Privacy Policy
Easy Invoice collects only the business data necessary to provide multi-tenant invoicing, CRM, and analytics services. All financial records and customer data are encrypted in transit and at rest, never sold, and fully deletable upon request at any time.
1. Introduction & Overview
Welcome to Easy Invoice. We are committed to safeguarding the privacy and integrity of your commercial data. This Privacy Policy explains how Engr. Tarikul Islam ("Developer", "we", "us", or "our") collects, processes, stores, and protects your information when you use the Easy Invoice mobile application (the "App").
By installing, registering, or using Easy Invoice, you consent to the data practices described in this Privacy Policy. If you do not agree with this policy, please do not use the App.
2. Information We Collect
We collect only data essential for operating your multi-business invoicing suite:
A. Commercial & Account Information You Provide
Depending on your role and feature usage, we collect:
- User Account Data: Name, email address, and authentication credentials.
- Business Organization Data: Business names, logos, contact info, invoice prefix rules, default currencies, shipping charges, and tax rates.
- Team & Role Configurations: Team member emails, assigned business associations, and access levels (Owner, Manager, Sales Staff).
- Product Catalog Data: Product titles, specialized category classifications (General Goods, Currency Exchange, Digital Codes, Services, Subscriptions), cost prices, and selling prices.
- Invoice & Transaction Data: Invoice line items, customer details, discounts, payment channels (bKash, Nagad, Cash, Bank Transfer, Split Payments), paid sums, and outstanding balances.
- Customer CRM Data: Customer names, phone numbers, addresses, historical purchases, and lifetime revenue records.
- Data Backup & Export Audit Records: Metadata regarding Excel data backups and export timestamps to ensure business security.
B. Automatically Collected Technical Data
Our systems automatically log limited diagnostic information:
- Device Model & OS Version: For compatibility optimization and responsive layout tuning.
- Crash Diagnostics: Anonymized stack traces to rapidly fix software anomalies.
- Usage Telemetry: Anonymized feature performance metrics to enhance user experience.
3. Device Permissions
Easy Invoice requests only the minimum device permissions necessary to perform its functions:
- Storage Access (READ/WRITE_EXTERNAL_STORAGE): Required to save exported PDF invoices and Excel backups locally on your device.
- Internet Access (INTERNET): Required to securely synchronize business records across devices and facilitate WhatsApp PDF document sharing.
- Notification Access (POST_NOTIFICATIONS): Optional — enables payment due date notifications and automated overdue invoice alerts.
- Camera Access (CAMERA): Optional — used to scan customer QR codes and product barcodes for rapid lookup.
4. How We Use Your Data
Your data is used strictly for legitimate commercial and application management purposes:
- To generate, format, sync, and store your invoices, products, and customer directories.
- To calculate accurate tax, discount, split payment, and due balance totals.
- To produce real-time KPI dashboards, product performance analytics, and staff performance PDF reports.
- To facilitate instant 1-tap WhatsApp PDF invoice sharing, printing, and file downloads.
- To generate secure Excel data backups and allow cross-account imports.
- To maintain export audit logs for business owners to detect and prevent data misuse.
- To enforce Role-Based Access Control and protect confidential business metrics from unauthorized staff.
5. Data Sharing & Third-Party Infrastructure
We do not sell, rent, monetize, or trade any of your business or personal data. We utilize reputable infrastructure providers strictly for cloud hosting and sync:
- Firebase (Google): Secure cloud database, real-time sync, and authentication infrastructure (https://firebase.google.com/support/privacy).
- Google Play Services: App deployment and authentication verification (https://policies.google.com/privacy).
6. Data Security & Encryption Standards
All data in transit between the Easy Invoice mobile client and backend databases is encrypted using TLS 1.3.
All stored multi-tenant business records, customer CRM data, and invoices are encrypted at rest using industry-standard AES-256 encryption.
Strict tenant isolation guarantees that no unauthorized business or user can access another entity's proprietary data.
7. Data Retention & Account Deletion
We retain your commercial data only while your account remains active or until you initiate data erasure.
You have the absolute right to delete your account, businesses, and all associated financial records at any time via Settings → Account Settings → Danger Zone → Delete Account or via our web portal.
Upon deletion, all database records, product catalogs, customer profiles, invoices, and backups are permanently purged within 30 days.
8. Global Privacy Rights (GDPR & CCPA)
You retain full global data rights over your commercial information:
- Right of Access: Request an export of your stored business data via Excel or JSON.
- Right to Rectification: Correct inaccurate client, product, or invoice records anytime.
- Right to Erasure: Permanently delete your account and all data records.
- Right to Data Portability: Export complete Excel backups for seamless migration.
- CCPA Disclosure: We do not sell personal or commercial information.
9. Policy Updates
We may update this Privacy Policy to reflect app enhancements or legal requirements. Material updates will be highlighted within the App with an updated revision date.
10. Contact & Data Protection Officer
For data privacy inquiries, contact:
- Developer: Engr. Tarikul Islam
- Support Email: easyinvoice.support@engtarikulislam.com
- Portal: https://app.engtarikulislam.com
- Location: Dhaka, Bangladesh
Executive Privacy & Data Protection Summary
Key transparency commitments for Easy Invoice users
Your location and circle data are 100% private. We never sell, rent, or trade personal data to advertisers.
Family connections are initiated exclusively by scanning dynamic in-app QR codes with 100% recipient accept/cancel control.
All telemetry, location updates, and messages are encrypted in-transit (TLS 1.3) and at-rest with bank-grade encryption.
Self-service 1-tap account deletion removes all personal data, circle links, and historical GPS logs within 48-72h.