Privacy Policy
Last updated: September 2026 (Version 2.0.4)
Welcome to Rivets: Simple Invoice Maker ("Rivets", "we", "our", or "us"). We are committed to safeguarding your personal data and providing clear, transparent information about how your information is handled.
1. Information We Collect
When you create an account and use the Rivets app, we collect the following data necessary to generate invoices and synchronize your account:
- Account Information: Your email address, password hash, and display name managed via Firebase Authentication.
- Business Profile Data: Business name, contact email, phone number, physical or mailing address, business logos (which you select from your device to display on your invoices, estimates, and receipts), invoice prefix, default tax rates, and payment handle configurations (such as PayPal, Venmo, Cash App, Zelle, and Bank transfer instructions). We do not collect or store your Tax ID/EIN.
- Customer Contacts: Customer names, client email addresses, billing addresses, and phone numbers that you enter to issue invoices and estimates.
- Invoices & Financial Records: Invoice numbers, line item descriptions, quantities, unit prices, discounts, taxes, contract terms, payment due dates, and paid/sent status.
2. Cloud Storage and Synchronization (Firebase)
Rivets stores and synchronizes your account profile, customers, and invoice records using Google Cloud / Firebase Firestore. This cloud infrastructure enables:
- Real-time synchronization across your supported devices.
- Cloud-assisted backup to help you access your business records when switching or restoring devices. (Please note that while cloud synchronization is maintained, you are encouraged to periodically export or archive local PDF copies of your records for your own independent bookkeeping.)
- Secure transmission encrypted via industry-standard Transport Layer Security (HTTPS / TLS 1.3).
3. Payment Processing & Billing
We do not store or process raw credit card numbers or debit card details on our servers.
- Apple App Store & Google Play In-App Purchases: In-app subscriptions and lifetime Pro purchases are processed directly by Apple through the Apple App Store (In-App Purchases) for iOS devices and by Google through Google Play In-App Billing for Android devices. Our application and servers receive verified purchase and subscription information (such as product identifiers, transaction IDs, purchase timestamps, subscription expiration dates, and entitlement statuses) solely to authenticate and activate premium features. All billing details, payment methods, and renewals are managed by Apple or Google under their respective privacy policies and terms.
- Peer-to-Peer & External Payments: When you include PayPal, Venmo, Cash App, Zelle, or bank instructions on your invoices, payment transactions occur directly between you and your client on those third-party platforms. Rivets does not act as a payment processor or take custody of client funds.
4. Device Permissions
Rivets may request specific device permissions solely to deliver core application functionality:
- Photo Library / Media (Logo Selection): Requested strictly when you choose to select a business logo from your device photos to customize the header of your invoice PDFs. Rivets does not access your camera, microphone, or other media files outside the specific image you select.
- Document Sharing & Storage (PDF Sharing): Used to generate, export, and share formatted PDF invoices, estimates, and receipts via email, text messaging, or device sharing sheets.
- Notifications (Optional Reminders): Used for optional local alerts reminding you of important app milestones or upcoming invoice due dates.
- Customer Overdue Notices (Contractor Control): Overdue notices or payment reminder messages to your customers are never sent automatically without your explicit review and approval. You maintain complete control over when to prepare, preview, and send payment reminders to your clients.
5. Application Updates & Technical Telemetry
To deliver timely bug fixes, stability improvements, and performance enhancements without requiring a full store re-download, Rivets utilizes Expo / EAS Over-the-Air (OTA) Updates hosted via Expo (650 Industries, Inc.).
When the app checks for or downloads an update bundle, standard technical telemetry is transmitted to the update service, including:
- Target runtime version and app release version (Version 2.0.4).
- Device operating system and platform architecture (iOS or Android).
- A pseudonymized, installation-specific device/client identifier generated by Expo to ensure the device reliably receives the correct update package.
This technical update data is used strictly for application maintenance, stability, and delivery of verified code bundles, and is never sold or used for cross-app advertising.
6. Data Retention & Account Deletion
You have the right to delete your account and all associated data at any time:
- In-App Deletion: You can delete your account directly inside the app by going to Settings → Delete Account. This immediately purges your profile, customer list, and all invoice records from our live databases.
- Web Deletion Request: You can also submit an online deletion request via our dedicated deletion portal at simpleinvoicemaker.app/delete-account or by emailing [email protected].
7. Third-Party Service Providers
We work with trusted industry providers to operate Rivets securely:
- Google Firebase / Google Cloud Platform: Authentication, cloud database storage, and backend hosting.
- Apple Inc.: App Store distribution, iOS in-app purchases, and subscription receipt verification.
- Google LLC: Google Play Store distribution, Android in-app billing, and purchase verification.
- Expo (650 Industries, Inc.): Mobile runtime framework and over-the-air update delivery.
8. Contact Us
If you have any questions about this Privacy Policy, your personal data, or wish to exercise your privacy rights, please contact our Data Protection Team at:
Website: https://simpleinvoicemaker.app
Account Deletion: https://simpleinvoicemaker.app/delete-account