Folio A

Privacy Policy

Last updated 30 September 2026. Plain language, describing what Duesheet actually does.

Duesheet is operated by DanixSoft (“we”, “us”). This policy explains what we collect when you use it, why, who else is involved, and the choices you have. It is not legal advice.

Who is responsible for what

For your account (your email, your workspace and your settings), we decide how the data is used, and this policy applies to us directly.

For your clients’ details and your invoices, you decide what to enter and why; we store and process them only to provide the service to you. You are responsible for having a lawful reason to hold your clients’ information and for telling them how you use it where the law requires.

What we collect

  • Account: your email address and a password, handled by our authentication provider. Passwords are stored hashed, never in plain text.
  • Workspace: your business name, address, contact details, tax number, payment instructions (such as bank, Payoneer or Wise details), invoice numbering and settings, and the email addresses of people you invite.
  • Your clients: names, company names, email and postal addresses, tax numbers and private notes that you enter.
  • Your records: proposals, invoices, recurring schedules, payments (including the rupee amounts and rates you enter) and a log of reminders sent.
  • Client activity on your links: when a client first opens an invoice or proposal, the name they type to accept a proposal and the time, a decline reason if they give one, and whether they have turned reminder emails off.

We do not use advertising trackers, and we do not sell, rent or share your data or your clients’ data for marketing.

How we use it

  • To run the service: store your records, calculate totals, produce PDFs and links, and show your dashboard.
  • To send reminder emails to your clients, only if you have set up email sending and only about your invoices, with an opt-out in every email.
  • To keep the service secure, to fix problems, and to tell you about important changes to your account or these terms.

Links you share

Invoice, proposal and client portal links contain a long random code. Anyone who has a link can open what it points to (for a portal link, all of that client’s sent invoices and proposals, your business details and your payment instructions), so share them as you would the documents themselves. You can replace a client’s portal link at any time, which stops the old one working. These pages are marked so search engines do not index them.

Who else processes data

  • Supabase, for the database and sign-in.
  • Vercel, for hosting the application.
  • Resend, for sending reminder and invite emails, only when email sending is configured.

These providers process data on our behalf under their own terms. We may disclose data where the law requires it.

Where data is stored

Our providers may store and process data outside Pakistan. By using the service you understand that your data, and the client data you enter, may be transferred to and held in other countries, protected as described here.

Security

  • Data is sent over encrypted connections (HTTPS).
  • Every record belongs to one workspace, and the database only lets that workspace’s members read or change it (row-level security).
  • Payments are append-only: they cannot be edited or deleted, only reversed by the owner with a matching entry.
  • No system is perfectly secure. If we become aware of a breach affecting your data we will tell you without undue delay.

Retention, export and deletion

We keep your data while your account is active. You can export invoices and payments as CSV, and download every invoice as a PDF, at any time. To close your account and delete your workspace’s data, contact us; we delete it except where we must keep records by law, and backups roll over in the normal course.

Website analytics

To see how Duesheet is used, we run DanixSoft’s own first-party, cookieless analytics. It is hosted by DanixSoft at admin.danixsoft.com and the data is stored in DanixSoft’s own database; no third-party analytics or advertising service is involved. It records:

  • the pages visited (the codes in invoice, proposal and client-portal links are masked);
  • the referring website and any UTM campaign tags in the link;
  • approximate location (country, region and city), derived from the IP address by our hosting provider;
  • browser, operating system and device type;
  • clicks on links and buttons (on signed-in screens and on the invoice, proposal and portal pages you share, the button or link text is not recorded);
  • conversion events such as sign-ups and sent invoices, recorded without any personal details;
  • page-load speed measurements (Core Web Vitals), which are timing numbers only;
  • time on page and how far down the page you scroll.

It does not use cookies or local storage, and it does not store IP addresses. Unique visitors are counted with a salted hash that rotates daily; the salt is deleted after a day, so the hash cannot be reversed or linked across days. This data is not sold or shared with advertisers.

Cookies and local storage

We use cookies needed to keep you signed in and to remember which workspace you are working in. Your theme choice is kept in your browser’s local storage. We do not use advertising cookies, and our website analytics use no cookies or local storage.

Your rights

You can see and correct most of your data directly in the app. You can ask us for a copy of your data, to correct it, or to delete it. Your clients can contact you about their data, and can switch off reminder emails from their portal link or any reminder email.

Law

We operate from Pakistan and aim to handle data consistently with applicable Pakistani law, including the Prevention of Electronic Crimes Act, 2016. This is a description of our approach, not a claim of certification.

Changes and contact

If we change this policy we will update the date above and, for significant changes, tell you in the app or by email. Questions: contact DanixSoft.