Privacy policy

Short version: no trackers and no advertising cookies. Dropping a file on the validator, pressing Generate on the generator, or calling the validation API without a key, sends that invoice to our servers to produce the result; it is processed in memory and dropped, never stored. Those free doors also keep a daily counter per IP address, so nobody can exhaust them for everyone else, and what that counter stores is a salted hash of your address, never the address itself. Beyond that, the only personal data we keep is what you hand over yourself — an email address, or your GitHub account if you sign in to get an API key. The detail follows.

If you subscribe, your card is never handled here: Polar Software Inc. sells the subscription and holds the billing details. See Payments.

What happens to your invoice

The file you drop on the validator, or the invoice data you type into the generator, is uploaded: to our own server first, which forwards it to einvoicekit's validation API to run the full official rule set. It is read into memory there, extracting the embedded XML from a Factur-X PDF where relevant, and checked. Once the result comes back, it is dropped: it is never written to a database, never logged and never kept beyond the request that processed it. Nobody looks at it, and there is nothing left afterwards for us to look at.

What we do collect

Why, and on what basis

Three purposes. If you ask for more API volume than the free tier gives you, to answer that request: the address, the volume and whatever you chose to write are recorded so we can get back to you with a number and a payment link — legal basis: steps taken at your request before a contract exists (GDPR article 6.1.b). If you sign in for an API key, to run the service you asked for: issue the key and count it against a daily allowance — legal basis: performance of a contract (article 6.1.b), which is also the basis for running a subscription you bought. And, on the free validator and generator and on validation API calls made without a key, to stop one visitor from exhausting them for everyone else, a daily limit keyed to a salted hash of your IP address — legal basis: legitimate interest (article 6.1.f), balanced by never keeping the raw address and by rows that carry nothing anyone could trace back to a person. We do not sell, rent or share the data, and we run no targeted advertising on it.

How long

Per purpose, and describing what the code actually does rather than a schedule nobody runs:

An account that has held a subscription keeps only the plan word for as long as the account exists, and it goes when the account does. The billing records themselves are Polar's, not ours, and Polar keeps them for the period its own policy and the tax law it answers to require.

Where it is stored, and who else is involved

In a Cloudflare, Inc. D1 database located in the Cloudflare D1, Western Europe (WEUR) region. The host may process data in the United States; it participates in the EU-US Data Privacy Framework and offers the European Commission's standard contractual clauses.

Besides the host, the full list of who else touches any of this is short and closed:

Nobody else. No advertising network, no data broker, no analytics vendor.

Cookies and local storage

No advertising or tracking cookie is ever set, and no third-party script is loaded. Browsing the site sets no cookie at all. One technical storage is used inside your browser and never transmitted on its own: the campaign parameters of your visit, kept for the lifetime of the browser tab only. Closing the tab removes them.

Signing in with GitHub to get an API key does set cookies, because it cannot work without them. They are strictly necessary, readable only by our server, and never used to follow you: one holds your sign-in session, valid for up to seven days, and one carries a freshly issued key from the server to the page that displays it, for two minutes. They expire on their own, and nothing about them is shared.

Payments

Payments do not happen on this site. Checkout and the billing portal are hosted by Polar (Polar Software Inc., 3500 South DuPont Highway, Dover, DE 19901, United States), which sells the subscription as reseller and carries the sales tax. Polar is the seller on your invoice. Your card is entered on Polar's own page and read by Stripe, Inc. on Polar's behalf. We never receive it, never store it and cannot see it, not even the last four digits.

What Polar collects to bill you (your name and email, billing address, business name and tax number if you give one, and the card type and its last four digits) stays with Polar, under its own privacy policy. Your invoices and payment history live in Polar's customer portal, which your dashboard links to. Polar is in the United States and transfers data under the European Commission's standard contractual clauses.

The only thing that crosses back to us is which plan your account is on. Cancelling is done in that same portal, and it takes effect at the end of the period you already paid for.

Security

The protections that matter here are the ones the design makes possible, so they are worth stating as facts rather than as adjectives:

Your rights

Where we rely on your consent, you can withdraw it at any time, and withdrawing it is as easy as giving it: one email, no reason needed. Withdrawal does not affect anything we lawfully did with the data before you withdrew it (GDPR article 13.2.c).

You have the right to access, rectify, erase, port, restrict and object. Email contact@einvoicekit.com and that is enough: no form, no proof of identity beyond what is strictly necessary. We answer within one month. If our answer does not satisfy you, you can lodge a complaint with the French data protection authority, the CNIL (cnil.fr), or with your own national authority.

Data protection officer

None appointed, and none required: article 37 asks for one where the core activity is large-scale monitoring of people or special-category data, and neither describes this site. Writing to contact@einvoicekit.com reaches the person who wrote this page.

Changes to this policy

The date at the bottom moves whenever the text does. A change that would widen what is collected, or add someone to the list above, is stated here before it takes effect, rather than edited in quietly.

Data controller

VIZALGO, 65 rue de la Croix, 92000 Nanterre, France. Nanterre Trade and Companies Register (RCS) 907 455 778. Contact: contact@einvoicekit.com.