← Back to Home

Privacy Policy

Last updated: March 17, 2026

1. Introduction

ChaseInvoices ("we", "our", "us") is operated as a sole trader registered with the UK Information Commissioner's Office (ICO registration number: C1892911). We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share information when you use our service at chaseinvoices.com.

2. Data Controller and Processor

When you use ChaseInvoices as a customer of our platform: We are the data controller for your account information (name, email, payment details). Our lawful basis for processing this data is contract performance — we need it to provide you with the Service.

When we send reminders to your customers: You are the data controller for your customers' personal data (names, email addresses, phone numbers, invoice details). We act as a data processor, processing this data on your behalf and under your instructions. Our relationship is governed by the Data Processing Agreement in our Terms of Service.

You are responsible for ensuring you have an appropriate lawful basis (such as legitimate interest or contract performance) to share your customers' data with us for sending invoice reminders.

3. Information We Collect

Account information: When you sign up, we collect your name and email address via Clerk (our authentication provider).

Stripe data: When you connect your Stripe account via webhooks, we receive and store invoice data including: customer names, email addresses, phone numbers, invoice amounts, payment statuses, due dates, and invoice URLs.

Configuration data: Your business name, reply-to email, webhook signing secret, and escalation rule preferences.

Usage data: We collect analytics events such as reminders sent, delivery statuses, and collection outcomes to power your dashboard.

Technical data: We may collect IP addresses, browser type, and device information through our analytics provider (PostHog) for product improvement.

4. Lawful Basis for Processing

Under UK GDPR, we process personal data on the following lawful bases:

  • Contract performance (Article 6(1)(b)) — Processing your account data to provide the Service you have signed up for
  • Legitimate interest (Article 6(1)(f)) — Sending transactional invoice reminders on your behalf to your customers, product analytics and improvements, and fraud prevention
  • Consent (Article 6(1)(a)) — Where you have explicitly opted in to SMS reminders in your account settings

5. How We Use Your Information

  • To provide the Service: sending invoice reminders via email and SMS on your behalf
  • To display your dashboard, analytics, and invoice data
  • To process payments for your subscription
  • To communicate with you about your account, including service updates and support
  • To improve and maintain the Service

6. Third-Party Services (Sub-processors)

We share data with the following third-party services as necessary to operate:

  • Clerk (US) — Authentication (name, email)
  • Stripe (US) — Payment processing and invoice data
  • Resend (US) — Email delivery (customer email addresses, reminder content)
  • Twilio (US) — SMS delivery (customer phone numbers, reminder content)
  • Supabase (US) — Database hosting (all stored data)
  • PostHog (US) — Product analytics (anonymised usage data)
  • Vercel (US) — Application hosting

We do not sell your data to third parties.

7. International Data Transfers

Our sub-processors are based in the United States. Personal data transferred from the UK to the US is protected under the UK Extension to the EU-US Data Privacy Framework, which provides an adequate level of data protection as recognised by the UK government. Each of our sub-processors is certified under this framework or has appropriate safeguards in place (such as Standard Contractual Clauses) to protect your data.

8. Data Retention

We retain your account data and invoice data for as long as your account is active. Reminder logs and analytics events are retained indefinitely to provide historical reporting. If you delete your account, we will delete your personal data within 30 days, except where we are required by law to retain it (for example, financial records may be retained for up to 6 years for tax purposes).

9. Data Security

We implement appropriate technical and organisational measures to protect your data, including encryption in transit (TLS), encrypted database connections, and access controls. Webhook signing secrets are stored securely and used only for signature verification.

10. Your Rights (UK GDPR)

Under UK GDPR, you have the right to:

  • Access — Request a copy of your personal data
  • Rectification — Correct inaccurate data
  • Erasure — Request deletion of your data
  • Portability — Receive your data in a machine-readable format
  • Restriction — Restrict processing of your data
  • Objection — Object to processing based on legitimate interests
  • Withdraw consent — Where processing is based on consent, you may withdraw it at any time

To exercise these rights, contact us at support@chaseinvoices.com. We will respond within one month.

If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint or by calling 0303 123 1113.

11. Email Unsubscribe

Your customers may unsubscribe from reminder emails at any time using the unsubscribe link included in every reminder email. Once unsubscribed, no further email reminders will be sent for that customer.

12. SMS Messages

ChaseInvoices may send automated SMS payment reminder messages to your customers on your behalf. SMS reminders are:

  • Only sent after you explicitly enable them in your account settings
  • Purely transactional — related only to outstanding invoices, never promotional
  • Currently available for UK mobile numbers only
  • Sent between 9am and 6pm UK time only

Your customers can opt out of SMS reminders at any time using the opt-out link included in each message. Message frequency varies based on your configured escalation rules. For SMS-related questions, contact us at support@chaseinvoices.com.

13. Cookies

We use essential cookies for authentication (Clerk session cookies). Our analytics provider (PostHog) may set cookies for product analytics. We do not use advertising cookies.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-app notice. The "Last updated" date at the top reflects the most recent revision.

15. Contact

For privacy-related questions or to exercise your data rights, contact us at support@chaseinvoices.com.