Skip to content
InvoSort

Last updated: August 24, 2026.

Privacy Policy

This Privacy Policy explains how InvoSort handles information when you create an account, upload invoices or send them through Telegram, review extracted invoice data, and manage billing. It is written for practical understanding and does not promise security certifications, legal outcomes, or accounting results.

For advertising measurement, see how Google describes its use of data from sites and apps in Google's Business Data Responsibility information.

Information we process

We process account information such as your name, email address, authentication details, workspace membership, subscription status, and product settings needed to run your account. We also process invoice files you upload or submit through connected Telegram intake, including PDF invoices, receipts, and related business documents.

When invoices are processed, InvoSort may extract invoice metadata such as vendor, date, amount, category, type, file status, and other fields shown in the dashboard. This data is used to help you review and organize invoice records.

Invoice processing

InvoSort uses AI-assisted extraction and classification workflows to read invoice files submitted through dashboard uploads or Telegram intake and turn them into structured data. Automated extraction can be imperfect, so users are responsible for reviewing invoice results before relying on them for bookkeeping, tax, reporting, or payment decisions.

Supported file types and scan quality may affect results. Blurry, incomplete, handwritten, password-protected, very large, or unusual invoice files may fail, take longer, or produce incomplete OCR and extraction output.

You are responsible for the files and content you upload. Do not upload documents unless you have the right to use them with the service and share them with service providers involved in processing and storing them.

Billing and payments

Subscription billing and payment handling are processed by Stripe. InvoSort receives billing status information needed to show your plan, manage access to billing tools, and support subscription workflows. We do not store full payment card numbers on InvoSort servers.

A newly verified account may receive one 14-day Individual trial without a payment method. It does not automatically become a paid subscription. Stripe receives billing information only after you explicitly choose a paid plan and continue to Checkout. Invoice usage limits and the 100 Invoice Pack may be used to manage upload volume for the applicable billing period.

Cookies, sessions, and page context

InvoSort uses cookies, local storage, and session data to keep you signed in, remember interface preferences, and operate protected app pages. During signup, short-lived necessary page state may hold the email submitted for pending verification and resend timing for up to 24 hours, or until verification succeeds or the signup is restarted. It is not used for analytics or marketing. Public pages may use Vercel geo or IP-derived headers, when available, for lightweight and non-blocking page personalization such as general location wording. This does not use browser GPS, does not require a location permission prompt, and is not stored for location tracking.

After you allow analytics, InvoSort may record browser funnel events such as signup-page views and submissions and enable consented analytics and performance providers. After you allow advertising measurement, InvoSort may also store recognized campaign fields, the landing path without its query or fragment, and the referring site origin for first-touch attribution. Authentication callback secrets and full callback queries are not included in that attribution. Analytics and advertising-measurement preferences can be changed at any time.

Cookie Policy

Google advertising measurement

When you affirmatively allow advertising measurement and arrive through a Google ad, InvoSort may retain the Google click identifier (GCLID) from your InvoSort landing URL. If that click later leads to a trial activation, InvoSort may send Google the pseudonymous GCLID, the trial-activation timestamp, and one random, stable pseudonymous transaction identifier so Google can measure and deduplicate the conversion. A GCLID is a pseudonymous advertising identifier; it is not described here as anonymous.

This conversion-measurement flow does not send Google your name, email address, phone number, postal address, or invoice files or invoice contents. It is used for measurement, not personalized advertising or remarketing, and the personalization consent signal remains denied. Learn more about how Google uses information from sites and apps that use its services in Google's Business Data Responsibility information.

When consented Google tags load in the browser, ordinary web requests can also make network information such as the device IP address available to Google. InvoSort does not add an end-user IP address to the separate server-side trial-conversion upload.

InvoSort keeps a versioned, server-timestamped record of the notice, available choices, and the choices you made. The receipt uses a random pseudonymous context and decision sequence so same-origin tabs, retries, and withdrawals converge on one history. It contains no name, email, network address, GCLID, or invoice data. Legacy choices that lack this durable receipt are not eligible for Google conversion delivery.

Service providers and storage

We rely on service providers for authentication, database storage, file storage, hosting, billing, and invoice processing. These providers process information only as needed to provide the service, operate infrastructure, secure accounts, process invoices, and manage subscriptions.

Analytics, performance, and ads measurement providers may include DataFast, Vercel Analytics, Vercel Speed Insights, Google Analytics, and Google Ads, depending on your consent settings and the page you visit.

When you withdraw advertising-measurement consent, InvoSort immediately enters a denied state in the browser, stops new measurement, and retains a pending request until the server acknowledges it. InvoSort then clears device-held first-touch campaign data and its attribution identifier and cancels conversion work that has not been committed for immediate provider dispatch. Work already committed by the final database dispatch authorization, or already sent to the provider, remains limited to receipt persistence and status polling and is not falsely reported as cancelled. Withdrawing analytics consent stops new browser funnel and analytics events. Existing account, security, operational, and consent records may be kept when needed to run and protect the service or meet lawful recordkeeping obligations.

How we use information

We use information to authenticate users, store and process invoices, display extracted invoice records, support billing, troubleshoot product issues, improve reliability, prevent abuse, and respond to support requests. We do not sell personal data.

Security and retention

We use practical safeguards provided by our authentication, hosting, storage, and payment providers, plus application access controls, to help protect account data and invoice records. No online service can guarantee absolute security.

We keep account, invoice, and billing records for as long as needed to provide the service, comply with operational needs, resolve disputes, prevent abuse, and support lawful recordkeeping. You may contact us if you need help with account or data deletion requests.

Contact

For privacy questions or account requests, contact support@invosort.com.