Privacy Policy
What happens to the information you type into MakeInvoicePDF, what our server keeps and for how long, and which outside services are involved.
In short
- There are no accounts. You use every tool without signing up or logging in.
- Until you ask for a PDF, what you type stays in your browser. Your draft is saved in this browser until you reset it.
- When you download a PDF, your document is rendered as a PDF on our server over an encrypted HTTPS connection. The server removes each working copy of the document when its step ends, or after 5 minutes at the latest, and the finished PDF when you download it, or 10 minutes after it is ready.
- Google Analytics sets cookies only if you allow them. Analytics never receives the amounts, names or other text you type.
Who we are
MakeInvoicePDF is an independent publisher and runs makeinvoicepdf.com. For questions about this policy, write to hello@makeinvoicepdf.com.
While you fill in a form
The form, the live preview and the totals work in your browser. Nothing you type is sent to us until you ask for a PDF.
The editor saves a draft in your browser's local storage, so you can close the tab and continue later. The draft holds everything in the form, including your logo if you added one. It stays on this device until you press Reset in the editor or clear this site's data in your browser. Anyone who uses the same browser profile can open it, so reset the form when you finish on a shared computer.
When you download a PDF
Download PDF opens a preview window with a short security check (see The security check). When you download, your browser sends these to our PDF server at api.makeinvoicepdf.com:
- the document as HTML: everything printed on it, such as names, addresses, tax numbers, line items, amounts, notes, payment details and your logo;
- the document's styles;
- the document type, the paper size, whether to fit everything on one page, and the file name, which is made from the document type and your document number;
- the token from the security check.
These requests carry no cookies, and your browser stores none from them.
On the PDF server
The PDF server is a virtual private server (VPS) that we run. Requests reach it through Cloudflare's network (Cloudflare Tunnel). On the server:
- The request is placed in a data store (Redis) under a random task number, with an expiry time.
- A separate step removes anything that does not belong in a document, such as scripts, and passes on a cleaned copy. The copy your browser sent is removed when this step ends.
- The PDF is rendered from the cleaned copy with WeasyPrint, an open-source HTML-to-PDF engine. The cleaned copy is removed when rendering ends.
- The finished PDF waits for your browser to fetch it. It can be downloaded once: it is removed from the data store as it is sent to you.
| What the server holds | When it is removed from the data store |
|---|---|
| The document your browser sent | When the cleaning step ends, and after 5 minutes at the latest |
| The cleaned copy of the document | When rendering ends, and after 5 minutes at the latest |
| The finished PDF | When your browser downloads it, or 10 minutes after it is ready |
| The task status and the file name | 10 minutes after they were last updated |
| Request counters for your IP address | Per-minute counters after 1 minute; the daily counter 1 minute after midnight UTC |
| The daily count of finished PDFs per document type | After 90 days |
The data store is set to keep its contents in the server's memory only, not on its disk: your document and the finished PDF are held in memory for the times shown above. When the data store restarts, everything in it is cleared.
The daily count adds one for each finished PDF under its document type, for example "invoice", for each day (UTC). It holds no document content, IP address or task number. We use it to see how much each tool is used.
Request limits and your IP address
To keep the service available, the server limits how many PDFs one connection can request per minute and per day, and how often it can check a task or download. It counts these requests by IP address, with the expiry times shown in the table above.
Server log
The server's software writes a technical log of events, such as a task being queued, finished or failed and the reason for a failure. We use it to find and fix problems.
The security check
Before a PDF is made, a check from Cloudflare Turnstile runs in the download window. It helps keep automated traffic off the PDF server. The check loads from challenges.cloudflare.com when the window opens, so Cloudflare receives technical information from your browser, including your IP address. Our server then sends the check's token and your IP address to Cloudflare to confirm the result. Cloudflare handles this under its own privacy policy.
Analytics
Google Analytics
We use Google Analytics 4 to see which pages and tools are used. It runs in Google's consent mode: analytics cookies are set only if you choose Accept all in the cookie banner, or tick Analytics in the cookie settings. If you do not, Google Analytics still receives page views and the events below, but without cookies. Advertising settings stay off whatever you choose: ad storage, ad user data and ad personalization are always denied.
Besides page views, the site sends these events: your cookie choice, opening the PDF preview, a PDF started, finished or failed, a calculator used, a template downloaded, a form reset, an industry preset applied, and a click on Edit online. With them it sends only short codes: the document type, template, paper size, currency code, calculator type, file format, industry and error code. It never sends the amounts, names or other text you type.
You can change your choice at any time with Cookie settings at the bottom of every page. When you withdraw consent, the site removes the Google Analytics cookies from your browser. Google processes this data under the Google Privacy Policy; see also how Google uses information from sites that use its services.
Cloudflare Web Analytics
We also use Cloudflare Web Analytics, which counts page views and measures how fast pages load. Cloudflare states that it does not use cookies or local storage for this. It runs whether or not you allow analytics cookies.
The Cookie Policy lists what the site stores in your browser.
Services we use
- Cloudflare delivers this website (Cloudflare Pages), carries requests to our PDF server (Cloudflare Tunnel) and runs the security check (Turnstile) and Web Analytics. Like any network that delivers web pages, it processes your IP address and technical details of each request. See the Cloudflare Privacy Policy.
- Google provides Google Analytics, as described above.
- A hosting provider rents us the virtual private server that runs the PDF server.
These providers may process data in countries other than your own.
If you email us
We receive your email address and what you write, and use them to reply. Please do not send whole invoices with other people's personal or bank details.
Your choices
- Remove your draft: press Reset in the editor, or clear this site's data in your browser settings.
- Change your analytics choice: use Cookie settings at the bottom of any page.
- Block analytics in your browser or with an extension: the generators and templates work without it. If your browser also blocks this site's storage, the editor still works but cannot keep your draft.
- Ask about your information: write to hello@makeinvoicepdf.com. There are no accounts, and nothing on the server is filed under a name or an email address, so we usually cannot find a document that belongs to you.
Changes to this policy
When what the site does with information changes, we update this page. The date at the top shows the last change.