Privacy notice

Last updated 17 August 2026

Who is responsible for what

For your own account details — your name, email address and business profile — PolitelyPaid is the controller.

For your clients’ details — their names, email addresses, billing addresses and tax numbers — you are the controller and PolitelyPaid is your processor. We hold and send that data on your instructions, and for no purpose of our own. We do not market to your clients, sell their details, or use them to train anything.

What we store

  • Your account: email address, name, and sign-in records.
  • Your business profile: business name, logo, address, tax number, contact details, currency and payment terms, payment instructions.
  • Your clients: contact and company name, billing email and CC recipients, billing address, tax number, timezone, and your own internal notes.
  • Activation events recording that you signed up and set up your account. These carry your user identifier and a timestamp, and never any detail about your clients.

Your notes on a client are internal to you. They are never shown to a client, never included in a message we send on your behalf, and never placed into an AI prompt.

How your reminders are written

On paid plans we draft the wording of your reminder emails with a language-model provider, so each message reads as though you wrote it. We send that provider only what one message needs: your client’s name, your name and business name, the invoice number, the amount outstanding and its currency, the due date, the date the reminder is due to go out, and how firm the message should be. That data is processed under an agreement that it is not used to train any model, and it is not retained by the provider beyond answering the request.

Nothing else goes with it: not your client’s email address, billing address or tax number; not your notes; not the invoice’s line items; not the payment link; and never another account’s data. Every drafted message is then checked against the invoice and against a list of things we will not say, and anything that fails is replaced with our own pre-written wording.

Accounts without AI personalisation use that pre-written wording for every reminder, and nothing about them reaches a language-model provider at all.

If you received an invoice through us

The invoice was sent by the business that issued it. PolitelyPaid delivered it on their instructions and records two things for them:

  • Whether the email was opened. The message contains a single 1×1 image. If your mail app loads it, we record the time and a coarse description of the app — “Apple Mail”, “Gmail”. We do not store your IP address or work out where you are. Many mail apps block that image and some load it automatically, so this is a weak signal and is presented to the sender as one.
  • Whether the invoice page was opened. We record the time a visit happened, deduplicated per browser session.

That is all. There is no click tracking: links in our emails are never rewritten. Every message carries a link that stops further messages about that invoice, or about every invoice from that business — it works immediately and needs no account. Once you use it, nothing further is sent to that address.

This data belongs to the business that issued the invoice, and it is deleted when their account is.

Security

All traffic is served over TLS. Data is encrypted at rest in our database and file storage. Every record is scoped to the account that owns it at the query layer, so one account cannot read another’s data even by guessing an identifier.

Getting your data out, and deleting it

You can export everything we hold for you as a machine-readable file from Settings, at any time, without asking us.

You can also delete your account from Settings. The first thing a deletion does — before anything else — is stop every reminder and cancel everything scheduled to go out, so nothing further reaches your clients. We then end all your sessions, email you a confirmation, and permanently remove your personal and client data within 30 days.

Processors we use

  • Neon — database hosting.
  • Vercel — application hosting.
  • Postmark — transactional email, including delivery and bounce reporting.
  • Google (Gemini) — drafting the wording of reminder emails, under a no-training agreement. Used only on plans with AI personalisation, and only for the fields listed above.

Contact

Write to privacy@politelypaid.com. Our Data Processing Agreement is available from the legal pages and from Settings, without contacting support.