Privacy Policy
Last updated: August 22, 2026
1. Introduction
Fabro ("we", "us", "our") operates the invoicing and payment automation platform available at fabro.app. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our Service.
We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws. By using the Service, you acknowledge that you have read and understood this Privacy Policy.
2. Data Controller
Fabro acts as the data controller for your personal data. For questions or requests related to your data, contact us at privacy@fabro.app.
3. Data We Collect
3.1 Account Data
When you create an account, we collect:
- Full name
- Email address
- Password (stored as a secure hash, never in plain text)
- Company or business name (optional)
3.2 Billing Data
When you subscribe to a paid plan, we collect:
- Payment method details (processed and stored by Stripe — we never store your full card number)
- Billing address
- Transaction history
3.3 Business Data
In the course of using the Service, you may input:
- Client names, email addresses, and contact details
- Invoice details (amounts, descriptions, due dates)
- Project and milestone information
- Payment reminder configurations
- Late fee rules and parameters
This data is provided voluntarily by you and is essential for the Service to function. You are responsible for ensuring you have the right to store your clients' data through our Service.
3.4 Usage Data
Depending on the platform and enabled configuration, we or our service providers may process:
- Browser type and version
- Device type and operating system
- Technical request data, which may include an IP address
- Feature-use events when product telemetry is enabled
- Crash reports, error logs, and diagnostic context
3.5 Cookies
The web application uses essential session storage and cookies for authentication, security, and core account functions. The public landing pages do not use advertising cookies. Optional product telemetry, when enabled on a platform, is described below and is not used to build advertising profiles.
4. How We Use Your Data
We use your data to:
- Provide and operate the Service (creating invoices, sending reminders, processing payments)
- Manage your account and subscription
- Send transactional emails (invoice confirmations, payment receipts, reminder notifications)
- Communicate important updates about the Service or your account
- Detect and prevent fraud, abuse, or security incidents
- Improve the Service through aggregated, anonymized analytics
Legal basis (GDPR): We process your data based on (a) contractual necessity (to provide the Service you subscribed to), (b) legitimate interest (to improve and secure the Service), (c) compliance with legal obligations, and (d) consent where a processing activity legally requires it.
5. Data Sharing
We do not sell, rent, or trade your personal data. We share data only with the following categories of third parties, strictly for the purposes described:
- Stripe — payment processing. Stripe receives your billing data to process subscription payments and client payments. See Stripe's Privacy Policy.
- Resend — transactional email delivery. Resend processes email addresses and email content to deliver invoices, reminders, and account notifications.
- Sentry — error monitoring. Sentry may receive technical error and diagnostic data; Fabro disables Sentry's default collection of personally identifying information.
- RevenueCat — if an iOS purchase is offered and used, RevenueCat may process a pseudonymous app-user identifier and App Store subscription events to determine access.
- TelemetryDeck — when iOS product telemetry is enabled, TelemetryDeck receives pseudonymous technical usage events. Fabro does not intentionally include invoice contents, client contact details, or payment amounts in those events.
- External e-invoicing provider — when direct transmission is enabled and authorised, the provider processes invoice and recipient data needed to transmit and track the document.
- Cloud infrastructure providers — store and process account and business data as part of running the Service.
We use contractual and transfer safeguards with service providers where required by applicable data protection law.
6. Data Retention
We keep account and business data while the account is active and for as long as needed to provide the Service. Confirming account deletion disables access and starts an irreversible deletion process. Residual copies may remain temporarily in protected backups until their normal expiry.
We retain limited billing, tax, payment, fraud-prevention, security, and dispute records for the period required by applicable law or our legitimate obligations. Service-provider logs follow the provider's applicable retention settings. We do not promise a post-deletion export window, so export needed records before confirming deletion.
7. Data Security
We implement appropriate technical and organizational measures to protect your data, including:
- Encrypted transport (TLS/HTTPS)
- Secure password hashing
- Two-factor authentication (optional)
- Dependency monitoring and updates
- Access control and authentication within the Service
- Rate limiting and abuse prevention
While we take reasonable measures to protect your data, no system is 100% secure. We will notify you promptly in the event of a data breach affecting your personal data, as required by law.
8. Your Rights (GDPR)
If you are located in the European Economic Area (EEA), you have the following rights regarding your personal data:
- Right of access — request a copy of your personal data
- Right to rectification — request correction of inaccurate data
- Right to erasure — request deletion of your personal data ("right to be forgotten")
- Right to restriction — request restriction of processing in certain circumstances
- Right to data portability — receive eligible data in a structured, commonly used, machine-readable format
- Right to object — object to processing based on legitimate interest
- Right to withdraw consent — withdraw consent for optional data processing at any time
To exercise any of these rights, contact us at privacy@fabro.app. We will respond within the period required by applicable law.
9. International Data Transfers
Your data may be processed in countries outside the EEA. Where this occurs, we ensure adequate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or the service provider's adherence to recognized data protection frameworks.
10. Your Clients' Data
When you use Fabro to store your clients' contact information and send them invoices or reminders, you act as the data controller for your clients' data. Fabro acts as a data processor on your behalf.
You are responsible for:
- Having a lawful basis to store and process your clients' data
- Informing your clients about how their data is processed
- Responding to your clients' data subject requests
11. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will promptly delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service where required. The "Last updated" date at the top of this page indicates the most recent revision.
13. Contact
For questions, concerns, or requests related to this Privacy Policy or your personal data, contact us at:
Email: privacy@fabro.app
You also have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated. In France, the supervisory authority is the CNIL (Commission Nationale de l'Informatique et des Libertés).