Privacy policy.
Last updated July 28, 2026
This explains what invoq collects, and why. We collect as little as we can.
What we collect
Your email address (to sign you in), the name you put on your profile if you set one, the project details you set up (name, logo, receiving wallet addresses, webhook URLs), the API keys you generate, and the invoices you create (amounts, descriptions, and your own reference ids). We also record the IP address behind a sign-up, a sign-in and each invoice or simulated payment you create, as evidence against abuse, and the User-Agent your software sends when it calls the API, which tells us which SDKs and tools people build with.
What we don’t collect
No passwords — we sign you in with a one-time email code. No payment-card data. And we never take custody of your funds. We run no advertising trackers, and nothing that follows you from site to site.
How it’s protected
Login codes, session tokens and API keys are stored only as hashes — of an API key we also keep the last four characters, so you can tell your keys apart — and webhook signing secrets are encrypted. IP addresses are kept as recorded, not hashed: they are write-only evidence against abuse, never used to profile you.
On-chain data is public
Wallet addresses and blockchain transactions are public by their nature. invoq reads public on-chain data to tell whether an invoice has been paid; we do not control what a blockchain records or who can see it.
How we use your data
To run the service: sign you in, show your dashboard, send login codes and essential service emails, and keep invoq secure. We do not sell your data.
Service providers
A small number of providers help us operate — email delivery, cloud hosting, and the blockchain node infrastructure that watches the chains for us — and process data on our behalf under confidentiality, including in other countries. On-chain data is public, as above.
Analytics
We measure traffic with Cloudflare Web Analytics: no cookies, no cross-site tracking, and no profile of you. To switch it off, set invoq_no_analytics to 1 in your browser’s local storage — on each invoq origin you use (the website, the dashboard, and the checkout pages), since a browser keeps them apart.
Data in your browser
We keep a session token plus your language, theme, and selected project in your browser’s storage, along with small flags for prompts you have dismissed and steps you have already passed, so you stay signed in and the app does not repeat itself — not for tracking.
Your choices
We keep your data while your account is active. You can edit or clear your project details at any time. To access or delete your account data, email help@invoq.money.