Privacy Policy
Crest Invoice is a personal software project operated by the Crest Invoice Team: Alina Riaby and Pavel Riaby.
This policy explains what happens to personal data when you create an invoice, use a Live Invoice, request returning access, contact us, or simply visit a Crest page — and which information never leaves your browser. If anything is unclear, email support@crest-invoice.com.
Your invoice choices
- Save or print a PDF: invoice contents stay in your browser and go only to the file or printer destination you choose. Crest does not receive them.
- Temporary public link: Crest stores the invoice until 30 days after its due date, or, when it is already overdue or has no due date, 30 days after link creation.
- Send & track: Crest stores one fixed calendar-year deadline when it creates the temporary invoice and returns that exact date before verification. Verification activates management without recalculating it. Activity and closing the invoice do not move that deadline.
- My Invoices: Account-Lite keeps the business name and owner email separately from invoice data until a future account-deletion control is available. Payment defaults exist only after an explicit save.
Who operates Crest
Alina Riaby and Pavel Riaby are joint controllers. Crest Invoice Team is the name they work under, not an incorporated legal entity. They decide together why and how Crest processes personal data, share responsibility for protecting it and for handling your requests, and use support@crest-invoice.com as their common contact. You may exercise your rights against either of them.
Crest does not sell or rent personal data, disclose it for advertising, or use it for targeted advertising.
What Crest processes, and why
What Crest receives depends on the features you use. Invoice details are usually entered by the invoice creator, not by the client named on the invoice, and the creator must have the authority to provide that client's data.
| What you do | What Crest processes | Why |
|---|---|---|
| Create a PDF or print an invoice | The invoice fields you enter: parties, items, amounts, dates, notes and payment instructions | Everything stays in your browser unless you choose a server-backed feature such as Send or Live Invoice. Loading the page itself can still create limited technical logs at the infrastructure level. |
| Create and send a Live Invoice | The invoice and contact details you submit, plus the access links, status changes, payment reports, Undo events and delivery records the invoice produces | To host, deliver and track the invoice you asked Crest to send. Narrow security and operational records rely on legitimate interests. |
| Sign in with an email code (Account-Lite) | Your email address, one-time-code records and a secure access session | To give you returning access to your invoices and to protect that access. Codes and sessions are never used for marketing. |
| Join the waitlist or contact Crest | The name, company and email you submit, plus limited source information | To answer your request. Optional marketing contact is always a separate choice, and withdrawing is as easy as joining. |
| Receive email from Crest or write to support | Email addresses, subjects, limited delivery records and whatever you send to support | To deliver the requested invoice, access code or reply. Transactional addresses are not reused for marketing. |
| Keep the service safe | Request metadata, authentication events and rate-limit records | Legitimate interests in preventing abuse and keeping Crest running, plus legal obligations where they apply. |
| Visit a measured page | Minimized first-party usage events and cookie-free analytics events | Legitimate interests in understanding aggregate product use. See the storage and analytics section below. |
| Handle a legal duty or claim | Only the records needed for the specific duty or claim | A legal obligation, or establishing, exercising or defending a claim — never a blanket reason to keep everything. |
A PDF-only invoice stays in your browser and in the file or print destination you choose. Crest receives invoice content only when you expressly choose Send, a Live Invoice or another server-backed feature, and the interface says what will be sent before you submit.
Who receives data
Crest shares data only to provide the feature you choose, or where disclosure is genuinely necessary and lawful:
- Hetzner provides the infrastructure used to run the Crest application and store its server-side data.
- Beget carries incoming and outgoing email for Crest.
- Analytics requests go to
analytics.gnomik.orgthrough Cloudflare. Its operator, processor role, origin hosting and retention remain unverified. - The invoice creator and the invoice recipient each receive the invoice information and status appropriate to their role.
- Professional advisers, public authorities or courts receive information only when it is necessary for advice, a legal duty or a specific claim.
Processing can happen outside your country. Crest states a provider's country, role or transfer safeguards only after verifying them for its actual account, rather than inferring them from the provider's public terms. Email support@crest-invoice.com for the current verified details that apply to your request.
How long Crest keeps data
Crest promises a fixed deletion period only where the current release actually enforces one. Everything else is described by its real trigger instead of a guess:
- Temporary Live Invoices: 30 days after the end of a future due date; if the invoice is already overdue or has no due date, 30 days after link creation. The link page, API and cleanup process follow the same stored deadline and reason. A hashed, non-reversible record of the link remains for a further 30 days solely to keep deleted or expired links invalid.
- Demo invoices are deleted within 24 hours; their hashed link records within 7 days.
- Managed Live Invoices and their invoice-scoped records are kept for one fixed calendar year from the stored server promise unless deleted sooner. Upgrading replaces the temporary-expiry rule with that already stored deadline. Viewing, sending, reminders, payment reports and closing do not extend or shorten it. Legacy managed invoices without a stored promise are backfilled from the earliest recorded upgrade, or from invoice creation when none was recorded.
- Deleting an invoice immediately hides it and disables its links. Undo is available against the server deadline for 15 seconds and restores the exact preceding invoice, link, reminder and activity state. After that, background cleanup permanently removes the invoice content, payment information, events, reminders and access records; a hashed record of the link remains for 30 days solely to prevent link reuse.
- Detailed delivery logs that are not removed with an invoice are deleted within 30 days. A minimal accepted-delivery marker stays with the invoice so Crest does not resend an accepted delivery, and is removed when the invoice is deleted.
- One-time sign-in codes expire after 30 minutes, and expired code records are deleted within 24 hours of expiry. Access sessions are deleted when they expire, and the access cookie lasts at most 30 days.
- Account-Lite identity (business name and owner email) is separate from invoice data and is not removed by invoice deletion; it remains until a future account-deletion control is available. Verified-owner payment defaults are stored only after an explicit save and can be replaced by another explicit save. No anonymous browser key ever stores payment defaults.
- Completion events are deleted after 30 days. Contact records they reference are deleted once no recent completion event or Live Invoice points to them; contacts tied to a Live Invoice have no fixed maximum yet.
- Waitlist entries are deleted after 180 days, or earlier if you withdraw.
- First-party usage events are deleted after 90 days.
- Ordinary web-server and application request logging is switched off, so routine access logs are not kept at all.
- Support email is kept only while your request, or a specific legal need, stays open; Crest has not set a fixed maximum for it yet.
- Backups do not yet have a verified automatic expiry, so Crest does not promise one yet.
- Records kept for a rights request, a security incident or a legal matter are deleted when that specific need ends, and are never reused for measurement or marketing.
Fixed retention periods for the technical and business records held by Crest's infrastructure, email and analytics providers have not been verified for Crest's exact accounts, so none are promised here. A rights response describes the verified outcome that actually applies to your request.
You can delete an invoice with its product control or by emailing support@crest-invoice.com. The 15-second reversible window is implemented in Crest's primary database. Provider delivery logs, an email already delivered to another mailbox, and backups sit outside that immediate purge guarantee; their timing is reported only when verified for your request. Crest does not promise instant erasure from systems it cannot truthfully control.
Your rights
Depending on the law that applies to you, you may ask to access, correct or delete personal data; restrict processing; receive portable data; object to processing based on legitimate interests, including direct marketing; and withdraw consent without affecting earlier lawful processing. Crest does not use invoice data for solely automated decisions with legal or similarly significant effects.
Email support@crest-invoice.com and mention the feature or invoice involved, without sending more sensitive data than the request needs. Crest asks only for what is reasonably needed to verify that the data is yours, responds within the time the governing law sets, and does not charge for normal requests. A lawful fee or refusal can apply only to a manifestly unfounded or excessive request, and comes with an explanation.
You may also complain to the competent data-protection authority. In Serbia this is the Commissioner for Information of Public Importance and Personal Data Protection. That complaint path never limits your other remedies.
Security, children and changes
Crest uses encryption in transit, secure HTTP-only access cookies, high-entropy access links, data minimization and access controls. Treat access links like passwords and share them only with the intended person. No internet service is completely secure.
If you suspect a privacy or security incident, email support@crest-invoice.com. Crest will assess the facts, contain the issue, keep only the evidence that is needed, and notify affected people and authorities when the applicable law requires it.
Crest is intended for people aged 18 or older who have legal capacity and authority to issue the invoice or act for its sender. It is not directed to children. If a child's data was submitted without appropriate authority, email support@crest-invoice.com so Crest can assess and delete it.
The version and effective date appear at the top. Material changes are announced through the product or by email, and prior versions remain retrievable. Continued use never stands in for consent where the law requires a separate choice.
Cookies, storage and analytics
Browser storage is broader than cookies. This table covers everything Crest keeps in your browser, plus the separate analytics network request:
| Mechanism | What it does | How long it lives | Where it goes |
|---|---|---|---|
__Host-crest_access and per-invoice cookies whose names begin with __Host-crest_invoice_access_ | Keep the Account-Lite or invoice access you requested; secure, HTTP-only, SameSite=Lax cookies | Up to 30 days | Sent only to Crest with matching requests |
crest-theme | Remembers the theme you choose | Until you clear browser data | Never leaves the browser |
crest-business-details | Reuses the Business details you explicitly enter on future new invoices in this browser; removing the field clears it | Until you remove it or clear browser data | Stays in the browser until you include it in an invoice operation you choose, such as Send invoice |
| Draft, live, demo, report and Undo keys | Draft recovery and safe retries for an operation you start | Browser-session lifetime unless the interface says otherwise | Sent to Crest only with that operation |
crest-generator-session-id | Created only when a feature needs draft recovery or safe retries | Browser-session lifetime | Accompanies the requested Crest operation only; never sent with analytics |
| Analytics request (network transmission, not storage) | Sends the website identifier, hostname and URL path of the page. The network connection also exposes request metadata such as IP address and user agent to the receiving infrastructure. Query and hash values, invoice content and the Crest session id are excluded. | One request per measured page or event; it does not persist data in browser storage | To analytics.gnomik.org through Cloudflare; the operator, origin hosting and retention remain unverified |
umami.disabled | Records your analytics opt-out for this site | Until you opt back in or clear it | Read locally by the analytics script; never sent as a Crest identifier |
Local and session storage are not cookies, but anything stored on your device can still be subject to terminal-device rules.
Crest sends minimized analytics to analytics.gnomik.org through Cloudflare. The operator, processor role, origin hosting, region and deletion arrangement remain unverified, and no fixed retention period for analytics events has been verified yet. The configuration is cookie-free, receives no persistent Crest identifier, respects browser Do Not Track, excludes URL query and hash values, and is not used for advertising, fingerprinting or cross-site tracking. It is separate from crest-generator-session-id.
The Analytics privacy control below lets you opt out or opt back in. Opting out stores only the single per-site preference documented above; opting back in removes it. Crest uses no generic cookie banner in this minimized configuration. This is Crest's product configuration, not a court or regulator decision.