Privacy Policy
1. Who We Are
MrInvoice.APP is a division of Quantum System, USA. We operate the website and service at mrinvoice.app (the "Site" and the "Service") — a subscription invoicing platform for small businesses. This Privacy Policy explains how we handle personal information collected through the Site and the Service.
2. Information We Collect
Contact form submissions
When you submit our contact form, we collect: your name, email address, and message content, plus phone number and company name if you choose to provide them. Submission is voluntary.
Account and service data
If your business subscribes to MrInvoice.APP, we store the data you enter to operate the Service on your behalf: user accounts (name, email), your company profile, and your business records such as customers, products, estimates, invoices, and payment history. Each subscriber's data is isolated from every other account.
Server and infrastructure logs
The Site is delivered through Cloudflare's global edge network. Cloudflare automatically collects standard network data including IP addresses, browser type and version, referring URLs, pages visited, and timestamps. This data is processed by Cloudflare as our infrastructure provider. See Cloudflare's Privacy Policy.
Cookies
We use only strictly necessary cookies: a session cookie and a security (CSRF) token required for signing in and using the Service. We do not use tracking pixels, analytics scripts, advertising tags, or any third-party marketing cookies.
3. How We Use Your Information
- Contact inquiries: to respond to your message and follow up on your interest in MrInvoice.APP
- Service operation: to provide the invoicing Service to your business — including sending invoices, estimates, and sign-in emails you request
- Infrastructure logs: for security monitoring, DDoS protection, and abuse prevention
- Business communications: to send you service updates or notifications related to your account
We do not sell, rent, or share your personal information with third parties for marketing or advertising purposes.
4. Legal Basis for Processing (EU/EEA Residents)
If you are located in the EU or EEA, we process your personal data under the following lawful bases under GDPR:
- Contract: operating the Service for your business's subscription
- Legitimate interest: responding to your inquiry and operating a secure website
- Consent: where you have voluntarily submitted your information
- Legal obligation: where required by applicable law
5. Data Retention
Contact form submissions are retained for up to 24 months and then securely deleted. Account and service data is retained for the life of the subscription and for a reasonable period after closure to allow reactivation and meet record-keeping obligations. Infrastructure logs are retained per Cloudflare's standard retention policies. You may request earlier deletion at any time.
6. Your Rights — EU/EEA Residents (GDPR)
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent at any time without affecting prior lawful processing
To exercise any of these rights, use our contact form. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
7. Your Rights — California Residents (CCPA)
- Right to know what personal information we collect, use, and disclose
- Right to delete personal information we hold about you
- Right to opt-out of the sale of personal information — we do not sell personal information
- Right to non-discrimination for exercising your privacy rights
To exercise these rights, use our contact form.
8. International Data Transfers
Your data may be processed in the United States and other countries where Cloudflare operates infrastructure. Where EU/EEA personal data is transferred outside the EEA, Cloudflare relies on Standard Contractual Clauses and other appropriate safeguards. See Cloudflare's Data Processing Addendum for details.
9. Security
All data transmitted to the Site is encrypted via HTTPS/TLS. Every sign-in requires a password plus a fresh one-time email code. Account data is backed up off-site nightly in encrypted form. We implement reasonable technical and organizational measures to protect personal information. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.
10. Children's Privacy
The Site is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected in an updated "Last Updated" date at the top of this page. Continued use of the Site after any changes constitutes acceptance of the updated policy.
12. Governing Law
This Privacy Policy is governed by the laws of the State of Delaware, USA.
13. Contact
For any privacy-related questions, requests, or complaints, please use our contact form.