Privacy Policy
Last updated: 23 August 2026
1. Who this policy is from
This Privacy Policy explains how Faris Alanezi trading as In-Vora (“In-Vora”, “we”, “us”) handles information when you use the In-Vora invoicing service. In-Vora is operated by an individual sole trader based in Victoria, Australia. In-Vora is not incorporated as a proprietary limited company, has not registered an Australian Business Number (ABN), and is not registered for GST.
2. What we collect
We collect only the information needed to run your account:
- Account credentials — the email address and password you provide at signup. Passwords are stored only as a bcrypt hash and cannot be recovered by us or seen in plaintext.
- Business information you enter during onboarding and in Settings — business name and, optionally, an owner name, business email, phone number, address, country, currency, your own ABN (if you have one), your own GST-registration status, tax rate, and invoice/quote numbering preferences and default notes. All of these except business name and country are optional.
- Business data you enter to run your business — clients, quotes, invoices, invoice line items, payments, and reminder history.
- Uploaded assets — a business logo image, if you choose to upload one.
- Basic technical logs — standard web-server request logs and error traces produced by our hosting provider, kept only for operational and security purposes.
We do not use any third-party product-analytics or user-tracking tool, and the site does not embed advertising trackers, remarketing pixels, or social-media share widgets that phone home.
3. Cookies
In-Vora sets only two cookies, both of which are strictly necessary to operate the app:
si_session— a session identifier set after you log in. It is HttpOnly, marked Secure in production, and usesSameSite=Lax. It expires when your session ends.flash— a very short-lived cookie (approximately 15 seconds) used to display one-time success or error messages after a form action, then removed.
There are no third-party cookies, no marketing cookies, no analytics cookies, and no consent banner because none of the cookies we set are optional.
4. What we do with the information
We use the information only for what is needed to provide the service to you, namely:
- authenticating you and keeping your account secure;
- storing and displaying your business data (clients, quotes, invoices, payments);
- generating PDFs and CSV exports of your own data at your request;
- when you enable email features, sending transactional email such as invoice delivery to your customers and password-reset emails to you (see section 5);
- when you subscribe to a paid plan, processing the subscription payment (see section 5);
- diagnosing errors, preventing abuse, and preserving the integrity of the service.
We do not sell your personal data or your customers’ data. We do not use the content of your invoices, quotes, or client records for advertising or to train machine-learning models.
5. Sub-processors we use
To run the service we share the minimum necessary information with a small number of sub-processors. Each is used for the purpose described:
- Railway — application hosting, PostgreSQL database hosting, and S3-compatible object storage for any business logo you upload.
- Stripe — subscription billing and payment processing when you are on a paid plan. Payment card details are entered directly on Stripe’s hosted checkout and Stripe’s hosted billing portal; we do not receive or store your full card number.
- Resend — transactional email delivery, used when email is enabled, for the emails described in section 4.
Sub-processors may be located outside Australia and may process data in other jurisdictions.
6. Marketing
In-Vora sends transactional and service emails only (for example, password resets, invoices you send to your customers, subscription notices). We do not send marketing emails without a separate opt-in, which we do not currently offer.
7. Security
We take reasonable technical measures to protect the information we hold, including: bcrypt password hashing (cost factor 12); HTTPS with HSTS preload on the app; strict security headers (X-Frame-Options DENY, X-Content-Type-Options nosniff, a strict referrer policy, and a permissions policy); server-side per-tenant authorisation on every request; a database-backed rate limiter; and nightly encrypted database backups (AES-256 with PBKDF2-derived keys) stored in object storage separate from the primary database. No system is perfectly secure and we cannot guarantee absolute security.
8. Retention and account deletion
You can delete your account at any time from Settings → Account by re-entering your password and typing DELETE to confirm. When you do:
- all live records associated with your account — your user record, your business record, and every client, quote, invoice, invoice line item, payment, reminder, active session, and password-reset record linked to it — are permanently deleted from the live database as part of the deletion action; and
- residual copies may remain in encrypted database backups on their normal expiry schedule: daily encrypted backups are retained for approximately 30 days and monthly encrypted backups are retained for approximately 12 months, after which they are removed by the backup workflow’s prune step. We do not selectively edit backups.
Any objects you have uploaded to storage (a business logo) are removed from live storage as part of the same deletion; encrypted backups of storage, if taken, are subject to the same retention windows.
9. Your rights
You can access, export, and correct your data at any time from within the app: your business data is visible in the UI, and you can export clients and invoices as CSV and download every invoice and quote as a PDF. You can update account details in Settings → Account. You can delete your account as described in section 8.
Depending on where you live, other rights may be available to you under local privacy or data-protection law. We do not make a general claim of compliance with any particular statute, but we will make reasonable efforts to honour a lawful request that we recognise as valid. Requests should be sent to the contact address in section 10.
10. Contact
For privacy-related questions or requests, contact the operator by email at support@in-vora.com. The operator does not currently maintain a separate postal address for the receipt of privacy correspondence.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top and, for material changes, notify you by email or in-app notice before the change takes effect.