This policy describes the product's current data practices without promising a specific hosting location, security certification, or retention schedule.
1. Who This Policy Covers
This policy explains how FINALDOC TECHNOLOGIES PRIVATE LIMITED ("InvoiceKaro", "we", "us") handles information when you use the InvoiceKaro website, app, public payment links, approval links, and client portals (the "Service").
InvoiceKaro is designed for businesses and is not intended for anyone under 18.
2. Information the Service Processes
Depending on the features you use, the Service processes:
• Account identifiers, such as a phone number or email address, and OTP verification metadata
• Business profile details, including business and owner names, addresses, GSTIN, logo, signature, UPI ID, and bank details you choose to provide
• Customer, invoice, payment, project, milestone, reminder, and evidence information
• Files or links you attach as proof of work
• AI/OCR prompts, images, or document content submitted to AI-powered features
• Support messages and billing references you send us
• Technical request data such as IP address, browser or user-agent, timestamps, and error logs
When someone uses an approval link, the Service can record the approver's name, optional email and comments, IP address, browser information, timestamp, and an integrity hash associated with the reviewed bundle.
3. Why We Process Information
We process this information to:
• Create and authenticate accounts using OTP verification
• Create invoices and PDFs, track invoice and payment status, and provide dashboards and exports
• Run project, evidence, reminder, public-link, approval, and client-portal workflows
• Process subscription orders and verify payments
• Provide configured email, WhatsApp, or SMS delivery features
• Provide AI/OCR features when requested
• Prevent abuse, enforce usage limits, diagnose failures, and support users
• Comply with valid legal obligations and protect the Service
4. Storage and Security
Account and product data is stored by the deployed InvoiceKaro server and database. Uploaded proof files use configured object storage in production; a local-disk fallback may be used for development. Evidence added as an external URL remains hosted by that external service. We do not claim that all data is hosted in a particular country.
Current safeguards include OTP-based sign-in, access tokens, expiring signed public links, access controls in the application, and SHA-256 integrity fingerprints for supported evidence and approval bundles. A hash helps detect a content change; it is not encryption and does not make a record permanent.
Production traffic should use HTTPS. We do not promise a particular TLS version, encryption-at-rest method, backup schedule, audit cadence, or absolute security. Protect OTPs, account access, API keys, and signed links, and contact us if you suspect unauthorized use.
5. Providers and Disclosure
The Service relies on providers that process data needed for their function. Depending on deployment and the feature used, these may include:
• Hosting and infrastructure providers
• OTP, email, WhatsApp, or SMS delivery providers
• Razorpay for eligible web plan-access checkout
• AI/OCR providers for content submitted to AI-powered features
• External sites that host evidence links or resources you choose to use
These providers receive the information necessary to perform the requested service and operate under their own terms and privacy policies. We may also disclose information when required by valid legal process, to investigate abuse or security incidents, in a corporate transaction, or with your direction. Do not put information into InvoiceKaro that you are not authorized to process or share.
6. Signed and Public Links
Payment, approval, and client-portal links are designed to be opened without signing into the owner's account. Anyone who obtains a valid link may be able to view the information behind it until the link expires or is revoked. Share these links only with intended recipients and revoke them when they are no longer needed.
Search engines are instructed not to index these pages, but that instruction cannot prevent a recipient, browser, messaging service, or link-preview service from accessing or retaining information after a link is shared.
7. Local Storage and Cookies
The web app uses browser storage for essential functions such as authentication state, preferences, and remembering that the cookie notice was dismissed. The app also uses device storage for comparable session and preference data.
As of this policy date, the InvoiceKaro frontend does not intentionally install Google Analytics or advertising cookies. Embedded or linked third-party services, such as payment checkout, hosted fonts, or external evidence sites, may use their own cookies or storage under their policies. Blocking essential browser storage may prevent sign-in or saved preferences from working.
8. Access, Correction, Export, and Deletion
You can edit supported profile records and delete supported invoices, customers, projects, evidence, or links in the app. Available exports currently include invoice PDFs and an invoice/payment CSV; this is not a promise that every field can be exported in every format.
The in-app Delete Account action requires a fresh OTP proof and typed confirmation. The server first deletes uploaded proof objects from configured local or object storage; if that storage step fails or times out, it reports a failure and does not delete the database account. After storage deletion succeeds, it deletes the owner and related active database records through database cascades. Deletion cannot recall invoices, messages, payment records, files, or links already received or retained by another person or provider. Provider logs, backups, or records may remain under the provider's policy or applicable law.
For an access, correction, or deletion question, contact privacy@invoicekaro.com. We may need to verify that you control the relevant account before acting.
9. Retention
Data remains in the active Service until it is deleted through an available product action, the account is deleted, or InvoiceKaro removes it for an operational or legal reason. Signed links can expire or be revoked, but recipients or external services may have retained copies.
We do not publish a fixed backup, log, support-message, or processor-retention period in this policy. Businesses remain responsible for keeping any invoice and tax records required by law before deleting data from InvoiceKaro.
10. Changes and Contact
We may update this policy as the Service, providers, or legal requirements change. The date shown on this page identifies the current version.
Privacy requests: privacy@invoicekaro.com
Grievances: grievance@invoicekaro.com
General support: support@invoicekaro.com
Phone: +91-8093712301
We do not promise a fixed acknowledgement or resolution time. We will review verified requests in accordance with applicable law and the information available to us.
Review this policy together with the Terms of Service before using InvoiceKaro.