Sharing invoices & payment links
Public links, and why the whole link matters.
User guide
Public links, and why the whole link matters.
Customers see their paperwork through public links: an invoice link that shows the printable document, and — for bank-transfer orders — a payment page where they upload their transfer slip.
Who can do this: sending is its own permission (Send invoice link on the invoice's menu); the links themselves need no sign-in — that is their point.
Send invoice link delivers the live document by email, SMS or WhatsApp. Every send is recorded — channel, destination, time and who sent it — on the invoice's own send log. Only the live document can be sent: a superseded or void one refuses, which is how the customer always receives the current truth.
For a bank-transfer order, the payment page is where the customer uploads proof of their transfer — landing on the order as proof uploaded for staff to verify. If the customer lost the link, the order's resend payment-proof link action mints the message again (it is only offered on bank-transfer orders, since no other method has a proof step).
Every public link carries an access token — the ?t=… at the end. It is the key: document
numbers are sequential and dated, so without the token a guessed URL would walk a store's
entire invoice history, each page carrying a customer's name and what they paid. With it: