[Operator name], [Street, ZIP City, Switzerland] ("we"), operates Qrilly. Contact for any privacy question: [contact email].
This policy follows the Swiss Federal Act on Data Protection (nFADP/nDSG).
Account: your name, email address and a hashed password (we never store the password itself).
Content you create: sender presets (your business name, address, IBAN, logo, numbering), clients, logged hours and invoices, including the names, addresses and email addresses of the people you bill.
Technical data: a session cookie that keeps you signed in, and your language and colour-mode choice kept in your browser. We do not use advertising or analytics trackers.
Only to run the service: to sign you in, to build and store your invoices and rebuild their PDFs, and to send the emails you ask for (confirmation, password reset, invoices).
Passwords are stored hashed. Client and invoice personal details are encrypted at rest with a key per account, itself protected by a server-held master key; other data (such as your presets, amounts and dates) is stored readable. See the Terms of use for the exact list. Connections use HTTPS.
Encryption at rest protects against a leak of the database alone; it does not hide your data from the operator of the service, who holds the master key.
We use service providers to run Qrilly: a hosting provider (Vercel), a database provider (MongoDB Atlas) and an email delivery provider (Resend). They process data on our behalf and may do so outside Switzerland, under appropriate safeguards.
Until you delete it (deleted invoices stay in a trash for 15 days first). You can delete your account and all its data yourself under Settings. As the issuer of invoices you are responsible for meeting your own bookkeeping retention duties (generally 10 years in Switzerland) - export your data before deleting.
You can access and download your data (Settings, "Export your data"), correct it in the app, and delete it (Settings, "Delete account"). For anything else, or to complain, write to us. You may also contact the Federal Data Protection and Information Commissioner (FDPIC).