Summary: We only collect data required to operate the service. We never sell your data to third parties.
1. Who We Are
Cashflow is an invoice management and cash flow service operated by a registered sole trader in Israel. This policy explains how we collect, use, and protect your personal data.
For any questions about this policy, contact us at: hello@gocashflow.co
2. Data We Collect
2.1 Data You Provide Directly
- Account details: Email address, password (stored encrypted)
- Invoices and documents: PDF files, images, and invoice data uploaded manually
- Supplier data: Names, contact details, and payment terms you enter
2.2 Data Collected Automatically
- Usage data: Number of invoices uploaded, dates, connected sources
- Technical logs: IP address, browser type, errors — for diagnostics only
- Billing details: Stripe customer ID (not card number — that is never stored by us)
2.3 Data from External Sources (Integrations)
If you choose to connect external services, the following data is collected:
- Gmail: Read access to emails with attachments identified as invoices only. We do not read, store, or process any other email content.
- Google Drive: Read access to files in folders you select. We do not access files outside the folders you configure.
- WhatsApp Business: Incoming messages containing invoice files only, via verified Webhook.
- Green Invoice: Invoices received via the VAT number you provide.
OAuth tokens for external services are stored encrypted and used solely for invoice sync.
3. How We Use Your Data
| Purpose | Legal Basis |
|---|---|
| Operating the service — reading invoices, managing suppliers, dashboard | Contract performance |
| Billing and payments via Stripe | Contract performance |
| Improving AI data extraction accuracy | Legitimate interest |
| Sending essential service updates (billing, policy changes) | Contract performance / Legal obligation |
| Technical error diagnostics | Legitimate interest |
We do not use your invoices to train AI models, for advertising, or for any purpose not listed above.
4. Sharing Data with Third Parties
We do not sell, trade, or rent your personal data. Data is shared only with the following service providers for operating the service:
- Anthropic (Claude AI): Invoice images and text are sent to Anthropic's API for data extraction. Anthropic is committed not to use API data for model training.
- Supabase: Database and user authentication. Servers located in EU (Frankfurt). Supabase Privacy Policy →
- Cloudflare R2: Invoice file storage (PDF and images). Servers located in EU. Cloudflare Privacy Policy →
- Stripe: Payment processing. Stripe holds PCI DSS Level 1 certification. Stripe Privacy Policy →
- Google: OAuth for Gmail and Google Drive (user consent only). Google Privacy Policy →
All providers have signed Data Processing Agreements (DPA) in accordance with GDPR requirements.
5. Storage and Security
5.1 Server Location
User data (database, files) is stored on servers in Europe (Frankfurt, EU). Some AI requests are processed on Anthropic servers in the US.
5.2 Security Measures
- HTTPS encryption for all traffic
- File encryption at rest (AES-256)
- Data isolation between users via Row-Level Security (RLS)
- OAuth tokens encrypted in the database
- Production data access limited to minimal team
5.3 Data Retention
- Active account: data retained indefinitely until account deletion
- After subscription cancellation: data retained for 30 additional days, then permanently deleted
- Technical logs: retained up to 90 days
6. Your Rights
Under the Israeli Privacy Protection Law and GDPR regulations (where applicable), you have the following rights:
- Access: Receive a copy of all data collected about you
- Correction: Fix inaccurate data
- Deletion: Request deletion of all your data ("right to be forgotten")
- Export: Receive your data in a structured format (JSON/CSV)
- Revocation: Disconnect integrations and revoke access to external services at any time
- Objection: Object to certain processing based on legitimate interest
To exercise any of these rights, contact us at: hello@gocashflow.co. We will respond within 30 days.
7. Cookies & Analytics
The application uses essential cookies only:
- Session token: To maintain login state (Supabase Auth)
- CSRF token: For protection against attacks
We do not use advertising or third-party tracking cookies.
We use Vercel Web Analytics, a cookieless analytics service, on both the marketing site and the authenticated application. It collects aggregated, anonymized usage data (e.g. pages visited, referring source, device type) to help us understand product usage — it does not use cookies, does not track you across other websites, and does not identify you personally. See Vercel's Web Analytics privacy documentation → for details.
8. Children
The service is not intended for children under the age of 18. We do not knowingly collect data from persons under this age.
9. Policy Changes
If we make material changes to this privacy policy, we will send a notice to your registered email address at least 14 days in advance. Continued use of the service after changes take effect constitutes agreement to the updated terms.
10. Contact
For questions, requests to exercise rights, or privacy complaints:
If you have not received a satisfactory response, you may contact the Israeli Privacy Protection Authority: gov.il/privacy →