  • Right to Delete — Request deletion of your personal information
  • Right to Opt-Out — We do not sell personal information, so this right is not applicable
  • Right to Non-Discrimination — We will not discriminate against you for exercising your rights
  • Right to Correct — Request correction of inaccurate personal information
  • Right to Limit Use of Sensitive Personal Information — Including precise geolocation

We do not sell or share personal information for cross-context behavioural advertising. We do not have actual knowledge that we sell or share personal information of consumers under 16 years of age.

To exercise your rights, contact us at jeffstechservice@gmail.com. We will respond within 45 days.

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and other US states with comprehensive privacy laws have similar rights and may contact us to exercise them.

🇨🇦 Canada — PIPEDA & Provincial Privacy Laws

Under the Personal Information Protection and Electronic Documents Act (PIPEDA) and provincial laws (Alberta PIPA, BC PIPA, Quebec Law 25), you have the right to:

  • Access your personal information held by us
  • Challenge the accuracy of your information
  • Withdraw consent for collection or use (which may limit your ability to use the app)
  • Know how your information is used and disclosed

We collect personal information only with your knowledge and consent, and only for purposes a reasonable person would consider appropriate. Unresolved complaints can be lodged with the Office of the Privacy Commissioner of Canada at priv.gc.ca.

Quebec residents: Under Law 25 (Act 64), you have additional rights including data portability and the right to be forgotten. Our délégué à la protection des renseignements personnels (Privacy Officer) can be reached at jeffstechservice@gmail.com.

🇳🇿 New Zealand — Privacy Act 2020

Under the New Zealand Privacy Act 2020 and its 13 Information Privacy Principles (IPPs), you have the right to:

  • Access the personal information we hold about you
  • Request correction of your personal information
  • Know how your information is collected, used and stored
  • Have your information protected by reasonable security safeguards

Mandatory data breach reporting applies — we will notify affected individuals and the Privacy Commissioner of any breach that poses a risk of serious harm. Unresolved complaints can be lodged with the Office of the Privacy Commissioner at privacy.org.nz.

8. Children's Privacy

Invoice Plus is a business application intended for adults. We do not knowingly collect personal information from anyone under the age of 16 (or 13 in the United States). If you believe a minor has provided us with personal information, please contact us and we will delete it promptly.

9. Data Breach Notification

In the event of a data breach that is likely to result in serious harm, we will:

Notification will be provided by email to your registered address and/or via an in-app notification.

10. How to Exercise Your Rights

To exercise any of your privacy rights (access, correction, deletion, portability, objection), please contact us:

We will respond within:

We may ask you to verify your identity before processing your request.

11. Cookies and Tracking

We offer optional biometric authentication (Face ID, fingerprint) for app access. Biometric data is processed entirely by your device's operating system and is never transmitted to our servers or stored by Invoice Plus.

Authentication via Google & Apple

You may optionally sign in using your Google or Apple account. When you do, we receive your name, email address and a unique identifier from that provider. This information is stored in our Supabase database to link your account across devices. We do not receive your Google or Apple passwords. You can disconnect at any time by contacting us.

The Invoice Plus mobile app does not use cookies. Our website at invoiceplusapp.com does not use tracking cookies or analytics beyond what Netlify provides for hosting purposes. We do not serve advertising on our website or in the app.

12. Changes to This Policy

We may update this policy from time to time. When we make significant changes, we will notify you through the app and update the "Last Updated" date at the top of this page. Continued use of the app after changes are posted constitutes acceptance of the updated policy.

13. Contact Us

Jeffrey Lyon
ABN 14 642 051 653
VIC, Australia
jeffstechservice@gmail.com

For privacy-specific inquiries, please include "Privacy Request" in your subject line and your country of residence so we can ensure your rights are addressed under the correct framework.