Legal
Privacy Policy
This policy explains how Talerivo processes personal data when you visit the service, create an account, manage invoices or use payment and email features.
This legal document is currently provided in English.
- Operator
- Artemi Tsinjonnoi
- Location
- Estonia
- Contact
- talerivo.support@gmail.com
- Last updated
- 6 August 2026
Contents
1. Who is responsible for your data
Talerivo is operated by Artemi Tsinjonnoi in Estonia. The operator is the data controller for account administration, billing, support, service security and product operations.
When a Talerivo user enters information about clients, invoice recipients or other contacts, that user normally decides why the information is used. Talerivo processes that information to provide the service. Users are responsible for having a lawful basis to add and use other people's information.
2. Data we process
- Account data, including name, email address, password hash or connected sign-in provider, profile image, language, country, currency, plan and account status.
- Business data, including business name, address, tax and registration identifiers, invoice branding, payment instructions, IBAN and BIC.
- Client data, including client type, name, email, phone, address, country, VAT number and notes.
- Invoice data, including invoice numbers, dates, line items, quantities, prices, tax settings, totals, payment terms, notes, statuses and historical seller/client snapshots.
- Payment and subscription data, including amounts, payment dates, Stripe customer, subscription, checkout and connected-account identifiers and status information.
- Security and technical data, including sessions, verification and reset tokens, request metadata, redacted audit events and rate-limit records. Rate-limit records store hashed bucket identifiers rather than raw email addresses, IP addresses or tokens.
- Support communications and transactional email delivery information.
3. How we receive data
We receive data directly from users, from people whose details a user enters into an invoice or client record, from use of the service, and from providers involved in authentication, email delivery, hosting, VAT validation and payments.
4. Why we process data
- To create and manage accounts, clients, invoices, PDFs, reports and public invoice pages, and to perform our contract with users.
- To send verification, password reset, invoice and reminder emails requested through the service.
- To provide subscriptions, billing, checkout, payment reconciliation and optional Stripe Connect features.
- To validate VAT numbers through the European Commission VIES service when a user requests validation.
- To protect the service, prevent abuse, troubleshoot failures and keep reliable audit records based on our legitimate interests in operating a secure service.
- To comply with legal obligations and establish, exercise or defend legal claims.
- Where consent is required, for the specific purpose explained when consent is requested.
5. Service providers and recipients
We share only the data needed for a provider to perform its service. Current provider categories and services include:
- Vercel for application hosting, delivery and operational logs.
- Neon for the PostgreSQL database.
- Resend for transactional email delivery.
- Stripe for subscriptions, billing, invoice checkout, payment status and hosted Connect onboarding.
- Google when a user chooses Google sign-in, and Google Fonts for font delivery in the browser.
- The European Commission VIES service for requested VAT-number validation.
- Professional advisers, courts, regulators or authorities where disclosure is required or legally justified.
6. International transfers
Some providers may process data outside Estonia or the European Economic Area. Where data-protection law requires safeguards for a transfer, we use the safeguards made available by the relevant provider and required by applicable law. Contact us if you need more information about a specific transfer.
7. Public invoice links
Public invoice pages and PDFs use hard-to-guess bearer links. Anyone who receives a valid link may be able to view invoice-relevant seller, client, line-item, tax, total, note and payment information. Users must treat these links as sensitive and share them only with intended recipients.
8. How long we keep data
We keep account and business information while an account is active and for as long as reasonably needed to provide support, secure the service, resolve disputes and meet legal obligations. Client, invoice and payment information is kept until the user deletes it, asks us to close the account, or retention is otherwise required for accounting, tax, fraud-prevention or legal purposes.
Verification and password-reset tokens expire after a limited period. Security records, operational logs and backups are retained according to operational need and provider schedules, then deleted or overwritten. We may verify identity before acting on an access, export or deletion request.
9. Cookies and browser resources
Talerivo uses cookies and similar storage that are necessary for authentication, sessions, security and user preferences. We do not currently use advertising or behavioural-tracking cookies. The browser may contact Google Fonts to load interface fonts, and pages reached through Stripe or Google are governed by those providers' own notices.
10. Your rights
Depending on applicable law, you may have rights to access, correct, erase, restrict or object to processing of your personal data, and to receive portable data. You may withdraw consent where processing relies on consent. Some rights are limited where data must be retained by law or is needed for legal claims.
Send requests to the contact email shown on this page. We may ask for information needed to verify identity. You may also complain to the competent data-protection supervisory authority in your country.
11. Security
We use access controls, password hashing, database-backed sessions, protected authentication cookies, same-origin protections, rate limiting, webhook signature verification, redacted logging and restricted public links. No online service can guarantee absolute security, so users should protect their credentials and promptly report suspected misuse.
12. Changes and contact
We may update this policy when the service, providers or legal requirements change. The date at the top shows the latest revision. Material changes will be communicated through the service or by another appropriate method.
Questions and privacy requests can be sent to the contact email shown on this page.