Privacy Policy

Effective date: June 29, 2026

Last updated: June 29, 2026

This Privacy Policy (the "Policy") describes how Lorithmic LLC ("Lorithmic", "we", "us", or "our") collects, uses, stores, shares, and protects information in connection with InvoCert and related services (collectively, the "Service").

Please read this Policy carefully. By using the Service, you agree to the practices described in this Policy.

This Policy should be read alongside our Terms of Service, which governs your use of the Service.

1. Who We Are

InvoCert is operated by Lorithmic LLC, a Wyoming limited liability company.

Lorithmic LLC30 N Gould St, STE 21289Sheridan, WY 82801, USA

For privacy inquiries and data subject requests: [email protected]

For product support: [email protected]

2. Who This Policy Applies To

This Policy applies to:

  • Merchants — individuals and companies who create accounts, manage workspaces, create invoices, and use the authenticated features of the Service.
  • Buyers — individuals and companies who access public payment pages, submit transaction references, or download documents through a public payment page without creating an account.
  • Visitors — individuals who visit invocert.com without creating an account or using the authenticated Service.

3. Information We Collect

3.1 Account and Workspace Information

When you create an account or workspace, we collect:

  • Email address — used for authentication, account security, and Service communications.
  • Password — stored as a cryptographic hash. We never store or have access to your plaintext password.
  • Business name — the name you assign to your workspace.
  • Business country — the country associated with your workspace, selected at creation and fixed after that.
  • Workspace logo — an optional Pro branding asset, collected when logo upload is enabled and you choose to upload one.

3.2 Invoice and Payment Data

When you create invoices or interact with payment pages, we collect and store:

  • Invoice content — buyer name, buyer company name, line items, quantities, unit prices, amounts, due dates, notes, and optional trade details such as purchase order numbers, order references, incoterms, HS codes, country of origin, port of loading, and port of discharge.
  • Wallet addresses — the receiving wallet addresses you configure for your workspace.
  • Transaction references — transaction hashes or other blockchain transaction identifiers submitted for payment verification, whether submitted by a buyer or by you as a merchant.
  • Verification results — the outcome of each verification attempt, including blockchain data retrieved during verification such as transferred amounts, sender addresses, block timestamps, confirmation status, and blockchain explorer links.
  • Payment records — amounts verified as received, timestamps, sender addresses, and related on-chain metadata.

3.3 Subscription and Billing Data

When you subscribe to a Pro plan, we collect and store:

  • Subscription invoice details — selected billing duration, monthly price, gross price, discount amounts, workspace credit applied, amount due, and billing period dates.
  • Subscription payment records — transaction references, on-chain amounts received, timestamps, and blockchain metadata for subscription payments.
  • Workspace credit balance — your running workspace credit balance used to offset future subscription invoices.

We do not collect or store payment card numbers, bank account numbers, or traditional payment credentials. All subscription payments are made in USDT TRC20 directly to our platform wallet on the TRON blockchain.

3.4 Telegram Integration Data

If you connect your workspace to Telegram:

  • Telegram chat ID — stored to enable delivery of invoice activity alerts to your connected Telegram account or bot conversation.
  • Bot interaction data — commands sent to the InvoCert Telegram bot during the workspace connection process.

3.5 Technical and Usage Data

We automatically collect certain technical information when you use the Service. This applies to merchants, buyers accessing public payment pages, and visitors to the website:

  • IP addresses — logged for all requests to the Service, including public payment page visits and transaction reference submissions, for security monitoring, rate limiting, abuse detection, and operational purposes.
  • Session data — session tokens and browser user agent strings, stored for authenticated merchants for authentication, security, and audit purposes. Buyers and visitors do not have authenticated sessions.
  • Operational logs — server-side logs of application events, errors, payment verification outcomes, email delivery results, and payment and status transitions, used for operational monitoring and debugging.
  • Usage data — features used, pages visited, and actions taken within the authenticated Service, used to understand how the Service operates and to maintain and improve it.

3.6 Information Submitted About Third Parties

When you create invoices, you may submit personal data about your buyers, such as their name or company name. You are responsible for ensuring you have a lawful basis to provide that information to us for processing as part of your use of the Service. We process that data on your instructions solely to operate the invoice and payment verification features of the Service. For merchants located in the European Economic Area, the United Kingdom, or Switzerland, the data controller and data processor relationship for buyer data is further described in Section 5.

4. How We Use Information

We use the information we collect to:

  • Provide the Service — create and manage accounts, workspaces, invoices, public payment pages, and subscription billing.
  • Verify transactions — query supported blockchain networks and third-party data providers to verify submitted transaction references against on-chain data.
  • Send notifications — deliver email and Telegram invoice activity alerts, subscription lifecycle emails, account security emails, and platform-level notifications as described in our Terms of Service.
  • Generate documents — produce commercial invoice PDFs, payment receipt PDFs, and subscription invoice PDFs from data stored in the Service.
  • Process subscriptions — manage Pro plan activation, renewal, workspace credit balances, and billing records.
  • Maintain security — authenticate users, detect and prevent fraud, abuse, and unauthorized access, enforce rate limits, and investigate suspicious activity.
  • Comply with legal obligations — respond to lawful government requests, court orders, legal process, and applicable regulatory requirements.
  • Improve the Service — analyze usage patterns, diagnose errors, and develop new features and improvements.
  • Communicate with you — respond to support inquiries and send Service-related communications.

5. Lawful Bases for Processing (GDPR)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, we process your personal data under the following lawful bases under the General Data Protection Regulation (GDPR) and applicable UK and Swiss data protection law:

  • Contract performance — processing necessary to provide the Service to you under our Terms of Service, including account management, invoice operations, payment verification, subscription billing, and document generation.
  • Legitimate interests — processing necessary for our legitimate interests in operating a secure and reliable service, including security monitoring, fraud and abuse detection, service improvement, and internal operational logging, where those interests are not overridden by your data protection rights.
  • Legal obligation — processing necessary to comply with applicable legal requirements, including responses to lawful government requests and regulatory obligations.
  • Consent — where we rely on your consent for a specific processing activity, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.

Merchants as data controllers for buyer data. When you submit personal data about your buyers — such as buyer names or company names — in invoices created through the Service, you are acting as the data controller for that personal data and we act as a data processor, processing that data on your instructions solely to operate the invoice and payment verification features of the Service.

If you require a Data Processing Agreement (DPA) for GDPR compliance purposes, please contact us at [email protected].

6. How We Share Information

We do not sell your personal information.

We do not share your personal information with third parties for advertising, marketing, or behavioral profiling purposes.

We share information in the following circumstances:

  • Service providers — we share information with third-party providers who help us operate the Service, including blockchain data providers, email delivery services, cloud storage providers, hosting providers, and security and monitoring tools. These providers process data only as needed to deliver services to us and are subject to contractual data protection obligations consistent with applicable law.
  • Blockchain networks — when verifying a transaction reference, the transaction identifier is transmitted to blockchain data providers to retrieve publicly available on-chain data. Blockchain transaction data is inherently public and visible to anyone on the network, but we disclose this transmission for transparency.
  • Legal requirements — we may disclose information when required to do so by applicable law, regulation, court order, government request, or legal process, or where we believe disclosure is necessary to protect our legal rights, your safety, or the safety of others.
  • Business transfers — if Lorithmic is involved in a merger, acquisition, reorganization, sale of assets, or change of control, your information may be transferred as part of that transaction. We will notify you of any material change as required by applicable law.
  • With your consent — we may share information for other purposes with your explicit consent.

7. Third-Party Services

The Service relies on third-party services to function. The following third-party providers may receive or process your information as part of normal Service operation:

  • TronGrid — a TRON blockchain data provider used to verify USDT TRC20 payment transactions. Transaction hashes are transmitted to these providers to retrieve on-chain transaction data.
  • Telegram — if you connect your workspace to Telegram, your workspace Telegram chat ID is stored and messages are delivered through the Telegram Bot API. Telegram's privacy policy governs Telegram's own data practices.
  • Email delivery providers — your email address and the content of emails sent to you are transmitted to our email delivery provider to send notifications, subscription emails, and account security emails.
  • Cloud storage providers — S3-compatible storage is used for workspace assets such as logos when that feature is enabled.
  • Hosting and infrastructure providers — all application data is processed and stored on servers operated by our hosting providers.
  • Analytics and security tools — we may use third-party tools to monitor application performance, detect errors, and identify security threats. These tools are used for operational purposes only and are not used for advertising or behavioral profiling.

Each third-party provider is subject to its own terms and privacy policies. We encourage you to review those policies for services you interact with directly.

8. Data Retention

We retain personal information for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements.

Specific considerations:

  • Account and workspace data — retained for the duration of your account and for a reasonable period after account closure, as required for security, legal, and operational purposes.
  • Invoice and payment records — retained for as long as necessary for your business operations, dispute resolution, and legal compliance obligations. The 30-day invoice history filter on the Free plan is a dashboard display filter only and does not delete underlying invoice or payment data.
  • Subscription and billing records — retained for as long as necessary for tax, accounting, audit, and dispute resolution purposes.
  • Session and log data — retained for a limited operational period for security monitoring and debugging purposes.
  • Telegram connection data — retained while your workspace has an active Telegram connection. Removed when you disconnect Telegram or close your account.

When you close your account or submit a data deletion request that we have verified, we will delete or anonymize your personal information in accordance with our retention obligations and applicable law, except where we are required or permitted to retain certain data for legal, tax, audit, fraud prevention, or dispute resolution purposes. We encourage you to export any records you need before closing your account. You can request account closure or data deletion by contacting [email protected].

9. Security

We implement technical and organizational measures designed to protect your information against unauthorized access, disclosure, alteration, or destruction. These measures include:

  • cryptographic hashing of passwords — plaintext passwords are never stored;
  • HTTPS encryption for all data in transit;
  • HttpOnly, Secure, and SameSite cookie protections for session tokens;
  • server-side enforcement of access controls and rate limits;
  • separate authentication systems and session stores for merchant and admin access;
  • logging and monitoring of verification outcomes, payment status transitions, and administrative actions.

No security measure is entirely infallible. We cannot guarantee that your information will never be accessed, disclosed, altered, or destroyed, and we are not responsible for security breaches caused by factors outside our reasonable control.

In the event of a data breach affecting your personal information, we will notify you and applicable regulatory authorities as required by applicable law, including within the timeframes required by GDPR where applicable.

If you believe your account has been compromised or want to report a security concern, contact us immediately at [email protected].

10. International Data Transfers

InvoCert is operated from the United States. If you access the Service from outside the United States, your personal information will be transferred to and processed in the United States.

If you are located in the European Economic Area, the United Kingdom, or Switzerland, this transfer may be subject to data protection requirements for cross-border transfers under the GDPR or applicable UK or Swiss law.

We transfer data to the United States in reliance on applicable legal transfer mechanisms, which may include standard contractual clauses or other safeguards recognized under applicable law. You may contact us at [email protected] to request further information about the transfer safeguards we rely on.

11. Your Privacy Rights

11.1 EEA, UK, and Switzerland (GDPR)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights under applicable data protection law, subject to exceptions and conditions:

  • Right of access — you may request a copy of the personal data we hold about you.
  • Right to rectification — you may request correction of inaccurate or incomplete personal data.
  • Right to erasure — you may request deletion of your personal data in certain circumstances, such as where the data is no longer necessary for the purpose for which it was collected.
  • Right to restriction of processing — you may request that we restrict processing of your personal data in certain circumstances.
  • Right to data portability — where processing is based on consent or contract and carried out by automated means, you may request your personal data in a structured, commonly used, machine-readable format.
  • Right to object — you may object to processing based on our legitimate interests.
  • Right to withdraw consent — where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
  • Right to lodge a complaint — you have the right to lodge a complaint with your local data protection supervisory authority. A list of EU data protection authorities is available at edpb.europa.eu. UK residents may contact the Information Commissioner's Office at ico.org.uk.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days of receipt of your request as required by applicable law. Where your request is complex or you have submitted multiple requests, we may extend this period by up to an additional two months, in which case we will notify you within the initial 30-day period and explain the reason for the extension. We may need to verify your identity before processing your request.

11.2 California Residents (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Right to know — you may request information about the categories and specific pieces of personal information we have collected about you, the sources of that collection, the business purpose for which we collected it, and the categories of third parties with whom we share it.
  • Right to delete — you may request deletion of personal information we have collected about you, subject to certain exceptions.
  • Right to correct — you may request correction of inaccurate personal information we maintain about you.
  • Right to opt out of sale or sharing — we do not sell personal information. We do not share personal information for cross-context behavioral advertising.
  • Right to non-discrimination — we will not discriminate against you for exercising your rights under the CCPA/CPRA.

Categories of personal information we collect:

CategoryExamplesCollected
IdentifiersEmail address, IP address, account ID, session IDYes
Commercial informationInvoice records, payment history, subscription recordsYes
Internet or other electronic network activitySession data, usage logs, access logsYes
Professional or employment-related informationBusiness name, business countryYes
Inferences drawn for profiling purposesNoneNo
Sensitive personal information as defined by CPRAPrecise geolocation, financial account numbers, government IDsNo

We do not sell personal information and we do not share personal information for cross-context behavioral advertising.

To exercise your CCPA/CPRA rights, contact us at [email protected] or [email protected]. We will respond within 45 days as required by applicable law. We may extend this period by an additional 45 days where reasonably necessary, with prior notice to you.

11.3 All Users

Regardless of your location, you may at any time:

  • Update your account information — correct or update your email address and account details from within your account settings.
  • Export your data — download invoice, payment, and document records from within the Service while your account is active.
  • Request account closure or data deletion — contact [email protected]. We will process your request in accordance with our retention obligations and applicable law and confirm when the action has been completed.
  • Contact us with questions — reach us at [email protected] with any privacy questions, concerns, or requests not addressed above. We will acknowledge your inquiry within 5 business days and respond in full as promptly as reasonably practicable.

12. Cookies and Similar Technologies

The Service uses the following types of cookies:

Session cookies — used to authenticate your login and maintain your authenticated state within the Service. These cookies are set with HttpOnly, Secure, and SameSite protections and are required for the authenticated Service to function. They expire when you log out or your session expires.

Functional cookies — a single functional cookie stores the ID of your last-selected workspace to redirect you to the correct workspace when you return to the Service. This cookie is used solely as a convenience feature. It is not used for analytics, advertising, behavioral profiling, cross-site tracking, or third-party data sharing. It is not required for the Service to function and is separate from your session authentication.

Third-party operational tools — we may use third-party tools for application performance monitoring and security that may set their own cookies or use browser storage. Where used, these tools are configured for operational purposes only and are not used for advertising or behavioral profiling.

We do not use advertising cookies, third-party behavioral tracking cookies, or cookies for cross-site profiling.

Do Not Track. Some browsers transmit "Do Not Track" signals to websites. Because we do not engage in behavioral tracking or cross-site profiling, we do not alter our data collection or use practices in response to Do Not Track signals. We do not track your activity across third-party websites.

13. Children's Privacy

The Service is offered for lawful business use by individuals aged 18 and older. We do not knowingly collect personal information from anyone under the age of 18.

If you believe we have inadvertently collected personal information from a minor, please contact us at [email protected] and we will take prompt steps to delete that information.

14. Changes to This Policy

We may update this Privacy Policy from time to time.

If we make material changes, we will provide notice by posting the updated Policy on the Service, sending an email to the address on file, or displaying an in-app notice, before the changes take effect where reasonably practicable. Changes required for legal compliance or security may take effect immediately upon notice.

Your continued use of the Service after an updated Policy takes effect constitutes your acceptance of the changes. If you do not accept the updated Policy, you should stop using the Service.

15. Contact

For all privacy inquiries, data subject access requests, deletion requests, DPA requests, or questions about this Policy:

Lorithmic LLC30 N Gould St, STE 21289Sheridan, WY 82801, USA[email protected]

For product support: [email protected]

We will acknowledge privacy inquiries within 5 business days and respond in full within the timeframe required by applicable law.

16. Summary

This summary is for convenience only and does not replace the full Policy above. In any conflict, the full Policy controls.

  • InvoCert is operated by Lorithmic LLC, a Wyoming limited liability company.
  • We collect account information, invoice and payment data, subscription and billing data, Telegram integration data, and technical and usage data including IP addresses from all users, merchants, buyers, and visitors.
  • We use your data to provide the Service, verify transactions, send notifications, generate documents, process subscriptions, maintain security, and comply with legal obligations.
  • We do not sell your personal information and we do not use your data for advertising or behavioral profiling.
  • Buyer names and company names submitted by merchants in invoices are processed by us on the merchant's behalf. Merchants are the data controllers for that data. DPAs are available on request for GDPR purposes.
  • Your data is transferred to and processed in the United States.
  • EEA, UK, and Switzerland users have rights under GDPR including access, rectification, erasure, portability, and the right to object. We respond within 30 days, with a possible extension of up to two additional months for complex requests. UK residents may contact the ICO at ico.org.uk.
  • California residents have rights under CCPA/CPRA including the right to know, delete, and correct.
  • We use session cookies and a single functional workspace cookie. We do not use advertising or behavioral tracking cookies and we do not respond to Do Not Track signals because we do not engage in cross-site tracking.
  • In the event of a data breach affecting your personal information, we will notify you and applicable authorities as required by law.
  • To exercise your rights or for any privacy question, contact [email protected]. We acknowledge within 5 business days.
Privacy Policy · InvoCert