Klaar

Privacy notice

Last updated 24 August 2026 · Written with POPIA in mind

A starting point, not legal advice. POPIA obliges you to tell people what you hold and why. This describes what the software actually does; have it reviewed before you rely on it commercially.

What we hold, and why

InformationWhy
Your name, email, phone To run your account and contact you about it
Business name, address, VAT and registration numbers These are legally required on a tax invoice
Bank details you enter Printed on your invoices so clients can pay you by EFT
Your clients' names, addresses and contact details To address invoices to them and deliver those invoices
Invoices, line items and payment records The service itself, and your tax record
Payment provider API keys To collect card payments into your account. Encrypted at rest
Support messages and chatbot transcripts To answer you, and to see where the product confuses people

What we never see

Card numbers. Payments happen on the payment provider's own page. No card details reach our servers, and none are stored here.

Your bank login. We show the account details you type so clients can pay you; we have no access to the account itself.

Your clients' information

When you add a client, you are the responsible party under POPIA and we process that information on your behalf. We do not market to your clients or use their details for anything beyond delivering your invoices and payment reminders.

Who else touches it

Our email provider, to deliver invoices and notifications. Our payment provider, to process payments. Our hosting provider, which stores the database. We do not sell personal information to anyone, ever.

How long we keep it

Invoice records are kept for at least five years, because South African tax law requires it — this applies even after you close your account. Support messages are kept for two years. Chatbot transcripts are kept for ninety days unless attached to a support ticket.

Your rights

You may ask what we hold about you, correct anything wrong, ask us to delete what we are not legally obliged to keep, and object to how we use it. Export is immediate and self-service, under Settings. For anything else, email us and we will respond within 30 days.

Keeping it safe

Passwords are hashed with BCrypt and never stored or recoverable in readable form. Payment provider keys are encrypted with AES-GCM before they are written to the database. Traffic runs over HTTPS. Each business's data is isolated at the query level, so one account cannot read another's.

If a breach ever puts your information at risk, we will tell you and the Information Regulator, as POPIA requires.

Contact

klaarinvoices@gmail.com · You may also complain to the Information Regulator of South Africa.