Legal
Version 1.0 · Effective April 10, 2025 · InvoiceFlow by S3Digital
We do not store payment card numbers, CVVs, or sensitive payment credentials. All payment processing is handled exclusively by Stripe, which is PCI DSS compliant. We only store Stripe-issued references (customer IDs, payment intent IDs) necessary to operate billing features.
We do not sell your data. We share data only with:
All data is transmitted over TLS 1.3 encryption. Access to production systems is role-restricted. We conduct regular security reviews. No system is 100% secure, but we take reasonable measures to protect your data.
We retain your data for as long as your account is active. Upon account termination, data is retained for 30 days before deletion unless a longer retention period is required by law.
You have the right to access, correct, export, or delete your personal data. To exercise these rights, contact us at support@s3digital.online. We will respond within 30 days.
We use cookies strictly for authentication sessions and basic analytics. We do not use third-party advertising cookies. You can disable cookies in your browser but this may affect platform functionality.
InvoiceFlow integrates with Stripe and other infrastructure providers. These services have their own privacy policies and data handling practices, which we encourage you to review.
If you are located in the European Economic Area, you have additional rights under GDPR including the right to restriction of processing, the right to data portability, and the right to lodge a complaint with a supervisory authority. Our legal basis for processing is legitimate interest and contractual necessity. Contact us to submit a GDPR data request.
Privacy questions? Contact us at support@s3digital.online.
InvoiceFlow by S3Digital · Privacy Policy v1.0