Privacy policy
DRAFT: pending legal review. Last updated: 2026-09-30.
Dhanlaxmi ("we", "us") is operated by [Legal entity name, to be filled], [Registered address, to be filled]. This policy explains how we handle personal data under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 ("DPDP law"), the Information Technology Act, 2000 including section 43A and the SPDI Rules, 2011, and other Indian law.
1. Who is responsible for what
- Your account and usage data (your name, phone, email, device and sign-in details): we decide why and how it is used. We are the Data Fiduciary.
- Your business records and your customers' and suppliers' details that you enter: you decide what to enter and why. You are the Data Fiduciary for that data and we are your Data Processor. You must have a lawful basis to enter it and to give us the instructions in these terms.
2. What we collect
| Data | Why | When |
|---|---|---|
| Name, email address and phone number | To create and secure your account, send one-time passwords and service messages | When you sign up |
| Business data: business name, GSTIN, addresses, customers, suppliers, items, invoices, payments, stock, books | To provide the service you asked for | As you use the app |
| Your customers' contact details that you enter | To let you bill and remind them | As you use the app |
| Device and log data: device type, operating system, app version, IP address, session and audit records | Security, sync, fraud prevention, legal log retention, support | While signed in |
| Files you upload: import files, logos, bank statements, support screenshots | To run imports, print your logo, reconcile, and help you | When you upload |
| Support conversations | To resolve your issue | When you contact us |
| Operational telemetry: sampled request timings and error counts | To keep the service fast and fix faults | Continuously |
| Payment data | Card, UPI and bank details are collected by Razorpay, not by us. We keep the order id, amount, status and plan | When you pay |
| Push notification token | To deliver notifications you have allowed | When you allow notifications |
We do not collect sensitive personal data such as health or biometric data. We do not use advertising SDKs and do not sell personal data.
3. Notice and consent (DPDP law)
We ask for your consent at sign-up for the purposes in section 2, in plain language, in English and Hindi. You can withdraw consent at any time in the app (More, then Delete account) or by writing to us. Withdrawal is as easy as giving consent. It means we can no longer provide the service, and we will stop processing except where the law requires us to keep records (section 6). Some processing is done without consent where DPDP law allows, for example to meet a legal obligation or respond to a medical emergency.
4. Why we use it
To provide and secure the service, meet legal obligations (tax, accounting record keeping, and security log retention), support you, prevent fraud and abuse, and improve reliability. We do not use your business data for advertising.
5. Who processes it for us, and where (including outside India)
Our infrastructure providers are Data Processors acting on our instructions. Some process data outside India. Under DPDP law, transfer outside India is allowed except to countries the Government restricts by notification; we will stop transfers to any country so restricted. Under the SPDI Rules we transfer only to providers that ensure the same level of protection.
| Processor | Purpose | Location | Data |
|---|---|---|---|
| Cloudflare, Inc. | Website and API delivery, DNS, security filtering, file storage (R2) | Global network; file storage region [to be confirmed] | Requests and IP addresses; encrypted uploaded files |
| Neon, Inc. | Primary database (PostgreSQL) | Singapore | Account and business data |
| Upstash, Inc. | Cache, rate limiting and session state | [region to be confirmed] | Session and rate-limit data |
| Resend, Inc. | Sign-in codes and service email | United States [to be confirmed] | Email address and message content |
| Razorpay Software Pvt. Ltd. | Payment collection | India | Payment details (held by Razorpay) |
| [SMS/WhatsApp provider, to be confirmed] | Messages you ask us to send | [to be confirmed] | Phone number and message |
| Apple and Google | Push notifications and app distribution | Global | Push token |
We will update this list before any new processor handles your data. We may disclose data to authorities where the law requires.
6. How long we keep it
- Short-lived security data (one-time codes, sign-in tokens): a few days to 30 days after expiry.
- Message delivery log: 180 days.
- Security and system logs: 180 days, kept as required by CERT-In directions of 28 April 2022. Processing logs required by DPDP law are kept for at least one year.
- Unsent support attachments: 7 days. Unconfirmed import previews: 30 days (your original import file is kept).
- Aggregated telemetry: up to 90 days.
- Your business books: for as long as your account is active.
- Books retained by law: posted invoices, ledgers, stock records and the audit log are kept in a locked archive for 72 months after the due date of the annual GST return for the year concerned (section 36 of the CGST Act, 2017 and related rules), then erased. [Confirm period and any longer requirement, such as the Companies Act audit-trail rules, with counsel.]
- Backups: encrypted backups (7 daily, 4 weekly, 12 monthly) may still hold deleted data until they rotate out. Restored data is re-deleted.
7. Your rights
You may: ask for a summary of the personal data we process and who we share it with (access); correct or complete it; ask us to erase it; nominate another person to exercise your rights if you die or become incapable; withdraw consent; and have your grievance redressed. You can export your data yourself at any time, free.
- Delete your account: in the app (More, then Delete account) or on the account deletion page if you no longer have the app.
- Other requests and complaints: write to the Grievance Officer in section 12. We acknowledge within 24 hours and resolve within 15 days; the law allows up to 90 days for DPDP requests and we aim to be faster.
- If we do not resolve your complaint, you may complain to the Data Protection Board of India, after first using our grievance process.
You must give accurate information and must not file false or frivolous complaints.
8. Children
The service is for businesses and is not directed at anyone under 18. We do not knowingly collect children's personal data and do not track or target children. If you believe a child has given us data, write to us and we will delete it, or obtain verifiable parental consent where the law lets us keep it.
9. Security and breaches
Encryption in transit and at rest, per-business file keys, access controls, audit logging and staff who cannot edit your books. See the security page. No system is perfectly secure. If a personal data breach occurs we will inform affected users and the Data Protection Board as DPDP law requires, and report cyber incidents to CERT-In within 6 hours of noticing them. To report a vulnerability, write to [email protected].
10. Cookies and similar technologies
See the cookie notice. Our website sets no advertising or analytics cookies.
11. Changes
We will post changes here with a new date, and tell you in the app for material changes, and ask again for consent where the law requires.
12. Grievance Officer and contact
- Name: [Grievance Officer name, to be filled]
- Email: [email protected]
- Address: [Registered address, to be filled]
- Hours: Mon-Sat, 10:00 to 18:00 IST
Privacy questions: [email protected]. General support: [email protected].