Legal

Privacy policy

Acquitonline is invoicing software for small businesses. This policy explains what we collect, why we have it, who else touches it, and how you get it back or get rid of it.

Who we are, and the two hats we wear

Acquitonline is operated by The Blue Agency, in Quebec, Canada. You can reach us at hello@acquitonline.com. In this policy, “we” is The Blue Agency and “the app” is the Acquitonline product at app.acquitonline.com.

We handle personal information in two different roles, and the difference decides who you should ask about what.

For the people who sign up — business owners and the team members they invite — and for visitors to this website, we decide why and how the information is used. We are responsible for it directly.

For the information a business enters about its own clients, the business decides. We only hold and process that information so the business can invoice with it. If you are a client of a business that invoices through Acquitonline and you want your details corrected or removed, ask that business first; we will help them do it, and we will act on a request sent straight to us where the law requires.

What we collect

We collect what invoicing needs and what keeps the service standing up. Nothing is bought from data brokers, and nothing is collected for advertising.

Your account
Your name, your email address, the language you prefer, and a password. The password is handled by our authentication provider and stored only as a hash — we never see or store the password itself.
Your business
Legal name, address, phone number, website, GST and QST registration numbers, logo and accent colour, payment terms, tax rates, numbering rules, and the offline payment instructions you choose to publish on your invoices.
Your clients, as you enter them
Client name, contact name, email address, phone number, billing address, language, currency, payment terms and any notes you add. You choose what to put here; we hold it for you.
Invoices and money
Invoice numbers, dates, line descriptions, quantities, amounts, discounts, the tax rates as they stood the day you sent the document, payments and refunds, the method used, and the payment processor's own reference for a card or bank-debit payment. A payer's card or bank details never reach us at all — they go straight to the processor. The one exception is in your own hands: the offline payment instructions you choose to publish are free text, so whatever banking details you put there are stored as you typed them and printed on your invoices, because that is what they are for.
Who did what
A log of actions taken in your account — who sent, voided, refunded or changed something, and when. It exists so an incident can be reconstructed. It is kept for as long as the business exists, and it is erased with the business.
Email we send for you
Every invoice, reminder and receipt is queued with its recipient address, its language and the values printed in it, so a failed send can be retried and so you can see what went out. We also record the delivery outcome our email provider reports back, including a bounce.
Technical information
Your IP address, used to rate-limit sign-in attempts, sign-ups, form submissions and payments, and to run the bot check. We do not write it into our own invoicing tables — it is a short-lived counter key that expires on its own — and it is never used to profile you. Two other places do hold it: our authentication provider keeps its own record of sign-in activity, as such a service does, and our diagnostic records of security events, such as a refused sign-in, carry the address the attempt came from. Payment links are stripped from all of those before they are written.
This website's contact form
Your name, business name, email address, an optional phone number, the topics you tick and your message. It is emailed to us and answered by a person. It is not stored in a database and it does not sign you up for anything — no newsletter, no list.

Why we use it

To give you the service you signed up for: to build, number, send and track invoices, to take payments, to issue subscription invoices on schedule, to send reminders, and to keep your team's access correct.

To keep the service safe and working: to rate-limit abuse, to verify that a form submission comes from a person, to detect and fix faults, and to keep an operational record of security-relevant events.

To answer you when you write to us.

To meet obligations the law puts on us, such as responding to a valid legal demand.

Under Quebec and Canadian privacy law we rely on your consent, on what is necessary to provide a service you asked for, and — for the security uses above — on our legitimate interest in keeping the service available and uncompromised. We do not sell personal information, we do not rent it, and we do not use it to train machine-learning models.

Cookies

We use cookies that are necessary to run the app. We do not use advertising cookies, and we do not run an analytics tracker on either the app or this website. This website sets no cookies at all.

The app's own cookies, and the one third-party pair a payment page causes, are the complete list:

acquit_session
Your signed-in session. Read by the server only, same-site, and secure in production.
sb-…-auth-token
The access and refresh tokens issued by our authentication provider when you sign in. Read by the server only, same-site, and secure in production.
acquit_recovery
A marker set while you are resetting your password, so the password form can tell it is really you finishing the flow. What it lets you do expires in fifteen minutes; the cookie itself is deliberately kept as long as a sign-in cookie, so that a used reset link cannot quietly become a way in later. Read by the server only, and cleared the moment you sign in or sign out.
lang
Whether you are reading in English or French. It is an ordinary preference rather than a secret, so unlike the three above it is not restricted to the server. It lasts a year and you can clear it in your browser.
__stripe_mid, __stripe_sid
Set by Stripe, not by us, and only on the public payment page when a business has online payments connected — that page loads Stripe's own script to collect the card details we never see. They are Stripe's fraud-prevention cookies and are governed by Stripe's privacy policy.

Who else processes it

We use a small number of service providers to run Acquitonline. Each one only gets what its job needs, each is bound by its own contract to process it on our instructions, and the list is exhaustive — if a provider is not below, it is not in the path.

Supabase
Our database and authentication. Holds your account, your business, your clients and your invoices. The database runs in the AWS ca-central-1 region, in Canada.
Vercel
Hosts and serves the app and this website. Sees the requests your browser makes, including your IP address.
Stripe
Takes card and bank-debit payments on the public payment page. Your client's payment details go straight to Stripe and never reach our servers; we keep only Stripe's reference for the payment, its amount and its status. Payments land in your own connected Stripe account, not in ours.
Resend
Delivers the invoices, reminders and receipts you send, and reports back whether they arrived; it also carries this website's contact form to us. Sees the recipient's address and the wording of the message. The invoice PDF is not attached to it: the message carries a link, and the document is built and sent when your client opens it.
Upstash
A Redis store that holds rate-limit counters. Sees an IP address, or an IP address paired with a keyed hash of an email address — never the address itself — as a short-lived counter key that expires on its own.
Sentry
Error diagnostics, enabled only when we configure it. What goes there is a fault, the code path it came from and a little context. Payment links are stripped out before anything is written, to Sentry or to our own logs — and we claim no more of that scrubber than that: a record of a security event, such as a refused sign-in, deliberately carries the IP address it came from.
Cloudflare
Runs the Turnstile bot check, when it is configured: on sign-up, sign-in and the password-reset request, on this website's contact form, and on the public payment page before a card is charged. Sees the challenge response and the IP address making the request — including your client's, on that last one.
GitHub
Holds our scheduled database backup, when one is configured. It is encrypted before it leaves us and GitHub stores only the ciphertext, which it cannot read; each copy is deleted after thirty days.

Where it is stored

Your invoicing data lives in a Canadian database — the AWS ca-central-1 region, near Montreal.

The servers that run the app are not pinned to a single country, and our email, error-reporting, rate-limiting and bot-check providers operate globally. So while your records rest in Canada, requests and the email you send through us may be processed elsewhere, including in the United States, and are then subject to the laws of that place. Where the law requires a transfer assessment before information leaves Quebec, we carry one out.

How long we keep it

While your account is open, we keep your business's records for as long as you want them — an invoice is a document you may need years from now, and it is not ours to expire.

Everything else is shorter by design. Rate-limit counters expire on their own within the window they police, usually minutes to an hour. Payment links expire on the schedule set when the invoice is sent. Sent email records are pruned once they are no longer needed to retry or explain a delivery. Diagnostic records follow our provider's retention, which is measured in weeks, not years.

One email record is deliberately longer than the rest. When a client's mailbox refuses our message for good, or someone reports it as spam, we keep a note of that address so we stop writing to it — sending again would be ignoring an answer we have already been given. That note is kept per business, it is shown to the business beside the address it is about, and it stays until the business tells us the mailbox works again, corrects the address, or deletes its account.

When you delete your account, we do not keep your records for a rainy day. See the next section for exactly what happens.

You are responsible for your own bookkeeping obligations. In Canada, a business must generally keep its books and records for six years. Save what you need before you delete anything — each invoice downloads as a PDF from its own page, and a full copy is a request you can make of us. Once it is deleted we cannot produce it again.

Deleting your account

You can delete your account yourself, from inside the app, without writing to us and without waiting for anyone to approve it. Open Settings, then Account.

If you own the business, you can delete the business and everything in it. That erases, permanently and immediately: your business profile and branding, your tax registration numbers, your tax rates and numbering series, your offline payment instructions, your Stripe connection, every client record, every invoice with its lines and tax snapshots, every subscription, every payment, withholding certificate and refund record, every payment link, every queued or sent email record and every note that an address refused our mail, the who-did-what log of actions taken in the account, your team's memberships, and the sign-in identity of every person whose only account was this business. There is no grace period and no recycle bin — when the confirmation completes, it is gone.

If you are a team member rather than the owner, you can leave the business. Your membership is removed and your sign-in identity is deleted along with it, unless you belong to another business on Acquitonline. The business's own invoices stay with the business, because they are its records and not yours. If you are the last remaining owner, leaving is not available — delete the business instead, or hand ownership to someone else first.

Two honest limits. Payments already taken are also recorded by Stripe, under your own Stripe account and its retention rules; deleting here does not delete there, and you can ask Stripe directly. And where a copy of your data exists in an encrypted operational backup, it is erased when that backup expires rather than the moment you press the button.

You can also write to hello@acquitonline.com and ask us to do it. Asking by email gets the same result as the button; it just takes longer.

Your rights

Quebec's Law 25 and Canada's PIPEDA give you rights over your personal information, and most of them you can exercise yourself inside the app.

If you are outside Canada, the same rights reach you under your own law. Acquitonline accepts sign-ups from businesses in Canada, the United States, the United Kingdom, France, Germany, the United Arab Emirates and Egypt, so for many readers that law is the GDPR or the UK GDPR, which name these rights access, rectification, erasure, portability, restriction and objection. They are exercised the same way: the section above, or an email to us. Your records are held in Canada, which the European Commission recognises as providing an adequate level of protection for personal data handled by organisations subject to PIPEDA.

Know and access
Ask what we hold about you and get a copy of it. Most of it is already on your screen in the app.
Correct
Fix anything inaccurate. Your own details and your business's are editable in Settings.
Delete
Delete your account and your data, as described above, or ask us to do it for you.
Portability
Receive the information you gave us in a structured, commonly used technical format, or have us send it to someone else where the law provides for it. There is no one-click export in the app yet, so this one is a request: write to us and we will produce it.
Withdraw consent
Withdraw your consent at any time, which for a service like this one means closing your account. Withdrawing does not undo what was lawfully done before.
Complain
If our answer does not satisfy you, you can complain to the Commission d'accès à l'information du Québec, or to the Office of the Privacy Commissioner of Canada.

How we protect it

Every request that reaches your business's data has to come through one of three doors, and each door is checked on its own: a signed-in session, a payment link whose secret we store only as a hash, or a signed webhook from a provider we have verified. Access between businesses is refused at the database itself, not merely in the interface.

Traffic is encrypted in transit. Passwords are stored as hashes by our authentication provider. Sign-in, sign-up and password-reset attempts are rate-limited. Payment links never reach a log line or an error report — only their fingerprint is ever stored or printed.

No system is perfect. If a confidentiality incident presents a risk of serious injury, we will notify the Commission d'accès à l'information du Québec and the people affected, as the law requires.

Children

Acquitonline is a tool for businesses and is not directed at children. We do not knowingly collect personal information from anyone under 14. If you believe a child has given us information, write to us and we will delete it.

Changes to this policy

When this policy changes we update the date at the top of the page. If a change materially affects how we use information you have already given us, we will tell account holders by email before it takes effect.

How to reach us

Write to hello@acquitonline.com with anything about this policy, any request about your information, or any complaint. We answer in English or French, and we respond to rights requests within the time the law allows — thirty days under Law 25.

Acquitonline is a product of The Blue Agency, Quebec, Canada.

Back to acquitonline.com