Privacy Policy

Last updated: 28 June 2026

This Privacy Policy explains how Electric Trade Solutions Ltd ("we", "us", or "our"), a company registered in England and Wales (company number 17055534), collects, uses, stores, and protects your personal data when you use the InvoiceFlow® application ("the App" or "the Service"). We are committed to protecting your privacy and complying fully with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and all applicable UK data protection legislation.

Please read this policy carefully before using the App. By using InvoiceFlow, you acknowledge that you have read and understood this Privacy Policy.

1. Who We Are (Data Controller)

Electric Trade Solutions Ltd is the Data Controller for personal data collected through InvoiceFlow.

  • Company: Electric Trade Solutions Ltd
  • Registered in: England and Wales
  • Company Number: 17055534
  • Trademark: InvoiceFlow® is a registered UK trademark (UK00004347223)
  • ICO Registration: Registered with the Information Commissioner's Office (ICO) — Registration Reference: ZC099605 (registered 27 February 2026, expires 26 February 2027)
  • Data Protection Contact: electrictradesolutions@invoiceflow.uk
  • Website: www.invoiceflow2026.uk

2. Data We Collect and Why

We collect the minimum data necessary to provide the Service. Here is what we collect and why:

2.1 Account and Identity Data

  • What: Full name, email address, authentication credentials
  • Why: To create and manage your account, authenticate you, and communicate with you about the Service
  • Legal basis: Contract performance (Article 6(1)(b) UK GDPR)

2.2 Business Profile Data

  • What: Business name, address, phone number, VAT/tax ID, bank account details (sort code and account number), and business logo
  • Why: To populate your invoices, quotes, and financial documents with your business information
  • Legal basis: Contract performance

2.3 Client Data

  • What: Your clients' names, email addresses, postal addresses, and phone numbers
  • Why: To enable you to create invoices and quotes addressed to your clients, and to send documents on your behalf
  • Legal basis: Contract performance and legitimate interests

Important: You, as the InvoiceFlow user, are responsible for ensuring you have a lawful basis to store your clients' data within the App.

2.4 Financial and Transaction Data

  • What: Invoice amounts, expense records, payment dates, tax figures, and bank transaction data (imported via CSV, Excel, OFX, or PDF statement uploads)
  • Why: To provide invoicing, expense tracking, accounting, bank reconciliation, and tax reporting features
  • Legal basis: Contract performance and legal obligation

2.5 Subscription and Billing Data

  • What: Subscription tier, billing status, and subscription period dates
  • Why: To manage your paid subscription and access to the App
  • Note: All payment card processing is handled directly by Stripe. We never see or store your card details
  • Legal basis: Contract performance

2.6 Technical and Usage Data

  • What: IP address, browser type, device type, pages visited, features used, and error logs
  • Why: To operate the App securely, fix bugs, and improve user experience
  • Legal basis: Legitimate interests

2.7 Email Tracking Data

  • What: Email delivery status (sent, delivered, opened, bounced) for invoices and quotes you send via the App
  • Why: To show you whether your clients have received and opened documents you sent
  • Legal basis: Legitimate interests

2.8 AI Processing Data

  • What: Receipt images, expense descriptions, invoice/quote text, and bank transaction descriptions you submit for AI-assisted processing (e.g. receipt scanning, expense categorisation, bank reconciliation matching, and payment term suggestions)
  • Why: To automatically extract data from receipts, suggest expense categories, match bank transactions, and generate draft invoice terms — reducing manual data entry
  • How: Data is sent to our AI processing providers (OpenAI and Google) solely for the purpose of generating the requested output. Providers do not use your data to train their models
  • Legal basis: Contract performance and legitimate interests

2.9 Push Notification and Device Data

  • What: Push notification subscription tokens and device identifiers (for receiving app notifications such as invoice payment alerts and overdue reminders)
  • Why: To send you timely notifications about your invoices, quotes, and account activity
  • Legal basis: Consent (you can disable notifications at any time in your device settings)

2.10 Camera and File Upload Data

  • What: Images captured via your device camera or uploaded files (receipts, supplier bills, bank statements, business logo)
  • Why: To process receipts and bills using AI extraction, import bank transactions, and display your logo on invoices
  • Legal basis: Contract performance and consent
  • Note: Camera access is only activated when you explicitly choose to snap a receipt or bill. No background camera access occurs

3. How We Use Your Data

We use your data only for the purposes described above, and specifically to:

  • Provide, operate, and maintain the InvoiceFlow Service
  • Process your subscription payments via Stripe
  • Send transactional emails (invoices, quotes, reminders) on your behalf via Resend
  • Generate financial reports and tax summaries
  • Enable bank reconciliation features (if used)
  • Provide the Client Portal feature, allowing your clients to view and pay invoices
  • Process receipt images and financial data using AI to extract information and suggest categories
  • Enable the Accountant Access feature, where you can invite an accountant to view your financial data (see Section 5A)
  • Send you push notifications about invoice payments, overdue reminders, and account activity
  • Improve the App, fix technical issues, and develop new features
  • Comply with legal, regulatory, and tax obligations
  • Respond to support and data subject requests
  • Prevent fraud and maintain the security of the Service

We do not use your data for advertising, profiling, or sell it to any third party.

4. Legal Basis for Processing

Under UK GDPR, we rely on the following legal bases:

  • Contract (Article 6(1)(b)): Processing necessary to provide the Service you subscribed to
  • Legal obligation (Article 6(1)(c)): Compliance with UK tax law, HMRC requirements, and financial regulations
  • Legitimate interests (Article 6(1)(f)): Operating and improving the Service, security monitoring, email delivery tracking, and fraud prevention — balanced against your rights and interests
  • Consent (Article 6(1)(a)): Where you have explicitly opted in (e.g. optional marketing communications, if applicable)

5. Client Portal and Token Security

When you enable the Client Portal feature, your clients receive a secure link to view their invoices. These links use cryptographic tokens generated from a combination of the client's email address and a server-side secret key. This means:

  • Only the intended client (with their specific email address) can access their portal
  • Tokens cannot be guessed or replicated without the server secret
  • Each client only sees their own invoices — no cross-client data access is possible

5A. Accountant Access Feature

InvoiceFlow includes an optional Accountant Access feature that allows you to invite your accountant or bookkeeper to view your financial data within the App. When you use this feature:

  • You control access: You invite the accountant by email and choose their access level (read-only or full access)
  • What they see: Your invoices, expenses, bank transactions, VAT returns, and financial reports — depending on the access level you grant
  • Activity logging: All actions performed by your accountant are logged (viewed data, reconciled transactions, filed VAT returns, etc.) and visible to you in the App
  • Revocation: You can revoke accountant access at any time, immediately removing their ability to view your data
  • Your responsibility: You are responsible for ensuring you have the lawful basis to share your clients' data with your accountant

Your accountant is a separate Data Controller or Processor for the data they access — their access is governed by their own professional obligations and data protection arrangements.

6. Sharing Your Data with Third Parties

We only share data with trusted third-party providers who are essential to delivering the Service. All processors are bound by data processing agreements:

  • Base44 — Cloud application platform and database hosting (data stored in EU/UK region)
  • Stripe — Subscription and payment processing. Their Privacy Policy governs payment data
  • Resend — Transactional email delivery service for sending invoices and quotes
  • OpenAI — AI processing for receipt data extraction, expense categorisation, and bank transaction matching (data used solely for processing your request, not for model training)
  • Google (Gemini) — AI processing for receipt scanning and web-context-enhanced features (data used solely for processing your request, not for model training)

We do not sell, rent, or trade your personal data with any third party for commercial purposes.

We may disclose data if required to do so by law, court order, or regulatory authority (e.g. HMRC, ICO, or law enforcement).

7. Data Retention

We retain your data for as long as your account is active and for a reasonable period thereafter to comply with legal obligations:

  • Active account data: Retained for the duration of your subscription
  • Post-cancellation: Account and business data deleted within 90 days of account closure, subject to legal obligations
  • Financial records: Invoice and financial data may be retained for up to 7 years as required by UK tax law (HMRC requirements)
  • Security logs: Technical access logs retained for up to 12 months
  • Backup data: Any data backups you create are stored encrypted and are deleted on account closure

You may request early deletion of your data at any time (subject to legal retention obligations) by emailing electrictradesolutions@invoiceflow.uk.

8. Your Rights Under UK GDPR

You have the following rights regarding your personal data. To exercise any right, email electrictradesolutions@invoiceflow.uk. We will respond within 30 calendar days:

  • Right of Access (Article 15): Request a copy of all personal data we hold about you (Subject Access Request / SAR)
  • Right to Rectification (Article 16): Request correction of inaccurate or incomplete data
  • Right to Erasure (Article 17): Request deletion of your data ("right to be forgotten"), where no legal basis exists to retain it
  • Right to Restriction (Article 18): Request we limit processing of your data in certain circumstances
  • Right to Data Portability (Article 20): Receive your data in a structured, machine-readable format (e.g. JSON or CSV export)
  • Right to Object (Article 21): Object to processing based on legitimate interests
  • Rights related to automated decision-making (Article 22): We do not use automated decision-making or profiling that produces legal or similarly significant effects

If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

9. Data Security

We implement appropriate technical and organisational security measures to protect your data, including:

  • All data transmitted over HTTPS/TLS encryption
  • Cryptographically secured client portal access tokens (HMAC-SHA256)
  • Role-based access controls — users can only access their own data
  • Regular security reviews of backend functions and data access patterns
  • No storage of payment card details (delegated entirely to Stripe)
  • AI processing limited to purpose-specific requests — no bulk data sharing or model training
  • Production data access restricted to authorised personnel only

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and affected individuals without undue delay, as required by Article 33 UK GDPR.

10. Cookies and Local Storage

The App uses:

  • Essential cookies: Required for authentication and session management. The App cannot function without these.
  • Local storage: Used to cache non-sensitive preferences (e.g. theme, UI settings) on your device

We do not use advertising cookies, third-party tracking cookies, or analytics cookies that track you across websites.

11. International Data Transfers

Your data is primarily stored and processed within the UK and EEA. Where any processing occurs outside the UK (for example, via US-based service providers such as Stripe), we ensure appropriate safeguards are in place including:

  • UK International Data Transfer Agreements (IDTAs) or EU Standard Contractual Clauses (SCCs)
  • Adequacy decisions where applicable

12. Children's Privacy

InvoiceFlow is a business tool intended for users aged 18 and over. We do not knowingly collect personal data from anyone under the age of 18. If you believe a minor has provided us with personal data, please contact us immediately and we will delete it.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in the law, our practices, or the Service. We will notify you of material changes by email and/or by displaying a prominent notice in the App at least 14 days before changes take effect. The "Last updated" date at the top always reflects the current version.

Continued use of the App after the effective date of changes constitutes your acceptance of the updated policy.

14. Contact Us

For any privacy-related questions, to exercise your rights, or to report a data concern: