Back

Privacy Policy

Last updated: 1/22/2026

1. Information We Collect

We collect: (a) your email address for account creation and authentication, (b) your Hiboutik API credentials (encrypted at rest), (c) vendor and invoice data synced from your Hiboutik account.

2. Legal Basis & Purpose

We process your data based on contract fulfillment (providing the invoice generation service you signed up for). We do not use your data for marketing or profiling.

3. Data Storage & Retention

Your data is stored in secure databases hosted by Supabase (EU region available). We retain your data until you delete your account. You can request deletion at any time.

4. Your Rights (GDPR)

You have the right to: access your data, rectify inaccuracies, request erasure, restrict processing, data portability, and object to processing. Contact privacy@autofacture.pro to exercise these rights.

5. Sub-Processors

We use: Supabase (database, EU), Vercel (hosting, US with EU data processing), Lemon Squeezy (payments, US/EU). Each processor has their own GDPR-compliant privacy policy.

7. International Transfers

Some sub-processors are US-based. Data transfers are covered by Standard Contractual Clauses (SCCs) as per GDPR requirements.

8. Contact

For privacy concerns: privacy@autofacture.pro. You also have the right to lodge a complaint with your local data protection authority (CNIL in France).