Tofu Apps Privacy Policy

Effective Date: December 16, 2025

You can see our previous Privacy Policy here.

INTRODUCTION AND SCOPE

This Privacy Policy (“Privacy Policy”) is delivered on behalf of GetPaid Inc. (“GetPaid,” “we”, “us”, and “our”) and governs the Personal Data (as defined below) and other data collected from or processed about you when you use the Tofu applications (“App”) and Web Services (“Web”), (each individually referred to as a “Service”, and collectively referred to as the “Services”), including by downloading, installing, registering with, accessing or otherwise using the Apps and Web (collectively referred to herein as “Use”).

We provide this Privacy Policy to explain our practices for collecting, using, processing, and disclosing the Personal Data and other data we process about users (“users”, “you”, or “your”, as applicable), and to tell you about the rights you may have in relation to your Personal Data and choices you may be able to make in relation to it.

By Personal Data we mean (i) information that is associated with an identified or identifiable natural person, and (ii) protected as personal data under applicable data protection laws.

All Tofu Services. This Privacy Policy applies to all Tofu applications operated by GetPaid Inc., including:

Most Tofu Apps operate independently and do not share user data or account information with each other. However, if this is enabled by the functionality of a specific App or the Web, a unified account may be used. When you create or use such a unified account, the same login credentials can grant access to all Tofu Apps and the Web. In this case, personal data and other information collected through your account may be shared and synchronized across these applications to support authentication, subscription verification, and seamless access to the full suite of services.

Please note that the web version of Invoice Maker and any other Tofu web interfaces may collect or process data differently from the mobile applications due to differences in functionality, browser technologies, and available features.

Accepting this Privacy Policy. Please read this Privacy Policy carefully to understand our privacy practices. We also encourage you to get acquainted with our Terms of Use to understand how we provide services to you.      

By accepting this Privacy Policy, you acknowledge that you understand and agree to the processing of your Personal Data and other information as described in this Privacy Policy.

If you do not wish to have your data processed in accordance with this Privacy Policy, please refrain from using the Tofu Apps and Web.

Questions? If you have any questions about this Privacy Policy or Services, please contact us at support@tofu.com. For additional contact information, please see Section 14: How to Contact Us, EEA/UK Representative, and Data Protection Officer.

U.S. State Supplements:

This Privacy Policy is designed to comply with data privacy laws across the United States, including:

If you are a resident of California, please see our California Notice at Collection and Privacy Notice, which provides detailed information about your rights and additional disclosures specific to California.

If you are a resident of Colorado, Connecticut, Virginia, Texas, Oregon, Tennessee, or any other U.S. state with privacy laws, please see our U.S. State Privacy Supplement (Non-California). The rights granted to you under these laws are also outlined in this Privacy Policy. These include:

TABLE OF CONTENTS

1. PERSONAL DATA WE COLLECT AND HOW WE COLLECT IT

We may collect Personal Data from and about you:


2. PERSONAL DATA YOU PROVIDE TO US DIRECTLY


You may provide Personal Data to us directly, or to service providers that act on our behalf, when you Use Invoice Maker. The Personal Data you provide depends on which features of Invoice Maker you Use and how you interact with the app.

Please note that not all authentication methods are available on all platforms or in all Tofu Apps and Web.

3. PERSONAL DATA AND OTHER DATA WE COLLECT AUTOMATICALLY

When you Use a Service, we or third parties we permit to do so, may automatically collect certain information, including Personal Data, from you (this is subject to your consent where this is required by law). The information collected from you automatically when you Use a Tofu App or Web may include:

We and third parties may use cookies, Software Development Kits (SDKs), and other tracking technologies to automatically collect the Personal Data and other data set forth above. For more information regarding our use of these technologies, please see Section 6: Cookies, Software Development Kits, and Other Tracking Technologies.

4. THE PURPOSES AND OUR LEGAL BASES FOR PROCESSING YOUR PERSONAL DATA

We may use your Personal Data and other data for a variety of purposes depending on the category of Personal Data and the way you Use and interact with the Tofu App, or Web, including the following:

5. TO WHOM WE DISCLOSE DATA

List of Service Providers (Subprocessors)

We may disclose your Personal Data, and other data and collected information to trusted third-party organizations such as contractors, business partners, service providers, third-party analytics providers and advertising partners that we use to support our business operations and who assist us in providing Services.

For transparency, below is a non-exhaustive list of our third-party service providers (“subprocessors”) who may process Personal Data or other data on our behalf, the purpose of their processing, and the categories of data involved:

Name Country Purpose of Processing Categories of Data Processed
Google Cloud Platform (GCP)
See here Terms of Service
USA Cloud hosting, storage, infrastructure Account data, business data, invoice/expense data, uploaded documents, analytics metadata
MongoDB Atlas
See here Terms of Service
USA / EU Database hosting Account data, client data, financial records, app usage data
Amplitude
See here Terms of Service
USA Product analytics Usage events, device info, IP address, feature interactions
AppsFlyer
See here Terms of Use
Israel / USA Attribution, campaign measurement Advertising identifiers (IDFA/GAID), device info, install events
Firebase (Google)
See here Terms of Service
USA Analytics, crash reporting, push notifications Device identifiers, IP address, crash logs, usage events, notification tokens
Appfigures
See here Terms of Use
USA App performance analytics Aggregated install and revenue metrics
Facebook Pixel
See here Terms and Policies
USA Advertising analytics (if marketing enabled) Device identifiers, advertising IDs, event tracking
Google Ads
See here Terms and Conditions
USA Advertising attribution Device identifiers, IP address, analytics event metadata
Twilio SendGrid
See here Terms of Service
USA Transactional email delivery Sender/recipient email, subject lines, message metadata
Brevo (Sendinblue)
See here Terms and Conditions
France Email delivery and marketing Recipient email, subject lines, message metadata
Stripe
See here Terms of Use
USA Payment processing Payment metadata, invoice identifiers, transaction status (no full card numbers stored by us)

While payment details are exclusively processed by these providers, we may process limited metadata related to transactions. This includes transaction IDs, payment status, or non-sensitive identifiers necessary for order confirmation, fraud prevention, service continuity, and compliance with applicable legal or regulatory requirements. These activities are carried out with strict adherence to data protection laws and solely for purposes directly related to service provision.

Our processors (Apple Pay, Stripe) certify PCI DSS compliance.

We encourage you to review the privacy policies of Apple Pay and Stripe for comprehensive details on how your sensitive payment data is managed. For questions or further assistance, please contact our Support team at support@tofu.com.

6. COOKIES, SOFTWARE DEVELOPMENT KITS, AND OTHER TRACKING TECHNOLOGIES

Analytics providers. When you Use an App, or the Web, we and our service providers, vendors, and partners, including third parties, may use technologies to collect or receive certain information about you and/or your Use of the App or Web. We also use third-party analytics tools like Google Firebase, AppsFlyer, and others to help us measure traffic and usage trends for the App or Web and for other purposes. Such analytics tools collect information via third-party SDKs incorporated into the App or Web, which includes information about features of the App or Web you visit or Use, your actions and interaction with the App or Web, and information about your subscription. Such information may be used to provide content, advertising, or functionality or to measure and analyze ad performance on the App or Web or other websites or platforms. Third parties may also use such information for their own purposes. For the avoidance of doubt, we do not use Image Data for advertising purposes.

Consumption Information. If we receive a refund request for an in-app purchase, we may provide Apple with information about your in-app purchase activity.

This data may include:

We process this data solely to assist Apple in evaluating refund requests, ensuring compliance with applicable laws and regulations, including GDPR and CCPA. Users can withdraw their consent to this processing at any time through the app settings or by contacting us.

Users can withdraw their consent to this processing at any time by adjusting the app settings:
Open the App > Go to Settings > Analytics > Toggle Off "Share consumption information".

For further assistance or to withdraw consent directly, users can also contact us via support@tofu.com.

Your Choices. Most browsers and devices are configured to accept cookies and similar tracking technologies automatically. You may be able to set your browser and device options so to limit such technologies. You can visit the Digital Advertising Alliance (“DAA”) Web choices tool at www.aboutads.info to learn more about this interest-based advertising and how to opt out of this kind of advertising by companies participating in the DAA self-regulatory program, and http://www.aboutads.info/appchoices for information on the DAA’s mobile app opt-out program. You can also opt out of receiving interest-based ads from members of the Network Advertising Initiative (“NAI”) by visiting the NAI consumer opt-out page at http://optout.networkadvertising.org/?c=1#!/. Opting out of receiving interest-based ads does not mean that you will no longer receive ads from us, but rather that the ads will not be tailored to your perceived interests.  

For users in the European Economic Area, United Kingdom and United States. You can opt out from processing of Personal Data via cookies, SDKs and other tracking technologies by clicking sending a request to support@tofu.com.

You may find that some parts of the App, or Web, may not function properly if you have refused certain tracking technologies, and you should be aware that disabling certain tracking technologies may prevent you from accessing some of our content. Your choices are typically device and browser-specific.

We honor Global Privacy Control (GPC) signals as required by U.S. and international privacy laws. GPC is a browser or device setting that allows you to control the sale or sharing of your personal data. If GPC is enabled on your device, we will process it as a valid opt-out request under applicable laws. For more information on enabling GPC, please visit globalprivacycontrol.org.

7. YOUR RIGHTS IN RELATION TO YOUR PERSONAL DATA

Access, modification, correction and erasure. You can send us an email at support@tofu.com to request access to, modification, correction, update, erasure or portability of any Personal Data that you have provided to us and that we have about you. You can also request deletion of your account inside the app, both for iOS and Android users. We may not accommodate a request to change information if we believe the change would violate any law or legal requirement or cause the information to be incorrect.

EEA/UK individuals. Individuals in the European Economic Area (“EEA”) and the United Kingdom (“UK”) have certain statutory rights in relation to their Personal Data including under the General Data Protection Regulation (Regulation (EU) 2016/679) (“EEA GDPR”) and the UK version of the EEA GDPR (“UK GDPR”) (collectively, the “GDPR”), including the rights specified below. You can exercise these rights by contacting us (for contact information, please see Section 14: How to Contact Us, EEA/UK Representative, and Data Protection Officer). We will do our best to accommodate your request or objection but please note that not all rights are absolute.

Please keep in mind that in case of a vague request to exercise any of the aforementioned rights we may engage with you in a dialogue to ask for more details if so needed to complete your request. In case this is impossible, we reserve the right to refuse granting your request.

Following the provisions of the applicable law, we might also ask you to prove your identity (for example, by requesting your username or some other proof of your identity) in order for you to invoke the mentioned rights. This is made to ensure that no right of third parties is violated by your request, and the mentioned rights are exercised by an actual Personal Data subject or an authorized person.

Third-Party Data Responsibility.

If you include any third-party Personal Data using the Services, including but not limited to email addresses of clients, contractors, or other recipients (for example when sending invoices, estimates, payment requests, or archives), uploaded documents, client names, or contact details, you represent and warrant that you have obtained all necessary consents, authorizations, or other valid legal bases required under applicable law to collect, use, and disclose such data via the Services.

We process third-party email addresses and other contact details solely for the purpose of providing the Services you initiate (such as delivering invoices, estimates, payment links, or related notifications). We do not use third-party email addresses entered by you for our own direct marketing campaigns.

When you upload documents, files or images that contain personal data of third parties, including biometric, medical or financial information, you act as the data controller for such third-party data. We process this information solely on your behalf and strictly for the purpose of providing the service. You are solely responsible for ensuring that you have a lawful basis (such as consent) to upload, store or process such information.

We do not independently verify the lawfulness of your use of third-party data and accept no responsibility or liability for your failure to comply with applicable legal obligations regarding such data. You remain solely responsible for the lawful processing of any third-party data you submit to the app.

Prohibited Content and User Responsibility

By using the Services, you agree not to upload any illegal, harmful, or unlawful content, including but not limited to:

Uploading such content is done at your own risk and responsibility. You are solely responsible for ensuring that the documents you upload do not contain illegal or unlawful material or content you do not have the right to share.

In the event that we detect unlawful content in the documents uploaded by users, we reserve the right to report such content to the relevant authorities for further investigation. This may include providing user-uploaded content or other relevant information to law enforcement or other regulatory bodies, as required by law.

We do not bear responsibility for any legal consequences arising from the uploading of prohibited content.

Manage your privacy rights. To enhance your experience, we provide in-app tools to manage your privacy rights, such as:

For additional assistance, contact us at support@tofu.com.

Requests related to personal or other data. If you are an individual in the EEA or UK, we will respond to your requests without undue delay and at the latest within one month from the date we receive your request. If your request is complex or if we receive a large number of requests, we may extend this period by an additional two months. In such cases, we will inform you of the extension and the reasons for the delay within the initial one-month period.

In any other case, we will process your requests related to personal data within 45 days from the date we receive them. If additional time is required due to complexity or volume of requests, we may extend this period by an additional 45 days. In such cases, we will notify you within the initial 45-day period.

You may submit your request by contacting us at support@tofu.com or through the app’s privacy settings.

8. YOUR CHOICES ABOUT OUR COMMUNICATIONS WITH YOU

Necessary communications. If you are using an App or the Web you may receive electronic communications from us (e.g., by posting in-app notices in Invoice Maker, push notifications or emails).  We send some of these communications to you, such as those related to your subscriptions, technical and security notices and updates to the Privacy Policy and Terms of Use, where necessary to perform our contract with you to provide the App or Web, or otherwise based on our legitimate interest in contacting you.

Communications related to the functionality of the App. Our Apps, and Web, allow users to send emails containing invoices, estimates, payment requests, or archive files either to themselves or to third parties. Email delivery is always initiated manually by the user within the app, or Web, interface.

Third-Party Recipients. If you choose to enter and use the email address of a third party (e.g., to send an invoice or estimate), you are solely responsible for ensuring that you have obtained the necessary consent from that person, as required by applicable data protection laws. We do not verify or validate the ownership of recipient email addresses entered by users.

OTP Delivery. For authentication purposes, we may send you a One-Time Password (OTP) via email. These emails are also processed via the providers mentioned above and initiated only by user request (e.g., during login or identity verification).

Marketing & Promotional Emails. We may use the email address associated with your account or business profile to send you marketing and promotional communications about Tofu products, features, and offers, where permitted by law. We will send such communications only where you have given us permission to do so or where this is otherwise allowed. You can withdraw your permission or opt out of marketing emails at any time by using the unsubscribe link included in our messages or by contacting us as seen in Section 14: How to Contact Us, EEA/UK Representative, and Data Protection Officer).

We do not send marketing emails to third-party email addresses that you enter into the Tofu Apps or Web on behalf of your own clients, contractors, or other contacts. Those addresses are used only to deliver user-initiated communications such as invoices, estimates, or payment requests.

In some cases, where permitted by applicable law, we may send informational or B2B communications to generic business email addresses (such as info@company.com).

Push Notifications. If you wish to opt-out of push notifications, you can do so through your mobile device settings by tapping “Settings” -> “Notifications” -> Choose the App -> press the toggle to allow or forbid push notifications from the app.

9. DATA SECURITY

We use reasonable and appropriate information security safeguards to help keep your Personal Data and other data secure and, in an effort, to protect it from accidental loss and unauthorized access, use, alteration and disclosure. We implement appropriate technical and organizational measures to protect your personal data, including encryption, secure servers, access controls, and regular security testing. We also require our third-party service providers to maintain equivalent safeguards.

Unfortunately, the transmission of information via the internet is not completely secure. Although we take measures to do our best to protect your Personal Data, we cannot guarantee the security of the collected information transmitted to or through the Tofu App and/or Web, or an absolute guarantee that such information may not be accessed, disclosed, altered, or destroyed.
Any transmission of your Personal Data is at your own risk. We are not responsible for the circumvention of security measures contained in the Tofu App and Web. Please understand that there is no ideal technology or measure to maintain 100% security.

The safety and security of your information also depends on you. For instance, we are not responsible for how you choose to share the photos or other information processed in your Invoice Maker account, such as via social media services. We are not responsible for the functionality, privacy, or security measures of any other organization.

In the event of a personal data breach, we have procedures to promptly assess, contain, and remediate the breach. Where required by law, we will notify the relevant data protection authorities and affected users in accordance with GDPR and applicable laws.

If you believe your data has been compromised, please contact us immediately at support@tofu.com.

10. DATA RETENTION

We retain Personal Data and other data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law (e.g. for tax, accounting, or legal compliance).

Specific retention periods include:

You may request account deletion by contacting support@tofu.com or using the in-app functionality.

Even if we delete some or all your Personal Data and other data, we may continue to retain and use anonymized data previously collected that can no longer be used for personal identification.

11. CROSS-BORDER DATA TRANSFERS

Certain of our service providers are incorporated in the United States. Accordingly, your Personal Data may be transferred to and stored in the United States.

Where required under the EEA GDPR, in case of transfers of personal data from the EEA to countries outside the EEA, where we cannot rely on adequacy decisions adopted by the European Commission (for more information, please see here) we ensure appropriate safeguards are in place to guarantee the continued protection of your personal data, particularly by signing the Standard Contractual Clauses of the European Commission (article 46(2)(c) GDPR). For more information on these Standard Contractual Clauses, please see here.

Where required under the UK GDPR, in case of transfers of personal data to countries outside the United Kingdom, we ensure appropriate safeguards are in place to guarantee the continued protection of your personal data, particularly by signing the UK Addendum to the EU Standard Contractual Clauses or the UK International Data Transfer Agreement, whichever is more appropriate in the given situation. For more information on UK Addendum and the UK International Data Transfer Agreement please see here. We may also guarantee the protection of your personal data by relying on adequacy decisions adopted or approved by the authorities in the United Kingdom.

12. CHILDREN’S PRIVACY

General age limitation. The Tofu Apps and Web are not intended for or directed at children under 13, and we do not knowingly collect or solicit any information from anyone under the age of 13 or knowingly allow such persons to Use the Tofu Apps and Web. If you are under 13, do not: (i) Use or provide any information in the Tofu App or Web, or through any of its features, or (ii) provide any information about yourself to us, including your name, address, telephone number or email address. If you are a parent or guardian and believe we have collected information from your child who is under the age of 13, please contact us at support@tofu.com.

If we discover that we have collected data from a child under the applicable age without verifiable parental consent, we will promptly delete that information and take steps to prevent further access to the Tofu Apps and Web.

Age limitation for EEA and/or UK individuals. You must be at least 16 years old in order to Use the Tofu Apps or Web. We do not allow Use of the Tofu Apps or Web, by EEA and/or UK individuals younger than 16 years old. If you are aware of anyone younger than 16 Using the Tofu Apps or Web, please contact us (for contact information, please see Section 14: How to Contact Us, EEA/UK Representative, and Data Protection Officer), and we will take the required steps to delete the information provided by such persons.


13. THIRD-PARTY WEBSITES AND SERVICES

We are not responsible for the practices employed by any websites or services linked to or from Invoice Maker, including the information or content contained within them. Where we have a link to a website or service, linked to or from Invoice Maker, we encourage you to read the privacy policy stated on that website or service before providing information on or through it.


14. HOW TO CONTACT US

General contact details. If you have any questions about this Privacy Policy or the App, please contact us via email at support@tofu.com.

Data protection officer. If you are an individual in the EEA or the UK and you wish to exercise your rights under Section 7: Your Rights In Relation to Your Personal Data, or you have any questions about this Privacy Policy or the Services, you can contact our data protection officer via email at support@tofu.com.


15. CHANGES TO OUR PRIVACY POLICY

The date this Privacy Policy was last revised is indicated at the top of the page. We may modify or update this Privacy Policy from time to time. Some changes do not require your consent. However, if we determine that the changes may pose risk to your rights and freedoms, we will ask for your consent to those changes separately from this Privacy Policy.