Simple Version: We collect the information you need to use our invoicing service. We keep it safe. We don't sell it to anyone. You can close your account and delete your data yourself at any time, in the app or from Account Settings on the website - no need to contact anyone.
1. Who We Are
Company: GK Tools Ltd, a private limited company registered in England and Wales (company number 16434833)
Registered office: 483 Green Lanes, London, N13 4BS, United Kingdom
ICO registration: ZB899192
Website: invoicer.gk.tools
Contact: support@invoicer.gk.tools
GK Tools Ltd is the data controller for the personal data described in this policy. We provide simple invoicing software for tradespeople. This privacy policy explains how we handle your personal data in accordance with UK GDPR and Data Protection Act 2018.
For the client details you enter into Invoicer (your customers' names, addresses, and other information), you are the data controller and we act as your data processor — we process that data only to provide the service and on your instructions. See our Terms of Service for the full processor terms.
2. What Information We Collect
Account Information
- Your name and email address
- Your business name and type of trade
- Bank details (account number and sort code) if you provide them
- Address details if you provide them
- Your mobile number, if you provide one — used only to send SMS login codes as a backup method when email isn't accessible, never for marketing. You can block SMS at any time via our SMS opt-out page
Customer Information (That You Enter)
- Your clients' names, addresses, and email addresses
- Invoice details (amounts, dates, descriptions)
- Insurance documents you upload
Payment Information
- Payment card details (processed securely by Stripe - we never see your full card number)
- Bank account details for Bacs Direct Debit (processed securely by Stripe - we never see your full account details)
- Subscription status and payment history
- Billing address
Technical Information
- IP address and browser type
- Pages you visit on our site, stored as fixed route names without query strings, login codes, document tokens, search terms, or record identifiers
- Login dates and times
3. Why We Collect This Information
We collect your information for these reasons:
- To provide the service: We need your business details to create and send invoices on your behalf
- To process payments: We need payment details to manage your subscription
- To communicate with you: We send you login codes, important service updates, and respond to your queries
- To provide personalized insights and the in-app assistant: We use aggregated business statistics (e.g., revenue, invoice counts, client counts) with Google AI to generate helpful daily business insights for you. If you choose to use the in-app assistant, we also share your message and the business details it needs to answer — see “Google AI (Invoicer Assistant)” under “Who We Share Your Information With” for exactly what that includes. If you choose to add an invoice you already have by photographing or uploading it, we send that document to Google AI to read — including your customer's details printed on it — see “Google AI (Reading an invoice you upload)” for exactly what that involves
- To comply with the law: We keep financial records as required by UK tax law
- To improve the service: We look at how people use the service to make it better
Legal Basis: We process your data under contract (to provide the service you signed up for), legal obligation (keeping financial records required by UK tax law), legitimate interests (running, securing and improving our business), and consent (marketing emails — you can withdraw consent at any time via the unsubscribe link).
4. How Long We Keep Your Information
- Active accounts: We keep your data while your account is active
- After you cancel: We keep your data for 7 years after you close your account (UK tax law requirement for financial records)
- Login codes: Expire after 15 minutes, automatically deleted after 30 days
- Login attempts: Automatically deleted after 90 days
- Activity logs: Kept for 2 years for security and audit purposes, then automatically deleted
- Email logs: Kept for 2 years, then automatically deleted
- Marketing emails: Until you unsubscribe
We run automated data cleanup processes to ensure we don't keep data longer than necessary.
5. Who We Share Your Information With
We only share your information with these trusted third parties, and each one is required by our agreement with them to protect your data to the same standard set out in this policy - they may not use it for anything beyond what is described below:
Stripe (Payment Processing)
We use Stripe to process all payments securely, including card payments and UK Bacs Direct Debit. They handle your payment details directly - we never see your full card number or bank account details. View Stripe's Privacy Policy
Google AI (Personalized Business Insights)
We use Google's Gemini AI to generate personalized daily business insights for you. For this feature only, we share aggregated, non-sensitive business statistics (revenue totals, invoice counts, client counts, location, business type) — not client names, email addresses, phone numbers, invoice line items, or payment details. We send only the aggregated statistics listed above; we do not permit this data to be used for model training under our API terms, and we don't store the prompts beyond generating your insight. View Google's Privacy Policy
Google AI (Invoicer Assistant)
Invoicer also includes an in-app assistant you can chat to. This is a separate feature from the daily insights above, and it shares considerably more with Google's Gemini AI, because it needs to know about your business in order to answer you.
When you send the assistant a message, we send Google:
- Your message, and the assistant's earlier replies in that conversation
- Your client list — client names, their email addresses (including any CC addresses) and any default rate you have set
- Your recent and unpaid invoices — invoice numbers, client names, amounts, dates, status, and invoice line items (description, quantity and price)
- Your quotes — quote numbers, client names, amounts and any deposit required
- Your business name and trade, and totals such as revenue and outstanding balance
We do not permit this data to be used to train Google's models under our API terms. If you would rather Google did not receive any of this, simply do not use the assistant — every other part of Invoicer works without it.
We also keep a log of assistant conversations (your messages, the assistant's replies, any action it took on your behalf, and the IP address the message came from) so we can investigate problems and misuse. Those logs are visible to us as the operator of the service, and are deleted in line with the retention periods in “How Long We Keep Your Information” above.
Google AI (Reading an invoice you upload)
If you choose to add an invoice or quote you already have — by taking a photo of it or uploading a PDF — we send that document to Google's Gemini AI so it can read the details off it for you. This is a separate feature again, and you only ever use it by deliberately choosing a file.
Because it is a picture of a real document, what we send includes everything printed on it. In practice that means:
- Your own business details — name, address, phone number, and any VAT details printed on it
- Your customer's details — their name, address, and any phone number or email address printed on the document
- The invoice or quote itself — its number, dates, what the work was, and the amounts
- Anything else that happens to be printed on the page you photograph
We do not permit this data to be used to train Google's models under our API terms. The document is sent to be read and is not stored by us afterwards — we keep only a record that a document was read, when, and what it cost us to do so, never the document or the details taken from it. Nothing is saved to your account until you have checked what we read and pressed save.
If a PDF is uploaded we convert it to an image first, and send only that image. If you would rather Google did not receive any of this, do not use this feature — you can always type the details in yourself, and every other part of Invoicer works without it.
Google Maps Platform (Address Suggestions)
Google Places provides address suggestions on business-profile and client forms. Invoicer does not contact Google just because you open one of these forms: the provider loads only after you focus or otherwise interact with the first address field. From then on, the address text you type is sent from your browser to Google so it can return matching addresses. This can include your business address or a client address, along with normal technical data such as your IP address and browser type. The address you choose or finish typing is then saved in Invoicer when you submit the form. View Google's Privacy Policy
Google reCAPTCHA (Login and Signup Security)
Google reCAPTCHA runs on customer login, administrator login, and signup to help distinguish legitimate requests from automated abuse. Its script may process normal browser, device, and interaction information under Google's terms. Our reCAPTCHA API call contains our public site key and a fixed action name; we do not include your email address, name, or login code in the reCAPTCHA API call. We use the result alongside our own rate limits and passwordless verification, not for advertising. Google Privacy Policy · Google Terms of Service
Email Service Provider
We use an email service to send you invoices and login codes. They only process emails on our instruction.
SMS Provider
We use an SMS provider to deliver login codes to your mobile number as a backup login method. They process your mobile number only on our instruction, and only to deliver that message.
Web Hosting
Our website is hosted on secure UK servers. The hosting provider has access to data only for technical maintenance.
Important: We will never sell your data to anyone. We will never use it for advertising. We only share what's necessary to provide the service.
6. Your Rights Under UK GDPR
You have these rights over your personal data:
- Right to access: You can ask us for a copy of all the data we hold about you
- Right to rectification: You can ask us to correct any wrong information
- Right to erasure: You can delete your own data at any time - in the app or from Account Settings on the website, under "Close My Account" - or ask us to do it for you. Either way, financial records are kept for the period described in section 4, as UK law requires
- Right to data portability: You can ask us to send your data to another service
- Right to object: You can object to how we use your data
- Right to restrict processing: You can ask us to limit how we use your data
- Right to withdraw consent: Where we rely on your consent, you can withdraw it at any time. For marketing emails, use the unsubscribe link in any marketing email. For the in-app assistant (see section 5), simply stop using it - every other part of Invoicer, including the app, works fully without it
To exercise these rights: Email us at support@invoicer.gk.tools. We'll respond within one month.
7. How We Protect Your Information
We take security seriously and follow industry best practices:
- Encryption in transit: All data is encrypted using HTTPS/TLS with HSTS enforcement
- Encryption at rest: Sensitive data like bank details is encrypted using AES-256-GCM
- Passwordless authentication: We use secure one-time codes and passkeys instead of passwords, eliminating password-related risks
- Rate limiting: Login attempts are rate-limited to prevent brute force attacks
- Secure hosting: UK-based servers with regular security updates and monitoring
- Access control: Data access is restricted to essential personnel only
- PCI DSS compliance: Payment card data is handled by PCI DSS Level 1 compliant Stripe (we never see your card details)
- Security headers: We implement HSTS, CSP, X-Frame-Options, and other security headers
- Data retention: We automatically delete expired login codes, old login attempts, and other temporary data
8. Cookies and Tracking
Essential Cookies
These cookies are necessary for the website to function and cannot be switched off:
- Session Cookie (USER_SESSID / ADMIN_SESSID): Keeps you logged in. Expires when you close your browser.
- Remember Me (invoicer_remember): Set only if you tick "remember me" on login. Lasts 30 days.
- CSRF Token: Security protection against cross-site attacks. Lasts for your session.
- Google reCAPTCHA (_GRECAPTCHA): Google sets this necessary cookie when reCAPTCHA is executed to provide its risk analysis on login and signup. It is used for abuse protection, not our analytics.
Analytics — Matomo (self-hosted)
We use Matomo, a self-hosted, open-source analytics platform, to understand which parts of Invoicer are useful and where people get stuck. This covers public marketing and shared client-document pages, plus ordinary signed-in app pages. Matomo runs entirely on our own UK-based infrastructure — this analytics data is not shared with third parties or sent abroad.
The data we collect is limited and anonymised:
- A fixed route name for the page visited (for example,
/invoices/view) — never the query string, login code, document token, invoice ID, search term, or other value from the URL - Referring site only (how you arrived here), without the referring page path or query string
- Approximate location (country/region only; the last two octets of your IP address are discarded before storage)
- Browser and device type
- Active time on a page and anonymous scroll milestones
- Whether a form was started, submitted, blocked by browser validation, or left unfinished, and whether an automatic save succeeded or failed, but never field values or other form contents
- Whether list filters returned any matches or a later results page was viewed, but never the search words, selected client or status, dates, sorting, page number, totals, or record contents
- Whether a key section is still empty (for example clients, invoices, quotes, insurance or helpers), or whether a client record was viewed while archived, but never any record or account detail
- Which fixed invoice state page was viewed (draft, scheduled, sent, overdue, paid, cancelled, or an active, paused or stopped recurring setup), whether a shared client page was payable, overdue, paid or cancelled, and whether a client revealed or dismissed the payment-confirmation form, but never the invoice, client, amount, payment date or bank details
- Which fixed quote state page was viewed (draft, sent, viewed, accepted, declined, expired or converted), whether a client showed accept or decline intent, and whether they selected or removed an optional extra, but never which optional item, document, client or amount
- Whether visible success or error feedback appeared, but never the message wording or underlying error detail
- Which generic feature action was attempted (for example open a client, invoice or quote; download, copy, convert, send, or update payment), but never the document, client, form value, record identifier, or recipient involved
- Which main Invoicer section you choose from a navigation link (for example, Clients or Invoices), using only a fixed section label — not the link text, full URL, query string or record identifier
- Which login step was reached, and whether login or signup reCAPTCHA was ready, unavailable, failed, or timed out, but never the email address, login code, reCAPTCHA token, or provider error
- Whether SMS fallback was revealed and whether its request was acknowledged or rejected, but never the email address, mobile number, login code, response text, or provider detail
- Which set of install instructions you choose, whether the browser install prompt was accepted or dismissed, and whether installation completed — never a device name or other device identifier
- Whether passkey setup or removal was started, unavailable, cancelled, not completed or failed, but never the passkey, device name, credential, browser error or account involved
- Whether you started address suggestions on a client-create, client-edit or business-profile form, but never the address text, selected suggestion, client or profile identity
- Whether a profile became ready or was no longer ready to invoice, but never which field changed or any profile or bank value
- Generic journey outcomes such as a client, invoice or quote being created, an invoice or quote being sent, a quote being accepted or converted into an invoice, a quote deposit being marked as paid, or an invoice being marked as paid, including whether it was the account's first client, invoice or quote, the account's first accepted quote, the account's first converted quote, the account's first paid quote deposit, or the account's first recorded paid invoice. For client creation we distinguish only whether a client was added directly, by copying an existing client, or through chat. For payments we distinguish only the fixed route — single, follow-up, bulk, client or chat — never the invoice, quote, client, amount, date or other record detail. We also record a signup completing, whether a subscription was started, changed, cancelled, or reactivated, whether a checkout was cancelled, and which generic subscription state was viewed, such as trial active, trial ending, payment processing, payment failed, active or ending. These subscription signals are never a price, amount, payment method, Stripe identifier or account identifier. We record whether a passkey was registered or removed, whether a client was archived, deleted, or restored, whether an insurance document was uploaded or removed, including whether an upload was the account's first, whether a document was downloaded, whether expiry reminder emails were turned on or off, whether helper access was invited, connected, or removed, whether unused helper invites were cancelled, whether an invite code or link was copied, whether a client was updated through the page or chat, whether a business profile was updated through the page or chat, whether an invoice or quote was updated through the page or chat, whether a recurring invoice was created, including whether it was the account's first recurring setup, and whether a recurring invoice was paused, resumed, or stopped — never the invite, person, account, invoice, client, schedule, amount, or other record detail. Helper measurement records only these fixed outcomes, never the invite code, link, person or account. Insurance measurement never includes the policy, provider, filename, expiry date or document contents. Business profile maintenance never includes the profile field or value.
- Whether dashboard guidance was shown or dismissed, and whether the AI welcome message was cached, newly generated, replaced by a local fallback, or unavailable — never the message, business figures, provider error, account identifier, or prompt contents
We do not send Matomo a user ID, account ID, email address, client identity, invoice or quote number, or anything you type. Admin pages and any session where an administrator, helper or impersonation is acting inside somebody else's account are excluded completely, so support activity cannot be mistaken for customer behaviour.
Matomo does not use analytics cookies and we do not attach an account-level identifier. We respect your browser's "Do Not Track" preference — if it is enabled, you will not be tracked. You can also opt out below.
Analytics — Google Analytics (consent-based)
We also use Google Analytics on our public marketing pages, to understand visitor numbers alongside Matomo. Unlike Matomo, Google Analytics uses cookies and only runs if you agree — you'll see a short banner asking for your permission the first time you visit. It only loads after you say yes, and never on your signed-in dashboard.
If you agree, Google Analytics collects:
- Pages visited and how you arrived here
- Approximate location (your IP address is anonymised before Google stores it)
- Browser, device type, and screen resolution
You can say no when the banner first appears, or change your mind any time using the "Cookie Settings" button at the bottom of any public page. Saying no clears any Google Analytics cookies already on your device.
Opting out
Matomo analytics is not running for this page. There is nothing to opt out of here. For Google Analytics, use the "Cookie Settings" button described above instead.
Managing Cookies
You can also:
- Clear cookies in your browser settings
- Use your browser's "Do Not Track" setting — we honour it automatically
9. Children's Privacy
Our service is for business users only. We don't knowingly collect information from anyone under 18. If you believe we've collected data from a child, please contact us immediately.
10. International Data Transfers
Your data is stored on UK servers. Some third-party services we use (Stripe for payments, Google for AI insights, address suggestions, security checks and analytics) may process data outside the UK. Where they do, transfers are protected by safeguards recognised under UK GDPR, such as the UK Extension to the EU–US Data Privacy Framework or the ICO's International Data Transfer Agreement / Addendum.
11. Changes to This Policy
We may update this privacy policy occasionally. If we make significant changes, we'll email you and update the "Last Updated" date at the top. Continued use of the service after changes means you accept the new policy.
12. How to Contact Us
If you have any questions about this privacy policy or how we handle your data:
Email: support@invoicer.gk.tools
We aim to respond promptly to all enquiries.
13. How to Complain
If you're unhappy with how we've handled your data, you have the right to complain to the UK's data protection authority:
Information Commissioner's Office (ICO)
Website: ico.org.uk/make-a-complaint
Phone: 0303 123 1113
Bottom Line: Your data is yours. We're just looking after it while you use our service. We keep it safe, use it fairly, and will delete it if you ask (after meeting our legal obligations).