DueNotice

Privacy Policy

Last updated September 19, 2026

This policy explains what DueNotice (a JustLedger product) collects and why. It is written in plain language. It is not legal advice.

What we collect

When you sign in we store your email and a session cookie so you stay signed in. For your business we store the name, currency, payment notes, and payment-account links you type in. For each customer you add we store name and optional email, phone, and notes. For invoices we store line items, dates, amounts, status, reminder drafts, payment records, and the public link. We also keep a short activity log (sent, viewed, paid, void) so you can see what happened.

Your device may store a theme preference on the phone. Our host (Vercel), database (Supabase), email provider (Resend), and payment provider (Stripe) receive what they need to run those parts.

What we do not collect

We do not sell your data. We do not run ads. We do not need your customer’s card number — Stripe handles cards. We do not read your personal mail, calendar, or files. We do not use a password; sign-in is a link to your email.

Why we collect it

To run your account, send the sign-in link, show your invoices, email an invoice when you ask, take a subscription payment, and (if you connect Stripe) let your customer pay you. We use logs to fix bugs and abuse.

Who we share with

Only processors that run the product: Vercel (hosting), Supabase (database), Resend (email), and Stripe (your DueNotice subscription and, if you connect it, customer cards). If we later use Grok to draft invoice wording, that text leaves our servers to xAI because you asked for a draft. We will not sell lists of your customers.

We may share information if the law requires it, or to protect you or us from fraud or abuse.

Public invoice links

Anyone with the link can see that invoice: names, line items, amounts, and how to pay. Do not post the link in public if you do not want that. Voided invoices are hidden from the public link.

Cookies

We use an httpOnly session cookie to keep you signed in. That is not an advertising cookie. You can sign out to clear it.

How long we keep it

Invoice, payment, and reminder records are money records. We do not hard-delete them in the app, because you may need a history later. Sign-in links expire in about 20 minutes and are one-time. If you want an account closed, write from the email on the account and we will work through what we can remove versus what we have to keep as a record.

Your choices

You can edit customers and invoices in the app. You can stop using the service. If you are in a place with extra privacy rights (for example some US states), write from your account email and we will handle the request in good faith.

Children

DueNotice is for businesses, not for children under 13. Do not create an account for a child.

Security

We hash sign-in tokens, keep sessions in cookies the browser cannot read with scripts, and scope your data to your account. No setup is perfect. Tell us if you think something is wrong.

Changes

If this policy changes, we will update the date at the top. Keep using DueNotice after that and you accept the new policy.

Contact

Privacy questions: write from the email on your DueNotice account. Operator: JustLedger. Product: DueNotice.