Legal
Privacy Policy
Version 1.3 · Last updated 4 September 2026
In plain English
- We don't sell your data and we don't use it for advertising. Our public website uses Google Analytics to count visits; the app itself carries no analytics or tracking of any kind.
- Your records are stored on servers in India.
- The AI features send data to a provider in the United States — including, for AI chat, your customers' names and phone numbers.
- Bill photos and voice recordings are never stored by us. They're processed and discarded.
- AI chat questions and answers are stored.
- Sharing an invoice creates a public link that needs no login and currently cannot be revoked.
- There is no in-app export or delete button yet — email our Grievance Officer and we'll do it.
This summary is for orientation only. The numbered sections below are what actually apply.
See also our Terms of Service.
Draft document
This policy has not been finalised or reviewed by a qualified advocate, and contains placeholder values. It is published here for internal review only.
This policy explains how EkamBase handles personal data in connection with EkamBase — our website, our web application, and the emails we send.
1. Our two roles
We handle two different kinds of personal data, and our responsibility differs between them:
- Your own data (your name, email, business details, sign-in records) — here we are the Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), and this policy governs it.
- Your customers' and suppliers' data that you record in the app — here you are the Data Fiduciary and we are your Data Processor. We act on your instructions. Your own privacy notice, not ours, governs your relationship with your customers.
If you are a customer of a shop that uses EkamBase and you want to exercise rights over your data, please contact that shop; we will assist them as their processor.
2. What we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account | Name, email address, password (stored only as a hash), role, workspace id, email-verified flag, timestamps | You, at signup or when accepting an invitation |
| Google sign-in (optional) | Email address, name, and your Google account identifier | Google, if you choose to sign in with Google |
| Business profile | Business name, industry, type, size, address, city, state, PIN code, phone, email, GSTIN | You, during onboarding and in settings |
| Your customers and suppliers | Names, phone numbers, addresses, GSTINs; invoice line items, totals and payment status | Entered by you, or extracted from a bill you scanned |
| Operational records | Products, batches, expiry dates, purchases, expenses, returns, orders, reports | Your use of the app |
| AI interactions | Your chat questions and the AI's replies | AI chat |
| Uploads (not stored) | Bill/invoice images and voice recordings | Sent for processing, then discarded — see section 4 |
| Authentication | Server-side session records with expiry and revocation state; sign-in tokens held in your own browser's local storage | Signing in |
| Technical | IP address, browser user agent and timestamps in server logs | Automatically, when you use the site |
We also process the email address of anyone you invite to your workspace, in order to send them the invitation.
For legal review
The host is now settled — a Microsoft Azure VM in an India region — so 'whichever host is chosen' no longer blocks this. What is still open is the retention half: how long server and access logs are kept. The retention table in section 7 says 'Not specified' for the same reason. Set a period and enforce it before either is published as a number.
3. Why we use it, and our lawful basis
- to create and operate your workspace, and authenticate you;
- to send transactional email — verification, password reset, and invitations;
- to provide the AI features you choose to use;
- to provide support when you contact us;
- to keep the Service secure and prevent abuse;
- to comply with law.
We do not use your data or your customers' data for advertising, we do not sell it, and we do not share it for any purpose other than those listed in section 4.
For legal review
Please map each purpose to a DPDP basis — consent under s.6 for account creation, service provision and the AI features; the s.7 "legitimate uses" list where applicable (security, legal compliance). Note that GDPR-style "legitimate interests" is not available under the DPDP Act, so that language must not be imported.
4. Who else processes your data
The AI features involve a transfer outside India
If you use bill scanning, voice entry or AI chat, content leaves India for processing. For AI chat that content includes a snapshot of your business data, which contains your customers' names and phone numbers. You can avoid this entirely by not using the AI features.
| Provider | What it receives | Why | Location |
|---|---|---|---|
| Groq | Bill/invoice images; voice recordings; for AI chat, a snapshot of your workspace (product and batch details, recent invoices, and up to several hundred customer names with phone numbers) plus your typed question | OCR extraction, speech-to-text, AI chat and insights | United States |
| Resend | Recipient email address and name, and the message content including tokenised links | Sending verification, password-reset and invitation emails | United States |
| Your Google account identity (we receive email, name and account id). Google's own script also sees your IP address and user agent when the sign-in button loads | Optional Google sign-in | United States | |
| Google Analytics | On the public website only (ekambase.com), not in the app: your IP address and user agent, which pages you view and where you arrived from, and a randomly generated id stored in a cookie on your device | Counting visits and understanding which pages people read, so we know what to write more of | United States |
| Fontshare (Indian Type Foundry) | IP address and user agent, on page load | Serving one of our web fonts | India |
| Microsoft Azure | All stored workspace data — every category in section 2 that we keep | Hosting the virtual machine our database runs on | India |
| Microsoft Azure | Requests, IP addresses, server logs | Hosting the virtual machine that serves the site and app | India |
| Razorpay | Your name and email address, and the plan you chose. The card, UPI or netbanking details you enter go straight to Razorpay's own checkout — we never see or store them | Taking subscription payments. Paid plans are not live yet, so nothing has been sent to them so far | India |
WhatsApp / Meta is not one of our processors. When you share an invoice, we prepare a link and your own WhatsApp account sends the message. What happens to it after that is governed by WhatsApp's own terms.
For legal review
Obtain and read Groq's and Resend's data-processing terms before this is published — specifically their retention, region, and whether they train on API inputs. The hosting rows are now filled in (Microsoft Azure, India region) and the security and cross-border sections have been updated to match. Razorpay is named as the gateway ahead of paid plans going live; please confirm whether naming a processor we have not yet sent data to needs any qualification beyond the sentence in the row.
5. Transfers outside India
Your records are stored in India. Our servers — both the application and the database — run in an India region of Microsoft Azure, and Razorpay processes payments in India. What leaves the country is the AI and email path: Groq, Resend and Google process data outside India, primarily in the United States. Using the AI features necessarily involves such a transfer; not using them means your data stays on servers in India.
For legal review
Please confirm the current DPDP position on transfers before publication — s.16 operates as a restriction-by-notification model rather than an adequacy or standard-contractual-clauses regime, and sector-specific localisation rules override it. Also confirm the commencement status of the Act and its Rules as at the publication date. Do not describe an adequacy or SCC framework; those are GDPR constructs and do not map.
6. Publicly shared invoices
Shared invoice links are public and permanent
Sharing an invoice creates a web address containing a random token. Anyone holding that address can open the invoice PDF — including the customer's name, phone number, GSTIN, address and line items — without signing in. The link does not expire and cannot currently be revoked.
We do not list or index these links anywhere. As the Data Fiduciary for your customers' data, it is your decision whether to share an invoice and with whom.
7. How long we keep things
| Data | Retention |
|---|---|
| Bill images and voice recordings | Not stored. Processed and discarded immediately. |
| Sign-in sessions | Expire automatically after 30 days |
| Password-reset links | Expire automatically after 1 hour |
| Email-verification links | Expire automatically after 24 hours |
| Unaccepted invitations | Expire automatically on their expiry date |
| AI chat questions and replies | No automatic expiry — see the note below |
| Business and workspace records | While your account is active, then per the grace and deletion windows in the Terms |
| Server and access logs | Not specified |
For legal review
AI chat logs currently have no automatic expiry in the database — they are kept indefinitely. Pick a period, then implement it as a database TTL (the same mechanism already used for sessions and tokens) before publishing the number. Do not state a retention period we don't enforce.
8. Your rights, and how to use them
As a Data Principal under the DPDP Act you have the rights below. Because the app does not yet have self-service controls for all of them, the honest position is that most are exercised by writing to our Grievance Officer.
- Access — ask for a summary of the personal data we process about you and who we share it with.
- Correction and completion — some of this you can do yourself in the app (your profile, business settings, and your own customer records). Otherwise, ask us.
- Erasure — ask us to delete your data. There is no in-app delete button yet, so this is a manual request. Some data may be kept where law requires it.
- Grievance redressal — raise a complaint with our Grievance Officer, and escalate to the Data Protection Board of India if you are not satisfied with our response.
- Nomination — nominate someone to exercise your rights if you die or become incapacitated. There is no in-app flow for this; write to us.
- Withdraw consent — you can withdraw consent at any time. Depending on what you withdraw, the related feature or your account may stop working.
To exercise any of these, write to us from the address registered on your account. If we can't verify that a request genuinely comes from you, we will ask for more information before acting — otherwise this channel would itself become a way to attack your account.
You also have duties under the DPDP Act: please don't file requests you know to be false, and don't impersonate someone else.
9. Children
The Service is for businesses and is restricted to users aged 18 and over. We do not knowingly collect children's personal data, and we do not do behavioural tracking or targeted advertising of any kind. If we discover we hold a child's data, we will delete it.
10. Cookies and local storage
Our public website (ekambase.com) uses Google Analytics, which sets cookies on your device holding a randomly generated identifier so that repeat visits can be counted as one visitor. We set no advertising cookies, and we run no advertising pixels. The app itself (app.ekambase.com) has no analytics at all — nothing you do inside your workspace is measured.
The app stores your sign-in tokens in your browser's local storage to keep you signed in. Clearing site data signs you out. Note that the third parties in section 4 — Google Analytics and the font provider on the website, and Google if you use Google sign-in — may set their own cookies or log the request when their resources load.
For legal review
Google Analytics is now live on the marketing website (not the app), so the earlier ‘no analytics at all’ position no longer holds and the question this note reserved is now live. The DPDP Act offers no ‘legitimate interests’ basis, so please advise whether a consent banner is required before the analytics cookie is set, and whether Consent Mode defaulting to denied is sufficient. Nothing is collected in the app, and no advertising or cross-site profiling is enabled.
11. How we protect data
What we actually do today:
- Passwords are stored only as a bcrypt hash — never in plain text, and not recoverable by us.
- Sign-in uses short-lived (8-hour) signed access tokens, plus longer-lived refresh tokens that are recorded server-side and can be revoked, and which expire after 30 days.
- Each workspace is isolated at the data-access layer: every query and aggregation is forced to filter by workspace id by construction, rather than relying on developers to remember it.
- Access within a workspace is role-based and default-deny for staff, with destructive actions restricted to the Owner.
- The website and app are served over HTTPS.
- Password-reset, email-verification and invitation links are single-use and time-limited.
What we deliberately do not claim
We are not claiming encryption at rest, any security certification (such as ISO 27001 or SOC 2), penetration testing, 24×7 monitoring, or guaranteed backups. Those are not in place, and we would rather say so than imply otherwise.
No method of transmission or storage is completely secure. Please use a strong, unique password, don't share your credentials, and sign out on shared devices.
For legal review
The data-residency half has landed and is now stated in section 5: the application and database both run in an India region of Microsoft Azure. The encryption-at-rest half has NOT. The database is a self-hosted Postgres container on that VM, not a managed service, so there is no managed encryption at rest, no managed backup and nothing certified — the 'what we deliberately do not claim' callout above stays exactly as it is. Do not let 'we know where the data is' drift into 'the data is protected there'; those are separate claims and only the first is true today.
12. If there is a data breach
If a personal data breach occurs, we will notify affected users and, where required, the Data Protection Board of India. Where the breach affects data you hold as a Data Fiduciary — your customers' data — we will tell you without undue delay so that you can meet your own obligations.
For legal review
Please advise the exact notification deadlines and required content to publish here; we have deliberately not guessed them. Operationally this clause also needs an incident-response runbook and a way to identify which workspaces are affected, before it can be honoured.
13. Changes to this policy
We will update the version and date at the top of this page when this policy changes, and record the change in the version history below. If a change materially expands what we do with your data, we will tell you and, where required, ask for fresh consent.
14. Contact us
If you are not satisfied with how we handle your complaint, you may escalate it to the Data Protection Board of India.