Draft for review — this is placeholder text, not legal advice. Have it reviewed by a qualified lawyer before publishing.

Privacy Policy

Last updated: 18 August 2026

This policy explains what personal data DIY Business collects, why we collect it, who we share it with, and the rights you have over it. It covers both the people who use our app (account holders) and the customer contacts our users store in the app.

Who we are

DIY Business ("we", "us") provides invoicing and recurring-billing software for small businesses. For the account data of our users we act as a data controller; for the customer and invoice data our users enter, we act as a data processor on their behalf.

Information we collect

Account and identity data — your name, email, organization, and role — managed through our authentication provider.

Business data you enter — your customers' names, contacts, addresses, invoices, line items, and payment records.

Payment data — when you subscribe to a paid plan, our payment processor handles your card details; we never see or store full card numbers.

Technical data — IP address, device and browser information, and log data generated when you use the app.

How we use your data and our lawful bases

To provide the service and perform our contract with you (creating and sending invoices, processing subscription payments).

For our legitimate interests in securing, maintaining, and improving the service.

To comply with legal obligations such as tax and accounting record-keeping.

With your consent, where the law requires it — for example, non-essential cookies.

Who we share it with (subprocessors)

We use a small set of vetted service providers to run the app. Each processes personal data only on our instructions and under a data-processing agreement:

Clerk — authentication and organization/user identity.

Stripe — subscription payments and billing.

Resend — sending your invoice and reminder emails.

Amazon Web Services (S3) — file and logo storage.

Some of these providers may process data outside your country; where that happens we rely on appropriate safeguards such as Standard Contractual Clauses.

How long we keep it

Records you delete are soft-deleted first and recoverable for 30 days, after which they are permanently purged.

Account data is kept for as long as your organization is active and deleted when you close the account, subject to any legal retention obligations.

Your rights

Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to restrict or object to certain processing, and to withdraw consent at any time.

You can exercise access, export, and deletion directly from Settings → Privacy & Data, or by emailing us.

If you are in the EU/UK, you also have the right to lodge a complaint with your local data-protection authority.

California privacy rights (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect, to access and delete it, to correct it, and to opt out of any "sale" or "sharing" of it.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. Our "Do Not Sell or Share My Personal Information" control is provided for transparency and to honor opt-out preference signals.

We will not discriminate against you for exercising any of these rights.

Cookies

We use only strictly-necessary cookies by default. See our Cookie Policy for details and to manage your preferences.

Security

We use industry-standard measures — encryption in transit, access controls, and per-organization data isolation — to protect your data. No system is perfectly secure, but we work to keep yours safe.

Children

The service is for businesses and is not directed at children under 16. We do not knowingly collect their data.

Changes to this policy

We may update this policy from time to time. Material changes will be announced in the app or by email.

Contact

Questions about this policy or your data? Email privacy@diybusiness.io.