Privacy policy
How InvoiceGen collects, uses, stores and discloses personal information, and how to access or correct the information we hold about you.
Last updated: 4 August 2026 · Effective: 4 August 2026 · InvoiceGen is operated by Venture Drake Pty Limited (ABN 59 159 237 126).
1. Who we are, and what this policy is
InvoiceGen is an online invoice and quote generator operated by Venture Drake Pty Limited (ABN 59 159 237 126) of Ground floor/44 North Ft Rd, Manly NSW 2095 — "we", "us", "our".
This policy explains how we collect, hold, use, disclose and protect personal information when you use invoicegen.com.au and the InvoiceGen application (the "Service"). It applies to everyone who uses the Service, and to people who visit our website, contact us, or receive an invoice generated through the Service.
We handle personal information in accordance with the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth). Where a term is defined in the Privacy Act — including "personal information" and "sensitive information" — it has that meaning here.
"Personal information" means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not it is true and whether or not it is recorded in a material form.
2. The two kinds of information in InvoiceGen
This is the most important thing to understand about InvoiceGen, so we have put it first.
Your information. When you sign up and use InvoiceGen, we collect information about you and your business. We decide how that information is handled, and this policy governs it in full.
Your clients' information. InvoiceGen is a tool you use to create documents. When you enter your client's or customer's name, address, email, phone number or ABN into an invoice or quote, you are the one who chose to collect it, you decide what to do with it, and you have the relationship with that person. We hold and process it so we can build and deliver the document you asked for, and we do not use it for anything else.
That means:
- If you are an InvoiceGen user, you are responsible for having the right to enter your clients' details, for giving them any privacy notice you are required to give, and for meeting your own obligations under the Privacy Act or any other law that applies to you. You can view, correct and delete your clients' details in your account at any time.
- If you are a client who has received an invoice generated through InvoiceGen, the business that sent it holds the underlying record and can usually resolve things fastest, so it is worth contacting them first. But you do not have to. You can make a request directly to us about your own personal information — including access, correction or deletion — and we will deal with it ourselves. See clause 13.
This allocation is between you and your clients. It does not reduce our own obligations. We hold your clients' personal information, so the Australian Privacy Principles apply to us in respect of it too: we keep it in Australia, secure it as described in clause 10, never sell it, never use it for our own marketing, and respond to requests made to us directly.
3. What personal information we collect
3.1 Account information. Your name, email address, password (stored hashed, never in readable form), and your business details — business or trading name, ABN, address, phone number, logo, GST registration status, and the payment details you choose to display on your invoices (typically a BSB and account number, or a PayID). Please do not enter payment card numbers.
3.2 Invoice and quote content. Everything you enter into a document, including your clients' names, contact details, addresses and ABNs, line-item descriptions, amounts, tax treatments, dates, payment terms, reference numbers, and any notes or attachments you add.
3.3 Communications. The content of emails and support messages you send us, and our replies.
3.4 Technical and usage information. Your IP address, browser type and version, device and operating system, referring page, the pages you view and the actions you take in the Service, timestamps, and error and diagnostic logs. Some of this is collected using cookies and similar technologies — see clause 11.
3.5 Delivery information. Where you send an invoice or quote through the Service, we record the recipient's email address, when the message was sent, and whether it was delivered, bounced or (where available) opened.
3.6 Marketing information. If you subscribe to updates, we record your email address, your subscription preferences and whether you have opened or clicked our emails.
4. Sensitive information
We do not seek and do not want sensitive information — that is, information about a person's health, racial or ethnic origin, political opinions or associations, religious or philosophical beliefs, trade union membership, sexual orientation or practices, criminal record, or biometric information.
Please do not enter sensitive information into free-text fields such as line-item descriptions, notes or attachments. Tax file numbers, other government identifiers, payment card numbers, passwords and login credentials are not "sensitive information" as the Privacy Act defines it, but they should never be entered into those fields either.
If any of this is entered anyway, we will not use it for any purpose other than storing and displaying the document you created, and we may delete it.
5. How we collect personal information
5.1 Directly from you — when you create an account, enter information into the Service, upload a file, contact us, or subscribe to updates.
5.2 From your use of the Service — automatically, through cookies, server logs and analytics, as described in clause 11.
5.3 From other people — most commonly, when an InvoiceGen user enters their client's details into an invoice. If you have received an invoice generated through InvoiceGen, we did not collect your details from you; the sender entered them.
Because we collect that information from someone else, we take reasonable steps to make sure you know about it: every document generated through InvoiceGen carries a link to this policy, and this policy tells you who we are, why we hold your information, who we disclose it to, and how to access, correct or complain about it. You can also ask us directly at any time.
5.4 Unsolicited personal information. If we receive personal information that we did not ask for — for example, in an attachment you upload or an email you send us — and we could not have collected it under APP 3, we will destroy or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.
6. Do you have to identify yourself?
You can browse invoicegen.com.au without telling us who you are, and you can make a general enquiry anonymously or under a pseudonym.
You cannot use an InvoiceGen account anonymously. We need a working email address to create your account, secure it, let you recover it, and send you the notices our Terms of Service require.
If you do not give us the information marked as required, we may not be able to create your account, generate a document, or answer your enquiry.
7. Why we collect, hold, use and disclose personal information
We use personal information for the following purposes, and for purposes related to them that you would reasonably expect:
| Purpose | What this involves |
|---|---|
| Providing the Service | Creating and securing your account, generating invoices and quotes, storing your documents, and delivering them to the recipients you nominate. |
| Supporting you | Answering your questions, troubleshooting, and restoring access to your account. |
| Keeping the Service secure | Authenticating logins, detecting and preventing fraud, abuse, spam and unauthorised access, and investigating suspected breaches of our Terms of Service. |
| Maintaining and improving the Service | Diagnosing faults, monitoring performance and reliability, and understanding which features are used so we can improve them. We do not use your invoice or client data to train artificial intelligence or machine learning models. |
| Producing anonymised statistics | Creating aggregated, de-identified statistics about how InvoiceGen is used — for example, average invoice values across all users — which we may use and publish. These do not identify you, your business or any individual, and cannot reasonably be re-identified. |
| Communicating with you | Sending service messages you cannot opt out of while you hold an account — security alerts, changes to our terms, and notices about your account. |
| Marketing | Sending you product news and tips, if you have consented or would reasonably expect it. You can opt out at any time — see clause 12. |
| Meeting our legal obligations | Responding to lawful requests, keeping records we are required to keep, and establishing, exercising or defending legal claims. |
We do not use personal information to make decisions that have a legal or similarly significant effect on anyone — see clause 14.
8. Who we disclose personal information to
We do not sell, rent or trade personal information, and we do not disclose it to third parties for their own marketing.
We disclose personal information to:
8.1 Service providers who help us run InvoiceGen, and only so they can perform that function for us:
| What they do | Where they are |
|---|---|
| Hosting the Service, its database and its encrypted backups | Sydney, Australia |
| Sending transactional email on our behalf — invoices, quotes, password resets and account notices. This necessarily includes the recipient's email address and the contents of the message, which the provider transmits and retains briefly in its delivery logs. | United States |
| Website and product analytics — Google Analytics 4 (Google LLC / Google Australia Pty Ltd) | United States |
We require these providers to protect personal information, to use it only for the purpose we engaged them for, and not to use it for their own purposes.
8.2 Recipients you nominate. When you send an invoice or quote, we deliver it to the email address you give us, on your instruction.
8.3 Our professional advisers — such as lawyers, accountants and auditors — where reasonably required, and on a confidential basis.
8.4 Where the law requires or permits it — including to a court, a regulator, a law enforcement agency, the Australian Taxation Office or the Office of the Australian Information Commissioner, in response to a lawful request; or where we reasonably believe disclosure is necessary to prevent a serious threat to life, health or safety, or to investigate unlawful activity.
8.5 A buyer or successor, if our business or the InvoiceGen product is sold, merged or restructured. We will require the recipient to handle personal information in accordance with this policy, and we will tell you if your information becomes subject to a different policy.
9. Where your information is stored, and when it goes overseas
Your account, your invoices and quotes, and your clients' details are stored at rest in our database and backups on servers located in Sydney, Australia. That is where the record of your data lives, and we do not replicate it to servers outside Australia.
Some personal information is nonetheless disclosed to service providers outside Australia, as clause 8.1 sets out. Specifically:
- Email you send through the Service. When you email an invoice or quote, a copy of that message — including the recipient's name and email address and the contents of the document — is transmitted through our email delivery provider in the United States, and is retained briefly in that provider's delivery and diagnostic logs. If you would rather this did not happen, download the document and send it yourself.
- Website and product analytics. Google, in the United States, receives the technical and usage information described in clause 3.4.
Before disclosing personal information to an overseas recipient, we take steps that are reasonable in the circumstances to ensure the recipient does not breach the Australian Privacy Principles — principally by contract, and by choosing providers with recognised security and privacy practices. We do not rely on your consent to send your information overseas, and we remain accountable for it under APP 8.1.
10. How we store and protect personal information
We hold personal information in electronic form only, in a hosted database and file store located in Sydney, Australia. We do not keep paper records of it.
The steps we take to protect it include:
- encryption in transit (TLS/HTTPS across the whole Service) and encryption at rest;
- passwords stored using a one-way hash — we cannot read your password, and neither can anyone who obtains our database;
- access controls, so that our people can access personal information only where they need it to do their job, and only through authenticated accounts;
- network and application-level protections, logging and monitoring;
- regular backups, held in Australia and encrypted; and
- keeping our software and dependencies patched.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, and you play a part too: use a strong, unique password, do not share your login, and tell us at contact@invoicegen.com.au if you think your account has been accessed without your authorisation.
11. Cookies, analytics and our website
11.1 Cookies we need. We use cookies that are essential to the Service — to keep you signed in, to remember your preferences, and to protect against cross-site request forgery. The Service will not work properly without them.
11.2 Analytics. We use Google Analytics 4 to understand how people find and use our website and the Service. Google Analytics sets a persistent identifier in your browser and processes your IP address, and that identifier may be personal information. We use the results in aggregate — to see which pages and features are used and where they break — and we do not use Google Analytics to identify you personally or to build a profile about you.
You can opt out of Google Analytics across all websites by installing Google's browser add-on at https://tools.google.com/dlpage/gaoptout, or by blocking cookies in your browser. Google's own handling of this information is governed by its privacy policy at https://policies.google.com/privacy.
11.3 Server logs. Our servers record standard technical information about each request, including IP address, timestamp and the page requested, for security, diagnostics and abuse prevention.
11.4 Do Not Track. Browsers vary in how they signal Do Not Track and there is no agreed standard, so we do not currently respond to those signals. Blocking or deleting cookies in your browser is effective.
11.5 Other websites. Our website links to other sites we do not control. This policy does not apply to them; check their own privacy policies.
12. Direct marketing
We will only send you marketing about InvoiceGen where you have asked for it, or where you hold an account and would reasonably expect to hear from us about the product.
Every marketing email includes a working unsubscribe facility. Once you unsubscribe, we will not send you another marketing message more than 5 working days later, as the Spam Act 2003 (Cth) requires — in practice we action unsubscribes immediately. You can also email contact@invoicegen.com.au and ask us to stop, or ask us how we got your address, and we will tell you.
Opting out of marketing does not stop service messages — security alerts, changes to our terms, and notices about your account — which we will keep sending you while you hold an account. We do not use or disclose personal information for the direct marketing purposes of any other organisation.
13. Accessing, correcting and deleting your information
13.1 In your account. If you hold an InvoiceGen account, you can view and correct most of your information, and your clients' details, directly in the Service at any time. You can also export your data at any time, free of charge.
13.2 Requesting access. You can ask us for a copy of the personal information we hold about you by emailing contact@invoicegen.com.au. We will ask you to verify your identity, and we will respond within 30 days. We do not charge for making a request, and we do not charge for giving you access.
We will give you access in the form you ask for where it is reasonable to do so. If we refuse access — which we may do only on the grounds set out in APP 12, for example where giving access would unreasonably affect another person's privacy — we will tell you in writing why, and how to complain.
13.3 Correction. If information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, tell us and we will correct it, free of charge. If we disagree, we will tell you why, and you can ask us to attach a statement to the record noting that you consider it inaccurate.
13.4 Deleting your account. You can delete your account and your data at any time from within the Service, or by asking us. Clause 15 explains what happens next.
13.5 If you received an invoice from an InvoiceGen user. The business that sent it holds the record and can change or delete it immediately, so contacting them first is usually quickest — and you may need to deal with them anyway about the invoice itself.
You are also entitled to come straight to us. Email contact@invoicegen.com.au and we will handle your access, correction or deletion request ourselves, within 30 days, free of charge. Where the information sits inside a document belonging to a user, we may need to contact that user to action it, and there are limited circumstances in which we may not be able to delete it — for example, where the user needs the record to meet their own tax record-keeping obligations. If that happens we will tell you why, in writing, and what your options are.
14. Automated decision-making
We do not use computer programs, artificial intelligence or automated processes to make decisions about you that could reasonably be expected to significantly affect your rights or interests.
Some parts of the Service are automated in a routine way — for example, spam and abuse detection, arithmetic such as GST calculations, and closing an account that has been dormant for 12 months after we have sent two warning emails. Any decision to suspend or close an account for breach of our Terms of Service is reviewed by a person before it takes effect.
If this changes, we will update this policy before the change takes effect.
15. How long we keep personal information
We keep personal information only for as long as we need it, and then destroy it or de-identify it, as APP 11.2 requires.
| Information | How long we keep it |
|---|---|
| Account information, invoices, quotes and client details | While your account is open |
| Inactive accounts | If you do not log in for 12 consecutive months, we email you twice — 30 days and 7 days beforehand — and may then close the account. Closure starts the 30-day window below. |
| After you delete your account, or it is closed | 30 days, so you can ask us for an export, then permanent deletion from our active systems. We cannot promise to restore a deleted account, so export before you delete. |
| Encrypted backups | Up to a further 90 days, after which backup copies are overwritten |
| Support and email correspondence | 2 years from the last message in the conversation |
| Server, security and delivery logs | 12 months |
| Marketing subscriber records | Until you unsubscribe, plus a suppression record of your email address kept indefinitely so we do not email you again |
| Anything we must keep by law | For the period the law requires, and no longer |
We may also retain information for longer where it is needed to establish, exercise or defend a legal claim, or where a regulator or court requires it. Where we do, we isolate it and stop using it for any other purpose.
Your own records. Deleting your InvoiceGen account deletes your invoices from our systems. The Australian Taxation Office generally requires businesses to keep records explaining their transactions for at least five years from the date the record was prepared or obtained, or the transaction completed, whichever is later — and longer for some records, such as those relating to capital gains tax assets. Export and keep your own copies before you delete.
16. Data breaches
We maintain a data breach response plan. If we become aware of unauthorised access to, unauthorised disclosure of, or loss of personal information we hold, we will contain it and assess it. Where we suspect an eligible data breach may have occurred, we will complete that assessment within 30 days of becoming aware of the grounds for suspicion, as section 26WH of the Privacy Act 1988 (Cth) requires.
An eligible data breach occurs where there is unauthorised access to, unauthorised disclosure of, or loss of personal information, and a reasonable person would conclude that it would be likely to result in serious harm to any of the individuals to whom the information relates. If that happens, we will notify the affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act.
Where a breach involves your clients' information, we will also notify you, promptly and with enough detail for you to meet any obligation you have to them.
17. Complaints
If you think we have mishandled your personal information, or breached the Australian Privacy Principles, please tell us first — most issues are quickest to fix directly, and the OAIC will normally expect you to have given us a chance to respond.
Email: contact@invoicegen.com.au Post: Privacy Officer, Venture Drake Pty Limited, Ground floor/44 North Ft Rd, Manly NSW 2095
Please describe what happened and how you would like it resolved. We will acknowledge your complaint within 5 business days, investigate it, and give you a written response within 30 days. If we need longer, we will tell you why and agree a new timeframe with you.
If you are not satisfied with our response, or we do not respond within 30 days, you can complain to the Office of the Australian Information Commissioner (OAIC). A complaint should generally be made within 12 months of when you became aware of the issue.
- Online: https://www.oaic.gov.au/privacy/privacy-complaints
- Phone: 1300 363 992
- Post: GPO Box 5288, Sydney NSW 2001
18. Changes to this policy
We may update this policy as our practices or the law change. The current version is always at https://invoicegen.com.au/privacy-policy/ and the "Last updated" date at the top tells you when it last changed. We keep previous versions and will provide one on request.
If we make a change that materially affects how we handle your personal information, we will give you at least 30 days' notice by email or through the Service before it takes effect.
19. Contact us
Privacy Officer Venture Drake Pty Limited (ABN 59 159 237 126), trading as InvoiceGen Ground floor/44 North Ft Rd, Manly NSW 2095 Email: contact@invoicegen.com.au Web: https://invoicegen.com.au