Privacy Policy
Last updated February 21, 2026
This Privacy Notice for Chompis ("we," "us," or "our") describes how and why we might access, collect, store, use, and/or share your personal information when you use our services, including when you visit chompis.io or engage with us in other related ways.
Questions or concerns? Contact us at support@chompis.io.
- We collect personal information you provide (name, email, business info, payment data) and some information automatically (IP address, usage data).
- Payment data is handled entirely by Stripe — we do not store card numbers.
- We do not collect information from third parties.
- We do not sell or share your personal information with third parties for marketing purposes.
- We retain your data for as long as your account is active, plus up to 3 months after termination.
- You have rights to access, correct, or delete your data at any time by contacting support@chompis.io.
- What Information Do We Collect?
- How Do We Process Your Information?
- Legal Bases for Processing
- When and With Whom Do We Share?
- Cookies and Tracking Technologies
- AI-Based Products
- Social Logins
- How Long Do We Keep Your Information?
- How Do We Keep Your Information Safe?
- Do We Collect Info From Minors?
- What Are Your Privacy Rights?
- Do-Not-Track Features
- US Residents — Specific Rights
- Updates to This Notice
- How to Contact Us
- Review, Update, or Delete Your Data
1.What Information Do We Collect?
Information you provide directly:
We collect personal information that you voluntarily provide when you register, use the Services, or contact us. This may include:
- Names, email addresses, usernames, passwords
- Phone numbers, mailing addresses, billing addresses
- Business profile information (business name, logo)
- Customer data you enter into the platform
- Invoice and payment records
Sensitive information: With your consent or as permitted by law, we may process financial data. All payment card data is handled and stored exclusively by Stripe — we do not store card numbers.
Social login data: If you register using Google or another social account, we receive profile information from that provider (name, email, profile picture).
Information collected automatically:
When you visit or use the Services, we automatically collect:
- Log and usage data (IP address, browser type, pages visited, timestamps, feature usage)
- Device information (operating system, device name, language preferences)
- Approximate location data based on IP address
2.How Do We Process Your Information?
We process your personal information to:
- Create and manage your account
- Deliver the Services, including sending automated invoice reminder emails on your behalf
- Process payments and manage subscriptions
- Respond to your support requests
- Send administrative communications (billing updates, policy changes)
- Prevent fraud and ensure platform security
- Analyze usage trends to improve the Services
- Send marketing communications (you can opt out at any time)
3.Legal Bases for Processing
We process your personal information only when we have a valid legal reason to do so — including your consent, to fulfill our contractual obligations to you, to comply with applicable law, or to serve our legitimate business interests.
If you are located in Canada, we may process your information with your express or implied consent, or in exceptional circumstances permitted by applicable Canadian law. You may withdraw consent at any time by contacting us.
4.When and With Whom Do We Share Your Information?
We do not sell your personal information. We share information only with the following service providers who help us operate the platform:
- Stripe — payment processing (stripe.com/privacy)
- Supabase — database and authentication, hosted in the United States
- Postmark — transactional email delivery for invoice reminders
- Vercel — application hosting infrastructure
We may also share information in connection with a merger, sale, or acquisition of all or part of our business, or as required by law.
We have not disclosed, sold, or shared any personal information to third parties for a business or commercial purpose in the preceding twelve (12) months, and we will not do so in the future.
5.Cookies and Tracking Technologies
We use cookies and similar tracking technologies to maintain session security, remember your preferences, and analyze usage of the Services. Some third-party service providers may also set cookies for analytics purposes.
You can configure your browser to refuse cookies, though doing so may limit some features of the Services. For more information, see our Cookie Policy.
6.AI-Based Products
As part of our Services, we may offer features powered by artificial intelligence or machine learning. These tools are provided through third-party AI service providers, which may include Anthropic and OpenAI. Your input and relevant personal information may be processed by these providers to enable AI features. You must not use AI features in any way that violates the terms or policies of any AI service provider.
7.Social Logins
If you register or log in using a social media account (such as Google), we receive certain profile information from that provider — typically your name, email address, and profile picture. We use this information only for the purposes described in this Privacy Notice and do not control how the social media provider uses your information.
8.How Long Do We Keep Your Information?
We retain your personal information for as long as your account is active or as needed to provide the Services. No purpose in this notice will require us to keep your personal information for longer than three (3) months past the termination of your account.
When we have no ongoing legitimate business need to process your personal information, we will delete or anonymize it. If deletion is not immediately possible (such as data stored in backup archives), we will securely isolate it from further processing until deletion is possible.
9.How Do We Keep Your Information Safe?
We have implemented appropriate technical and organizational security measures to protect your personal information. However, no electronic transmission or storage technology can be guaranteed to be 100% secure. You should only access the Services within a secure environment. Transmission of personal information to and from our Services is at your own risk.
10.Do We Collect Information From Minors?
We do not knowingly collect, solicit data from, or market to children under 18 years of age. By using the Services, you represent that you are at least 18 years old. If we learn that personal information from a user under 18 has been collected, we will deactivate the account and delete the data promptly. If you become aware of any such data, please contact us at support@chompis.io.
11.What Are Your Privacy Rights?
Depending on your location, you may have the right to:
- Request access to and a copy of your personal information
- Request correction of inaccurate data
- Request deletion of your personal information
- Restrict or object to the processing of your personal information
- Data portability (where applicable)
- Withdraw consent at any time (without affecting prior lawful processing)
To exercise any of these rights, contact us at support@chompis.io.
Opting out of marketing: You can unsubscribe from marketing emails at any time by clicking the unsubscribe link in any email we send. You will continue to receive service-related communications necessary for your account.
Account termination: You can request account deletion by contacting us. Upon deletion, we will remove your data from active databases within the retention window described in Section 8. We may retain limited information as required to prevent fraud or comply with legal obligations.
SMS and text message reminders: Chompis offers optional SMS invoice reminders as a Pro plan feature. If you enable SMS reminders for a customer, you confirm that you have obtained appropriate consent from that customer to receive text messages. Standard message and data rates may apply. Customers can reply STOP at any time to opt out, and we will honor all opt-out requests immediately. No mobile phone numbers or SMS consent data will be shared with third parties or affiliates for marketing or promotional purposes.
12.Controls for Do-Not-Track Features
Most web browsers include a Do-Not-Track ("DNT") feature. Because no uniform technology standard for DNT has been finalized, we do not currently respond to DNT signals. California law requires us to disclose this practice. If a standard is adopted that we must follow, we will update this notice accordingly.
13.US Residents — Specific Privacy Rights
If you are a resident of California, Colorado, Connecticut, Texas, Virginia, or other states with applicable privacy laws, you have the following rights:
- Right to know whether we are processing your personal data
- Right to access your personal data
- Right to correct inaccuracies
- Right to request deletion of your personal data
- Right to obtain a copy of personal data you previously shared with us
- Right to non-discrimination for exercising your rights
- Right to opt out of targeted advertising or profiling
To exercise these rights, email support@chompis.io or submit a data subject access request. We will verify your identity before processing requests. If your request is denied, you may appeal by emailing us, and if the appeal is denied, you may submit a complaint to your state attorney general.
California "Shine The Light": California residents may request information about categories of personal information disclosed to third parties for direct marketing purposes in the preceding year. We do not disclose personal information for such purposes, but you may submit a written request using the contact details below.
14.Do We Make Updates to This Notice?
We may update this Privacy Notice from time to time. The updated version will be indicated by an updated "Last updated" date at the top of this page. If we make material changes, we may notify you by email or by posting a prominent notice on the Services. We encourage you to review this notice periodically.
15.How to Contact Us
If you have questions or comments about this notice, please contact us at:
16.How to Review, Update, or Delete Your Data
You have the right to request access to the personal information we collect from you, correct inaccuracies, or request deletion. To exercise these rights, email us at support@chompis.io or submit a data subject access request. We will respond within 30 days.