Biller | ZeroFy
Privacy policy
We keep your data minimal, secure, and never sell it to anyone. This policy explains exactly what we collect, why, and what you can do about it.
1. Who we are
Biller | ZeroFy is an online invoice creation and management service operated at billing.zerofy.me. When this policy refers to "we", "us", or "our", it means the operator of this service. "You" refers to any person who visits, uses, or creates an account on Biller | ZeroFy.
If you have any questions about this policy or how we handle your data, you can contact us at:
- Email: hello.zerofy@gmail.com
- Phone: +91 87895 00326
2. What data we collect
2.1 Account data
When you create an account, we collect:
- Your name — provided by you at signup, stored in our database and in Supabase Auth user metadata.
- Your email address — used for authentication, account communications, and as your login identity.
- A hashed password — managed entirely by Supabase Auth. We never see or store your plain-text password.
2.2 Invoice data
When you save an invoice while signed in, we store the full contents of that invoice in our MySQL database, including:
- Your biller name and address
- Your customer's name, email, and address
- Invoice number, invoice date, and due date
- Line items (descriptions, quantities, unit prices, and line totals)
- Tax rate, discount amount, and the final invoice total
- Any notes you add to the invoice
- Currency selection and branding preferences (custom header, hide header setting)
Invoices created in guest mode (without an account) are stored only in your browser's local storage and are not sent to our servers.
2.3 Profile preferences
We store your profile settings in our database, including your display name, custom invoice header text, and the option to hide the header from invoices. These are set and updated by you from the account page.
2.4 Payment data
When you upgrade to a paid plan, payment is processed by PayU. We do not receive or store your card number, CVV, or bank details. After a successful payment, PayU sends us a verified callback containing your name, email, the plan selected, the transaction amount, and a transaction ID. We store the transaction ID and plan status in our database for reconciliation and support purposes.
2.5 Consent records
We record two types of consent for legal audit purposes:
- Cookie consent: When you accept or decline the cookie banner, we record the timestamp, your IP address, browser/device information (user agent), session ID, the consent version, and your account identifier if you are signed in at the time.
- Signup consent: When you create an account, your acceptance of these terms and this privacy policy is recorded with the timestamp, your IP address, browser/device information, the versions of the terms and policy you agreed to, and your account details.
2.6 Technical data
When you interact with the service, our server receives standard technical information including your IP address, browser type and version, and the pages you request. This information is used for security, debugging, and service operation. It is not used for advertising or tracking.
2.7 Local browser data
We store certain data in your browser's local storage to improve your experience:
- Invoice draft (
zerofy-invoice-draft) — your current invoice in progress, saved automatically so you don't lose your work. - Invoice count (
zerofy-generated-count) — the number of invoices you have created, used to enforce the free plan limit. - Account cache (
zerofy-account) — a local copy of your name, email, and user ID to speed up the initial page load. - Cookie consent preference (
zerofy-cookie-consent-v1) — your cookie banner response, so the banner does not reappear.
This data stays in your browser and is cleared when you log out. You can clear it manually at any time through your browser settings.
3. How we use your data
We use the data we collect solely to provide and operate the Biller | ZeroFy service. Specifically:
- To authenticate your identity and maintain your session
- To save, retrieve, and display your invoices
- To apply your plan status (free or paid) and enforce plan limits
- To process payments and activate paid features after a successful transaction
- To send transactional emails such as account confirmation and password reset (via Resend)
- To maintain legal records of consent for regulatory compliance
- To investigate and resolve technical issues or support requests
We do not use your data for advertising, behavioural profiling, or sale to third parties.
4. Cookies and local storage
We use one cookie set by this service:
zerofy_consent— set when you accept the cookie banner. Expires after one year. Used only to remember your consent so the banner does not show again.
Supabase Auth uses browser local storage (not a traditional cookie) to persist your login session. This is a technical necessity for authentication to work across page loads.
We do not use any advertising cookies, cross-site tracking cookies, or third-party analytics cookies. Google Fonts are loaded from Google's CDN; Google may set its own cookies subject to Google's privacy policy, which we do not control.
If you decline the cookie banner, no consent cookie is set. The service will still function, but your session will not be remembered across visits in the same way.
5. How we share your data
We do not sell, rent, or trade your personal data. We share data only with the following third-party providers, and only as necessary for them to perform their function:
- Supabase — receives your email, password (hashed), and name for authentication. Manages your login session and issues JWT tokens used to verify your identity. Supabase privacy policy.
- PayU — receives your name, email, and payment details when you initiate a plan upgrade. Processes the transaction and sends us a verified result. PayU privacy policy.
- Resend — receives your email address to deliver transactional emails such as account confirmation and password reset. Resend privacy policy.
- Google Fonts — your browser loads fonts from Google's CDN. Google may log your IP address and browser details when the font files are fetched. Google privacy policy.
We may disclose your data if required by law, a court order, or a legitimate government authority.
6. Data storage and security
Account and authentication data is stored by Supabase on secure infrastructure. Invoice data, profile settings, payment records, and consent logs are stored in a MySQL database on our hosting server. All connections to the service are encrypted via HTTPS/TLS.
We implement reasonable technical and organisational measures to protect your data against unauthorised access, loss, or misuse. However, no system is perfectly secure. You are responsible for keeping your account password confidential.
Passwords are never stored in plain text. Authentication is handled entirely by Supabase using industry-standard hashing.
7. Data retention
We retain your data for as long as your account remains active or as needed to provide the service. Specifically:
- Account data: Retained until you request account deletion.
- Invoice data: Retained until you delete individual invoices or request full account deletion.
- Payment records: Transaction IDs and plan status may be retained beyond account deletion for financial record-keeping and legal compliance.
- Consent records: Cookie and signup consent logs are retained for legal compliance purposes. They may be anonymised rather than fully deleted on account deletion.
8. Your rights
You have the following rights over your personal data:
- Access: You can view your name, email, and profile settings at any time from the account page.
- Correction: You can update your name and custom header at any time from the account page.
- Deletion of invoices: You can delete individual invoices from your invoice history at any time.
- Account deletion: You can request full deletion of your account and all associated personal data. We will process this within 30 days. Contact us at hello.zerofy@gmail.com with your registered email address and the subject "Account deletion request".
- Data portability: If you need an export of your invoice data, contact us and we will provide it in a readable format.
- Withdraw consent: You can clear your cookie consent at any time by clearing your browser's local storage and cookies for this site. This will cause the cookie banner to reappear on your next visit.
9. Children's privacy
Biller | ZeroFy is intended for use by individuals and businesses, not by children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
10. Changes to this policy
We may update this privacy policy from time to time. When we make material changes, we will update the version number and date at the bottom of this page. Continued use of the service after changes are published constitutes your acceptance of the updated policy. We encourage you to review this page periodically.
11. Contact us
For any questions, concerns, or requests related to this privacy policy or your personal data, please contact us:
- Email: hello.zerofy@gmail.com
- Phone: +91 87895 00326
For account deletion or data export requests, please email us with your registered email address and a clear description of your request. We aim to respond within 7 business days.
Last updated: August 2026 · Version 1.0