Back

Privacy Policy

Last updated: 18 February 2026 · Complies with India's DPDP Act 2023

1. Who we are

HisabX ("we", "us") is operated by HisabX Technologies, Pune, Maharashtra, India. This policy explains how we collect, use, share, and protect personal data of dealers, managers, CSAs, credit customers, and CAs who use the HisabX platform.

2. Data we collect

  • Identity — name, phone number, role (Dealer / Manager / CSA / CA / Credit customer), email if provided, hashed password/PIN.
  • Business data — pump name and address, dispenser configuration, HISABs, cashbook entries, credit customer statements, staff attendance records, shift photos.
  • Operational uploads — printer-receipt images, fleet-card slips, cash-handover photos, staff selfies + GPS coordinates at check-in.
  • Device / usage data — IP address, user-agent, session timestamps, error logs (via Sentry, anonymised).
  • Communications metadata — Telegram chat IDs (if linked), WhatsApp opt-in status, email delivery receipts from Resend.
  • AI processing inputs — 30-day aggregate KPIs of your pump are sent to our AI provider(s) for insight generation. No CSA names or customer PII are included in AI payloads.

3. Why we process it

  • Deliver core Service — HISAB verification, cash reconciliation, reports, PDFs, statements.
  • Secure your account — brute-force lockout, session invalidation, refresh-token rotation.
  • Send transactional notifications you have opted in to (WhatsApp, Telegram, email).
  • Provide AI insights and OCR (with the safeguards in Section 2).
  • Meet legal obligations — statutory financial record retention, tax compliance, lawful requests.
  • Improve the product — aggregated, anonymised usage analytics.

4. Legal basis (DPDP Act 2023)

We rely on: (a) your consent, taken at sign-up and per-feature (WhatsApp/Telegram opt-in, GPS at check-in); (b) legitimate uses under Section 7 of the Act — service provision, employment, and legal compliance; and (c) contractual necessity for paid subscriptions.

5. Who we share data with

We never sell personal data. We share only with these categories of processors, strictly on your behalf and under written contracts:

  • Resend — transactional email delivery (invites, password resets).
  • Twilio — WhatsApp Business messaging for opt-in alerts.
  • Telegram — bot notifications you have connected.
  • Emergent object storage — uploaded images.
  • Google / Gemini + emergentintegrations — OCR and AI insights on aggregated data.
  • Sentry — anonymised error monitoring (if configured).
  • Law-enforcement — only under a valid Indian court order or lawful government direction.
  • Chartered Accountants — only if you invite them via the CA Add-on; their access is read-only and audited.

6. Data location and transfers

Primary data is stored in India (Mongo Atlas Mumbai region). Some processors (Resend, Sentry, Google AI) may process data outside India under adequate safeguards including SCCs. We do not transfer data to jurisdictions restricted by the Central Government under the DPDP Act.

7. Retention

  • Live operational data — kept as long as your account is active plus 90 days after termination.
  • Financial records — retained for 8 years to meet Indian statutory audit requirements.
  • Refresh tokens & password-reset tokens — auto-expire via TTL indexes (7 days / 30 min respectively).
  • Backup ZIPs — retained 30 days (auto) or as long as you keep them (manual).

8. Your rights as a data principal

Under the DPDP Act 2023 you may:

  • Access your personal data (any time from your profile / Data-Ops page).
  • Request correction or updation of inaccurate data.
  • Request deletion of your data (see /delete-account).
  • Withdraw consent for optional features (WhatsApp alerts, GPS, AI insights).
  • Nominate a person to exercise these rights on your behalf in the event of death or incapacity.
  • Lodge a complaint with the Data Protection Board of India.

To exercise any right, email privacy@hisabx.in from your registered address. We respond within 30 days.

9. Security measures

  • Passwords hashed with bcrypt (cost 12).
  • Sessions delivered via httpOnly + Secure + SameSite=None cookies.
  • Refresh-token rotation with family-reuse revoke.
  • Brute-force lockout — 10 failed attempts / 3-minute cool-off per identifier.
  • URL masking so route paths don't leak feature enumeration.
  • TLS 1.2+ in transit; AES-256 at rest.
  • Force-logout tools for admins after any config reset.
  • Every mutating admin action written to an immutable audit trail.

10. Children's data

HisabX is a B2B tool and not directed at children. We do not knowingly collect data from anyone under 18. If we discover such data, we delete it promptly.

11. Cookies

We use only essential cookies for authentication (access + refresh tokens). No third-party ad or tracking cookies. No cross-site tracking.

12. Changes to this Policy

We revise this policy from time to time. Material changes will be notified via in-app banner and email at least 14 days before they take effect.

13. Contact

Data-protection queries: privacy@hisabx.in · Grievance officer: grievance@hisabx.in · Postal: HisabX Technologies, Pune, Maharashtra, India.