Legal

Privacy Policy

Effective: July 21, 2026

This Privacy Policy describes how Aegis Invoice LLC, a Delaware limited liability company ("Aegis", "we", "our", or "us"), collects, uses, and shares personal information when you use the Aegis / AegisInvoice invoicing platform at aegisinvoice.com (the "Service"). This Policy is incorporated by reference into our Terms of Service.

1. Who this policy applies to

This Policy applies to:

  • Account users, meaning individuals who sign in to Aegis on behalf of a Customer organization (Aegis team members, Admins, Managers, Team Leads, and Users);
  • Invoice recipients, meaning individuals whose email, name, phone, and billing details are entered by a Customer organization into Aegis for the purpose of being invoiced or notified;
  • Website visitors, meaning anyone browsing our marketing pages at aegisinvoice.com.

2. Information we collect

2.1 Account data

When you create or are invited to an Aegis account, we collect your name, email address, role, password hash (Argon2id), and metadata about the organization and teams you belong to. We may also collect a phone number if you provide one for account security (OTP), notifications, or support.

2.2 Invoice and customer data

Customers may enter information about their own customers into Aegis, including name, email, phone number, and billing address. That data is controlled by the Customer; Aegis processes it as a service provider on the Customer's behalf.

2.3 Phone numbers and SMS

We may collect phone numbers from account users and from Customer-entered contact records to send transactional and (where opted in) account-related SMS, including OTP codes, invoice notifications, payment reminders, and security alerts. Message frequency varies. Message and data rates may apply. Consent to SMS is not a condition of purchase. You can opt out by replying STOP; reply HELP for help, or email support@aegisinvoice.com. We do not sell phone numbers for marketing. When SMS is enabled, messages may be transmitted through a third-party SMS / CPaaS provider under contractual terms. Carriers are not liable for delayed or undelivered messages.

2.4 Payment information

Aegis does not collect or store full card numbers (PAN), card verification values (CVV or CVC), or card expiration dates. When an invoice is paid on a branded pay page (for example, /pay/{token}), cardholder data is entered into Authorize.Net Accept Hosted (iframe) and is processed by Authorize.Net against the Customer's own merchant account. Aegis receives only the transaction status, provider transaction ID, authorization code, card brand (for example, Visa or Mastercard), and the last four digits of the card number. A defense-in-depth scrubber strips any unexpected sensitive fields before persistence.

Platform subscription billing for Aegis access may be processed separately by Stripe. Stripe processes subscription payment details under its own privacy terms; Aegis does not use Stripe to process invoice payments that settle to a Customer's Authorize.Net merchant account.

2.5 Technical and security data

We log IP address, user agent, and timestamps for authentication, abuse prevention, fraud detection, and auditing. These records are associated with user sessions and audit-log entries.

2.6 Cookies

We use a small number of first-party cookies:

  • aegis_token, a non-secret sign-in presence flag used only so the application can route signed-in and signed-out visitors correctly. It does not carry your authentication token; the bearer token used to authenticate API requests is held in browser storage and validated server-side against your session.
  • aegis_theme, which remembers your light or dark theme preference.

We do not use third-party advertising or tracking cookies.

3. How we use information

  • to provide, operate, and maintain the Service;
  • to authenticate users and enforce the role hierarchy and scoping model;
  • to process invoices, branded pay pages, and reconcile payment status from Authorize.Net;
  • to bill platform subscriptions (when applicable) via Stripe;
  • to send transactional email and SMS (OTP, invoice notices, payment reminders, security alerts) as described in this Policy and our Terms of Service;
  • to surface optional chargeback alerts when a Customer connects Chargeblast or a similar provider;
  • to detect, investigate, and prevent security incidents;
  • to maintain an append-only audit trail of material activity;
  • to communicate with you about the Service (transactional email, SMS where consented, and support);
  • to comply with legal obligations.

We do not sell personal information and we do not use it for behavioral advertising. We do not sell phone numbers for marketing.

4. Legal bases (for users in the EEA and UK)

Where applicable, we rely on the following legal bases:

  • Contract, to provide the Service you or your organization requested;
  • Legitimate interests, to secure the Service, prevent fraud, and audit activity;
  • Legal obligation, to comply with applicable law;
  • Consent, where required (including for certain SMS or optional communications), and revocable at any time (for SMS, reply STOP or contact us).

5. Sharing of information and subprocessors

We share personal information with service providers (subprocessors) only as needed to operate the Service:

  • Payment providers: Authorize.Net for Customer invoice payments via Accept Hosted; Stripe for platform subscription billing when used;
  • Email delivery services for transactional email;
  • SMS / CPaaS providers when messaging features are enabled, to deliver OTP, invoice, reminder, and security SMS under 10DLC / A2P programs where applicable;
  • Hosting and infrastructure providers under contractual confidentiality and data-protection terms;
  • Chargeback alert providers (for example, Chargeblast) when a Customer connects that integration;
  • Law enforcement or government authorities when required by law or to protect rights, safety, or property, or in connection with a corporate transaction (for example, a merger or acquisition).

6. Data retention

We retain account data for the life of the account and for a reasonable period after termination for legal, tax, and audit purposes. Audit logs may be retained for up to the retention window stated in your subscription plan. On account termination, tenant data is permanently deleted thirty (30) days after the export window closes. SMS opt-out records may be retained as needed to honor STOP requests and comply with carrier and legal requirements.

7. Security

We take security seriously. Highlights include AES-256-GCM encryption for payment-provider credentials at rest, Argon2id password hashing, single-session enforcement, TLS in transit, one-time codes for sensitive actions (stored hashed), an append-only audit log, and rate limiting on sensitive endpoints. Card PAN, CVV, and expiry are not stored by Aegis. No system is perfectly secure; we do not warrant that unauthorized access will never occur. See our Security page for details.

8. Your choices and rights

Depending on your jurisdiction (including under GDPR, UK GDPR, CCPA/CPRA, and similar laws), you may have rights to:

  • access the personal information we hold about you;
  • request correction or deletion;
  • object to or restrict processing;
  • request portability of your data;
  • opt out of SMS by replying STOP (or as otherwise instructed);
  • opt out of the "sale" or "sharing" of personal information as those terms are defined by U.S. state privacy laws (we do not engage in either).

To exercise these rights, email support@aegisinvoice.com. If you are an invoice recipient, please contact the organization that invoiced you first, because it is the controller for your information.

9. International transfers

Personal information may be processed in countries other than the one in which you reside, including the United States. Where required, we use contractual safeguards such as the Standard Contractual Clauses to protect cross-border transfers.

10. Children

The Service is not directed at children under 16, and we do not knowingly collect personal information from children. If we learn we have collected such information, we will delete it promptly.

11. Changes to this Policy

We may update this Privacy Policy from time to time. When we make material changes we will notify you by email or through the Service, and we will update the Effective date above.

12. Governing law

This Policy is governed by the laws of the State of Delaware, United States, without regard to its conflict-of-laws principles, consistent with the governing-law and dispute-resolution provisions of our Terms of Service (venue in New Castle County / Wilmington, Delaware; binding arbitration and class waiver as stated there).

13. Contact

Aegis Invoice LLC, a Delaware limited liability company. Questions or data-subject requests? Email us at support@aegisinvoice.com.