DRAFT: pending legal review. This text is not final and is not yet legally binding advice or terms.

Privacy policy

DRAFT: pending legal review. Last updated: 2026-09-30.

Dhanlaxmi ("we", "us") is operated by [Legal entity name, to be filled], [Registered address, to be filled]. This policy explains how we handle personal data under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 ("DPDP law"), the Information Technology Act, 2000 including section 43A and the SPDI Rules, 2011, and other Indian law.

1. Who is responsible for what

2. What we collect

DataWhyWhen
Name, email address and phone numberTo create and secure your account, send one-time passwords and service messagesWhen you sign up
Business data: business name, GSTIN, addresses, customers, suppliers, items, invoices, payments, stock, booksTo provide the service you asked forAs you use the app
Your customers' contact details that you enterTo let you bill and remind themAs you use the app
Device and log data: device type, operating system, app version, IP address, session and audit recordsSecurity, sync, fraud prevention, legal log retention, supportWhile signed in
Files you upload: import files, logos, bank statements, support screenshotsTo run imports, print your logo, reconcile, and help youWhen you upload
Support conversationsTo resolve your issueWhen you contact us
Operational telemetry: sampled request timings and error countsTo keep the service fast and fix faultsContinuously
Payment dataCard, UPI and bank details are collected by Razorpay, not by us. We keep the order id, amount, status and planWhen you pay
Push notification tokenTo deliver notifications you have allowedWhen you allow notifications

We do not collect sensitive personal data such as health or biometric data. We do not use advertising SDKs and do not sell personal data.

3. Notice and consent (DPDP law)

We ask for your consent at sign-up for the purposes in section 2, in plain language, in English and Hindi. You can withdraw consent at any time in the app (More, then Delete account) or by writing to us. Withdrawal is as easy as giving consent. It means we can no longer provide the service, and we will stop processing except where the law requires us to keep records (section 6). Some processing is done without consent where DPDP law allows, for example to meet a legal obligation or respond to a medical emergency.

4. Why we use it

To provide and secure the service, meet legal obligations (tax, accounting record keeping, and security log retention), support you, prevent fraud and abuse, and improve reliability. We do not use your business data for advertising.

5. Who processes it for us, and where (including outside India)

Our infrastructure providers are Data Processors acting on our instructions. Some process data outside India. Under DPDP law, transfer outside India is allowed except to countries the Government restricts by notification; we will stop transfers to any country so restricted. Under the SPDI Rules we transfer only to providers that ensure the same level of protection.

ProcessorPurposeLocationData
Cloudflare, Inc.Website and API delivery, DNS, security filtering, file storage (R2)Global network; file storage region [to be confirmed]Requests and IP addresses; encrypted uploaded files
Neon, Inc.Primary database (PostgreSQL)SingaporeAccount and business data
Upstash, Inc.Cache, rate limiting and session state[region to be confirmed]Session and rate-limit data
Resend, Inc.Sign-in codes and service emailUnited States [to be confirmed]Email address and message content
Razorpay Software Pvt. Ltd.Payment collectionIndiaPayment details (held by Razorpay)
[SMS/WhatsApp provider, to be confirmed]Messages you ask us to send[to be confirmed]Phone number and message
Apple and GooglePush notifications and app distributionGlobalPush token

We will update this list before any new processor handles your data. We may disclose data to authorities where the law requires.

6. How long we keep it

7. Your rights

You may: ask for a summary of the personal data we process and who we share it with (access); correct or complete it; ask us to erase it; nominate another person to exercise your rights if you die or become incapable; withdraw consent; and have your grievance redressed. You can export your data yourself at any time, free.

You must give accurate information and must not file false or frivolous complaints.

8. Children

The service is for businesses and is not directed at anyone under 18. We do not knowingly collect children's personal data and do not track or target children. If you believe a child has given us data, write to us and we will delete it, or obtain verifiable parental consent where the law lets us keep it.

9. Security and breaches

Encryption in transit and at rest, per-business file keys, access controls, audit logging and staff who cannot edit your books. See the security page. No system is perfectly secure. If a personal data breach occurs we will inform affected users and the Data Protection Board as DPDP law requires, and report cyber incidents to CERT-In within 6 hours of noticing them. To report a vulnerability, write to [email protected].

10. Cookies and similar technologies

See the cookie notice. Our website sets no advertising or analytics cookies.

11. Changes

We will post changes here with a new date, and tell you in the app for material changes, and ask again for consent where the law requires.

12. Grievance Officer and contact

Privacy questions: [email protected]. General support: [email protected].