Effective 2026-09-27

Version 2026-09-27

Privacy Policy

EasyInvoiceFlow

Last updated: 27 September 2026

Effective: 27 September 2026

1. Who we are and what this policy covers

EasyInvoiceFlow is operated by LIST HOUZE PTY LTD (ACN 702 090 168, ABN 52 702 090 168), an Australian company. In this policy, "we", "us" and "our" mean LIST HOUZE PTY LTD.

This policy explains how we handle personal information through easyinvoiceflow.com, the EasyInvoiceFlow web app, any mobile app we publish, and our related support and communications. The service is available internationally. Privacy rights and obligations depend on the laws that apply to the particular processing, including the Australian Privacy Act 1988 (Cth) and Australian Privacy Principles where applicable. Section 13 explains additional rights where the EU GDPR or UK GDPR applies.

Our privacy contact is privacy@easyinvoiceflow.com. Full contact details are in section 16.

2. Account information and customer information

Information about our users. We determine how personal information is used to manage accounts, subscriptions, support, security and our business operations. This includes information about individual subscribers and people acting for a business. Where data protection law uses that term, we are the controller for those activities.

Information our users put into the service. Businesses enter information about customers, customer contacts and other people when creating quotes, invoices and related records. The business determines why that information is collected and how it should be used. We process it on the business's instructions to provide the service. Where applicable law treats the business as controller and us as processor, section 5.1 of the Terms of Service sets out our data processing obligations.

Businesses using the service must give appropriate privacy information to the people whose information they enter, have any required authority or lawful basis, and use the service lawfully. If you receive an invoice or quote from one of our users, contact that business about its use of your information. If you contact us, we will help identify or refer your request to the relevant business where appropriate, while meeting any obligations that apply directly to us.

3. Personal information we collect

Information you or your business provide

If you choose a third-party sign-in option, we receive the account information that provider makes available through the permissions shown to you, such as your name, email address and account identifier. This does not give us access to your password for that provider.

Information collected through use of the service

Some information comes from the business that creates your account or sends you a document, or from authentication and payment providers. You do not have to provide optional information. If information is necessary to create an account, process a payment or deliver a requested feature, we may be unable to provide that function without it.

Sensitive information. The service is not designed for health records or other sensitive personal information. We do not ask you to provide information about health, racial or ethnic origin, political or religious beliefs, sexual orientation, or criminal history. Do not include it in customer notes, documents or attachments. If such information is submitted, it may be processed as part of that content; contact us if it needs to be removed.

4. How we use personal information

We use personal information as needed to:

We process customer information entered by a business to provide the requested service and meet our legal obligations. We do not use those customer records to send our own marketing to that business's customers.

We do not sell personal information. Section 13 explains our legal bases for processing where the EU GDPR or UK GDPR applies.

The service lets a business share a quote with a recipient through a link. A person who has that link may be able to view the quote and accept or decline it without creating an account. Treat the link as confidential and share it only with the intended recipients. A recipient can forward it to someone else.

The shared document may include the business and customer information placed on it, including contact details, descriptions, prices and payment instructions. Check the document before sharing it. When a recipient responds, we record the response, its time and any information submitted through the response form.

Deleting information from your account does not delete copies already downloaded, emailed or retained by another person.

6. Who receives personal information

We use providers to operate the service. We give them information relevant to their functions and require appropriate privacy and security protections. Some providers also process information for their own legal, security or account-management purposes, as explained in their own privacy notices.

Further information is available in the providers' notices: Supabase, Vercel, Resend, Stripe and Google. Provider location lists and subprocessors can change. Contact us for information about the arrangements relevant to your account.

We may also disclose information:

Changes to providers processing customer information on a business's behalf are governed by section 5.1 of the Terms of Service. Other material changes to this policy are addressed in section 15.

7. International processing and transfers

EasyInvoiceFlow is operated from Australia. Our primary application database and file storage are in Sydney, Australia. This does not mean all processing stays in Australia: hosting, email delivery, payments, authentication, support and other provider operations can involve the countries described in section 6.

Privacy laws in another country may differ from those where you live. Where Australian privacy law applies, we take the steps required by that law in relation to overseas disclosures, including reasonable steps to protect information where required. Using the service does not waive your privacy rights or remove our obligations for overseas disclosures.

Where the EU GDPR, UK GDPR or another applicable law requires safeguards for a particular international transfer, the required transfer arrangements must be in place before that transfer occurs. Depending on the circumstances, these may include an applicable adequacy decision, properly completed contractual safeguards and any required assessment or supplementary measures. A general reference to these mechanisms in this policy does not itself put them in place.

You can contact privacy@easyinvoiceflow.com for information about the locations and transfer safeguards applicable to your information, including a copy or description of relevant safeguards where the law provides that right. Businesses requiring specific processing locations or transfer arrangements should contact us before uploading the affected information.

8. Security and data breaches

We take reasonable technical and organisational measures designed to protect personal information against unauthorised access, loss, misuse and disclosure. These include encrypted connections, authentication, access controls and restrictions on access to production systems. Access to business records is intended to be limited to authorised users and the people with whom those records are shared.

Logos and brand images used on shared documents may be publicly accessible. Do not upload confidential information to a field intended for a public logo or brand image. Protect your account credentials and shared document links, and tell us promptly if you suspect unauthorised access.

No internet service can guarantee absolute security. We will assess suspected breaches and notify affected people, business customers and regulators when applicable law requires. Where the Australian Notifiable Data Breaches scheme applies, we will meet its assessment and notification requirements. Section 13 addresses EU and UK notifications. Our obligations when processing customer information for a business are also set out in section 5.1 of the Terms of Service.

9. Cookies, browser storage and analytics

We use cookies or similar browser storage for functions such as sign-in, security, remembering settings, retaining an unsaved draft on your device and recording privacy choices. Some of these technologies are necessary for a feature you request to work.

Where we use optional analytics or marketing technologies, we ask for consent before enabling them. Google Analytics may be used for usage measurement after you agree. Declining optional analytics does not prevent you from using the core service.

You can change your choice using the privacy or cookie controls presented in the service. If you cannot find or use those controls, contact privacy@easyinvoiceflow.com for assistance. You can also manage browser storage through your browser. Blocking essential storage can affect sign-in and other features. Clearing storage or changing devices may require you to choose again.

Where reCAPTCHA is enabled, it processes technical and interaction signals to help detect abuse. We use security technologies for security purposes and obtain consent where legally required for the particular implementation.

10. Marketing and service messages

We send EasyInvoiceFlow marketing emails only where you have opted in. You can unsubscribe through the link in a marketing message or contact us. We will honour your request within the time required by applicable law.

Necessary messages about account access, requested documents, billing, security and important service changes are separate from marketing. You may continue to receive those messages while they are relevant to your account or transactions.

11. Retention and deletion

We retain information only for as long as needed for the purposes described in this policy, taking account of the type of information, the service relationship, security needs and applicable legal requirements.

Deleting an individual user's account may not remove business records that an organisation is entitled or required to retain. We will distinguish those records from personal account information when handling a request. You should export business records you need before closing an account and keep the records your own business is legally required to retain.

12. Requests and complaints

You can contact privacy@easyinvoiceflow.com to request access to or correction of personal information, account closure, deletion, or information about our handling of your data. Other rights depend on the law that applies, as explained in section 13. Available app controls can also be used to manage account information and download documents.

We may need to verify your identity and authority to act for a business. We aim to respond within 30 days and will meet the applicable legal time limit. If we cannot grant all or part of a request, we will explain the reason where permitted and any available complaint options. We do not charge to make a request or correct personal information. Any charge for providing access must be permitted by law, reasonable, and explained before it is incurred.

Making a privacy complaint. Email us with the issue, relevant dates and the outcome you seek. We will acknowledge the complaint, investigate it and aim to provide a written response within 30 days. If more time is needed, we will explain why and provide an expected response date.

If you are not satisfied, or we have not responded within a reasonable time, you may contact the Office of the Australian Information Commissioner on 1300 363 992, or a privacy regulator with jurisdiction over your complaint. This process does not restrict any right to complain directly to a regulator or seek another legal remedy.

13. Additional information where EU or UK data protection law applies

This section applies to the extent the EU General Data Protection Regulation or UK GDPR governs our processing of your personal information. International availability does not mean every processing activity is governed by every country's laws.

Our role and legal bases

Our controller and processor roles are explained in section 2. For processing where we act as controller, our legal bases depend on the activity and relationship:

For customer information we process on a business's behalf, that business is responsible for identifying its applicable legal basis. Our contract with the business is not automatically a contractual legal basis for processing information about every person named on an invoice.

Your rights

Subject to the conditions and exceptions in the applicable law, you may request access, correction, erasure, restriction of processing and data portability. Portability applies to qualifying information processed by automated means on the basis of consent or a contract; a document download is not necessarily the full response to a portability request.

You may object to processing based on legitimate interests for reasons relating to your situation. You may object to direct marketing at any time. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal. Where relevant, you also have protections concerning decisions based solely on automated processing that produce legal or similarly significant effects. Contact us to request review if you believe such a decision has affected you.

We normally respond within one month of receiving a rights request. Where the applicable law permits an extension for complexity or the number of requests, we may extend by up to two further months and will explain the extension within the initial period. Requests are normally free; a fee or refusal will be used only where permitted by the applicable law, with an explanation.

You can complain to the competent supervisory authority. In the EEA, this may be the authority where you habitually live, work or believe an infringement occurred. In the UK, you can contact the Information Commissioner's Office.

Transfers, retention and breaches

Sections 7 and 11 explain international processing and retention. You can ask us about the arrangements relevant to your information.

Where we are the controller and notification is required, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach. If notification is later, we will explain the delay. We will notify affected individuals without undue delay where the applicable high-risk notification requirement is met, subject to lawful exceptions. When acting as processor, we will notify the relevant business without undue delay so it can assess its own obligations.

14. Children

Accounts are intended for adults using the service for business purposes. A person must be at least 18 to create an account. We do not knowingly invite children to register.

Business documents can nevertheless contain information relating to a child. The business entering that information is responsible for having a lawful reason and limiting it to what is necessary. If you believe a child has registered or that information about a child has been submitted improperly, contact us so we can assess and address it.

15. Changes to this policy

We may update this policy to reflect changes to the service, our practices or applicable law. The date at the top identifies the current version. We will give appropriate notice of material changes, including by email or in the app where appropriate, before they take effect unless the law or an urgent security need requires otherwise.

If a change requires your consent, we will ask for it. Continuing to use the service does not replace consent where consent is legally required.

16. Contact

LIST HOUZE PTY LTD

ACN 702 090 168 | ABN 52 702 090 168

Privacy: privacy@easyinvoiceflow.com

Legal: legal@easyinvoiceflow.com

Support: support@easyinvoiceflow.com