Paid Privacy Policy
This Privacy Policy explains how Terrasoft Inc ("Terrasoft," "we," "us," or "our") handles information in connection with the Paid mobile application (the "App"), the account and billing service, and the Paid website at [https://usepaid.vercel.app](https://usepaid.vercel.app).
1. The short version
Paid remains local-first for your work. Invoices, estimates, client records, business details, saved items, expenses, selected images, and generated documents are stored on your device. Those records are not uploaded to or synchronized with Terrasoft's backend.
If you choose Sign in with Apple, Terrasoft's separate backend verifies the Apple identity token and creates an authenticated billing session. The backend stores limited account and entitlement data, not your invoice or client database. Eligible signed-in users in the United States may be offered Stripe billing when Terrasoft enables the production switch. Apple in-app purchase remains the fallback for users who are outside the eligible flow or whose eligibility cannot be confirmed. The production Stripe switch is currently off.
The current release has no active product analytics or advertising provider. PostHog, Meta, and TikTok are not active.
2. Information handled locally on your device
Depending on how you use Paid, the App may locally handle:
- business name, trade, email address, phone number, postal address, logo, tax label and rate, payment instructions, and payment link;
- customer names, email addresses, phone numbers, and postal addresses;
- invoice and estimate numbers, dates, status, line items, quantities, prices, discounts, deposits, tax amounts, balances, notes, and currency;
- saved products or services and their prices;
- expenses, categories, amounts, dates, notes, and selected receipt images;
- generated PDFs, CSV exports, and reports; and
- settings such as payment terms, document prefixes, onboarding status, and notification choices.
This content can include personal information about your customers or other people. You are responsible for providing required notices and having a lawful basis to use it.
Contacts you select
If you use the contact picker, the App may access the contact you select and copy available name, email, phone, and postal-address fields into a local client record. The feature is intended to use only the contact you choose, not upload your address book. Depending on the iOS access path, iOS may ask for Contacts permission. You can manage access in iOS Settings.
Images you select
If you choose a photo, the App may locally store the image you select, such as a business logo or receipt image. The receipt feature downsizes and recompresses a local copy. iOS may provide a limited photo picker or ask for Photos permission. You can manage access in iOS Settings.
Notifications
With your permission, the App schedules local notifications for invoice follow-up and certain purchase reminders. Notification content may include an invoice number, customer name, amount, payment status, due timing, or subscription amount and timing. Depending on your iOS settings, this content may be visible on the lock screen. Paid does not send invoice content to a Terrasoft notification server.
3. Account and authentication information
Sign in with Apple is optional for local invoicing but is required for the eligible Stripe billing path. When you sign in:
1. Apple provides the App with an identity token and an Apple-scoped user identifier. Apple may provide your email address and, generally only on the first authorization, your name. The email may be an Apple private relay address.
2. The App sends the identity token to Terrasoft's backend over HTTPS. The backend verifies its signature, issuer, audience, and validity with Apple.
3. Terrasoft stores the Apple-scoped subject and email address provided in the verified token. The backend does not store the identity token as an account record.
4. The backend returns a signed, expiring Terrasoft session token. The App stores that token in the iOS Keychain using device-only protection and sends it to authenticate billing and entitlement requests.
The App also stores the Apple-scoped user identifier and any provided name and email in local preferences. Signing out removes the local Terrasoft session token and locally saved Apple sign-in fields. Signing out does not delete the backend account record, cancel a Stripe subscription, or delete local invoices.
Signing in does not back up or synchronize invoices, clients, receipts, or other local business content.
4. Billing and transaction information
Stripe web billing
When the production switch is enabled, Terrasoft may offer Stripe Checkout to an authenticated user whom the service confirms is eligible in the United States. The App opens Stripe Checkout in Safari and returns through a Paid deep link. Stripe collects and processes payment method, billing, transaction, tax, fraud-prevention, and related information under Stripe's privacy policy. Terrasoft does not receive your full card number.
Terrasoft's backend stores or processes the information needed to manage access, including:
- Apple-scoped subject and email;
- Stripe customer ID and, where applicable, subscription ID;
- entitlement type, entitlement status, subscription status, and refund status;
- Stripe Checkout session ownership and callback status during verification;
- Stripe event IDs and received timestamps used to process signature-verified webhooks once and prevent duplicates; and
- record creation or update timestamps and operational security logs.
The service may also receive a two-letter country signal or trusted infrastructure country result to decide whether web billing is eligible. Network providers may process IP address and request metadata for routing, security, and country determination.
A return to the App does not by itself grant access. Terrasoft verifies the Checkout session and relies on authenticated entitlement responses and Stripe's signature-verified webhooks for purchase, renewal, payment failure, cancellation, and refund status.
Apple in-app purchase
Apple processes App Store subscriptions and lifetime purchases for the fallback path. Terrasoft does not receive your full payment-card or bank-account details. Through StoreKit, the App receives product and verified entitlement information needed to show offers, complete or restore a purchase, and determine access. Apple separately handles transaction, device, account, tax, and fraud-prevention information under Apple's policies.
5. Website and support information
Paid's public website and legal pages are hosted by Vercel at [https://usepaid.vercel.app](https://usepaid.vercel.app). The pages do not intentionally run Terrasoft product analytics or advertising trackers. Vercel may process IP address, browser and device details, requested URL, timestamps, and security or delivery logs to host and protect the site.
If you contact support, Terrasoft receives the information you choose to send, such as your email address, message, attachments, and diagnostic context. Do not send customer records, complete invoices, bank details, tax identifiers, identity tokens, session tokens, or full payment details unless Terrasoft provides an approved secure method.
6. How we use information
We use information to:
- verify Sign in with Apple and create an authenticated session;
- determine eligibility for the available billing route;
- create Stripe Checkout and customer-portal sessions when enabled and eligible;
- associate a Stripe customer and transaction with the correct Paid account;
- verify purchases, renewals, cancellations, refunds, payment failures, and entitlements;
- prevent duplicate webhook processing, fraud, abuse, and unauthorized access;
- provide support and communicate about an account or purchase;
- operate, secure, debug, and maintain the backend and website;
- comply with tax, accounting, legal, and regulatory duties; and
- establish, exercise, or defend legal claims.
Local business content is used on your device to provide invoice, estimate, client, expense, reporting, PDF, export, and reminder functions. Terrasoft does not remotely use that content because the backend does not receive it.
7. Service providers and disclosures
We disclose limited information to providers that perform services for Paid:
- Apple: Sign in with Apple, StoreKit purchases and restores, operating-system permissions, and any Apple device backup you enable.
- Stripe: Checkout, subscription and lifetime billing, customer portal, payment processing, fraud prevention, refunds, and billing events for eligible web purchases.
- Google Cloud: Hosting for the separate Terrasoft backend and Firestore account, billing, entitlement, configuration, and webhook-event records.
- Vercel: Hosting, delivery, and security for the Paid website and legal pages.
- Email and support providers: Delivery and storage of messages you send to support.
We may also preserve or disclose information in our possession if reasonably necessary to comply with law or legal process, protect rights and safety, investigate fraud or abuse, or complete a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. The current App has no active analytics, advertising, or attribution provider.
8. Storage, retention, and deletion
Local content
Invoice and business content is stored in local App files. Receipt images are stored as compressed local image data. Preferences and some sign-in fields are stored in local preferences. The Terrasoft session token is stored in the iOS Keychain. Apple may include some App data in an iCloud or computer device backup depending on your settings. We do not control those backups.
Local information remains until you edit or delete it, reset App data, or remove the App, subject to iOS behavior and backups. Deleting a document does not remove copies you exported or shared. Deleting the App generally removes its local container, but a later device restore may restore backed-up data.
Backend account and billing records
We retain backend account, entitlement, subscription, and event records while the account or purchase is active and as reasonably needed to provide access, process billing, prevent fraud and duplicate events, resolve disputes, maintain financial records, enforce agreements, and comply with tax, accounting, and legal duties. Stripe, Apple, Google Cloud, Vercel, and support providers retain information under their own policies and our configured service terms.
You may request deletion of Terrasoft's backend account data by emailing brennan@terrasoft.co. Signing out or deleting the App does not itself send a backend deletion request and does not cancel a subscription. Before requesting deletion, cancel any Stripe subscription through the customer portal and retain records you need. We will delete or deidentify information that is not required for an active entitlement or a permitted retention purpose. We may retain transaction, refund, fraud-prevention, security, tax, accounting, and legal records where permitted or required. Deletion of the backend account does not delete local App content, Apple records, Stripe records that Stripe must retain, or copies you shared.
9. Security
We use iOS Keychain protection for the Terrasoft session token, HTTPS for backend requests, Apple identity-token verification, signed and expiring backend sessions, authenticated billing endpoints, server-selected Stripe prices, signature-verified Stripe webhooks, and event deduplication. Google Cloud hosts the production backend data environment. No method of storage or transmission is completely secure, and we cannot guarantee that information will never be lost or accessed without authorization.
Protect your device and Apple Account with a strong passcode and current software. Never share a Paid session token or Stripe portal link. Export independent copies of local records you must retain.
10. Your choices and privacy rights
You can:
- use local invoicing without Sign in with Apple;
- sign out to remove the local Terrasoft session token and locally saved Apple sign-in fields;
- manage or cancel a Stripe-billed subscription through the Stripe customer portal in Paid;
- manage or cancel an Apple-billed subscription through your Apple Account;
- decline Contacts, Photos, Camera, or Notifications access, subject to loss of the related feature;
- edit or delete local client, document, expense, saved-item, business, and settings information where controls are available;
- reset core local App data; and
- delete the App, subject to device backups and copies you exported.
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information Terrasoft controls, and to appeal or complain to a regulator. To request access, correction, deletion, or a copy of backend account and billing information, email brennan@terrasoft.co. We may verify your identity, for example through the associated Apple credential or email, before completing a request.
Terrasoft generally cannot retrieve, export, or delete your local invoice and client database because it is not sent to us. The in-app reset control may not clear every separately stored preference or Tools-library record. For the most complete local deletion, first export anything needed, cancel billing separately, sign out, and then delete the App.
11. Your role when handling customer data
When you put another person's information into Paid, you generally decide why and how it is used. You are responsible for your privacy notices, permissions, security, retention, and responses to that person's rights. Terrasoft is not your legal adviser and does not remotely host that local customer database.
12. Children's privacy
Paid is intended for adults conducting business and is not directed to children under 13. We do not knowingly collect personal information online from children under 13. If you believe a child has provided personal information to us, contact brennan@terrasoft.co.
13. International processing
Apple, Stripe, Google Cloud, Vercel, and email providers may process information in the United States and other countries under their policies and contractual safeguards. Web billing is currently designed for eligible United States users only, but authentication, Apple billing, website hosting, and support may involve international processing. Local invoice and client data remains on your device unless you choose to export or share it.
14. Analytics and future changes
The App contains an analytics event layer, but no analytics provider key is active. PostHog, Meta, and TikTok collection is not active. Before activating analytics or advertising, Terrasoft must assess consent requirements, update this Policy and App Store disclosures, identify providers and purposes, and configure appropriate controls.
We may update this Policy as Paid or the law changes. We will update the date above and provide additional notice or request consent where required. A future change that uploads or synchronizes invoice, client, receipt, or other local business content would require a new privacy review and updated notice before collection begins.
15. Contact
Controller and operator: Terrasoft Inc
Address: 333 Main St, Redwood City, CA
Privacy questions and requests: brennan@terrasoft.co
Support: brennan@terrasoft.co