Fabro
FeaturesPricing
FRLog inTry on the web
FeaturesPricing
FRLog inTry on the web

Privacy Policy

Last updated: September 25, 2026

Fabro is published by Eddy Naboulet, entrepreneur individuel (EI), a French sole trader under the micro-entrepreneur regime, SIREN 531 743 870, at 30 rue Sainte-Philomène, 33300 Bordeaux, France. See the legal notice for publisher and hosting details.

1. Introduction

Fabro ("we", "us", "our") operates the invoicing and payment automation platform available at fabro.app. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our Service.

We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws. By using the Service, you acknowledge that you have read and understood this Privacy Policy.

2. Data Controller

Eddy Naboulet, entrepreneur individuel (EI), publisher of Fabro, acts as the data controller for your personal data. For questions or requests related to your data, contact us at privacy@fabro.app.

3. Data We Collect

3.1 Account Data

When you create an account, we collect:

  • Full name
  • Email address
  • Password (stored as a secure hash, never in plain text)
  • Company or business name (optional)

3.2 Billing Data

When you subscribe to a paid plan, we collect:

  • Payment method details (processed and stored by Stripe — we never store your full card number)
  • Billing address
  • Transaction history

3.3 Business Data

In the course of using the Service, you may input:

  • Client names, email addresses, and contact details
  • Invoice details (amounts, descriptions, due dates)
  • Project and milestone information
  • Payment reminder configurations
  • Late fee rules and parameters

This data is provided voluntarily by you and is essential for the Service to function. You are responsible for ensuring you have the right to store your clients' data through our Service.

3.4 Usage and Diagnostic Data

We process the following usage data. It is never used for advertising profiles.

  • Account events: our servers record a limited set of pseudonymous events (account created, trial started and ended, subscription started, changed, or cancelled, payment failed, plan limit reached). They are keyed by an internal account identifier and contain neither your name nor your email address.
  • Acquisition data: when you sign up, the campaign parameters of the link that brought you (utm_source, utm_medium, utm_campaign, utm_content, utm_term, or ref), the host of the referring website, if any, and the first web app page you opened are recorded with your account and these events. Until then, the web app (app.fabro.app) keeps them in your browser's local storage for up to 30 days; they are deleted from your browser once your new account has recorded them.
  • Error reports: the web app, our API, and the iOS app report errors with technical context such as browser or device type, operating system, and app version.
  • iOS app events: the iOS app sends pseudonymous usage events (onboarding and subscription steps, document actions such as created or sent) to operate and improve the app.
  • Web app upgrade events: the web app sends anonymous events about the upgrade path (billing page viewed, upgrade prompt viewed, checkout clicked, plan change confirmed), with the plan or feature concerned. Their random identifier stays in memory until the page is closed or reloaded and is not linked to any account.
  • Website audience: the public website fabro.app may measure page views, page leaves, and clicks on sign-up buttons (events $pageview, $pageleave, and landing_cta_clicked) without cookies or any storage on your device; data is kept in memory for the open page only. The campaign parameters of your visit and the referring website's host travel in the site's links up to the sign-up page; they are not stored.
  • Technical request data, which may include an IP address, processed by our hosting and service providers to deliver and secure the Service.

3.5 Cookies

The web application uses essential session storage and cookies for authentication, security, and core account functions, and local storage for the sign-up campaign parameters described in Section 3.4. The public website fabro.app sets no cookies: its audience measurement keeps no identifier on your device. No advertising cookies are used.

4. How We Use Your Data

We use your data to:

  • Provide and operate the Service (creating invoices, sending reminders, processing payments)
  • Manage your account and subscription
  • Send transactional emails (invoice confirmations, payment receipts, reminder notifications)
  • Communicate important updates about the Service or your account
  • Detect and prevent fraud, abuse, or security incidents
  • Understand how the Service is used and which campaigns bring new accounts, through pseudonymous and aggregated analytics

Legal basis (GDPR): We process your data based on (a) contractual necessity (to provide the Service you subscribed to), (b) legitimate interest (to improve and secure the Service), (c) compliance with legal obligations, and (d) consent where a processing activity legally requires it.

5. Data Sharing

We do not sell, rent, or trade your personal data. We share data only with the following categories of third parties, strictly for the purposes described:

  • Stripe — payment processing. Stripe receives your billing data to process subscription payments and client payments. See Stripe's Privacy Policy.
  • Resend — transactional email delivery. Resend processes email addresses and email content to deliver invoices, reminders, and account notifications.
  • PostHog (PostHog, Inc., US Cloud) — product analytics and error monitoring: the account events, acquisition data, error reports, iOS app events, web app upgrade events, and website audience measurement described in Section 3.4. Fabro does not intentionally send invoice contents, client contact details, invoice payment amounts, or your name or email address. Session recording and automatic capture of web interactions are disabled. Data is hosted in the United States; see Section 9.
  • RevenueCat — if an iOS purchase is offered and used, RevenueCat may process a pseudonymous app-user identifier and App Store subscription events to determine access.
  • External e-invoicing provider — when direct transmission is enabled and authorised, the provider processes invoice and recipient data needed to transmit and track the document.
  • Cloud infrastructure providers — store and process account and business data as part of running the Service.

We use contractual and transfer safeguards with service providers where required by applicable data protection law.

6. Data Retention

We keep account and business data while the account is active and for as long as needed to provide the Service. Confirming account deletion disables access and starts an irreversible deletion process. Residual copies may remain temporarily in protected backups until their normal expiry.

We retain limited billing, tax, payment, fraud-prevention, security, and dispute records for the period required by applicable law or our legitimate obligations. Service-provider logs follow the provider's applicable retention settings. We do not promise a post-deletion export window, so export needed records before confirming deletion.

7. Data Security

We implement appropriate technical and organizational measures to protect your data, including:

  • Encrypted transport (TLS/HTTPS)
  • Secure password hashing
  • Two-factor authentication (optional)
  • Dependency monitoring and updates
  • Access control and authentication within the Service
  • Rate limiting and abuse prevention

While we take reasonable measures to protect your data, no system is 100% secure. We will notify you promptly in the event of a data breach affecting your personal data, as required by law.

8. Your Rights (GDPR)

If you are located in the European Economic Area (EEA), you have the following rights regarding your personal data:

  • Right of access — request a copy of your personal data
  • Right to rectification — request correction of inaccurate data
  • Right to erasure — request deletion of your personal data ("right to be forgotten")
  • Right to restriction — request restriction of processing in certain circumstances
  • Right to data portability — receive eligible data in a structured, commonly used, machine-readable format
  • Right to object — object to processing based on legitimate interest
  • Right to withdraw consent — withdraw consent for optional data processing at any time

To exercise any of these rights, contact us at privacy@fabro.app. We will respond within the period required by applicable law.

9. International Data Transfers

Your data may be processed in countries outside the EEA. Where this occurs, we ensure adequate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or the service provider's adherence to recognized data protection frameworks.

In particular, PostHog processes analytics and error data in its US Cloud region, in the United States. These transfers rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU-U.S. Data Privacy Framework.

10. Your Clients' Data

When you use Fabro to store your clients' contact information and send them invoices or reminders, you act as the data controller for your clients' data. Fabro acts as a data processor on your behalf.

You are responsible for:

  • Having a lawful basis to store and process your clients' data
  • Informing your clients about how their data is processed
  • Responding to your clients' data subject requests

11. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will promptly delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service where required. The "Last updated" date at the top of this page indicates the most recent revision.

13. Contact

For questions, concerns, or requests related to this Privacy Policy or your personal data, contact us at:

Email: privacy@fabro.app

You also have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated. In France, the supervisory authority is the CNIL (Commission Nationale de l'Informatique et des Libertés).

Fabro—© 2026 Fabro. All rights reserved.
SupportPrivacyTermsLegal notice