Legal

Privacy Policy

Last updated 29 August 2026

Puyer Inc. (“Puyer”, “we”, “us”) provides invoicing software at https://puyer.org. This notice explains what personal data we process when you visit the site, create an account, issue invoices, pay a Puyer subscription, or open a public invoice link. It is product documentation, not legal advice.

Who we are

Puyer Inc. operates Puyer. Puyer is software for freelancers, self-employed professionals, and small businesses. We are not the merchant of record for invoices you send to your customers. Invoice payments are processed on your connected Stripe account. Puyer does not hold your customers’ funds and does not charge transaction fees on those payments. Our revenue is Puyer Pro and Puyer Business subscriptions only.

Questions: privacy@puyer.org (privacy) or support@puyer.org (product). Website: https://puyer.org.

Who this notice covers

  • Visitors to puyer.org and related pages (pricing, legal, public invoices).
  • Users who sign in with an email magic link and use the workspace (invoices, clients, products, reports, team, billing).
  • People whose details an issuer stores in Puyer (clients, invoice recipients) — the issuer is typically the controller of that customer data; we process it to provide the service.
  • People who pay an invoice through Stripe on a public invoice page (Stripe, not Puyer, collects card details).

Personal data we process

We collect only what we need to run the product. Typical categories:

  • Account: email address; optional name; organization membership and role.
  • Workspace content you enter: business profile, logos, clients, products/services, invoices, notes, bank-transfer details (only if you explicitly consent to store them), reminder settings.
  • Authentication: magic-link tokens handled by Supabase Auth; session cookies so you stay signed in.
  • Subscriptions: Stripe customer and subscription identifiers, plan, and status for Puyer Pro / Business. We do not store full card numbers.
  • Invoice payments: payment status and related Stripe event data for invoices paid on your connected account. Card PAN and CVC go to Stripe, not to Puyer.
  • Team: invite emails, roles (OWNER, ADMIN, MEMBER, VIEWER).
  • Technical: IP address, user agent, request IDs, and security logs. Logs redact secrets, tokens, and bank identifiers.
  • Communications: transactional email (magic links, invoice send, reminders, invites) via our email provider.

We do not ask for passwords. Sign-in is email magic link only.

How we use data

  • Provide the service: accounts, invoices, PDFs, public share links, clients, reports, team, reminders.
  • Process Puyer subscriptions on our Stripe platform account.
  • Let you connect Stripe so your customers pay you directly on your connected account.
  • Send transactional email you request (sign-in, send invoice, reminders, invites).
  • Secure the service: rate limits, origin checks, abuse prevention, audit logs of product actions (not payment credentials).
  • Comply with law and enforce our Terms.

We do not sell personal data. We do not use your invoice contents to advertise to your customers.

Legal bases (where GDPR / UK GDPR apply)

  • Contract: creating an account, issuing invoices, subscriptions, Connect onboarding.
  • Legitimate interests: securing the service, preventing abuse, understanding aggregate product reliability. You may object where the law allows.
  • Consent: optional cookie categories in the cookie window; storing bank-transfer details on an invoice; any future marketing email (we do not send promotional mail by default).
  • Legal obligation: tax, accounting, or lawful requests where they apply to us as a software provider.

Processors and sharing

We share data with service providers who process it on our instructions, and with Stripe as described below:

  • Supabase — authentication, Postgres database, file storage (logos, generated PDFs).
  • Vercel — application hosting.
  • Stripe — Puyer subscription billing on our platform account; Stripe Connect so invoice payments settle on your connected account. Stripe’s privacy notice applies to payment data Stripe collects.
  • Resend — transactional email.
  • Inngest — background jobs (reminders, webhooks follow-up).
  • Upstash — optional Redis for rate limits in production.

Public invoice links are unguessable but not behind a login. Anyone with the link can see the invoice’s public fields (business details, line items, totals, payment status). Do not put secrets in invoice notes.

We may disclose data if required by law, to protect users or the service, or in a merger or sale of the business, with appropriate safeguards.

Retention

We keep account and workspace data while the account is active. You can delete or cancel invoices according to product rules (paid invoices are not hard-deleted). Session cookies last as configured by Auth. Magic-link return cookies expire in minutes. Logs are kept only as long as needed for security and debugging. You may request deletion of your account data at the privacy email; we will retain what we must for legal, dispute, or security reasons.

Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or port personal data, to object to certain processing, and to withdraw consent. Email the privacy address. If you are in the EEA or UK, you may complain to your supervisory authority (for example the ICO in the UK). If you are in California, you may have additional rights under the CCPA/CPRA; we do not sell or share personal information as those terms are defined for advertising.

Issuers who store client data in Puyer remain responsible for their own privacy notices to those clients.

International transfers

Our hosts and processors may store or process data in the United States and other countries. Where required, we rely on appropriate transfer tools (such as standard contractual clauses) used by those providers.

Children

Puyer is for business use. We do not knowingly collect data from children under 16 (or the age required in your country). If you believe we have, contact us and we will delete it.

Changes

We will update this page when our practices change. The date at the top is the latest revision (29 August 2026). Material changes may also be noted in-product.

© 2026 Puyer Inc.. This page is informational and does not constitute legal advice.

Puyer

The simplest way to create invoices and get paid online.

Product

  • Features
  • Pricing
  • Templates

Company

  • Help
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy

© 2026 Puyer Inc. All rights reserved.