EFFECTIVE 27 JULY 2026 · REVIEWED 11 AUGUST 2026
Privacy Notice
This page explains how the Invoice Maker web service is operated by Glipo Yazılım. For questions, contact destek@invoicemake.app .
Who controls the data
Glipo Yazılım operates Invoice Maker and acts as controller for account and workspace data, except where a provider acts independently for its own legal obligations. Contact the support address above for privacy requests. This notice applies to the web application and public website.
Data we process
We may process account email and profile details; business, client, product, invoice, quote, payment and expense records; settings and exports; authentication and security logs; error diagnostics; subscription identifiers; support correspondence; and optional analytics events after consent. Invoice Maker does not store full card details.
Purposes and legal grounds
Account and workspace data are used to perform the service contract. Security, abuse prevention, reliability and support are processed where necessary for the service and legitimate operational interests, subject to applicable law. Billing records are processed for contract and legal obligations. Google Analytics loads only after an affirmative choice and is based on consent where required.
Providers and international processing
Firebase supports authentication, Paddle handles checkout and merchant-of-record billing, Arislytic may receive technical error diagnostics, Google Analytics receives consented usage data, and hosting/PostgreSQL infrastructure stores application records. When the operator enables new-account, Web Premium or mobile account-link alerts, the Telegram Bot API receives the details needed to deliver the selected operational notification. A new-account alert includes the account name, email, locale, signup time and aggregate account count. A Web Premium alert covers first Premium access through Paddle on the web and includes the account name, email, plan, web/Paddle source, activation time and aggregate active Web Premium count. A mobile account-link alert is sent when account pairing completes—not for a RevenueCat Premium event—and includes the account name, email, platform, link time and the account's active linked-mobile-installation count. Anyone with access to the configured Telegram chat or channel may see those details. Providers may process data in other countries under their contractual and legal safeguards. We limit data sent to each provider to the service it performs.
Retention and deletion
Active workspace data is retained while the account is used. A confirmed workspace deletion removes active application records; security, transaction and provider records may remain for fraud prevention, dispute handling, backups and mandatory legal periods. Operational backups rotate on a controlled schedule. Analytics retention follows the configured GA4 property period. We do not keep data merely because it might be useful later.
Your choices and rights
You can export the workspace, correct many records in the product, request access or deletion, and decline analytics without losing core service access. Depending on applicable law, you may also have rights to restriction, objection, portability and complaint to a supervisory authority. We may verify identity before fulfilling a request.