Effective 2026-09-27
Version 2026-09-27
Privacy Policy
EasyInvoiceFlow
Last updated: 27 September 2026
Effective: 27 September 2026
1. Who we are and what this policy covers
EasyInvoiceFlow is operated by LIST HOUZE PTY LTD (ACN 702 090 168, ABN 52 702 090 168), an Australian company. In this policy, "we", "us" and "our" mean LIST HOUZE PTY LTD.
This policy explains how we handle personal information through easyinvoiceflow.com, the EasyInvoiceFlow web app, any mobile app we publish, and our related support and communications. The service is available internationally. Privacy rights and obligations depend on the laws that apply to the particular processing, including the Australian Privacy Act 1988 (Cth) and Australian Privacy Principles where applicable. Section 13 explains additional rights where the EU GDPR or UK GDPR applies.
Our privacy contact is privacy@easyinvoiceflow.com. Full contact details are in section 16.
2. Account information and customer information
Information about our users. We determine how personal information is used to manage accounts, subscriptions, support, security and our business operations. This includes information about individual subscribers and people acting for a business. Where data protection law uses that term, we are the controller for those activities.
Information our users put into the service. Businesses enter information about customers, customer contacts and other people when creating quotes, invoices and related records. The business determines why that information is collected and how it should be used. We process it on the business's instructions to provide the service. Where applicable law treats the business as controller and us as processor, section 5.1 of the Terms of Service sets out our data processing obligations.
Businesses using the service must give appropriate privacy information to the people whose information they enter, have any required authority or lawful basis, and use the service lawfully. If you receive an invoice or quote from one of our users, contact that business about its use of your information. If you contact us, we will help identify or refer your request to the relevant business where appropriate, while meeting any obligations that apply directly to us.
3. Personal information we collect
Information you or your business provide
- Account and contact details: name, email address, sign-in information and account preferences. Where a password is used, our authentication service stores a protected password hash rather than a readable password.
- Business details: business name, business registration or tax identifiers, address, phone number, logo, bank details intended to appear on documents, and brand settings.
- Business records: customer details, quotes, invoices, reusable items and categories where available, payment records, notes, attachments and uploaded files.
- Subscription and payment information: plan, billing contact details, subscription status and payment transaction records. Card payments are handled by Stripe. We do not store full card numbers or card security codes, but may receive limited payment information such as the card brand, last four digits and payment status.
- Communications: support requests, feedback, privacy requests and other messages you send us.
If you choose a third-party sign-in option, we receive the account information that provider makes available through the permissions shown to you, such as your name, email address and account identifier. This does not give us access to your password for that provider.
Information collected through use of the service
- Sign-in and session records, IP addresses and approximate location derived from an IP address.
- Device, browser, operating system and app information.
- Service activity, error and diagnostic records used to operate, support and protect the service.
- Email delivery information, such as delivery, bounce and failure events.
- Quote acceptance or decline records, including the time and information the recipient submits.
- Analytics information where analytics is enabled in accordance with section 9.
Some information comes from the business that creates your account or sends you a document, or from authentication and payment providers. You do not have to provide optional information. If information is necessary to create an account, process a payment or deliver a requested feature, we may be unable to provide that function without it.
Sensitive information. The service is not designed for health records or other sensitive personal information. We do not ask you to provide information about health, racial or ethnic origin, political or religious beliefs, sexual orientation, or criminal history. Do not include it in customer notes, documents or attachments. If such information is submitted, it may be processed as part of that content; contact us if it needs to be removed.
4. How we use personal information
We use personal information as needed to:
- create and manage accounts and business workspaces;
- provide quotes, invoices, documents, customer records and payment-recording features;
- deliver messages and documents you ask us to send;
- process subscriptions and payments;
- provide support and communicate about accounts, security, billing and changes to the service;
- protect accounts and the service, prevent fraud and spam, investigate problems and enforce our terms;
- understand service performance and improve features, subject to the choices described in section 9;
- send product marketing where you have opted in;
- meet applicable legal obligations, maintain required business records and handle disputes.
We process customer information entered by a business to provide the requested service and meet our legal obligations. We do not use those customer records to send our own marketing to that business's customers.
We do not sell personal information. Section 13 explains our legal bases for processing where the EU GDPR or UK GDPR applies.
5. Shared quote and document links
The service lets a business share a quote with a recipient through a link. A person who has that link may be able to view the quote and accept or decline it without creating an account. Treat the link as confidential and share it only with the intended recipients. A recipient can forward it to someone else.
The shared document may include the business and customer information placed on it, including contact details, descriptions, prices and payment instructions. Check the document before sharing it. When a recipient responds, we record the response, its time and any information submitted through the response form.
Deleting information from your account does not delete copies already downloaded, emailed or retained by another person.
6. Who receives personal information
We use providers to operate the service. We give them information relevant to their functions and require appropriate privacy and security protections. Some providers also process information for their own legal, security or account-management purposes, as explained in their own privacy notices.
| Provider or feature | Purpose and information involved | Location information |
|---|---|---|
| Supabase | Database, authentication and file storage for accounts and business content | Primary application database and storage in Sydney, Australia; provider support and related operations may involve other countries |
| Vercel | Web hosting, content delivery and associated request and diagnostic information | Global infrastructure, including the United States; processing depends on deployment and delivery locations |
| Resend | Delivery of service and document emails, including recipient addresses, message content and delivery records | United States and supporting provider operations |
| Stripe | Subscription payments, billing and payment-related fraud prevention | International operations, including the United States; relevant Stripe entities and processing locations depend on the service and account |
| Google sign-in, if you choose it | Authentication and the account information authorised through the sign-in flow | Google's international infrastructure, including the United States |
| Google reCAPTCHA, where enabled | Protection against automated abuse using device, browser, interaction and related technical signals | Google's international infrastructure, including the United States |
| Google Analytics, where enabled with consent | Website or product usage measurement | Google's international infrastructure, including the United States |
Further information is available in the providers' notices: Supabase, Vercel, Resend, Stripe and Google. Provider location lists and subprocessors can change. Contact us for information about the arrangements relevant to your account.
We may also disclose information:
- to authorised members or administrators of your business workspace;
- to recipients when you or your business share a document or instruct us to send a message;
- to professional advisers, insurers and auditors where needed and subject to appropriate confidentiality;
- in connection with a proposed or completed business sale or restructure, subject to appropriate safeguards and any legally required notice;
- where disclosure is required or permitted by law, necessary to establish or defend legal claims, or reasonably necessary to address fraud, security threats or a serious threat to someone's safety.
Changes to providers processing customer information on a business's behalf are governed by section 5.1 of the Terms of Service. Other material changes to this policy are addressed in section 15.
7. International processing and transfers
EasyInvoiceFlow is operated from Australia. Our primary application database and file storage are in Sydney, Australia. This does not mean all processing stays in Australia: hosting, email delivery, payments, authentication, support and other provider operations can involve the countries described in section 6.
Privacy laws in another country may differ from those where you live. Where Australian privacy law applies, we take the steps required by that law in relation to overseas disclosures, including reasonable steps to protect information where required. Using the service does not waive your privacy rights or remove our obligations for overseas disclosures.
Where the EU GDPR, UK GDPR or another applicable law requires safeguards for a particular international transfer, the required transfer arrangements must be in place before that transfer occurs. Depending on the circumstances, these may include an applicable adequacy decision, properly completed contractual safeguards and any required assessment or supplementary measures. A general reference to these mechanisms in this policy does not itself put them in place.
You can contact privacy@easyinvoiceflow.com for information about the locations and transfer safeguards applicable to your information, including a copy or description of relevant safeguards where the law provides that right. Businesses requiring specific processing locations or transfer arrangements should contact us before uploading the affected information.
8. Security and data breaches
We take reasonable technical and organisational measures designed to protect personal information against unauthorised access, loss, misuse and disclosure. These include encrypted connections, authentication, access controls and restrictions on access to production systems. Access to business records is intended to be limited to authorised users and the people with whom those records are shared.
Logos and brand images used on shared documents may be publicly accessible. Do not upload confidential information to a field intended for a public logo or brand image. Protect your account credentials and shared document links, and tell us promptly if you suspect unauthorised access.
No internet service can guarantee absolute security. We will assess suspected breaches and notify affected people, business customers and regulators when applicable law requires. Where the Australian Notifiable Data Breaches scheme applies, we will meet its assessment and notification requirements. Section 13 addresses EU and UK notifications. Our obligations when processing customer information for a business are also set out in section 5.1 of the Terms of Service.
9. Cookies, browser storage and analytics
We use cookies or similar browser storage for functions such as sign-in, security, remembering settings, retaining an unsaved draft on your device and recording privacy choices. Some of these technologies are necessary for a feature you request to work.
Where we use optional analytics or marketing technologies, we ask for consent before enabling them. Google Analytics may be used for usage measurement after you agree. Declining optional analytics does not prevent you from using the core service.
You can change your choice using the privacy or cookie controls presented in the service. If you cannot find or use those controls, contact privacy@easyinvoiceflow.com for assistance. You can also manage browser storage through your browser. Blocking essential storage can affect sign-in and other features. Clearing storage or changing devices may require you to choose again.
Where reCAPTCHA is enabled, it processes technical and interaction signals to help detect abuse. We use security technologies for security purposes and obtain consent where legally required for the particular implementation.
10. Marketing and service messages
We send EasyInvoiceFlow marketing emails only where you have opted in. You can unsubscribe through the link in a marketing message or contact us. We will honour your request within the time required by applicable law.
Necessary messages about account access, requested documents, billing, security and important service changes are separate from marketing. You may continue to receive those messages while they are relevant to your account or transactions.
11. Retention and deletion
We retain information only for as long as needed for the purposes described in this policy, taking account of the type of information, the service relationship, security needs and applicable legal requirements.
- Active accounts and business content: retained while the account is open and the information is needed to provide the service. Cancelling a paid plan does not by itself delete the account or its records.
- Account closure or deletion: request deletion through available account controls or by contacting us. We aim to complete removal from active systems within 30 days after verifying an authorised request and resolving any necessary account or shared-workspace checks. We will explain any lawful reason for retaining particular records and meet any applicable statutory deadline.
- Required records: we may retain limited billing, transaction, consent, complaint or dispute records for the period required by applicable law or reasonably needed to establish, exercise or defend legal claims. This does not justify retaining all customer content indefinitely.
- Backups: deleted information may remain until the relevant backup is overwritten or expires. It is restricted from ordinary use. If a backup is restored, relevant deletion instructions must be reapplied. Contact us for the retention arrangements applicable to your account.
- Logs and analytics: kept for the period reasonably needed to diagnose issues, protect the service and perform the permitted analysis, then deleted or de-identified where appropriate.
Deleting an individual user's account may not remove business records that an organisation is entitled or required to retain. We will distinguish those records from personal account information when handling a request. You should export business records you need before closing an account and keep the records your own business is legally required to retain.
12. Requests and complaints
You can contact privacy@easyinvoiceflow.com to request access to or correction of personal information, account closure, deletion, or information about our handling of your data. Other rights depend on the law that applies, as explained in section 13. Available app controls can also be used to manage account information and download documents.
We may need to verify your identity and authority to act for a business. We aim to respond within 30 days and will meet the applicable legal time limit. If we cannot grant all or part of a request, we will explain the reason where permitted and any available complaint options. We do not charge to make a request or correct personal information. Any charge for providing access must be permitted by law, reasonable, and explained before it is incurred.
Making a privacy complaint. Email us with the issue, relevant dates and the outcome you seek. We will acknowledge the complaint, investigate it and aim to provide a written response within 30 days. If more time is needed, we will explain why and provide an expected response date.
If you are not satisfied, or we have not responded within a reasonable time, you may contact the Office of the Australian Information Commissioner on 1300 363 992, or a privacy regulator with jurisdiction over your complaint. This process does not restrict any right to complain directly to a regulator or seek another legal remedy.
13. Additional information where EU or UK data protection law applies
This section applies to the extent the EU General Data Protection Regulation or UK GDPR governs our processing of your personal information. International availability does not mean every processing activity is governed by every country's laws.
Our role and legal bases
Our controller and processor roles are explained in section 2. For processing where we act as controller, our legal bases depend on the activity and relationship:
| Activity | Legal basis where applicable |
|---|---|
| Providing an account, subscription, requested support and related communications to an individual contracting with us | Taking requested steps before a contract or performing that contract |
| Managing business accounts and communicating with their employees or representatives | Our legitimate interests in providing and administering services for the business |
| Security, abuse prevention, service reliability, dispute handling and enforcing lawful terms | Our legitimate interests in protecting the service, users and legal rights, subject to the individual's interests and rights |
| Optional analytics and marketing communications | Consent |
| Compliance with a legal duty recognised as a legal obligation under the applicable GDPR | Legal obligation |
| Other necessary administration and compliance with obligations not falling within that GDPR legal-obligation basis | Legitimate interests where that basis is available and the individual's interests and rights do not override it |
For customer information we process on a business's behalf, that business is responsible for identifying its applicable legal basis. Our contract with the business is not automatically a contractual legal basis for processing information about every person named on an invoice.
Your rights
Subject to the conditions and exceptions in the applicable law, you may request access, correction, erasure, restriction of processing and data portability. Portability applies to qualifying information processed by automated means on the basis of consent or a contract; a document download is not necessarily the full response to a portability request.
You may object to processing based on legitimate interests for reasons relating to your situation. You may object to direct marketing at any time. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal. Where relevant, you also have protections concerning decisions based solely on automated processing that produce legal or similarly significant effects. Contact us to request review if you believe such a decision has affected you.
We normally respond within one month of receiving a rights request. Where the applicable law permits an extension for complexity or the number of requests, we may extend by up to two further months and will explain the extension within the initial period. Requests are normally free; a fee or refusal will be used only where permitted by the applicable law, with an explanation.
You can complain to the competent supervisory authority. In the EEA, this may be the authority where you habitually live, work or believe an infringement occurred. In the UK, you can contact the Information Commissioner's Office.
Transfers, retention and breaches
Sections 7 and 11 explain international processing and retention. You can ask us about the arrangements relevant to your information.
Where we are the controller and notification is required, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach. If notification is later, we will explain the delay. We will notify affected individuals without undue delay where the applicable high-risk notification requirement is met, subject to lawful exceptions. When acting as processor, we will notify the relevant business without undue delay so it can assess its own obligations.
14. Children
Accounts are intended for adults using the service for business purposes. A person must be at least 18 to create an account. We do not knowingly invite children to register.
Business documents can nevertheless contain information relating to a child. The business entering that information is responsible for having a lawful reason and limiting it to what is necessary. If you believe a child has registered or that information about a child has been submitted improperly, contact us so we can assess and address it.
15. Changes to this policy
We may update this policy to reflect changes to the service, our practices or applicable law. The date at the top identifies the current version. We will give appropriate notice of material changes, including by email or in the app where appropriate, before they take effect unless the law or an urgent security need requires otherwise.
If a change requires your consent, we will ask for it. Continuing to use the service does not replace consent where consent is legally required.
16. Contact
LIST HOUZE PTY LTD
ACN 702 090 168 | ABN 52 702 090 168
Privacy: privacy@easyinvoiceflow.com
Legal: legal@easyinvoiceflow.com
Support: support@easyinvoiceflow.com