Spoonbill is an invoicing tool for freelancers and small businesses. This policy explains what personal data we process when you visit this site or use the Spoonbill app, why we process it, and the rights you have.
The short version: we store what an invoicing service needs to work — your account, your business profile, your clients and your invoices — and nothing else. No advertising, no tracking, no selling of data.
Who is responsible
Spoonbill is operated by DK Labs (Dzmitry Kandratsenka), Rua Miguel Araujo 141, 4425-177 Porto, Portugal (the "controller" in the sense of the GDPR). The fastest way to reach us about anything in this policy is the email address at the end of this page.
What we process
Account and sign-in. When you create an account we process your email address, your display name and the sign-in method you chose (Google, Apple, or email and password). Sign-in is handled by Google Firebase Authentication; if you use a password, it is stored by Firebase — we never see it.
Business data you enter. Your business profile (name, address, tax identifiers, bank details you choose to print on invoices), your clients and your invoices are stored so we can provide the service. Invoice PDFs are kept in our object storage so sent invoices stay unchanged.
Your clients' data. Names, addresses, email addresses and VAT IDs of your invoice recipients are processed on your instructions — to create invoices, email them, and send payment reminders you enable. When a recipient opens an invoice link, we record that the invoice was viewed so we can show you its status.
Emails we send. Verification codes, invoices, payment reminders and account notices are delivered through our email provider. We keep a record of what was sent to build the invoice timeline you see in the app.
Feedback. If you send feedback from the app, we receive your message and the contact email you provide. It is forwarded to our team inbox and our internal Slack channel so we can respond.
Server logs. Like every web service, our servers record technical access data (IP address, browser type, timestamps) to keep the service running and secure. Logs are kept briefly and are not used to profile you.
Why we may process it
We rely on the legal bases of Art. 6(1) GDPR:
- Contract (Art. 6(1)(b)) — almost everything above: providing your account, storing your invoices, sending them on your instruction.
- Legitimate interests (Art. 6(1)(f)) — keeping the service secure, preventing abuse, answering feedback, and product analytics inside the app.
- Legal obligation (Art. 6(1)(c)) — where laws require us to keep or disclose certain records.
- Consent (Art. 6(1)(a)) — website analytics, and anything else we explicitly ask for; you can withdraw it at any time with effect for the future.
Who else is involved
We use a small number of service providers (processors) who handle data on our behalf and under our instructions:
- Google Ireland Ltd. / Google LLC — Firebase Authentication for sign-in.
- Gcore (G-Core Labs S.A.) — runs the servers, database and object storage that hold your data; the infrastructure is located in the United States.
- Our email delivery provider — sends verification codes, invoices and reminders.
- Mixpanel, Inc. — product analytics and session replay; the project uses Mixpanel's EU data residency, on the website it only receives anything once you have allowed it, and in-app replays are masked before they are sent.
- Slack Technologies — receives feedback messages only, so the team sees them quickly.
Where a provider processes data outside the EU/EEA — as with our US-hosted infrastructure — transfers are protected by the EU standard contractual clauses or an adequacy decision such as the EU-US Data Privacy Framework. We never sell personal data or share it for advertising.
How long we keep data
- Account and business data: until you delete it or your account.
- Invoices: until you delete them. Statutory retention duties for issued invoices (for example under tax law) rest with you — export your PDFs before deleting.
- Server logs: a few weeks, then deleted or anonymized.
- Feedback: as long as needed to follow up.
Your rights
Under the GDPR you can at any time:
- request a copy of the data we hold about you (Art. 15),
- have inaccurate data corrected (Art. 16),
- have your data deleted (Art. 17),
- restrict processing (Art. 18),
- receive your data in a portable format (Art. 20),
- object to processing based on legitimate interests (Art. 21),
- withdraw any consent you have given (Art. 7(3)).
You also have the right to lodge a complaint with a data protection supervisory authority, for example the one at your place of residence.
How we protect data
All connections are encrypted in transit (TLS). Access to production systems is restricted, and your invoice documents are stored in access-controlled object storage. No method of transmission or storage is 100% secure; if a breach ever affects your data, we will notify you as the law requires.
Children
Spoonbill is a business tool and not directed at children. We do not knowingly process data of anyone under 16; if you believe a child has provided us data, contact us and we will delete it.
Changes to this policy
We will update this page when our data practices change and adjust the date at the top. For material changes we will notify you in the app or by email.