Back to Home

Privacy Policy

Last updated: 1 March 2026

1. Introduction

e-Invoice.app ("we," "our," or "the Site") is operated from New South Wales, Australia. For data protection purposes, the data controller is e-Invoice.app, contactable at team@e-invoice.app.

This Privacy Policy explains how we collect, use, and share information when you use the Site. It applies to all visitors, whether browsing as an unauthenticated guest or as a signed-in user.

2. Information We Collect

2.1 Information from LinkedIn

When you sign in with LinkedIn, we collect:

  • Your full name
  • Email address
  • LinkedIn profile picture
  • LinkedIn profile URL
  • Professional headline/job title (if publicly available)

2.2 User-Generated Content

We collect content you create on the Site, including:

  • Comments and discussions about e-Invoice requirements
  • Feedback and issue reports
  • Vendor upvotes and endorsements

2.3 Automatically Collected Information

We automatically collect certain information when you use the Site:

  • Device information (browser type, operating system, screen resolution)
  • Usage data collected via third-party analytics (pages viewed, session duration, navigation paths)
  • Referrer URL and page path
  • IP address (used for rate limiting and general location; not stored long-term)
  • General location data derived from IP address

2.4 Vendor Match Tool Data

When you use the Vendor Match Tool, we collect:

  • Company information (industry, size, entity count, headquarters location, budget range)
  • Invoice volume and processing requirements
  • ERP systems and integration preferences
  • Country coverage requirements
  • Contact details (name, email, phone number, job title, company name, website, LinkedIn URL)

This data is stored as Vendor Match Tool sessions and is shared with our appointed procurement partner only upon your explicit consent at the submission step.

2.5 Sponsorship Analytics

We track anonymised impressions and clicks on sponsored content to measure sponsorship performance. This tracking uses a temporary session-based identifier (cleared when you close the tab). Sponsorship analytics are not used for behavioural advertising or user profiling.

2.6 Colleague Invitations

When you invite colleagues via the Site, we collect the email addresses of the people you invite. These email addresses are stored solely to send the invitation and track invite history. We do not add invited individuals to marketing lists or share their email addresses with third parties. Invited individuals' data is retained only as part of your invite history.

2.7 Public Profile Visibility

If you have discoverability enabled (the default setting), your name, company, job title, and LinkedIn URL are visible to other signed-in users via the community discovery feature. You can disable discoverability at any time in your profile settings.

3. How We Use Your Information

We use your information to:

  • Provide and improve our e-Invoice tracking and vendor directory services
  • Verify user identity and prevent fraudulent activity
  • Enable community discussions and professional collaboration
  • Match you with relevant vendors through the Vendor Match Tool
  • Measure sponsored content performance
  • Send important updates about e-Invoice compliance changes
  • Analyse site usage to improve the service
  • Enforce rate limits and prevent abuse
  • Log API access for security monitoring
  • Track your last active timestamp
  • Send invitations to colleagues on your behalf when you use the invite feature

4. Information Sharing

We share information in the following circumstances:

4.1 Public Information

Your name, profile picture, and comments are visible to all visitors of the Site. If you have discoverability enabled, your name, company, job title, and LinkedIn URL are also visible to other signed-in users.

4.2 Service Providers

We use the following categories of third-party service providers to operate the Site:

  • Database & Authentication Provider - stores user profiles, content, and handles secure sign-in via LinkedIn OAuth (EU region)
  • Hosting & Deployment Provider - serves the Site globally via edge network infrastructure (global, US-headquartered)
  • Analytics Provider - collects anonymised website usage data (pages viewed, session duration, navigation paths) via cookies (data may be processed in the United States)
  • Content Delivery & Security Provider - provides CDN, DDoS protection, and web performance analytics (global network, US-headquartered)
  • Email Delivery Provider - sends transactional emails such as invitations, Vendor Match Tool submissions, and enquiry confirmations (US-headquartered)
  • Rate Limiting Provider - request throttling to prevent abuse (global edge network)

We use LinkedIn as our sole authentication provider. No other social media platforms are integrated.

4.3 Data Sharing with Procurement Partner

When you submit a procurement request through the Vendor Match Tool, your submission data (company details, requirements, and contact information) is shared with our appointed procurement partner for vendor matching and selection support. This sharing occurs only upon your explicit consent at the submission step and is transmitted via encrypted email through our email delivery provider.

4.4 Sponsor Enquiries

When you submit contact or quote requests through a sponsor enquiry form, your data (name, email, company name, and message) is shared with the relevant sponsor for direct follow-up.

Upon receiving that data, the sponsor becomes an independent data controller under GDPR and applicable privacy laws. e-Invoice.app does not act as a processor on behalf of the sponsor, and each sponsor is independently responsible for its handling of the data, including any further use, retention, and your rights against the sponsor.

4.5 Sponsor Trademarks & Brand Assets

Sponsor logos, names, and brand marks displayed on the Site and our communications are used under licence from the respective sponsor. Their display does not imply ownership, affiliation, or endorsement beyond the relevant sponsorship arrangement.

4.6 Legal Requirements

We may disclose your information if required by law, regulation, legal process, or governmental request, or to protect our rights, users, or the public from harm or illegal activities.

5. Data Retention

We retain your information for as long as your account is active or as needed to provide our services. When you delete your account:

  • Your personal profile information is permanently deleted
  • Your comments are transferred to a system account and retained indefinitely as anonymised community content to preserve discussion integrity
  • Vendor upvotes are retained in anonymised form to preserve directory integrity

Specific retention periods:

  • Account data - retained while your account is active; deleted upon account deletion
  • Vendor Match Tool sessions - 24 months, then anonymised
  • API access logs - 12 months
  • Sponsorship and vendor analytics - 24 months
  • Rate limiting data - expires within minutes
  • Analytics data - 14 months (per our analytics provider's configuration)
  • Invite history - retained while your account is active; deleted upon account deletion
  • Comment views - retained for 24 months for analytics purposes

6. Your Rights

6.1 All Users

Regardless of your location, you have the right to:

  • Access - request a copy of your personal data
  • Rectification - correct inaccurate information
  • Deletion - request deletion of your account and personal data
  • Data Portability - receive your data in a structured, machine-readable format
  • Object - object to processing of your data for analytics or profiling
  • Restrict Processing - request restriction of processing in certain circumstances
  • Opt-out - unsubscribe from non-essential communications

To exercise these rights, contact us at: team@e-invoice.app

6.2 Australian Privacy Act 1988

If you are located in Australia, you have the right to:

  • Access and correct personal information held about you
  • Complain to the Office of the Australian Information Commissioner (OAIC) if you are unsatisfied with our handling of your data

We collect personal information only for purposes directly related to our functions and activities, as required by Australian Privacy Principle 3.

6.3 GDPR (EU/EEA/UK Residents)

If you are located in the EU, EEA, or UK, you have additional rights under the GDPR:

  • Right to lodge a complaint with your local Data Protection Authority
  • Right to withdraw consent at any time (where processing is based on consent)
  • Right to data portability between service providers

The legal bases on which we rely are set out in Section 10.

6.4 CCPA / CPRA (California Residents)

If you are a California resident, under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:

  • We do not sell or share personal information
  • You have the right to know what personal information we collect and disclose
  • You have the right to request deletion of your personal information
  • You have the right to correct inaccurate personal information
  • You have the right to limit the use of sensitive personal information
  • We will not discriminate against you for exercising your privacy rights

7. Cookies and Tracking

7.1 Essential Cookies

Authentication session cookies and CSRF protection tokens are required for sign-in functionality. These cookies are strictly necessary and cannot be disabled while using authenticated features.

7.2 Analytics Cookies

We use third-party analytics cookies (such as _ga and _gid) to measure pages viewed, session duration, and navigation paths. You can manage your analytics cookie preferences at any time using the cookie settings panel accessible from the site footer, or by adjusting your browser settings. Our CDN provider may also set a performance measurement beacon; this does not use persistent cookies.

7.3 Local and Session Storage

We store your cookie consent preferences in your browser's local storage (category selections only, no personal data) and a temporary session identifier for analytics purposes (automatically cleared when you close the tab).

We do not use advertising cookies, retargeting pixels, or sell data to advertisers.

7.4 Opting Out

You can opt out of analytics data collection using the cookie preferences panel (accessible via "Cookie Settings" in the site footer) or by adjusting your browser settings. We do not currently respond to "Do Not Track" browser signals, as no consistent standard exists for them.

8. Data Security

We implement security measures including:

  • Encrypted data transmission (HTTPS/TLS)
  • Access control policies on all database tables
  • LinkedIn OAuth for secure authentication
  • Distributed rate limiting to prevent abuse
  • IP-based access controls and request throttling
  • Periodic security reviews and updates

Data breach notification: In the event of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme (Part IIIC of the Privacy Act 1988). For EU/EEA users, we will also notify the relevant Data Protection Authority within 72 hours as required by GDPR Article 33.

9. Children's Privacy

The Site is not intended for users under 18 years of age. We do not knowingly collect information from anyone under 18. If we become aware that we have collected personal data from a person under 18, we will delete it without undue delay. If you believe we hold data from a minor, contact us at team@e-invoice.app.

10. Legal Basis for Processing (GDPR)

For users in the EU/EEA/UK, we process personal data under the following legal bases:

  • Consent - Vendor Match Tool submissions, sponsor enquiries, colleague invitations
  • Legitimate interest (Article 6(1)(f)) - vendor directory listings compiled from publicly available information, Site security, fraud prevention, analytics for service improvement
  • Contract performance - account creation, authentication, core service delivery
  • Legal obligation - compliance with tax/regulatory requirements, law enforcement requests, data breach notifications

11. Automated Decision-Making

Vendor rankings on the Site are computed algorithmically based on multiple factors including data quality, coverage, and community engagement. These rankings affect vendor visibility on the Site but do not produce legal effects or similarly significant effects on individuals. You may contact us at team@e-invoice.app to query any automated processing relating to your data.

12. International Data Transfers

Your information may be transferred to and processed in countries other than your own. Specifically:

  • Our database is hosted on cloud infrastructure in the EU region
  • Our application is served via a global edge network
  • Our analytics provider may process data in the United States
  • Our CDN/security provider operates a global network

Where data is transferred outside of the EU/EEA, we rely on adequacy decisions, standard contractual clauses, or other GDPR-compliant safeguards to ensure your data is protected.

13. Governing Law & Severability

This Privacy Policy is governed by the laws of New South Wales, Australia. If any provision of this Privacy Policy is found to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Continued use of the Site after changes constitutes acceptance of the updated policy for processing based on legitimate interest or contract performance. Where processing is based on consent, we will seek your renewed consent where required by applicable law.

15. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

  • Email: team@e-invoice.app
  • Website: https://www.e-invoice.app

This Privacy Policy complies with the Australian Privacy Act 1988, GDPR (EU), CCPA (California), and other applicable data protection regulations. By using e-Invoice.app, you acknowledge that you have read and understood this Privacy Policy. See also our Terms of Service.