Privacy Policy

Last updated: 27 July 2025

Supplemental update: 17 February 2026 — Additional disclosures added for UK HMRC integrations (including Making Tax Digital for Income Tax Self Assessment) and a layered “key privacy information” summary, plus security incident reporting and breach notification information, and a purpose-to-lawful-basis mapping for UK GDPR/EEA GDPR transparency.

Key privacy information

This Privacy Policy is a layered notice. The sections at the top summarize how we handle personal information in Invoice24 (i24) AKA !24 free. Additional region-specific rights information appears further below.

This policy covers the Invoice24 software and services (including web and mobile apps), and (where enabled) features that connect to third parties such as payment processors and UK HMRC integrations (including Making Tax Digital for Income Tax Self Assessment (MTD ITSA)).

Who we are

Invoice24 (i24) is provided by i24 Limited. For the personal information described in this Privacy Policy, i24 Limited is generally the data controller (or equivalent) and is responsible for protecting that personal information. You can contact us using the details in the “How to Contact Us” section at the bottom of this page.

Personal information we process

Depending on how you use the Services, we may process the following categories of personal information (some of which may relate to your customers, suppliers, or other third parties if you upload that data into the Services):

  • Account and profile data (for example, name, email address, phone number, password (hashed), and authentication/security details such as multi-factor authentication information).
  • Billing and subscription data (for example, plan selection, billing address, payment status, and transaction references). Payment card processing is typically handled by our payment partners rather than stored by us.
  • Invoice and business records data you choose to create, upload, import, or store in the Services (for example, invoices, line items, contact details for your customers, suppliers, or contractors, notes, attachments, and activity history).
  • Communications and support data (for example, messages you send us, support tickets, and feedback).
  • Device, usage, and log data (for example, IP address, timestamps, device/app/browser details, diagnostic logs, and security events).
  • Marketing preferences (for example, opt-in/opt-out choices and communication settings).

How we use personal information

We use personal information to provide and operate the Services; process subscriptions and payments; secure accounts and prevent fraud/abuse; provide customer support; communicate service-related messages; and improve and develop the Services. Where required, we will obtain consent for specific processing (for example, certain marketing communications).

Lawful bases

Where UK GDPR/EEA GDPR apply, we process personal information only where we have a lawful basis. Depending on the context, this may include: (a) your consent, (b) performance of a contract with you / steps at your request, (c) compliance with a legal obligation, and/or (d) legitimate interests (for example, to keep the Services secure and prevent fraud), balanced against your rights.

Purposes and lawful bases (UK/EEA)

The table below provides a practical mapping between common processing activities, the types of personal information involved, why we process it, and the lawful basis we rely on (where UK GDPR/EEA GDPR apply). The exact lawful basis can vary depending on your use of the Services and the specific context.

Processing activityExamples of dataWhy we do itTypical lawful basis
Create and manage your accountAccount/profile data, authentication details, contact detailsProvide the Services and enable accessPerformance of a contract / steps at your request
Deliver core product featuresInvoice and business records data, activity historyGenerate and manage invoices and related recordsPerformance of a contract / steps at your request
Process subscriptions and paymentsBilling/subscription data, transaction referencesBill for the Services, manage subscriptions, prevent payment fraudPerformance of a contract; legitimate interests; legal obligation (where applicable)
Customer support and communicationsCommunications and support data, account identifiersRespond to queries, troubleshoot issues, communicate service messagesPerformance of a contract; legitimate interests
Security, fraud prevention, and abuse detectionDevice/usage/log data, security events, IP address, timestampsKeep the Services safe, detect and prevent fraud, enforce policiesLegitimate interests; legal obligation (where applicable)
Improve and develop the ServicesUsage data, diagnostic logs, feedback (where provided)Fix bugs, improve reliability and featuresLegitimate interests; consent (where required)
Marketing communications (where enabled)Contact details, marketing preferencesSend product updates and offers (you can opt out)Consent (where required); legitimate interests (where permitted)
Comply with legal/regulatory requirementsBilling records, audit/security logs, account identifiersMeet legal obligations, respond to lawful requests, maintain required recordsLegal obligation
HMRC-connected features (UK), where you choose to use themData you instruct us to submit, submission metadata/status, HMRC-required audit dataEnable HMRC integration and transmit/receive information with HMRCPerformance of a contract / steps at your request; legal obligation (where applicable); legitimate interests (security)

Who we share personal information with

We may share personal information with:

  • Service providers that help operate the Services (for example, hosting, storage, customer support tooling, email delivery, security monitoring), under contractual safeguards.
  • Payment processors (for example, Stripe) when you enable payment-related features, to process transactions and help prevent fraud.
  • Government authorities and regulators where required by law or where needed to respond to valid legal process.
  • HM Revenue and Customs (HMRC) when you connect and use HMRC-related features (see the “HMRC and Making Tax Digital (UK)” section below).

International transfers

We may process or store personal information in countries other than the country where you live. Where required, we use appropriate safeguards for international transfers (for example, contractual protections and security measures) and limit access on a need-to-know basis.

Security

We implement reasonable administrative, technical, and organizational security measures designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure. As the controller (or equivalent) for personal information we handle as described in this Privacy Policy, we are responsible for implementing appropriate measures to protect that information. However, no method of transmission or storage is completely secure.

Security incident reporting

If you believe you have found a security vulnerability, suspect unauthorised access to an Invoice24 account, or believe Invoice24 data may have been exposed, please report it as soon as possible by emailing hello@i24app.com with the subject line “Security Incident”. Please include sufficient detail to help us investigate (for example, the affected account email, relevant dates/times, and a description of what you observed).

Where we become aware of any issue concerning the security of personal or customer data in connection with HMRC integrations (including Making Tax Digital for Income Tax Self Assessment (MTD ITSA)), we will report it to HMRC within 72 hours by contacting SDSTeam@hmrc.gov.uk, and will provide a breach contact name and telephone number.

Where a personal data breach is reportable under applicable data protection law (including UK GDPR), we will notify the UK Information Commissioner’s Office (ICO) without undue delay and, where feasible, within 72 hours of becoming aware of it. If a breach is likely to result in a high risk to individuals’ rights and freedoms, we will also notify affected individuals without undue delay.

HMRC and Making Tax Digital (UK)

If you use features that connect Invoice24 to HMRC (including features designed to support Making Tax Digital for Income Tax Self Assessment (MTD ITSA)), we will process additional data to enable those features.

Authorisation and HMRC sign-in details: HMRC authorisation is designed so that you authenticate directly with HMRC and grant authority for specific scopes. We do not need you to provide your HMRC username and password to us in order to use HMRC-connected features.

Data you ask us to send to HMRC: This may include information you provide or generate in the Services that you instruct us to transmit to HMRC (for example, summaries, updates, and submission metadata/status information returned by HMRC).

Fraud prevention and audit data: When using certain HMRC APIs (including MTD-related APIs), HMRC requires software providers to submit specific user audit data (fraud prevention header data). To provide these HMRC-connected features, Invoice24 may collect and transmit to HMRC certain technical and contextual information (for example, device/app/browser details, timestamps, network and connection information, identifiers, and similar audit data required by HMRC specifications).

This data is used for transaction monitoring and fraud prevention and may be legally required for certain HMRC API requests. Missing or incorrect data may cause HMRC-connected features to fail.

Information Retention

We keep personal information for as long as needed to provide the Services, comply with legal or regulatory obligations, resolve disputes, enforce agreements, and protect the security and integrity of the Services. Retention periods vary depending on the type of data, how it is used, and applicable legal requirements.

If you request deletion (or delete information within the Services where available), we will take reasonable steps to delete personal information within a reasonable time, subject to required or permitted retention (for example, billing records, fraud prevention, security logs, and legally required recordkeeping).

Complaints

If you have concerns about how we use personal information, you can contact us using the details below. Depending on where you live, you may also have the right to lodge a complaint with a relevant data protection supervisory authority.

What you can do to manage your privacy

When it comes to controlling the privacy of your personal information, you have options.

  • Update your privacy settings. By going to your account settings, you can modify your privacy settings.
  • Manage marketing communications from us. You can use the marketing preference tools in your account settings to adjust your preferences for marketing communication.
  • Access or Deletion. Contact us using the link provided in the "How to Contact Us" section for Australia below to request access to or deletion of your personal information.
  • Correct your personal information. By making changes directly in our goods and services, you can modify and correct your personal information whenever you choose.
  • Objection and Restriction. Contact us using the link provided in the "How to Contact Us" section for Australia below to object to data processing or request a restriction.

Brazil

Sharing with Credit Bureaus

We won't be able to give you any more customised recommendations based on your credit profile if you live in Brazil and have requested to have your registration cancelled on each of our partners as permitted by Brazilian Federal Law No. 12,414/2011.

If you are a resident of Brazil, you may have the following rights:

  • Access, Correction, Anonymization or Deletion. Your personal information can be requested for access, correction, anonymization, or deletion.
  • Objection and Restriction. You have the option to ask us to stop processing your personal information or to limit how we can use it.
  • Portability. You can request portability of your personal information.
  • Withdraw Consent. You have the right to withdraw your permission at any time if we gathered and processed your personal information with your consent. Withdrawing your consent has no effect on the lawfulness of any processing we performed previous to your withdrawal, nor on processing of your personal information performed in reliance on legitimate processing grounds other than consent.
  • File a complaint. You have the right to lodge a complaint with a supervisory authority over our acquisition and use of your personal information.

To exercise any of your rights, please contact us at the link provided below in the "How to Contact Us" section for Brazil.

What you can do to manage your privacy

When it comes to managing the privacy of your personal information, you have options.

  • Update your privacy settings. You may change your privacy settings by going to your account settings.
  • Manage marketing communications from us. You can adjust your marketing communication options in your account settings by going to the marketing preference tools.
  • Correct your personal information. You can change your personal information in our goods and services at any time to modify and amend it.
  • Request a copy of your personal information. You can obtain a copy of your personal information by contacting us via the link provided in the "How to Contact Us" section for Brazil below.
  • Delete your personal information. You may request that we erase your personal information by contacting us via the link provided below in the "How to Contact Us" section for Brazil.
  • Objection, Restriction & Portability. You may request objection, limitation, and portability rights by contacting us using the link provided below in the "How to Contact Us" section for Brazil.

Canada

While we take precautions to secure your personal information, it may be revealed in response to valid demands or requests from governments, regulators, courts, and law enforcement officials in those other territories or nations.

If you are a resident of Canada, you may have the following rights:

  • Access, Correction or Deletion. You have the right to request access to, modify, or remove your personal information (provided we no longer have a business need to retain your personal information). Even if you request that your personal information be deleted, we may retain certain aspects in order to: meet our legal or regulatory compliance (for example, maintaining records of transactions you have made with us); exercise, establish, or defend legal claims; and protect against fraudulent or abusive activity on the i24 Platform. Data retained for these purposes will be handled in accordance with the guidelines outlined in "Information Retention."
  • Withdraw consent. You have the right to withdraw your consent to the collection, use, and dissemination of your personal information at any time. Withdrawing your consent has no effect on the lawfulness of any processing we performed previous to your withdrawal, nor on processing of your personal information performed in reliance on legitimate processing grounds other than consent.
  • File a complaint. You have the right to file a complaint with the appropriate Privacy Commissioner regarding our collection and use of your personal information.

What you can do to manage your privacy

When it comes to managing the privacy of your personal information, you have options.

  • Update your privacy settings. You can change your privacy settings by going to your account settings.
  • Manage marketing communications from us. You can adjust your marketing communication options in your account settings by going to the marketing preference tools. You can also unsubscribe by clicking the unsubscribe link at the bottom of marketing emails.
  • Cookies and other tracking technologies. By visiting the Digital Advertising Alliance of Canada Opt-Out Page, NAI Opt-Out Page and the Choices Opt-Out Page., you may be able to opt-out of interest-based advertising.
  • Correct your personal information. You can change your personal information in our goods and services at any time to modify and amend it.
  • Request a copy of your personal information. You can obtain a copy of your personal information by contacting us via the link provided in the "How to Contact Us" section for Canada below.
  • Delete your personal information. You can ask us to erase your personal information by contacting us via the link provided in the "How to Contact Us" section for Canada below.

India

Where Indian individuals' data is involved, you hereby agree that "reasonable security practises and procedures" under section 43A Explanation (ii) of the Information Technology Act, 2000 means this i24's Privacy Statement and such data security procedures as i24 may implement from time to time and as i24 may inform you of from time to time.

What you can do to manage your privacy

When it comes to managing the privacy of your personal information, you have options.

  • Update your privacy settings. You can change your privacy settings by going to your account settings.
  • Manage marketing communications from us. You can adjust your marketing communication options in your account settings by going to the marketing preference tools.
  • Correct your personal information. You can change your personal information in our goods and services at any time to modify and amend it.

Mexico

If you are a resident of Mexico, you may have the following rights known as “ARCO rights”:

  • Access. You have the right to know what personal information we hold about you, how we use it, and under what conditions we use it. If you exercise your right of access, you will be sent electronic copies of your personal data.
  • Rectification. You have the right to request that your personal data be corrected if it is outdated, incorrect, or incomplete (Rectification).
  • Deletion/Cancellation. You have the right to request that we remove your personal information from our records or databases if you believe it is being used in violation of the applicable laws' principles, duties, and obligations.
  • Opposition/Rejection. You have the right to object to the use of your personal information for certain purposes.

What you can do to manage your privacy

When it comes to managing the privacy of your personal information and exercising your ARCO rights, you have options. Please keep in mind that we must validate your request before executing your rights. After we receive a request, we will respond with whether the request for access, rectification, cancellation, or opposition is appropriate, and if so, we will make a determination within 15 business days after that date. The deadlines may be extended in accordance with the conditions of the applicable laws.

  • Update your privacy settings. You can change your privacy settings by going to your account settings.
  • Manage marketing communications from us. You can adjust your marketing communication options in your account settings by going to the marketing preference tools.
  • Correct your personal information. You can change your personal information in our goods and services at any time to modify and amend it.
  • Request a copy of your personal information. You can obtain a copy of your personal information by contacting us via the link provided in the "How to Contact Us" section for Mexico below. Please give a clear and exact description of the personal data you seek to access, as well as any additional element that aids the location of your data, when making a request.
  • Delete your personal information. You can ask us to erase your personal information by contacting us via the link provided in the "How to Contact Us" section for Mexico below. Please include a clear and exact description of the personal data you desire to delete/cancel, as well as any other element that helps the location of your data, when making a request.
  • Objection. You may request objection, limitation, and portability rights by contacting us using the URL provided below in the "How to Contact Us" section for Mexico. Please include a clear and accurate description of the personal data you intend to oppose, as well as any other element that helps the location of your data, when making a request.

How to limit the use and disclosure of your personal information

If you are a Mexican resident, you may also limit the use or disclosure of your personal information by contacting us via the link provided in the "How to Contact Us" section for Mexico, below.

How to withdraw your consent

If you are a Mexican resident, you may also limit the use or disclosure of your personal information by contacting us via the link provided in the "How to Contact Us" section for Mexico, below.

United Kingdom and EEA

UK and EEA Legal Representative

i24 Inc.'s UK and EEA representatives are:
In the United Kingdom: i24 Ltd.; contact information for i24 Ltd. can be found in the "How to Contact Us" section below.

Legal Basis of Processing

The type of personal information and the exact context in which we acquire it will determine our legal justification for collecting and processing the personal information detailed in this Privacy Statement. However, we will generally process your personal information when:

We have your permission to do so; we have a contract with you, and it is necessary to process your personal information in order to perform our contract with you, including providing you with the benefits of the i24 Platform and running our business; we have your consent to do so; we have a contract with you; we have a contract with you; we have a contract with you

The processing is necessary for us to operate our operations, improve and grow the i24 Platform, communicate with you, sell our offers and services, and personalise your experience, as well as detect criminal activity; and/or To adhere to legal obligations, such as applicable laws and regulations.

We may share your personal information, including your contact details, date of birth, and the information you give us about your employment, income, and housing and employment expenses, with third parties to determine your eligibility for a credit card or a personal loan through the i24 Platform. You can find more information about their data protection practises in their privacy policies by contacting us at hello@i24app.com.

If you are a resident of the UK or EEA, you may have the following rights:

  • Access, Correction or Deletion. You have the right to request access to, modify, or remove your personal information. Please keep in mind that even if you request that your personal information be deleted, certain aspects may be retained in order for us to: meet our legal or regulatory compliance (for example, by keeping records of transactions you have made with us); exercise, establish, or defend legal claims; and protect against fraudulent or abusive activity on our Service. Data retained for these purposes will be handled in accordance with the procedures outlined in the section "Information Retention."
  • Objection and Restriction. You have the right to object to our processing of your personal information or to request that we limit our processing of your personal information.
  • Portability. You can request portability of your personal information.
  • Withdraw Consent. You have the right to withdraw your consent at any time if we treat your personal information with your consent. Withdrawing your consent has no effect on the lawfulness of any processing we performed previous to your withdrawal, nor on processing of your personal information performed in reliance on legitimate processing grounds other than consent.
  • File a complaint. You have the right to lodge a complaint with a supervisory authority over our collection and use of your personal information.

What you can do to manage your privacy

When it comes to managing the privacy of your personal information, you have options.

  • Update your privacy settings. You can change your privacy settings by going to your account settings.
  • Manage marketing communications from us. To change your marketing communication preferences, go to the bottom of the marketing emails and click unsubscribe.
  • Request a copy of your personal information. You can get a copy of your personal information by emailing hello@i24app.com.
  • Correct your personal information. You can change your personal information in our goods and services at any time to modify and amend it.
  • Delete your personal information. You can ask us to erase your personal information by emailing us at hello@i24app.com.
  • Cookies and other tracking technologies. By visiting Network Advertising Initiative or Your Online Choices you may be able to opt out of such interest-based advertising.

How to Contact Us

If you have any questions or concerns concerning this Privacy Statement or our practises, please write to i24 Limited,

20 Bankside, Station Approach, Kidlington, OX5 1JE, UK.

Alternatively, you can contact us by email at hello@i24app.com.