Privacy Policy

Invincimail — ABN 25 192 826 642  |  Gladstone QLD 4680, Australia  |  Effective date: [DATE]

1. Introduction and Who This Policy Applies To

This Privacy Policy describes how Invincimail (ABN 25 192 826 642) collects, uses, stores, and discloses personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

This Policy applies to all individuals who visit invincimail.com, subscribe to the Invincimail service, or whose email communications are processed through the Invincimail platform.

2. What Personal Information We Collect and Why

From subscribers at account creation:

  • Username — account identification
  • Contact email address — account communication, billing notifications, security alerts
  • Password (stored as a Firebase Authentication hash, never in recoverable form) — authentication

From subscribers at checkout:

  • Protected email address(es) — provision of the scanning service
  • Email provider type (Google Workspace or Microsoft 365 Business) — service routing

From payment processing:

  • Stripe customer ID — subscription management and billing
  • Subscription plan and status — service provisioning

Note: payment card details are collected directly by Stripe and are never transmitted to or stored by Invincimail.

From the inbox filter service (Gold Plan and Platinum Plan):

  • Email metadata — sender address, subject line, received timestamp, risk score, and AI detection percentage — for provision of the inbox scanning service and dashboard display

Note: Invincimail does not store full email body content. Body content is processed transiently during scanning and is not persisted.

From the encryption service (Platinum Plan only):

  • Encrypted email body and attachment content — stored temporarily in Google Cloud Storage for recipient retrieval using AES-256-GCM end-to-end encryption
  • Sender and recipient email addresses — service delivery
  • Encryption receipt metadata — timestamp, method, delivery status — for compliance and audit

From website visitors:

  • IP address and browser information collected automatically by Firebase Hosting and Google Cloud infrastructure
  • Contact form submissions including name, email address, and message content

3. How We Store Personal Information and For How Long

  • Email scanning metadata (sender, subject, risk score, AI percentage) is stored in our Firestore database and automatically deleted after 14 days.
  • Processed message records used for deduplication are automatically deleted after 14 days.
  • Encryption compliance receipts are automatically deleted after 14 days.
  • Encrypted message content stored in Google Cloud Storage is automatically deleted after 15 days.
  • Secure message portal records are automatically deleted after 14 days.
  • Customer account information including username, contact email, and subscription details is retained for the duration of the subscription and for a period following account deletion as required by applicable law.
  • Cloud audit logs are retained for 12 months.

4. Third Parties Who Receive Personal Information

Google LLC (Google Cloud Platform) — hosts all Invincimail infrastructure including database, compute, storage, and authentication services. Customer data including account information and email metadata is stored on Google Cloud servers located in Australia (australia-southeast1 region). Google's privacy policy is available at policies.google.com/privacy.

Stripe Inc — processes all payment transactions on behalf of Invincimail. Stripe receives billing contact information and transaction data. Card payment data is handled exclusively by Stripe. Stripe's privacy policy is available at stripe.com/au/privacy.

Amazon Web Services (AWS) — provides email delivery services (Simple Email Service) for transactional emails sent from our service address. AWS receives the recipient email address and email content of transactional notifications. AWS servers used are located in ap-southeast-2 (Sydney). AWS's privacy policy is available at aws.amazon.com/privacy.

Microsoft Corporation — provides identity services and email API access for Microsoft 365 Business subscribers through Microsoft Graph API. Microsoft receives the protected email address and associated Graph API access tokens for Microsoft 365 customers only. Microsoft's privacy policy is available at privacy.microsoft.com.

Cloudflare Inc — provides bot protection services (Turnstile) on our website forms. Cloudflare may process IP address and browser information to verify that form submissions are from humans. Cloudflare's privacy policy is available at cloudflare.com/privacypolicy.

5. How Customers Can Access or Correct Their Information

Customers may access, update, or correct their personal information by logging into their Invincimail account and accessing the account portal in the top left of screen, or by contacting us at contact@invincimail.com.

We will respond to access and correction requests within thirty (30) calendar days. In some circumstances we may be unable to provide access to certain information — for example where doing so would unreasonably affect the privacy of other individuals. We will explain our reasons if we are unable to fulfil a request.

6. How to Make a Privacy Complaint

If you believe Invincimail has not handled your personal information in accordance with the Australian Privacy Principles, you may lodge a complaint by contacting us at contact@invincimail.com. We will acknowledge your complaint within five (5) business days and will endeavour to resolve it within thirty (30) business days.

If you are not satisfied with our response, you may refer your complaint to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.

7. Data Security

Invincimail implements commercially reasonable technical and organisational measures to protect personal information against unauthorised access, disclosure, alteration, or destruction. These measures include:

  • End-to-end encryption for email content where enabled (AES-256-GCM)
  • Encryption of data in transit using TLS
  • Access controls restricted to the sole operator and designated service accounts
  • Multi-factor authentication on all administrative accounts
  • Automated deletion of personal data in accordance with the retention periods described in this Policy

No method of transmission over the internet or electronic storage is completely secure. While we strive to protect personal information, we cannot guarantee absolute security.

8. Contact Details for Privacy Matters

For privacy-related enquiries, requests, or complaints, please contact: