Incleus Privacy Policy
Effective Date: September 13, 2026
Incleus is invoicing software for independent operators and small trades. Your records are yours: this policy describes what we do with them on your behalf, not what we may take from them. It explains what we collect, why, who else touches it, and what we will not do with it — in alignment with the Personal Information Protection and Electronic Documents Act (PIPEDA). It describes the service as it actually runs today, not as it is planned.
1. Accountability and our dual role
Incleus is responsible for the personal information under its control. We act as a Data Controller for the account and business data you provide in order to use Incleus. We act as a Data Processor for the information about YOUR clients and staff that you enter or upload — names, addresses, amounts, hours — which remains yours and which we process on your instructions. We have appointed a Privacy Officer; you may contact them at privacy@incleus.com.
2. What we collect
We limit collection to what the service needs to do its job. Everything below is collected because a feature you are using requires it.
- Your account: Your email address and a password hashed by Supabase Auth, the name and role of each member of your organization, and their chosen working language. We never see your password.
- Your business details: Your business name, address, contact line, tax registration number, late-payment terms and logo — the letterhead printed on your documents. Note that your logo is served publicly: it has to be, because it appears on the payment page a client opens from an emailed link.
- Your clients: Names, email addresses, postal and tax addresses, tax registration numbers and exemption status. This is personal information about people who are not our users, entrusted to us by you, and it is treated as sensitive because of its role in financial records.
- Your financial records: Invoices, quotes and receipts with their line items and tax, payments and refunds, disputes and adjustments you record, and your tax registrations and calculation usage. Card numbers are never handled by Incleus — payments run through Stripe, which collects card details directly.
- Your staff, on the Operations plan: Time entries, clock-in and clock-out times, who did which work, and the bill and cost rates attached to each worker. This is information about your employees and subcontractors. Cost and pay data is restricted to owners and admins by the database itself, not merely hidden in the interface.
- Documents you upload, on the Operations plan: Receipts, supplier invoices and odometer photographs, together with the line items read from them and the mileage claims built on them. These are stored privately in Canada and are reachable only through short-lived links issued to members of your organization.
- Summaries derived from your own records: Incleus derives, for your eyes only, summaries of how your clients pay — how early or late invoices were settled, amounts billed, balances outstanding — from your own transaction history. These are visible only within your organization, are never shown to the client they describe, and are never pooled, shared or combined across accounts. Incleus does not operate a credit-scoring or reputation service and assigns no rating, score or label to any person or business.
3. How it is protected
We implement safeguards scaled to the sensitivity of the data, and we would rather tell you where they stop than imply they go further.
- Encryption: Data is encrypted in transit using TLS and at rest through database disk encryption.
- Tenant isolation: Every business record is scoped to one organization and enforced by Postgres row-level security, which is default-deny. Isolation between organizations is tested on every build, by asking as one organization for another's records by id and requiring zero.
- Private document storage: Uploaded receipts and photographs live in a private bucket. Access is by expiring signed link only, issued to members of the organization that uploaded them.
- Internal access: Restricted on a need-to-know basis.
- Two-step verification: You can protect your own sign-in with an authenticator app, from Settings › Security. It is offered to every account and required of none — we recommend switching it on, especially for owners and admins. Without it, sign-in is by email and password alone, so the strength and uniqueness of your password is what stands between an attacker and your records.
- A record of who opened what: Two reads are recorded, because both can carry a lot of information out at once. When the accountant export is run we record who ran it, over what period, and how many records it covered. When a receipt or odometer image is opened we record who opened it, which document, and how long the link stayed valid — those links are short-lived keys that keep working until they expire, so the window matters. Owners and admins can read both histories for their own organization. They exist so that if an account is ever misused, the question “what did they take?” has an answer instead of a worst-case assumption.
4. Sub-processors
We engage the following third parties to deliver the service, and we use contractual means to require a comparable level of protection. These are the only ones; when that changes, so does this list.
- Vercel: Application hosting and request processing.
- Supabase: Database, authentication and file storage, in the ca-central-1 region (Canada Central).
- Stripe: Tax calculation, payment processing and subscription billing. Stripe collects payment card details directly and Incleus never receives them.
- Anthropic: Reading uploaded receipts and odometer photographs. When you upload one, the image is sent to Anthropic so its line items or its reading can be proposed, and it is processed outside Canada. Nothing that comes back becomes a cost until a person has checked it. If you would rather no image left the country, enter costs and readings by hand — every screen that offers extraction also accepts typing.
- Resend: Delivering transactional email, including the documents you send to clients.
5. Where your data is held
Your account, business and financial records, and your uploaded documents, are stored and processed in the ca-central-1 region (Canada Central) through Supabase. Two sub-processors work outside Canada: Stripe, for payments and tax calculation, and Anthropic, for reading uploaded images. Information processed by them is subject to the laws of the jurisdictions where that processing happens.
6. How long we keep it
We keep personal information only as long as its purpose requires. Financial records are the exception that shapes everything else: CRA-style record-keeping runs to roughly six years, so Incleus voids and soft-deletes rather than destroying. A deletion request removes client personal information from active use while preserving the integrity of the historical financial record. An issued invoice can never be altered afterwards by anyone, including us.
7. Breach notification
Incleus maintains an internal register of security incidents. If a breach involving personal information under our control creates a real risk of significant harm, we will notify the Office of the Privacy Commissioner of Canada and every affected individual as soon as reasonably possible.
8. What we do not do
These are not aspirations. Each is a rule the software enforces, and changing any of them would mean changing the database, not this page.
- We will never sell, rent, licence or trade your data or your clients' data to anyone, for marketing or for any other purpose or price. That commitment survives any sale, merger or reorganisation of Incleus — a buyer takes your records subject to it or does not take them at all.
- We do not pool your records with other businesses', and we run no cross-customer scoring, rating or reputation service.
- We do not let an automated reading become a cost on its own — a person confirms every extracted figure before it is saved.
- We do not produce a figure for tax owed. We report tax collected and tax paid as separate facts; what is owed is a determination for you and your accountant.
- We run no advertising trackers and no third-party analytics inside the application.
- We do not read your records to investigate a problem unless you have asked for help and agreed to it, and then only as far as fixing it requires — and we tell you what we needed to see. Unlike the four above, this one is a rule we hold ourselves to rather than one the database enforces: an administrator's key can reach your records, which is exactly why the commitment is written down and why the export and document-access logs exist.
9. Your rights
You may access the personal information we hold about you, challenge its accuracy and ask us to correct it. You can export your own records at any time from the accountant export, without asking us. Requests are handled within 30 days.
10. Challenging our compliance
If you believe we have fallen short of this policy or of PIPEDA, write to privacy@incleus.com and we will respond. If a concern is not resolved to your satisfaction, you have the right to complain to the Office of the Privacy Commissioner of Canada.