Legal (draft)
Privacy policy
What data Fiscalane handles, why, and who else touches it. Written in plain language; a lawyer has not reviewed it yet.
Who is responsible
Data controller: [OPERATOR LEGAL NAME], [postal address], [country]. Privacy contact: [privacy email address].
For the invoices you write, you are the controller of your customers' personal data and Fiscalane processes it for you to provide the service. A data-processing agreement is available on request [to be prepared].
What Fiscalane handles
- Invoice content you enter: business and customer names (including Arabic names), addresses, tax identifiers, bank details, line items and notes. Invoices contain personal data when a party is an individual.
- Draft invoices created without an account, which are autosaved in your browser's local storage on your own device.
- Account data when you sign up: your email address, your sign-in method, and, for Google sign-in, the name, profile picture and account identifier Google shares with Firebase Authentication.
- If you save them to an account: your business profile (company name, address, tax or VAT number, bank account number (IBAN) and an optional logo image), your clients, and your invoices.
- When you issue an invoice, Fiscalane's server writes an archive record with a SHA-256 hash of the invoice content, the invoice number and a timestamp. The record is stored in your account so you can check later that an invoice was not changed. It does not contain the invoice text.
- Billing data: your plan and subscription status, and the Dodo Payments customer and subscription identifiers linking your account to the payment provider. Card details are handled by Dodo Payments and are never seen or stored by Fiscalane.
Why it is used, and on what basis
Invoice and account data are used to provide the product: to render your invoice, calculate totals, run the compliance check, generate the PDF or UBL file, and store your saved records. Billing data is used to know which plan your account is on and to let you manage your subscription. The hash archive is used to let you verify your own records.
Likely legal bases, to be confirmed by a lawyer: performing the contract with you (accounts, saved invoices, billing); legitimate interests (security, preventing abuse, the integrity of your archive); legal obligations (billing and tax records). Fiscalane does not rely on consent for any processing today.
Readiness checker
The e-invoicing readiness checker reads the spreadsheet (CSV) file you choose entirely inside your browser. The file and its rows are never uploaded to Fiscalane or to any server; closing the page discards them. If you tick items on the process checklist, those ticks are kept in your browser's local storage.
Importing a CSV into your account
This is separate from the readiness checker above. When you are signed in, the Import CSV page in your dashboard reads the file you choose inside your browser and shows a preview. Nothing is stored until you press Save; then each invoice in the file is stored in your account as a draft, in the same way as an invoice you type in yourself (customer names and tax identifiers, line items and amounts, the numbers and dates in your file). Drafts are readable only by you, are not issued or sent anywhere, and can be deleted like any other draft. The file itself is not kept. Importing the same file again leaves drafts that already exist as they are.
PDF and e-invoice generation
PDF files are generated in your browser. Validated UBL export is a request to Fiscalane's server, which checks your invoice, generates the XML and returns it to you; it requires a signed-in account on a plan that includes it. The export route does not save your invoice. Hosting-level request logs are an open item above. Fiscalane does not send your invoice to your customer or to any network on your behalf.
Who else is involved
- Google (Firebase Authentication and Cloud Firestore) provides sign-in and the database. Data location: [EU multi-region | Doha] [to be decided]. Google may process some authentication data in other countries, including the United States, under its standard terms [to be reviewed].
- Firebase Authentication sends sign-in emails, such as password resets, on Fiscalane's behalf. Fiscalane sends no other email today.
- Dodo Payments is the merchant of record for subscriptions. It collects payment details, tax and billing address under its own privacy policy and sends Fiscalane your customer id, subscription id and status.
- Google Vertex AI (Gemini, EU region) is used only for the optional "Ask AI for a VAT category suggestion" button, and only when you click it and the feature is switched on: the description of that one invoice line, the seller and buyer country codes and a yes/no flag for whether the buyer has a VAT number (never the number itself) are sent for one suggestion. No names, amounts, addresses or tax numbers are sent. The suggestion is not stored on Fiscalane's side, is not verified and is never applied automatically. The provider terms, retention and training terms, and this wording have not been reviewed yet [to be reviewed by a lawyer].
- The hosting provider that serves the site and runs the API [not yet chosen].
Fiscalane does not sell personal data and does not use advertising trackers.
Cookies and browser storage
Fiscalane sets no advertising or analytics cookies. Your browser stores: your sign-in state (Firebase Authentication), your theme choice, and the invoice drafts you create without an account. These are needed for the feature you use and stay on your device until you clear them.
Security
Data travels over HTTPS and is stored in Google's managed database with encryption at rest. Database rules allow only the signed-in owner to read an account's records, API routes verify your sign-in token on the server, and plan state and archive records can be written only by the server. No security certification or audit is claimed.
How long data is kept
- Account, profile, clients and invoices: until you delete them or the account is closed [retention details to be confirmed].
- Archive records: [decision pending: whether they are kept or removed when an invoice or account is deleted].
- Billing identifiers: as long as tax and accounting law requires [to be confirmed for the operator's jurisdiction]; Dodo Payments keeps its own records.
- Backups: [to be decided]; deleted data may remain in backups until they rotate out.
Your rights and choices
- You can use the editor without an account; clearing your browser data removes local drafts.
- You can delete saved invoices and clients from your account.
- To close your account and have your data deleted, email [privacy email address] from the address on the account. In-product deletion is not built yet.
- Depending on where you live you may have rights to access, correct, export, restrict or erase your personal data, to object to processing, and to complain to a data-protection authority [authority to be named]. We answer requests within one month where the law sets that period [to be confirmed].
Business use and children
Fiscalane is offered to businesses, freelancers and professionals and is not intended for anyone under 18.
Breaches, automated decisions and disclosure
If a personal-data breach affects you, we will tell you and the competent authority without undue delay as the law requires [deadlines to be confirmed]. Fiscalane takes no decisions about people by automated means. Data may be disclosed when the law requires it.
Changes
This draft will change before launch. A dated, reviewed version will replace it, and material changes will be announced in the product.