Privacy Policy
Last updated: July 2026
1. What we collect
- Account information: your email address and password (handled by our authentication provider, Supabase).
- Business profile: business name, address, phone, email, GSTIN, logo, invoice signature, and payment method details (bank accounts, UPI IDs) you choose to add.
- Client records: names, contact details, and any notes you save about them.
- Invoice data: line items, amounts, dates, notes, and export/shipping details you enter.
- Feedback you submit through the "Give feedback" button, including an optional contact email.
2. How we store it
Your data lives in a Supabase-managed Postgres database, which Supabase encrypts at rest at the infrastructure level as a baseline for all data we store.
On top of that baseline, we individually encrypt the following fields using Supabase Vault (field-level encryption, distinct from the whole-database encryption above) — these values are never stored as plain text, even within our own database:
- Bank account details: account number, IFSC code, SWIFT code, and account holder name.
- UPI IDs and their labels.
- Your GSTIN.
- Your clients' email address, phone number, address, and any notes you've saved about them.
Other fields — like invoice line items, dates, amounts, and business profile contact details — are covered by the database-wide encryption in the first paragraph, but not individually field-encrypted. Many of these also appear directly on the invoice PDFs you generate and send to your clients, so there's limited additional benefit to encrypting them a second time within our own database.
3. Who can access it
Your account data is scoped to your own account — other users of Paycheque cannot see your clients, invoices, or payment details through the app. In the interest of being straightforward: as the operator of Paycheque, we retain the administrative database access necessary to run and support the Service (for example, to investigate a bug you report or respond to a legal request); we don't use this access to read your data in the ordinary course of business, and the field-level encryption in Section 2 exists specifically to reduce what would be exposed even in the event of unauthorized access to the underlying database (for example, a stolen backup).
4. Third parties we use
- Supabase — database hosting, authentication, and file storage.
- Resend — delivering transactional emails (invoice copies, account notifications, feedback).
- PostHog — product analytics (which features are used, not the content of your invoices or messages).
We don't sell your data to anyone.
5. Cookies
We use essential cookies to keep you signed in, and PostHog analytics cookies to understand how the Service is used.
6. Your rights
You can view and edit your business profile, clients, and invoices at any time while signed in. You can permanently delete your account and all associated data — business profile, clients, invoices, and payment details — from Settings → Account & Security → Delete my account. This is immediate and cannot be undone.
7. Data retention
We keep your data for as long as your account is active. If you delete your account, your data is permanently removed as described above.
8. Children's privacy
Paycheque is a business tool intended for freelancers and contractors, not children. We don't knowingly collect data from anyone under 18.
9. Changes to this policy
If we make material changes to this policy, we'll update the "last updated" date above.
10. Contact
Questions about this policy or your data? Email support@paycheque.cc.