Privacy notice
Last updated 24 August 2026 · Written with POPIA in mind
What we hold, and why
| Information | Why |
|---|---|
| Your name, email, phone | To run your account and contact you about it |
| Business name, address, VAT and registration numbers | These are legally required on a tax invoice |
| Bank details you enter | Printed on your invoices so clients can pay you by EFT |
| Your clients' names, addresses and contact details | To address invoices to them and deliver those invoices |
| Invoices, line items and payment records | The service itself, and your tax record |
| Payment provider API keys | To collect card payments into your account. Encrypted at rest |
| Support messages and chatbot transcripts | To answer you, and to see where the product confuses people |
What we never see
Card numbers. Payments happen on the payment provider's own page. No card details reach our servers, and none are stored here.
Your bank login. We show the account details you type so clients can pay you; we have no access to the account itself.
Your clients' information
When you add a client, you are the responsible party under POPIA and we process that information on your behalf. We do not market to your clients or use their details for anything beyond delivering your invoices and payment reminders.
Who else touches it
Our email provider, to deliver invoices and notifications. Our payment provider, to process payments. Our hosting provider, which stores the database. We do not sell personal information to anyone, ever.
How long we keep it
Invoice records are kept for at least five years, because South African tax law requires it — this applies even after you close your account. Support messages are kept for two years. Chatbot transcripts are kept for ninety days unless attached to a support ticket.
Your rights
You may ask what we hold about you, correct anything wrong, ask us to delete what we are not legally obliged to keep, and object to how we use it. Export is immediate and self-service, under Settings. For anything else, email us and we will respond within 30 days.
Keeping it safe
Passwords are hashed with BCrypt and never stored or recoverable in readable form. Payment provider keys are encrypted with AES-GCM before they are written to the database. Traffic runs over HTTPS. Each business's data is isolated at the query level, so one account cannot read another's.
If a breach ever puts your information at risk, we will tell you and the Information Regulator, as POPIA requires.
klaarinvoices@gmail.com · You may also complain to the Information Regulator of South Africa.