Privacy Policy

How Friendly Office collects, uses, discloses, and protects your information.

Last updated July 31, 2026

This Privacy Policy explains how Friendly Office LLC, a Washington limited liability company (“Friendly Office,” “we,” “us,” or “our”), collects, uses, discloses, and protects information in connection with the Friendly Office invoicing application and the website at friendly-office.com (the “Service”). It applies to visitors to our website, people who create an account, and members of a workspace. By using the Service, you agree to this Policy. This Policy is incorporated into our Terms of Service.

1. Our Two Roles: Account Data and Customer Data

Friendly Office is a tool that businesses use to manage their own billing. Our handling of information falls into two categories:

  • Account and usage data. For information about you as an account holder and workspace member—such as your name, email address, and how you use the Service—we determine the purposes and means of processing and act as the responsible business for that information.
  • Customer data you upload. When you add your own billing customers, invoices, and payment records, that data (including any personal information about your customers) is yours. We process it on your behalf and under your instructions, as a service provider, solely to operate the Service. You are responsible for that data and for having a lawful basis to provide it to us.

2. Information We Collect

Information you provide directly:

  • Account information—your first and last name, email address, and password (which we store only in hashed form).
  • Workspace information—the name of each business workspace you create, the members you invite (by email address) and their roles, and your workspace settings.
  • Customer and invoicing data—the records you enter about your billing customers (such as name, company, email, phone number, and billing address) and the invoices, line items, taxes, discounts, due dates, notes, terms, payment records, and attachments you create.
  • Communications—information you provide when you contact us for support or otherwise correspond with us.

Information collected automatically:

  • Authentication and device data—when you sign in, we record session details such as your IP address and browser user-agent string to operate and secure the Service.
  • Document view and signing activity—when someone opens the customer-facing link to an invoice or agreement, or signs an agreement, we record the time of the visit together with the visitor’s IP address, browser user-agent string, and the country resolved from that address. This gives the business that sent the document a record of when it was opened, and forms part of the audit trail evidencing an electronic signature. Because these visitors are usually the recipients of a business that uses the Service rather than our own account holders, we collect this information on that business’s behalf as described in Section 1.
  • Log data—our servers automatically log requests, including timestamps, pages or endpoints accessed, and error and diagnostic information.
  • Analytics data—we use Google Analytics to understand how visitors and users interact with the Service. Google Analytics uses cookies and similar technologies to collect information such as the pages you view, referring URLs, approximate location derived from your IP address, and general device and browser characteristics. See Section 4 for details and your choices.
  • Cookies—we use strictly necessary cookies to keep you signed in and to protect against cross-site request forgery, and analytics cookies as described in Section 4.

Information from third parties: When you subscribe to a paid plan, our payment processor (Stripe) provides us with limited billing information such as a customer and subscription identifier, plan, subscription status, and the outcome of payment attempts. We do not receive or store your full payment card number.

3. How We Use Information

We use the information we collect to:

  • provide, operate, maintain, and secure the Service;
  • authenticate you, manage workspaces and member access, and enforce tenant isolation between workspaces;
  • send invoices, payment reminders, and related communications to the recipients you designate;
  • process subscriptions and payments and prevent fraud and abuse;
  • respond to your support requests and send you service and transactional messages, such as email confirmations and account notices;
  • monitor and improve the Service, diagnose problems, and develop new features; and
  • comply with legal obligations and enforce our Terms of Service.

We do not use the customer and invoicing data you upload for our own purposes beyond providing and improving the Service, and we do not use it to build advertising profiles.

4. Cookies and Similar Technologies

We use two categories of cookies and similar technologies:

  • Strictly necessary cookies keep you signed in across pages, maintain your session, and protect against cross-site request forgery. Because these are essential, they cannot be disabled through an in-product setting; you can block or delete them through your browser, but parts of the Service may then stop working.
  • Analytics cookies are set by Google Analytics, a service provided by Google LLC, to help us measure and improve how the Service is used. We do not use cookies for third-party advertising.

You can decline analytics cookies by blocking or deleting cookies in your browser or by installing the Google Analytics Opt-out Browser Add-on. Google describes how it processes data when you use sites that integrate Google Analytics at policies.google.com/privacy. We have configured Google Analytics to collect usage data for our own analytics purposes and not to serve advertising.

5. How We Disclose Information

We do not sell your personal information. We disclose information only as described below:

  • Service providers. We share information with vendors who process it on our behalf and under contract, solely to provide services to us. These currently include Stripe, Inc. (payment processing), Resend (transactional email delivery), Amazon Web Services (file and attachment storage), DigitalOcean (application and database hosting), and Google LLC (website analytics through Google Analytics). Each is permitted to use the information only to perform services for us.
  • Recipients you designate. When you send an invoice or reminder, we transmit the content and recipient address you provide to deliver that message on your behalf.
  • Within your workspace. Data in a workspace is available to the members of that workspace according to their roles, as configured by the workspace owner or admins.
  • Legal and safety. We may disclose information if required by law, subpoena, or other legal process, or where we believe disclosure is necessary to protect our rights, your safety or the safety of others, or to investigate fraud or security issues.
  • Business transfers. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.

6. Data Retention

We retain your information for as long as your account or workspace is active and as needed to provide the Service. When you close your account, we mark it for deletion and then permanently delete or irreversibly anonymize the associated data through a scheduled purge process. We may retain certain information for a limited additional period where necessary to comply with legal, tax, or accounting obligations, resolve disputes, prevent fraud and abuse, or enforce our agreements. Backups containing your information are retained for a limited time and then overwritten on a rolling basis.

The document view and signing activity described in Section 2 has two different lifespans. A view recorded against an invoice is deleted when that invoice is deleted, and we keep only the most recent opens of any one document rather than an unbounded history. Entries in an agreement’s audit trail—including the address, browser, and time recorded when it was viewed and signed—are retained for the life of the executed agreement, because they are the evidence that establishes a valid electronic signature and we may need them for the establishment, exercise, or defense of legal claims.

7. Security

Friendly Office is a multi-tenant financial application, and protecting your data is central to how we build it. Every request is authenticated and scoped to the authenticated tenant, so one workspace cannot read or modify another workspace’s data. We encrypt data in transit using TLS, store passwords only in hashed form, restrict internal access, and rely on payment processing by Stripe so that full card data does not touch our systems. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you as required by applicable law.

8. Your Choices

You can review and update your account and workspace information at any time from within the Service. You can manage your subscription and billing details through the Stripe-hosted billing portal, and you can close your account, which begins the deletion process described in Section 6. We send service and transactional messages that are necessary to operate the Service and that you cannot opt out of while your account is active.

9. Your California Privacy Rights

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), gives you certain rights regarding your personal information. The categories of personal information we collect are described in Section 2 and include identifiers (such as name, email address, and IP address), commercial information (such as subscription and payment records), and internet or network activity (such as log data, analytics data about your interaction with the Service, and records of when a document sent to you was opened or signed). We collect this information from you, automatically through your use of the Service (including through Google Analytics), and from our payment processor, and we use and disclose it for the business purposes described in this Policy.

We do not sell your personal information for money, and we do not use Google Analytics or any other tool to share your personal information for cross-context behavioral advertising, as those terms are defined under the CCPA. We use Google Analytics solely for our own analytics purposes. To the extent the use of analytics cookies could be considered “sharing” under California law, you may opt out using the cookie controls and Google Analytics opt-out described in Section 4. We do not knowingly collect or process sensitive personal information for purposes that would trigger a right to limit its use. Subject to the CCPA, you have the right to:

  • know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients;
  • request that we delete personal information we collected;
  • request that we correct inaccurate personal information; and
  • not receive discriminatory treatment for exercising these rights.

To exercise these rights, contact us at [email protected]. We will verify your request using the information associated with your account, and you may use an authorized agent to submit a request on your behalf with proof of authorization. If your personal information is contained in data that another Friendly Office business customer uploaded about you, please direct your request to that business, for which we act only as a service provider; we will assist that business as required.

10. Children’s Privacy

The Service is intended for businesses and is not directed to children. You must be at least 18 years old to use it. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided us personal information, contact us and we will take steps to delete it.

11. Where Your Information Is Processed

We operate the Service in the United States, and your information is stored and processed there. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, where data-protection laws may differ from those in your jurisdiction.

12. Third-Party Links

The Service may contain links to third-party websites or services that we do not control, including those of our service providers. This Policy does not apply to those third parties, and we encourage you to review their privacy practices.

13. Changes to This Policy

We may update this Policy from time to time. When we make material changes, we will revise the “last updated” date above and, where appropriate, provide additional notice, such as by email or an in-product notice. Your continued use of the Service after the changes take effect constitutes your acceptance of the updated Policy.

14. Contact Us

If you have questions about this Policy or our privacy practices, or to exercise your rights, contact Friendly Office LLC at [email protected].