honest Invoices

Privacy Policy

Last updated: February 2026

Overview

Honest Invoices ("we", "our", "us") is operated by Airtisan. We respect your privacy and are committed to protecting your personal data. This policy explains how we collect, use, and safeguard your information when you use our invoicing application.

Information We Collect

Account Information

When you create an account, we collect your email address and password (stored securely via Supabase Authentication).

Business Information

To generate invoices, you provide us with your business name, contact details, and bank details (account number and sort code). This information appears on your invoices and is stored securely.

Job and Invoice Data

We store information about your jobs, time entries, materials, and generated invoices. This is your business data and remains yours.

Voice Recordings

When you use our voice-to-invoice feature, audio recordings are temporarily processed to extract job details.

Recordings are processed by OpenAI's Whisper API for transcription. Audio recordings may be retained temporarily for quality improvement purposes. Transcripts are stored to help you review and edit entries.

You may request deletion of specific voice recordings by contacting us.

Payment Information

We use Stripe to process subscription payments. We do not store your card details—these are handled entirely by Stripe. We only store a Stripe customer ID to manage your subscription.

How We Use Your Information

  • To provide the invoicing service you signed up for
  • To process your voice recordings into invoice data
  • To manage your subscription and payments
  • To improve the accuracy of our AI features
  • To send important service updates (rare, essential only)
  • To respond to support requests

We do not sell your data. We do not send marketing emails unless you opt in.

Third-Party Services

We use the following services to operate Honest Invoices:

  • Supabase — Database and authentication (EU hosting available)
  • Stripe — Payment processing
  • OpenAI — Voice transcription and AI processing
  • Vercel — Website hosting

Each service has their own privacy policy and handles data according to their terms.

HMRC Integration (Making Tax Digital)

If you connect your HMRC account for Making Tax Digital compliance, we will:

  • Store your HMRC authorization tokens (encrypted) to submit quarterly tax updates on your behalf
  • Access your HMRC business information and tax obligations
  • Submit your income and expense data to HMRC as required by MTD regulations
  • Never share your HMRC data with any third parties

You can disconnect your HMRC account at any time from Settings. When disconnected, we will delete your HMRC tokens within 24 hours.

Lawful basis: Performance of contract (MTD compliance service) and legal obligation (UK tax law compliance).

Data Security

We implement appropriate security measures including:

  • Encrypted connections (HTTPS)
  • Secure password storage (hashed and salted)
  • Row-level security on our database ensuring you can only access your own data
  • Regular security updates and monitoring

However, no method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

Your Rights

Under UK GDPR, you have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your data ("right to be forgotten")
  • Export your data in a portable format
  • Object to processing
  • Withdraw consent for data processing

To exercise any of these rights, contact us at support@honestinvoices.co.uk.

Data Retention

We retain your data for as long as your account is active.

If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal, accounting, or regulatory purposes (such as for tax records).

Voice recordings and transcripts are retained while your account is active. You may request deletion of specific recordings at any time.

Data Exports

You can export your invoice data at any time through the Service interface. Upon request, we will provide your complete data in a common machine-readable format (CSV or JSON) within 7 days.

Cookies

We use essential cookies only—for authentication and keeping you logged in. We do not use tracking or advertising cookies.

International Data Transfers

Your data is primarily stored within the EU/UK. However, some of our service providers (such as OpenAI) may process data outside the EU. We ensure appropriate safeguards are in place for any international transfers.

Children's Privacy

Our Service is not intended for anyone under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.

Changes to This Policy

We may update this policy occasionally. We'll notify you of significant changes via email or an in-app notice at least 30 days before they take effect.

Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

Contact

For privacy-related questions or to exercise your data rights, contact us at:

Email: support@honestinvoices.co.uk

Data Protection Officer: v.l.hawley@hotmail.com (for formal GDPR requests)