Privacy Policy
At Facturia (published by LFD Starter LLC), the protection of your personal data is an absolute priority. This privacy policy aims to inform you transparently about how we collect, use, and protect your data, in full compliance with the General Data Protection Regulation (GDPR — EU Regulation 2016/679) and applicable data protection legislation.
1. Data Controller
The data controller is:
- LFD Starter LLC
- 539 W. Commerce St #6909, Dallas, TX 75208, United States
- Contact: contact@facturia.ink
2. Data Collected
As part of the use of Facturia, we collect only the data strictly necessary for the operation of the service:
- Identification data: last name, first name, email address (upon registration or login via Google OAuth).
- Billing data: information relating to your companies, clients, and invoices that you create through the service.
- Technical data: session cookies strictly necessary for authentication.
3. Commitment Not to Exploit Data
Facturia does not use, sell, rent, share, or monetize its users' personal data in any way.
More specifically:
- Your data is never transmitted to third parties for commercial, advertising, or profiling purposes.
- Your data is never used to train artificial intelligence models or for research purposes.
- Your invoices, client information, and company data remain strictly private and are accessible only to you.
- No advertising, tracking, or behavioral analytics cookies are used on the site.
- We do not use any third-party tracking tools (no Google Analytics, no Facebook Pixel, no retargeting solutions).
4. Purposes of Processing
Your data is processed exclusively for the following purposes:
- Creation and management of your user account.
- Provision of the invoicing service (creation, sending, and storage of invoices).
- Management of your subscriptions and payments (via Stripe, which acts as a processor).
- Service-related communication (transactional emails only).
5. Legal Basis for Processing
The processing of your data is based on:
- Performance of the contract (Article 6.1.b of the GDPR): processing is necessary for the provision of the service to which you have subscribed.
- Legitimate interest (Article 6.1.f of the GDPR): ensuring the security and proper functioning of the service.
6. Processors
For the operation of the service, we use the following processors, all GDPR-compliant:
- Cloudflare — Hosting of the application (Workers & Pages), the database (D1), and file storage (R2), on a secure, GDPR-compliant global network.
- Stripe — Payment processing (PCI-DSS certified, GDPR-compliant). Facturia does not store any banking data.
- Google (Gemini API) — AI processing for invoice generation. Messages are sent on a one-time basis and are not stored by Google to train models.
- Resend — Sending of transactional emails (confirmation, password reset, sending of invoices).
7. Retention Period
Your data is retained for the duration of your use of the service. If you delete your account, all of your personal data will be deleted within 30 days, with the exception of data that we are required to retain for legal obligations (in particular issued invoices, retained for 10 years in accordance with accounting obligations).
8. Your Rights (GDPR)
In accordance with the General Data Protection Regulation, you have the following rights:
- Right of access (Article 15): to obtain confirmation that data concerning you is being processed and to obtain a copy of it.
- Right to rectification (Article 16): to have inaccurate or incomplete data corrected.
- Right to erasure (Article 17): to request the deletion of your personal data.
- Right to restriction of processing (Article 18): to request the restriction of processing in certain cases.
- Right to data portability (Article 20): to receive your data in a structured, commonly used, and machine-readable format.
- Right to object (Article 21): to object to the processing of your data on legitimate grounds.
To exercise any of these rights, contact us at contact@facturia.ink. We undertake to respond within 30 days.
9. Data Security
We implement appropriate technical and organizational measures to protect your data against any unauthorized access, alteration, disclosure, or destruction:
- Encryption of data in transit (HTTPS/TLS).
- Encryption of data at rest in the database.
- Secure authentication (passwords hashed via bcrypt, secure sessions, Google OAuth login).
- Strict data isolation per user account: each user accesses only their own data.
- No storage of passwords in plain text.
10. International Data Transfers
Some of our processors may be located outside the European Economic Area (EEA). In such cases, we ensure that appropriate safeguards are in place in accordance with the GDPR, in particular through the Standard Contractual Clauses (SCCs) approved by the European Commission or through the EU-US Data Privacy Framework.
11. Right to Lodge a Complaint
If you believe that the processing of your data does not comply with the regulations, you have the right to lodge a complaint with the competent supervisory authority. In France, this is the CNIL (French Data Protection Authority): www.cnil.fr.
12. Changes to the Policy
We reserve the right to modify this privacy policy at any time. In the event of a substantial change, we will inform users by email or via a notification within the application. The date of the last update is indicated below.
Last updated: July 2026