Privacy Policy
This is a courtesy translation. The German version of this page is the legally binding one.
This page covers what Invoclara actually does today. It is not a substitute for review by a qualified lawyer.
Who we are
Invoclara is operated by Markus Schmetterling, Heggerstraße 23, 45525 Hattingen, Germany, who is the controller for the processing described here. For any privacy question, contact us at the address on our Contact page.
What data we collect
Account data (name, email address, password hash) when you sign up — or, if you choose to sign in with Google, GitHub or Apple, the name, email address and account ID that provider shares with us. Business data (company name, country) you provide during onboarding. Content you upload for checking (website URLs; invoice files and the data extracted from them). Usage data (which features you use, how many checks you run) needed to enforce plan limits. Technical data such as your IP address, as described under "Hosting" and "Security and abuse prevention". Payment data is handled entirely by Lemon Squeezy, our merchant of record — we never see or store your card details.
Why we process it
To provide the compliance-checking service you signed up for (contract performance, Art. 6(1)(b) GDPR); to keep the service secure, enforce usage limits and prevent abuse (legitimate interest, Art. 6(1)(f) GDPR); to process payments (contract performance, via Lemon Squeezy); to meet legal obligations such as tax record-keeping where applicable (Art. 6(1)(c) GDPR); and, only where you have consented, for live chat and marketing measurement (Art. 6(1)(a) GDPR).
Hosting
The website and its server functions are hosted by Vercel Inc. (USA); the server functions run in Vercel's Dublin (Ireland) region. When you visit a page, your browser necessarily transmits your IP address, the requested URL, the time, your browser type and the referring page; Vercel processes this to deliver the page and keeps it in short-lived server logs. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in delivering a secure, working website. Our database, authentication and file storage run on Supabase in the EU (AWS region Ireland).
Security and abuse prevention
To protect accounts against password guessing and the service against spam, we store your IP address together with a request counter when you log in, sign up, reset your password, use the cross-border check, or request a callback, and we limit how many accounts can be created from one IP address within seven days. These entries are deleted automatically after eight days at the latest. When you set a password, we check whether it has appeared in a known data breach using the "Pwned Passwords" service of Have I Been Pwned: only the first five characters of a SHA-1 hash of your password leave our server — never the password itself, and never your IP address. Legal basis: Art. 6(1)(f) GDPR (security of the service and of your account).
Account emails
Emails needed for your account — such as sign-up confirmation and password reset — are sent through Resend (USA) as our email delivery provider. Resend processes your email address and the content of those emails. Legal basis: Art. 6(1)(b) GDPR.
Sign-in with Google, GitHub or Apple
Where these options are offered and you choose one, you are redirected to that provider to sign in. The provider then tells us your name, email address and an account ID, and learns that you are signing in to Invoclara. We receive no password from them. Legal basis: Art. 6(1)(b) GDPR. The provider's own privacy policy applies to what happens on their side.
Cross-border VAT check
If you enter a VAT ID in our cross-border check, we verify it with the European Commission's VIES service. We store the result — VAT ID, whether it is valid, and the registered name and address VIES returns — for 30 days so the same number isn't queried again and again, then delete it automatically. For our own statistics we record only the anonymous parameters of each check (countries, B2B or B2C, goods or services, outcome) — no VAT ID, no IP address and no account. Legal basis: Art. 6(1)(f) GDPR.
Who else sees it
We use the following service providers as processors (Art. 28 GDPR): Supabase (database, authentication and file storage, hosted in the EU), Vercel (hosting and cookieless visitor statistics), Resend (account emails), Plausible Insights OÜ, Estonia (cookieless visitor statistics, hosted in the EU), Anthropic (AI-assisted explanation of check results — invoice or website content is sent to Anthropic's API solely to generate that request's explanation, and is not used to train their models) and, only if you allow live chat in the cookie banner, Tawk.to (chat widget, chat history and any contact details you provide in the chat). Lemon Squeezy sells our subscriptions as merchant of record and processes your payment data under its own privacy policy. With your consent, Google receives data for ad-conversion measurement — see below.
Google Ads conversion measurement
Only if you allow "Marketing" in the cookie banner, we load Google's conversion tag (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). It records whether a visit that started with a click on one of our Google ads led to a sign-up. Google receives your IP address, device and browser information and the pages visited, and sets cookies (see our Cookie Policy). We don't use Google for remarketing, personalised advertising or Google Analytics. Data may be transferred to Google LLC in the USA. Legal basis: your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG), which you can withdraw at any time via "Cookie settings" in the footer.
Transfers outside the EU
Some of our providers are based in the USA (Vercel, Resend, Anthropic, Tawk.to, Lemon Squeezy, and Google LLC). Where personal data is transferred there, the transfer is based on the European Commission's adequacy decision for the EU–US Data Privacy Framework if the recipient is certified under it, and otherwise on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR).
Callback requests
If you request a callback through one of our free tools, we store the phone number you provide along with your explicit consent to be contacted for that purpose (legal basis: consent, Art. 6(1)(a) GDPR). This data is used only to carry out the requested callback and isn't used for any other marketing purpose.
How long we keep it
Uploaded invoices, website scans, and their results are kept for your organization's configured retention period (365 days by default) or until you delete them, whichever is sooner. Account data is kept until you delete your account. IP addresses stored for abuse prevention are deleted after eight days at the latest; VAT check results after 30 days. You can delete any individual scan or invoice, or your entire account, at any time from Settings. Where the law requires us to keep records longer (for example for tax purposes), we keep them only for that purpose and period.
Your rights
Under GDPR you have the right to access, correct, delete, or export your data, and to restrict certain processing. Where we rely on legitimate interest (Art. 6(1)(f) GDPR), you can object to the processing on grounds relating to your particular situation (Art. 21 GDPR). Where we rely on your consent, you can withdraw it at any time with effect for the future — for cookies, via "Cookie settings" in the footer (Art. 7(3) GDPR). You can exercise most of these rights directly in Settings; for anything else, contact us. You also have the right to lodge a complaint with a data protection supervisory authority.
AI and your data
We do not use your uploaded invoices, scan results, or account content to train AI models — ours or any third party's. AI is used only to generate the specific explanation you requested, at the time you requested it.
Cookies
See our Cookie Policy for the cookies and similar technologies this site uses, and how to change your choice.
Changes to this policy
We update this policy before we start using a new service or a new kind of data. Last updated: 23 September 2026.