Last updated: June 9, 2026
1. Who We Are
InvoiceStack is an individual project operating at invoicestack.app. For the purposes of the GDPR, the Data Controller is the individual operating this website, reachable at the contact below.
For privacy questions: legal@invoicestack.app
A Data Protection Officer (DPO) has not been appointed as we do not meet the criteria under GDPR Art. 37.
2. What We Collect
2.1 Through the Extension
- License key — purchased via Lemon Squeezy, transmitted to validate your usage.
- Airbnb invoice HTML & booking codes — sent to our API (
api.invoicestack.app) for PDF generation. - These are processed transiently and deleted immediately after the download response is sent. PDFs exist only in memory during generation and are never persisted.
2.2 Through Our Website (WordPress)
- Nothing by default. No accounts, no comments, no user registration.
- If you sign up for product updates (future), we collect only your email address with explicit consent.
2.3 Through Our Server (api.invoicestack.app)
- PDF files: Generated and deleted after download. Never stored.
- Usage counter: A pseudonymous identifier (hash of your license key) + remaining credits count. This hash cannot be reversed to identify you. No personal data is tied to it.
- Server logs (Apache): IP address, timestamp, requested URL. Retained for 14 days for security and abuse prevention. Legal basis: legitimate interest (GDPR Art. 6.1.f).
2.4 Through Payments (Lemon Squeezy)
- We do not receive or store your payment details.
- Lemon Squeezy processes all payments as our merchant of record.
- See Lemon Squeezy Privacy Policy.
2.5 Analytics
- Our website uses RankMath SEO connected to Google Analytics.
- GA may set cookies (see Cookie Policy).
- IP addresses are anonymized.
3. B2B Outreach
We may contact businesses using publicly available professional email addresses (e.g., company websites, LinkedIn) to introduce our service. We only contact addresses associated with business entities, not private individuals.
- Legal basis: Legitimate interest (GDPR Art. 6.1.f).
- Every email includes an unsubscribe link.
- Opted-out addresses are never re-contacted.
- We do not purchase email lists.
4. How We Use Your Data
- Validate your license key
- Generate invoice PDFs
- Track remaining credits on your license
- Optional: send product updates (only with your consent)
- Protect our server against abuse (log analysis)
5. Data Sharing
- Lemon Squeezy — payment processing and license validation.
- Google Analytics — anonymized website traffic analysis.
- No other third parties. We do not sell, rent, or trade your data.
6. Your Rights (GDPR)
As an EU resident, you have the right to:
- Access — request a copy of any personal data we hold.
- Rectification — correct inaccurate data.
- Erasure — request deletion of your data.
- Restriction — limit how we process your data.
- Portability — receive your data in a machine-readable format.
- Objection — object to processing based on legitimate interest.
- Withdraw consent — at any time, where processing is consent-based.
- Complaint — lodge a complaint with your local data protection authority.
To exercise any of these rights, contact: legal@invoicestack.app
7. Data Retention
| Data | Retention |
|---|---|
| License usage counters | While license is active, or until deletion requested |
| Server logs (Apache) | 14 days |
| PDF files | Deleted immediately after download |
| Email for product updates | Until you unsubscribe |
8. Security
All data transmission is encrypted via HTTPS. Our server is hosted on Hetzner (Helsinki, Finland — EU), who acts as a sub-processor under GDPR. We follow reasonable security practices to protect your data.
9. Children’s Privacy
Our service is not directed to individuals under 16. We do not knowingly collect data from children.
10. Changes to This Policy
Updates will be posted on this page. Significant changes will be communicated via email if you are subscribed to product updates.