Moneybird Invoicing
Pricing Docs NL Install app

Privacy Policy

Last updated 24 August 2026

1. Who controls this data

Yanis De Maesschalck, trading as YDM Design, Roombaardstraat 40, 9810 Nazareth-De Pinte, Belgium. VAT BE0699694751. Contact: info@ydmdesign.be.

2. What data we process

  • Your CRM OAuth access and refresh tokens and your Moneybird OAuth access and refresh tokens, stored encrypted on our servers. We never store a Moneybird password; access is granted over OAuth and you can revoke it yourself.
  • Order and contact data from your CRM needed to create an invoice: customer name, address, email address, and VAT number where mapped.
  • Invoice log metadata: status, timestamps, and retry history for each invoice attempt.

3. Cookies

The dashboard uses a single session cookie to keep you signed in while it's embedded in your CRM. It's used only for authentication, is marked HTTP-only and secure, and carries no tracking or analytics purpose.

4. Why we process this data

We process this data to perform the invoicing service you configured, on the basis of the contract formed when you install and use the app.

5. Who we share data with

  • Your CRM platform: the source of your order and contact data.
  • Moneybird: generates and delivers the invoices, over Peppol or email.
  • Neon: hosts our application database (AWS Frankfurt, Germany).
  • Railway: hosts the application itself (Amsterdam, the Netherlands).
  • Cloudflare: stores the daily database backups, in R2 storage under EU jurisdiction, for 90 days.
  • GitHub: runs the automated backup job, and temporarily processes the database in doing so.

6. How long we keep it

We keep your configuration and invoice logs for as long as the app stays installed, plus a reasonable period afterwards for bookkeeping and dispute-handling purposes. You can request earlier deletion by contacting us.

When we delete data, it remains present in the daily backups for up to 90 days, after which those expire on their own. Backups are not edited: doing so would destroy their value as a restore point.

7. Your rights

Under GDPR, you can request access to, correction of, or deletion of your data, ask us to restrict or object to processing, and request a copy in a portable format. Contact info@ydmdesign.be for any of these requests.

8. International transfers

Your data stays within the European Union: the application runs on Railway in Amsterdam (the Netherlands), the database is hosted by Neon in Frankfurt (Germany), and the backups sit with Cloudflare in storage under EU jurisdiction.

One processing step may leave the EU. The daily backup job runs on GitHub's infrastructure, which gives no geographic guarantee as to where that job is executed; the database passes through it temporarily before being written to storage in the EU. GitHub (Microsoft) participates in the EU-US Data Privacy Framework and additionally relies on standard contractual clauses. The same contractual safeguards apply to our other providers where they would process outside the European Economic Area.

9. Security

Your Moneybird OAuth tokens and your CRM platform's access and refresh tokens are encrypted at rest with AES-256-GCM, all traffic is served over HTTPS, and access to the app's endpoints is rate-limited. The backups contain those same encrypted values — the key itself is never stored alongside them.

10. Changes & contact

We may update this policy from time to time; the current version, with its update date, is always available at this page. Questions can be sent to info@ydmdesign.be.

Moneybird Invoicing · made by YDM Design
Terms · Privacy · Documentation
Moneybird Invoicing is an independent integration and is not affiliated with, endorsed by, or sponsored by Moneybird.