Privacy notice
How Get Me Paid handles personal information
This notice explains the information used to provide Get Me Paid, why it is used, who it may be shared with and the choices and rights available to individuals.
Last updated: 3 July 2026
Get Me Paid is operated by OSTOYA DIGITAL SOLUTION LTD, company number 17290506.
Registered office: 32 Mayfly Road, Swaffham, England, PE37 8JF.
Legal and privacy contact: legal@ostoya.io.
This notice should be read alongside the information shown when particular details are collected.
Who we are
Get Me Paid is invoice software for UK freelancers, sole traders and small businesses. The service lets organisations manage customers, business settings, branded invoices, invoice emails, subscriptions and account access.
Get Me Paid is a software product operated by OSTOYA DIGITAL SOLUTION LTD, a company registered in England and Wales with company number 17290506.
Registered office: 32 Mayfly Road, Swaffham, England, PE37 8JF.
For privacy questions, rights requests or concerns about how personal information is handled, email legal@ostoya.io or use the Get Me Paid contact page.
Our role
Get Me Paid determines how account, subscription, security, product-operation and support information is used for operating the service and is generally acting as controller for those purposes.
When a business uses Get Me Paid to store its customers’ details and prepare invoices, that business will usually decide why the information is used. Get Me Paid processes that information to provide the invoicing service and may be acting as a processor for that customer and invoice-recipient data.
Account holders, organisation members and people who submit the public contact form should read this notice. Businesses using the service remain responsible for having an appropriate reason to enter and use their customers’ details and for giving their own privacy information where required.
Information we use
The service uses the following categories of information. The examples are representative and do not list every database field.
Account and authentication
- Name, email address, email-verification status and profile image where supported.
- Password authentication credentials are stored by the authentication system; the notice does not imply plain-text password storage.
- Verification codes, password-reset tokens, session tokens, session expiry, session IP address and user agent.
Organisation and membership
- Organisation name and slug, members, roles, statuses, joining dates and invitations.
- Invitation email address, invitation token, accepted status and expiry.
Business, payment and branding settings
- Business name, business email, phone number, address, VAT number, UTR where entered, business type, VAT/CIS defaults, invoice defaults, terms and notes.
- Bank name, account name, sort code, account number and payment instructions.
- Logo upload reference, invoice template and accent colour.
Customers and invoice recipients
- Company name, contact name, email address, phone number, postal address, VAT number, notes and payment-term overrides entered by an organisation user.
- This information may relate to people who do not hold a Get Me Paid account.
Invoices, VAT, CIS and payment status
- Invoice numbers, issue and due dates, line-item descriptions, service dates, quantities, prices stored in pence, VAT/CIS details, notes, terms and PDF output.
- Invoice status, sent date, paid date, customer contact details and amount payable.
Billing and subscription
- Stripe customer, subscription, price and product identifiers, subscription status, billing period dates, trial dates, cancellation status and payment-problem state.
- Webhook event identifiers, event type, processing status, attempts and limited error information. Card details are handled through Stripe-hosted billing flows; the audited application stores Stripe identifiers rather than card numbers.
Email and communication settings
- Provider selection, sender name, sender email, reply-to address and custom SMTP details where configured.
- Encrypted SMTP credentials and encrypted Google or Microsoft OAuth tokens where an organisation enables those integrations.
- Invoice email recipients, subjects, delivery status, provider message identifiers and errors.
Contact enquiries
- Name, email address, organisation name, enquiry category, subject and message submitted through the public contact form.
- A hidden anti-spam field, request origin checks and transient rate-limit keys are used for abuse prevention.
Push notifications and device information
- Push endpoint, browser push encryption keys, user agent, notification preferences and reminder delivery logs.
- Browser/device information may also be used for PWA display-mode support.
Technical, security and audit information
- IP addresses, user agents, request metadata, authentication events, billing-admin audit records, application errors, origin checks and rate-limit information.
- Server and application logs may contain operational details needed to investigate faults and security events.
First-party product and activation analytics
- A small set of first-time milestone records: account registration, workspace creation, first customer, first invoice, first invoice sent, billing checkout opened and confirmed subscription start.
- The record contains the event type, timestamp, an internal account or organisation identifier and a fixed source label. It does not store invoice content, customer details, email addresses, IP addresses, user-agent strings or advertising identifiers.
- These records are stored in Get Me Paid’s own service database to understand sign-up, onboarding and billing friction. They are not an advertising pixel or third-party behavioural analytics service.
How information is obtained
Information is provided directly by account users during registration, verification, onboarding, settings configuration, customer management, invoicing and billing actions.
Some information is entered by another organisation member, such as an invitation email address or customer details entered by a subscribing business.
Subscription status comes from Stripe billing events. Email-integration data is obtained when an organisation configures custom SMTP, Gmail or Microsoft sending. Technical information comes from browsers, devices, server requests, security checks and audit activity. Public enquiries come from the contact form.
Why we use it and likely lawful bases
The applicable lawful basis may depend on context. ICO guidance explains that organisations should identify a lawful basis for each purpose and include it in privacy information.
| Purpose | Examples | Likely lawful-basis category |
|---|---|---|
| Provide the service | Create accounts, authenticate users, manage organisations, store customers, create and send invoices, generate PDFs, provide reminders and maintain settings. | Performance of a contract or steps requested before entering a contract. |
| Subscription billing | Create Stripe Checkout sessions, manage subscriptions, process billing webhooks and provide billing portal access. | Contract, and legal obligations where billing or accounting records must be maintained. |
| Security and abuse prevention | Sessions, IP and user-agent information, audit records, rate limiting, origin validation, webhook verification and error investigation. | Legitimate interests in protecting the service, users and records. |
| Customer support and enquiries | Respond to public contact-form messages, account questions, billing enquiries and support correspondence. | Steps requested before contract, contract, or legitimate interests in responding to enquiries. |
| Legal and regulatory needs | Maintain records, respond to lawful requests, handle disputes and protect legal rights. | Legal obligation where applicable, or legitimate interests in managing legal and operational risk. |
| Optional communications and push notifications | Store notification preferences, push subscriptions and send enabled reminder notifications. | Contract or legitimate interests for service reminders; browser permission is required for web push delivery. |
| Product improvement and activation analytics | Count first-time registration, workspace, customer, invoice, invoice-send, checkout and subscription milestones to identify friction in the service. | Legitimate interests in understanding and improving the service, balanced against the limited, first-party and non-content nature of the records. |
Customer and invoice-recipient information
Subscribing organisations enter customer and invoice-recipient details so they can prepare, send and manage invoices. Invoice recipients may not have their own Get Me Paid account.
Get Me Paid uses that information to provide invoice records, calculate totals server-side, generate private PDFs, send invoice emails, record email attempts, manage invoice status and support reminders.
The audited repository does not show unrelated marketing use of invoice-recipient details by Get Me Paid. The information may still be accessed or used where needed for support, security, legal compliance, service operation or troubleshooting.
A person whose details appear only as a customer or invoice recipient may find that the organisation that entered the data is the most appropriate first contact. Get Me Paid may need to coordinate with that organisation, but the individual may also contact Get Me Paid through the contact page.
International transfers
The repository verifies Stripe, optional Google Gmail, optional Microsoft email and web-push functionality, but it does not verify production hosting, database, backup, email-provider or logging locations.
Some service providers may process information in countries outside the UK. Where this occurs, appropriate transfer arrangements and safeguards are used where required.
Provider-specific transfer locations and safeguards should be reviewed before production launch and whenever providers change.
Retention
Some technical expiry periods are implemented: password-reset tokens expire after one hour, email verification codes expire after ten minutes, and invitations have an expiry timestamp. Other business, billing, audit, email-log, reminder-log, upload, backup and application-log retention schedules were not verified as formal policy in the repository.
Information is retained for as long as it is needed to provide the service, maintain business and security records, resolve disputes and meet legal obligations. Different records may be kept for different periods.
Account and organisation records may remain while the account or service relationship continues. Invoice and customer data remain under the subscribing organisation’s control within the service. Some billing, audit, security or backup records may be retained after active use ends. Deletion requests may be subject to legal or operational exceptions and may not result in immediate deletion from backups.
First-party activation analytics records are retained only for as long as reasonably needed to understand and improve the sign-up, onboarding and subscription journey. A formal retention schedule for these records should be approved and documented before it is relied on as a fixed retention period.
Security
Implemented safeguards include authenticated access, organisation scoping, role-based permissions, server-side membership checks, private invoice/PDF/logo routes, private upload storage, server-side invoice total calculation, Zod validation, PostgreSQL transactions for invoice numbering, contact-form rate limiting and origin checks, webhook verification, and audit records for billing-admin actions.
Sensitive email-provider credentials and OAuth tokens are stored encrypted where those integrations are configured. Production use should also rely on HTTPS and controlled infrastructure access.
No online service can guarantee absolute security.
Automated rules
Get Me Paid uses automated rules to manage functions such as subscription access and reminders. It does not currently use personal information to make solely automated decisions that produce legal or similarly significant effects about individuals.
Your rights
Depending on the circumstances, data protection rights may include access, correction, erasure, restriction, portability, objection, withdrawal of consent where consent is used, and the right to complain to the ICO.
These rights are not always absolute and may depend on the processing, the role of Get Me Paid, the role of the subscribing organisation and applicable exceptions. Identity verification may be required before information is disclosed or changed.
If your information was entered by a business as customer or invoice-recipient data, the business that entered it may be the most appropriate first contact. You may still contact Get Me Paid through the contact page, and Get Me Paid may need to coordinate with that business.
Contact and complaints
Please contact Get Me Paid first at legal@ostoya.io so the issue can be reviewed.
You also have the right to complain to the UK Information Commissioner’s Office. The ICO recommends normally giving the organisation a chance to respond before bringing a complaint to the ICO.
Changes to this notice
This notice may be updated when features, providers, legal requirements or data practices change. The last-updated date will be revised when the notice changes.
ICO guidance reviewed for this notice says privacy information should be clear and include purposes, lawful bases, recipients, retention information and rights where relevant. It also notes that guidance is under review following the Data (Use and Access) Act 2025.
