BillMyBusiness
Privacy PolicyTerms of ServiceRefunds & CancellationSub-processorsGrievance RedressalContact

Privacy Policy

This policy explains what personal data BillMyBusiness handles, why, where it is kept, who else sees it, and what you can ask us to do about it. It is written to be read, not to be skimmed past.

1. Two different roles, and why it matters to you

BillMyBusiness handles two quite different kinds of personal data, and our responsibilities differ for each. Getting this distinction right is the whole basis on which we are allowed to touch your records.

  • Your own account. When you sign up, we decide what to collect and why — your name, email, mobile number and business details. For this data we are the data fiduciary. Everything in this policy about notice, consent and your rights applies to us directly.
  • The records you put into the product. Your customers, your suppliers, your employees, their phone numbers, their GSTINs, their transaction history. You decide what to collect and why; we hold and process it on your instructions. For this data you are the data fiduciary and we are a data processor. We do not use it for our own purposes, we do not sell it, and we do not mine it.

The practical consequence: if one of your customers asks what data is held about them, that question is for you to answer, not us — you collected it. We will help you answer it.

2. What we collect

From you, as an account holder

  • Name, email address, mobile number, and the password you set (stored only as a one-way hash — we cannot read it).
  • Your business name, address, state, GSTIN and PAN, where you provide them.
  • If you sign in with Google: your email address and basic profile from Google. Nothing else.
  • Sign-in records: IP address, device and browser description, and times of access.
  • Your subscription and payment history, excluding card and bank credentials (see §5).
  • Anything you write to us in a support conversation.

What you put in, about other people

Customer and supplier names, contact details, addresses, GSTINs, PANs and transaction records; employee or team member details where you add them; and any documents or images you upload. You are responsible for having a lawful basis to give us this data.

What we do not do

There are no third-party analytics, no advertising trackers, no session recording, no fingerprinting and no cookies used for tracking anywhere in this product. We do not build profiles. We do not sell data to anybody, for any purpose, ever. Your session is kept in your browser’s local storage so you stay signed in; that is not a tracking cookie and it is not shared.

3. Why we are allowed to hold it

For your account data: to provide the service you asked for, to keep it secure, to bill you, and to meet our own legal obligations. Where the law requires your consent, we ask for it when you create your account and record that you gave it.

For the records you put in: your instruction, under the Terms of Service.

4. Where your data is kept

Our database, application servers and backups are hosted in Singapore (AWS ap-southeast-1). Your data is therefore stored outside India.

This is lawful. Indian law does not require this data to be stored in India, and no government notification restricts transfers to the country we use. We are telling you because you should know where your records physically are, not because there is a problem with it. Backups are encrypted before they are written.

5. Payments

Subscription payments are processed by Razorpay. Card numbers, CVVs, UPI PINs, net-banking credentials and bank account numbers are entered on Razorpay’s own checkout and never reach our systems at any point. We store the payment reference, the amount and whether it succeeded.

Separately, if you record your own bank details or UPI ID so they can be printed on your invoices, we store those, because that is what you asked us to do with them.

6. Who else sees it

Only the service providers we need to run the product, listed in full on our sub-processors page. Each receives only what it needs for its function.

Our own staff

Support and engineering staff can, in defined circumstances, access an account to investigate a problem. When that happens it is recorded: who did it, when, why, and every action taken while inside. Access is limited by role and time. We will not do it for any reason other than operating the service, meeting a legal obligation, or a request from you.

Legal disclosure

We may disclose data where compelled by a valid order of a court or an authority with jurisdiction. Where we are lawfully permitted to tell you, we will.

7. How long we keep it

The most important line in this table is the first one: we do not automatically delete your books. They are records you are required by tax and company law to preserve for years, and a product that quietly deleted them would put you in breach.

DataKept forWhy
Invoices, purchases, payments, ledgers and vouchersAt least 8 years; not deleted by any automatic processThese are your books of account. Section 36 of the CGST Act read with Rule 56 requires 72 months from the due date of the annual return; s.128 of the Companies Act requires 8 years; Rule 6F of the Income-tax Rules requires 6. We do not delete them on a timer, because doing so would put you in breach.
Your account details and business profileFor as long as your account is openNeeded to provide the service.
One-time passcodes and password-reset tokens24 hoursOnly ever needed once. The codes themselves are stored as one-way hashes and are never written to our delivery log in readable form.
Message delivery log (who we messaged, about what, and whether it arrived)30 daysLong enough to answer "did my invoice reach the customer?". Content of authentication messages is never stored.
Sign-in sessions30 days after expirySo a revoked session remains evidence that it was ended deliberately.
Security and sign-in attempt records180 daysMatches the rolling period in the CERT-In Directions of 28 April 2022 for maintaining ICT system logs.
Audit trail of changes made in your accountApproximately 3 yearsThis is what answers "who changed this figure, and when?" if a number is ever disputed. The Limitation Act allows three years to bring a contract claim.
Error and performance diagnostics30 to 90 daysOperating the service.

8. Security

  • Passwords and one-time codes are stored only as Argon2 hashes. Nobody at BillMyBusiness can read them.
  • Two-factor authentication is available and can be required.
  • Traffic is encrypted in transit; backups are encrypted at rest.
  • Third-party credentials you connect are encrypted with AES-256-GCM before storage.
  • Changes to your records are written to a tamper-evident audit trail.
  • The content of authentication messages — passcodes, reset links — is never stored in our delivery log.

No system is perfectly secure, and we will not claim otherwise. If a breach affects your data we will tell you and the relevant authority as the law requires.

9. Your rights

Regarding the data we hold about you as an account holder, you may:

  • See it — request a copy of what we hold about you.
  • Correct it — most of it you can edit yourself in Settings.
  • Export it — your business records can be exported at any time, in open formats, from Reports. This works even if your subscription has lapsed. Your books are yours.
  • Delete it — you can close your account and delete your data from Settings. See the limits below.
  • Withdraw consent — though this may mean we can no longer provide the service.
  • Complain — to our Grievance Officer, and after that to the appropriate authority.

Limits on deletion, stated honestly. When you delete your account we remove your data from the live system. Two things survive: encrypted backups, until they age out of their retention window and are destroyed on schedule; and records we are independently required by law to keep, such as evidence of payments made to us. We will not use either for anything else.

10. Children

BillMyBusiness is a product for businesses and is not directed at children. We do not knowingly create accounts for anyone under 18. If you believe a child has an account, tell the Grievance Officer and we will remove it.

11. Changes

If we change this policy in a way that materially affects you, we will tell you by email or in the product before it takes effect. Every version is dated.

12. Contact

For any question about this policy, or to exercise a right above, contact our Grievance Officer at grievance@billmybusiness.in. Full details are on the grievance page.

This service is operated by the operator of BillMyBusiness.

Version 1.0-draft · Last updated 21 August 2026

Draft

© 2026 BillMyBusiness