Privacy Policy
Last updated: 30 August 2026
Invatechs Ltd, a company registered in England and Wales (company number 13176452), registered office Blue Tower, MediaCityUK, Salford Quays, Salford, England, M50 2ST, is the controller of the personal data described in this policy. You can reach us at support@payed.me.
1. Who this policy is for, and the part it does not cover
payed.me is invoicing software for small businesses and freelancers. This policy explains what we do with data about you, our user — your account, your billing, and how you use the service.
It does not govern the information you load about your own clients. When you add a customer, raise an invoice or record an expense, you decide what to collect and why; we only hold and process it on your instructions. In data protection terms you are the controller of that information and we are your processor. Those obligations are set out in our Data Processing Agreement, not here.
If you are a client of one of our users and want to know why your details appear on an invoice, please contact the business that invoiced you. We cannot answer for their records.
2. What we collect
Information you give us
- Account — your name, email address, password (stored only as a bcrypt hash, never in readable form), and any company details you add.
- Content you create — customers, invoices, quotes, receipts, credit notes, expenses, mileage, time entries, tasks, inventory, purchase requests, and documents you attach.
- Messages — anything you send through our contact form or the in-app assistant.
Information created automatically
- Sign-in records — your user identifier, sign-in and sign-out times, and the IP address the session came from, kept as a security audit trail.
- Session tokens — so you stay signed in. These are opaque tokens rather than self-describing ones.
- Analytics — only if you accept. See section 7.
Card details never reach us. Payments are handled by Stripe on their own systems. We receive confirmation that a payment succeeded, not the card number.
We do not collect special-category data, we do not build advertising profiles, we do not sell data, and we do not use your content to train any AI model.
3. Why we process it, and on what legal basis
| Purpose | Lawful basis |
|---|---|
| Running the service — your account, documents, PDFs, and sending mail on your behalf | Performance of a contract |
| Taking payment for a paid plan | Performance of a contract |
| Keeping the service secure — sign-in records, rate limiting, fraud prevention | Legitimate interests |
| Answering support and contact messages | Legitimate interests |
| Analytics | Consent, withdrawable at any time |
| The AI assistant | Performance of a contract — it is optional and runs only when used |
| Meeting accounting and tax obligations | Legal obligation |
4. Where your data is held
| What | Where |
|---|---|
| Main database — accounts and all business records | DigitalOcean managed PostgreSQL, Amsterdam, Netherlands |
| Document attachments | Amazon S3, London, United Kingdom — encrypted at rest, versioned, no public access |
| Sign-in records, session tokens, background jobs | Application servers provided by our group company Invatechs PL, Poland |
| Websites | AWS Amplify |
Traffic between your browser and us is encrypted, and so is the connection between our servers and the database, which is additionally authenticated against a pinned certificate authority.
We are established in the United Kingdom and our servers are in the European Economic Area. Transfers between the UK and the EEA are covered by the adequacy decisions in force in both directions, so no additional safeguard is needed for that leg.
5. Who else processes it
Each of these acts on our instructions under a data processing agreement, and receives only what its job requires.
| Provider | Purpose | Location |
|---|---|---|
| Invatechs PL | Our Polish group company, which provides the hardware our application runs on. Its staff do not access your data. | Poland |
| DigitalOcean | Managed database | Netherlands |
| Amazon Web Services | Attachment storage; website hosting | UK / EEA |
| Stripe | Card payments and subscriptions | EEA / United States |
| Resend | Delivering your invoices, quotes, receipts and reminders | EEA / United States |
| Postmark | Standby email delivery, so mail still goes out if the first provider fails | United States |
| Zoho | Our own inbound mailboxes | EEA |
| Google Analytics | Usage statistics — only with your consent | United States |
| OpenRouter, and the AI providers named in section 6 | The optional AI assistant | United States |
We do not sell or rent your data, and we do not share it for advertising.
Where a provider processes outside the UK and EEA, the transfer is made under the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, incorporated into that provider's data processing terms.
6. The AI assistant
The assistant is optional. Everything else in payed.me works without it, and if you never open it, nothing in this section happens.
When you use it, your message and the records needed to answer it are sent to OpenRouter, Inc. (United States), which routes the request to one of afixed set of providers we have vetted: Microsoft Azure (US), CoreWeave, DeepInfra and Parasail. The request cannot reach any provider outside that list.
Before anything leaves our servers:
- Some fields are never sent at all. Email addresses, telephone numbers, postal addresses and tax numbers are excluded at source — the assistant cannot see them.
- Identifying values in the fields that are sent are replaced with stable substitutes, and restored in the reply. This covers customer and contact names, supplier names, colleague names, journey start and end points, and a customer's town.
We instruct the gateway to route only to providers that do not retain request content and do not train on it.
Two limits we would rather state than imply.
This substitution is pseudonymisation, not anonymisation. We keep the ability to reverse it, because that is what lets the assistant act on the right record — so the data remains personal data in law.
And a name that is not a record in your account — someone you simply mention in a sentence — cannot be substituted, because there is nothing to match it against.
7. Cookies and analytics
Strictly necessary. A small amount of browser storage keeps you signed in and remembers your cookie choice. It cannot be switched off without breaking sign-in, and it is not used for tracking.
Analytics. We use Google Analytics 4 to see which pages are useful. It is off until you accept, nothing is stored before you choose, and we never use it for advertising. You can change your mind at any time through "Cookie settings" in the footer.
8. How long we keep it
We keep your account and its contents for as long as your account is open.
After you close it we delete or anonymise your data within30 days, except where we must keep records longer to meet accounting and tax obligations — as a UK company we are generally required to retain records relating to invoices and payments for six years. Sign-in records are kept for 30 days. Backups age out on their own cycle.
9. Your rights
You may ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to another provider. Where we rely on consent you may withdraw it at any time, which does not affect what we did before you withdrew it.
Email support@payed.me and we will reply within one month. If you are not satisfied you may complain to the Information Commissioner's Office, the UK supervisory authority. If you are in the EEA you may instead complain to your local supervisory authority.
Our representative in the European Union is Invatechs PL, Ogrodowa 58, 00-876 Warszawa, Poland. You may contact them or us on any matter relating to our processing of your personal data.
For information about your clients, those rights are exercised against you rather than us, and we would refer such a request on to you.
10. Security
Passwords are hashed with bcrypt and never stored readably. Traffic is encrypted in transit, the database connection is authenticated against a pinned certificate authority, and attachments are encrypted at rest. Access to production systems is restricted, database ports are not exposed to the internet, and the AI assistant cannot change anything without you confirming the specific action first.
No service can promise perfect security. If a breach affects your rights we will tell you and the supervisory authority as the law requires.
11. Children
payed.me is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16.
12. Changes
If we change this policy we will post the new version here and update the date above. For changes that materially affect your rights we will tell you by email before they take effect.
Questions about this page? Email support@payed.me.