Legal
Privacy Policy
Last updated: September 2026
1. Who we are
EInvoiceFile (https://einvoicefile.com) provides a REST API for European e-invoicing. For questions about this policy, use our contact form or email support@einvoicefile.com.
We are the controller for account, billing metadata, and support messages you send us. For invoice files you submit to the API, we act as a processor on your instructions: they are handled for that request only and are not kept as invoice archives.
2. Data we collect
- Account data: work email, name, account type, country, workspace identifiers, and hashed session tokens.
- API keys and usage: key identifiers, plan, call counts, endpoint, status code, and timestamps — not invoice XML/PDF content.
- Billing: plan and transaction metadata. Card payments are processed by Polar as merchant of record. We do not store full card numbers.
- Support: name, email, account type, and the query you send via Contact (up to 500 characters).
- Invoice documents: processed in memory for the API call and discarded when the response is sent. They are not written to MongoDB.
3. Where data lives
Application servers run on Amazon Web Services in Frankfurt (eu-central-1). Account, keys, usage metadata, and contact requests are stored in MongoDB in the EU. We do not intend to transfer invoice content outside the EEA.
4. Legal basis (GDPR)
Account and billing data: Art. 6(1)(b) GDPR (contract). Security logs and fraud prevention: Art. 6(1)(f). Support messages: Art. 6(1)(b) or (f). Invoice payloads: processing necessary to provide the API you requested.
5. Recipients
- AWS: hosting in Frankfurt.
- MongoDB: account and operational data (EU).
- Polar: checkout and subscriptions (independent controller for payment data).
6. Retention
Account data is kept while the workspace is active and deleted after closure, except where tax or accounting law requires longer retention of billing records. Technical API logs follow your plan. Invoice files are not retained after the HTTP response. Contact messages are kept only as long as needed to answer you.
7. Your rights
You may request access, correction, erasure, restriction, portability, or objection under the GDPR. Email support@einvoicefile.com or use the contact form. You may also delete your account from the dashboard where that feature is available.
8. Security
Production traffic uses TLS. Sessions use an encrypted cookie. See Trust & Security for architecture details. Report a security issue to security@einvoicefile.com.
9. Changes
We will update this page when the policy changes. Material changes affecting paid accounts will be announced by email where we have a contact address.