Privacy Policy
Last updated: May 20, 2026
1. Overview
This Privacy Policy explains how Duet, operated by AutomateWithUs (“Duet,” “we,” “us”), collects, uses, and protects information when you use the Duet invoicing service. It applies to merchants who use Duet.
2. Information We Collect
- Account information — your name, email address, and password, handled through our authentication provider, Clerk.
- Business information — your business name, business type, contact details, and the dual-pricing settings you choose.
- Invoice and customer data — the customers, line items, amounts, and notes you enter to create invoices and payment pages.
- Payment data — payments are processed by Square. Duet does not collect or store full card numbers or bank account numbers; we receive payment status and limited transaction details from Square.
- Usage and device data — log data, IP address, and basic analytics needed to operate and secure the service.
3. How We Use Information
We use information to:
- provide, maintain, and improve the Duet service;
- process and track invoices and payments;
- communicate with you about your account and the service;
- secure the service and prevent fraud and abuse; and
- comply with our legal obligations.
4. Service Providers (Sub-processors)
We share information with vendors that help us operate Duet, under contracts that limit their use of it:
- Clerk — user authentication and account management;
- Supabase — application database hosting;
- Square — payment processing;
- Resend — transactional email delivery;
- Vercel — application hosting and infrastructure;
- Upstash — rate limiting and abuse protection.
5. How We Share Information
We do not sell your personal information. We share it only with the service providers listed above, when required by law, to protect rights and safety, or in connection with a merger, acquisition, or other business transfer.
6. Your Customers’ Information
When you enter your customers’ details into Duet, you act as the controller of that information and Duet processes it on your behalf. You are responsible for providing any notices and obtaining any consents your customers are owed.
7. Data Retention
We retain information for as long as your account is active and as needed to provide the service, and then for a reasonable period to meet legal, tax, and recordkeeping obligations.
8. Security
We use technical and organizational measures to protect information, including encryption of sensitive credentials. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Your Rights
Depending on where you live, you may have the right to access, correct, delete, or port your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at duet@automatewith.us.
10. California Privacy (CCPA/CPRA)
California residents may request access to or deletion of their personal information and may opt out of any “sale” or “sharing” of personal information. Duet does not sell personal information. We will not discriminate against you for exercising these rights.
11. European Users (GDPR)
Where the GDPR applies, our legal bases for processing are performance of our contract with you, our legitimate interests in operating and securing the service, and compliance with legal obligations. You may have rights to access, rectify, erase, restrict, or port your data, and to lodge a complaint with a supervisory authority.
12. Cookies
Duet uses a small number of cookies: a session cookie that keeps you signed in, and a referral cookie (duet_ref) that records which partner referred you. We do not use advertising cookies.
13. Children’s Privacy
Duet is intended for businesses and is not directed to children under 13. We do not knowingly collect information from children.
14. International Transfers
We operate in the United States. If you access Duet from outside the U.S., your information will be processed in the U.S.
15. Changes to This Policy
We may update this Policy and will post the updated version with a new “Last updated” date.
16. Contact
Privacy questions can be sent to duet@automatewith.us.