Client Invoices Privacy Policy
This privacy policy explains what personal information Client Invoices collects, why we collect it, who we share it with, and the rights you have over it. It applies to all information collected by or submitted to Client Invoices.
Client Invoices is operated by Sanderson Howe Limited (NZBN 9429049408096), a company incorporated in New Zealand. You can contact us about anything in this policy at team@clientinvoices.com.
What Client Invoices does
Client Invoices is a tool for sharing invoices. A business connects its Xero accounting organisation to Client Invoices, browses its Xero contacts and invoices, and shares a client's invoices with that client by email. Sharing a client gives the recipient that client's finalised sales invoices, rather than a single invoice the business selects. Those clients then sign in to view the invoices shared with them and pay them through Xero's secure online invoice page. Understanding these two kinds of user is the key to this policy.
Our roles
New Zealand privacy law does not use the words "controller" and "processor". The Privacy Act 2020 asks who is an agency holding personal information, and treats information held solely as agent for someone else as being held by that other person instead. There are three different situations here, and the honest answer differs for each.
- A provider's own account information — the name, email and billing details of a business that signs up. We are the agency. We decide what we collect and why, and we answer to you for it directly.
- Xero contacts a provider has not shared with anyone. When a provider connects Xero we mirror their contact list so they can search and browse it. Those contacts are shown to that provider and to nobody else, we never contact them, and the mirror is deleted when the organisation is disconnected — by the provider, or by us when nobody has used it for the period set out in the User Terms. We hold that as agent for the provider, whose own Xero it came from and who remains responsible for it. If you are one of those contacts and want to know what is held about you, the business you deal with is the one that holds it.
- Anyone a provider has actually shared invoices with. This is different, and we do not hide behind the provider for it. Once a provider shares with you we email you, we hold your address and the invoices in order to show them to you, we record whether our mail arrived and when you last opened the portal, and we keep our own security records. Some of that we do for our own purposes rather than on anyone's instructions — for example, we stop sending to an address that permanently rejects our mail, which protects delivery for every other business using us. So for you we are an agency in our own right.
What that means if a provider has shared invoices with you: you do not have to work out which of us to approach. You can ask us for a copy of what we hold about you, ask us to correct it, or complain — at team@clientinvoices.com — or you can go to the business that shared them. Either works. What is on the invoice itself is theirs to change, because it lives in their Xero.
We tell you all of this when we first email you, and again on the screen you see before you enter the portal — on every plan, including ones where the portal carries the provider's own branding. Branding changes how the portal looks; it does not change who is holding your information.
Connecting Xero
When a provider connects Xero, we use Xero's official OAuth authorisation — we never see or store your Xero password. We request the minimum, read-only access we need: your identity (so we can sign you in), and read access to your Xero contacts and invoices. By default we cannot change anything in your Xero organisation. Your authorisation tokens are encrypted at rest, and you can disconnect at any time from your account or from within Xero, which immediately revokes our access.
One exception, which only you can switch on. If you connect a Stripe account to an organisation and turn on auto-invoicing, Xero asks you separately to approve permission for us to create contacts, sales invoices and payments in that organisation — so that a payment your customer makes becomes an invoice in your books. We use it for nothing else, we never edit or delete anything, and your other organisations stay read-only. Turning auto-invoicing off, or withdrawing the permission in Xero, ends it.
Information we collect
Providers. We collect your name and email address when you create an account. You sign in with Xero rather than a password — we never issue you one, so there is no password of yours for us to hold or to lose. When you connect Xero we receive your organisation name and the contacts and invoices you choose to work with (including invoice numbers, line items and amounts). If you subscribe to a paid plan, your payment card details are collected and processed by our payment provider, Stripe — we do not store full card numbers, only a Stripe customer reference. We automatically record technical data such as IP addresses and browser types to maintain security and understand aggregate usage of the service.
People who pay a provider through Stripe. If a provider has connected a Stripe account and turned on auto-invoicing, then when you pay them we receive, from their Stripe account, your email address, your name if you gave one, and the amount, currency and line items of what you paid for. We receive this from the provider's Stripe account rather than from you, and we use it for one thing: raising the matching sales invoice in that provider's Xero organisation and making it available to you. It is the same information you gave the provider at checkout — we are not adding to it, buying it, or looking it up anywhere else.
Clients. When a provider shares invoices with you, we hold your email address (so we can send your sign-in link), your name as it appears on the invoices, and the invoices themselves. We sign you in using a one-time, expiring link rather than a password, so we never collect or store a password for you. We record when you last signed in for security purposes.
Email delivery records
For each email we send to a client — an invitation or a sign-in link — we record what happened to it: the recipient's address, the subject, and whether our mail provider reported it as sent, delivered, delayed, opened, clicked, bounced, or marked as spam, together with any failure message their mail server returned. The sharing provider can see these records for their own clients only.
We keep this because an email that silently fails is indistinguishable from one that was ignored, and a provider chasing an unpaid invoice needs to know which it was. It also lets us stop sending to an address that permanently rejects our mail, which protects delivery for everyone else.
Whether an email was "opened" is measured with a small tracking image and is approximate only: many mail apps block such images, so an email that was read may show as unopened. We do not treat it as reliable and neither should anyone reading it.
Delivery records are deleted automatically 24 months after the email was sent. See Retention.
Portal view records
We record when a client last opened a provider's portal, and when they last opened a particular invoice, so the provider can see whether the invoice reached someone rather than guessing. We keep only the most recent time for each — not a history of every visit — and the sharing provider can see it for their own clients only.
This is a record of an actual signed-in page view, which is a different and more reliable thing than the email "open" described above; the two are labelled separately wherever a provider sees them. Requests that identify themselves as automated — search engine crawlers, link scanners run by corporate mail systems — are excluded, because those are not a person looking at anything.
Because only the latest time is stored, these records are overwritten as a client uses the portal and are removed with the share itself when access is revoked or the provider's account is deleted.
Invoice data we hold
When a provider shares a client with you, we store a copy (a snapshot) of each of that client's shared invoices and a secure link to each invoice's Xero-hosted online invoice page, so you can view and pay them reliably. We hold these only for as long as the share is active: when a provider revokes a share or deletes their account, the client loses access and the snapshots are removed. Payment of an invoice happens on Xero's secure online invoice page — Client Invoices does not process or store your clients' card or bank details.
How we use your information
We use personal information to:
- provide the Services, Site and customer support;
- connect to your Xero organisation and display and share the invoices of the clients you choose;
- verify your identity for security purposes, including issuing one-time sign-in links;
- resolve disputes and troubleshoot problems;
- prevent, detect and investigate fraud, abuse and other prohibited or illegal activities, and enforce our User Terms;
- send you service-related messages such as sign-in links, billing receipts and legal notices;
- produce anonymised, aggregated statistics about how the service is used.
Client Invoices does not sell, rent or lease personal information to anyone. We do not run advertising, do not share data with advertising networks, and do not build marketing profiles of you or your clients. We do not use your Xero data for anything other than providing the service to you.
Legal bases for processing personal data
Contract - to provide the Services, Site and customer support; verify your identity for security purposes; resolve disputes and troubleshoot problems; and enforce our User Terms, the processing is necessary for the contract we have with you.
Agent for the provider - when we mirror a provider's Xero contacts so they can browse their own client list, we hold that information for them rather than for ourselves, and act on their instructions with it. Under the GDPR this is the processor role; under the Privacy Act 2020 it is the agent rule in section 11.
Legal obligation - to prevent, detect and investigate potentially prohibited or illegal activities, the processing is necessary for us to comply with the law.
Legitimate interests - to keep the service secure, prevent fraud and abuse, and improve our Services, the processing is necessary for our legitimate interests or the legitimate interests of a third party unless there is a good reason to protect your personal data which overrides those legitimate interests.
Third parties
Xero is not on this list, and that is deliberate. Xero is where a provider's contact and invoice information comes from, not somewhere we send it. It is the provider's own accounting platform, held under their own agreement with Xero and governed by Xero's privacy policy. We read from it with the provider's authorisation; we do not disclose anything to it.
We share personal information only with the service providers below, and only to the extent needed to run Client Invoices:
- Stripe — two separate things, worth keeping apart. First, payment processing for provider subscriptions: a provider's card details go directly to Stripe and are governed by Stripe's privacy policy. Second, where a provider has connected their own Stripe account for auto-invoicing, Stripe is a source we read from rather than somewhere we send information: with that provider's authorisation we read the payments made to them, including the payer's name and email, so we can raise the matching invoice in their Xero. We do not send Stripe anything about a provider's customers, and we never hold the keys to a provider's Stripe account.
- Resend — delivery of the email we send: invitations, one-time sign-in links and billing receipts. Resend receives the recipient's address and the message, and reports back what happened to it. Resend is a United States company and uses its own suppliers to send, including Amazon Web Services; its list of sub-processors is public and they are all in the United States. Governed by Resend's privacy policy.
- DigitalOcean — hosting of our infrastructure. Our servers, and the files stored on them, are in Sydney, Australia.
- Sentry — error monitoring. When something goes wrong on the site, the technical details of the failure are sent to Sentry so we can fix it. We configure Sentry not to send personal information with those reports.
- Google reCAPTCHA — our contact form and the client sign-in page are protected by reCAPTCHA to prevent spam and abuse; when you use either, a token and your IP address are sent to Google for verification, governed by Google's privacy policy.
- Google Fonts and jsDelivr — the typeface and a small number of scripts our pages use are loaded from these services. Like any web request, that sends your IP address and browser type to them.
- Analytics — we use Google Analytics to understand how our website is used. Analytics storage is denied by default, so unless you opt in it sets no cookies and receives only anonymous, aggregate pings. If you accept analytics cookies via our cookie banner, Google Analytics sets cookies that measure your visits and returning sessions; you can decline (or later withdraw) without affecting the service. Like any web request, the data Google receives includes an IP address and browser type. We do not use this for advertising or cross-site tracking.
We may disclose personal information in response to subpoenas, court orders, or other legal requirements; to exercise our legal rights or defend against legal claims; to investigate, prevent, or take action regarding illegal activities, suspected fraud or abuse, or violations of our policies; or to protect our rights and property.
In the future, we may sell to, buy, merge with, or partner with other businesses. In such transactions, user information may be among the transferred assets.
This policy applies only to Client Invoices. Xero, Stripe, and other services you use have their own privacy practices that we do not control.
Cookies
Client Invoices always sets essential cookies: a session cookie and a security (CSRF) cookie required for signing in and using the service safely, and a "remember me" cookie. For clients signing in through a portal we set that cookie automatically, so a one-time link does not have to be requested on every visit; it is long-lived, and clearing this site's data in your browser removes it. These are necessary for the service to work as described and need no consent.
On the client portal — the pages a client signs in to — Google Analytics is not loaded at all unless that client has opted in on the notice screen shown before they enter. Declining is a real choice: the portal works identically either way, and nothing is sent to Google. That opt-in is stored against the client's record rather than in a cookie, so it survives clearing the browser and can be changed by asking us.
Elsewhere on our website we use analytics cookies (Google Analytics) only if you accept them. When you first visit we show a cookie banner; analytics storage stays denied until you click "Accept", and choosing "Decline" keeps analytics anonymous and cookieless. We remember your choice on your device so we don't ask again. We set no advertising or cross-site tracking cookies.
You can change your mind at any time by clearing this site's data in your browser (which removes the saved choice and shows the banner again), and you can block cookies in your browser settings — though signing in will not work without the essential ones.
Sending information overseas
Some of the businesses above are outside New Zealand, so using them means your information goes overseas. Principle 12 of the Privacy Act 2020 governs when we may do that, and the position differs depending on what the recipient does with it:
- Our hosting, email, payment and error-monitoring providers handle information only to do the job we have engaged them for, on our instructions and for no purpose of their own. Under the Privacy Act they hold it as our agent rather than receiving a disclosure from us, so Principle 12 is not engaged — but we still require contractual protections from each of them.
- Google is different. reCAPTCHA and Google Analytics both let Google use what they receive for Google's own purposes, so sending information to them is a genuine cross-border disclosure. We rely on your authorisation for it: on the client portal, Google Analytics does not load at all unless you have opted in on the screen you see before entering, and you can decline without losing anything. reCAPTCHA protects our sign-in and contact forms against automated abuse, and is disclosed on those forms before you use them.
Where your data is stored
Our servers run on DigitalOcean in Sydney, Australia, and that is where your information is stored. Files you upload — an organisation's logo, for example — are held on those same servers rather than in a separate storage service.
Sanderson Howe Limited is a New Zealand company and operates from New Zealand. New Zealand holds a European Commission adequacy decision, so personal data can flow from the EEA to us without additional safeguards. Australia does not hold one, so for the onward hosting of EEA and UK personal data in Sydney we rely on standard contractual clauses with DigitalOcean rather than on adequacy.
Under New Zealand law DigitalOcean holds this information to run our servers on our instructions, and for no purpose of its own — so it is a supplier holding information for us rather than someone we disclose it to. Australia's own privacy law also applies to information held there.
Email is the exception, and it goes further. Everything we send — invitations, sign-in links, receipts — is delivered by Resend, a United States company, which uses its own suppliers (including Amazon Web Services) to do it. So a recipient's email address, the message itself and the record of what happened to it are processed in the United States, not in Sydney, and Resend keeps those records in the United States whichever region the mail is sent from. The United States holds no European Commission adequacy decision, so for EEA and UK personal data we rely on standard contractual clauses here too.
Security of your personal information
All traffic to and from Client Invoices is encrypted in transit using TLS. Your Xero authorisation tokens are encrypted at rest, and access to personal information is restricted to those who need it to operate the service. Payment card numbers never touch our servers — they are handled by Stripe, and client invoice payments are handled by Xero. No service can guarantee absolute security, but we design for holding as little personal data as possible, for as short a time as possible.
If something goes wrong
If personal information we hold is lost, or accessed or disclosed without authorisation, we assess whether it is likely to cause serious harm. If it is, we notify the Office of the Privacy Commissioner and the people affected as soon as we can, as Part 6 of the Privacy Act 2020 requires. Where the information came from a provider's Xero organisation we tell that provider promptly as well, so they can meet their own obligations — and neither of us waits to work out whose responsibility it is before telling the other.
If you are in the EEA or UK, we will notify the relevant supervisory authority within 72 hours of becoming aware of a breach where the GDPR requires it, and notify you directly where the breach is likely to result in a high risk to your rights and freedoms.
Retention
We retain account data for as long as you have an account with us, plus any period required for accounting, tax or legal obligations. Shared invoice snapshots are kept only while a share is active and are removed when the share is revoked or the account is deleted. One-time sign-in links expire 15 minutes after they are issued and can be used once; we store only a hashed form of the link, never the link itself, and spent links are deleted daily. Email delivery records — what happened to each invitation or sign-in email we sent a client — are deleted 24 months after the email was sent. We keep a security log of significant actions — who shared or revoked what, and when, with the IP address it came from — for 12 months. Sign-in sessions hold an IP address and browser type until the session is cleared. When a job in our system fails, the technical record of it (which can include an email address) is kept for 7 days. A client account that has not been used for 12 months, and that no longer has access to anything, is erased.
When you delete your account, your data is removed from our live systems immediately; disconnecting Xero revokes our access to your accounting data.
Your information additional rights
Depending on your location, you may have additional rights regarding your information, including:
- Access and portability: You can request a copy of your personal data provided to Client Invoices by contacting us.
- Correction: You can update your personal data.
- Deletion: You can request Client Invoices to delete your personal information, except where retention is required by law, by contacting us.
- Withdrawal of consent or objection to processing: You can request Client Invoices to stop processing your personal data in certain situations by contacting us.
New Zealand Privacy Act 2020
As a New Zealand company we comply with the Privacy Act 2020 and its Information Privacy Principles. You have the right to access and correct personal information we hold about you. Our Privacy Officer is William Tonkin-Howe, who can be reached at team@clientinvoices.com. If you are not satisfied with our response to a privacy concern, you can complain to the Office of the Privacy Commissioner at privacy.org.nz.
If you are in the EEA or the UK
Who is responsible. Sanderson Howe Limited, a New Zealand company, is the controller of the personal data described in this policy. New Zealand holds a European Commission adequacy decision, so personal data may flow from the EEA to us without additional safeguards. Where we send data onward to a processor outside an adequate country, we rely on standard contractual clauses.
Your rights. You have the right to access the personal data we hold about you, to receive it in a portable form, to have it corrected or erased, to restrict or object to our processing of it, and to withdraw consent at any time where we rely on consent. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects — we make no such decisions. Exercise any of these by emailing team@clientinvoices.com; we respond within one month, and will tell you if we need longer.
Complaints. You may complain to your local supervisory authority. We would rather you told us first so we can put it right.
Article 27 representative. If we are required to appoint a representative in the EEA or the UK, we will name them here. If you are in the EEA or UK and need one before that appears, contact us and we will tell you who to deal with.
If you are in California
You have the right to know what personal information we have collected about you, where we got it, why we hold it and who we have disclosed it to; to receive a copy in a portable form; to have it corrected; and to ask us to delete it. You may not be discriminated against for exercising any of these.
We do not sell or share personal information as those terms are used in California law, and we have not done so in the preceding twelve months. We run no advertising and do not disclose anything to advertising networks.
Exercise these rights by emailing team@clientinvoices.com. We will verify that the request is genuinely yours before acting on it, and you may use an authorised agent — tell us and we will explain what we need from them.
How to exercise your rights
To make such a request, contact Client Invoices at team@clientinvoices.com. All such requests are subject to verification of the identity of the requestor and the legitimacy of the request. We respond as soon as we reasonably can, and no later than 20 working days after we receive the request, as the Privacy Act 2020 requires. Establishing that a request is genuine is part of that, and does not extend the 20 working days. If we need longer, we will tell you before the 20 working days are up, explain why, and give you a date.
To the extent we act as a provider's processor (for example, when we display invoices on their behalf), you can exercise your rights over that invoice data directly with the provider who shared it with you.
Your responsibilities as a provider
If you use Client Invoices to share invoices with your clients, you remain the controller of the contact and invoice data in your Xero account. You are responsible for connecting only Xero organisations you are authorised to access, for sharing invoices only with the people they are intended for, for having a lawful basis to process the personal data they contain, and for honouring your clients' requests for access, correction and deletion. Only use Client Invoices to share invoices for legitimate billing purposes.
Withdrawing consent
You can withdraw your consent for processing of your information and use of the Services at any time. To permanently delete your account, please email team@clientinvoices.com requesting the closure of your account and deletion of your data. This deletion is permanent and your account cannot be reinstated. We will only keep information that we are required to by law.
Opt-out & unsubscribe
Client Invoices sends service-related messages only — sign-in links, invitations, billing receipts and legal notices. These are part of the service and cannot be unsubscribed from while you are using it; clients stop receiving them when the provider who invited them revokes their access. We do not send marketing email and do not operate a newsletter. If that ever changes we will ask for your consent separately first, and every such message will carry an unsubscribe link.
Children and minors
Client Invoices is an accounting tool for businesses. It is not directed at or intended for use by children, and we do not knowingly collect their personal information.
Governing law
Your information is provided to us in accordance with the laws of New Zealand.
Changes to this statement
Client Invoices updates this policy when our practices change. We encourage you to review it to stay informed about how we protect your information.
Contact information
For inquiries regarding Client Invoices's privacy practices, please contact Client Invoices at team@clientinvoices.com.
Last updated: August 31, 2026