Privacy Policy
Last updated: 30 November 2025
1. We only collect what we need
Name, email, company name, invoice data, and payment links you create. Bank or payment-gateway connections are encrypted and never stored in plain text.
2. We never sell or share your personal data
Not with advertisers, not with third-party marketers, not with anyone.
3. How we use your data
To send your invoices and reminders
To show your dashboard, reports, and cashflow forecasts
To improve the product (only anonymized usage data)
4. Payments & banking
All card and bank transactions are handled directly by Stripe and Xendit. We never see or store your full card or bank account numbers.
5. Security
Bank-grade AES-256 encryption at rest and in transit
SOC-2 Type II compliant
Regular independent security audits
Two-factor authentication available on all accounts
6. Your rights
Access all of your data at any time
Export everything in one click (CSV/JSON)
Delete your account and all data permanently — instantly and irreversibly
7. Cookies & analytics
We only use essential cookies plus privacy-friendly analytics (Plausible). No cross-site tracking, no personal profiling.
8. Changes to this policy
If we ever make a material change, we’ll email you and give you 30 days’ notice.
That’s the whole policy — no fine print, no surprises.
Any questions? hello@tagihly.com — we reply fast.
