Privacy Policy

InvoiceBhai Technologies Pvt Ltd · Effective date: 1 March 2026 · Compliant with the Digital Personal Data Protection Act, 2023 (DPDP Act)

1. Introduction

InvoiceBhai Technologies Pvt Ltd (CIN: U62099UP2026PTC245290), having its registered office at 1 Shivaji Marg, Hewett Road, Lucknow - 226018, Uttar Pradesh, India ("Company," "we," "us," "our"), is committed to protecting the privacy and personal data of individuals who use the InvoiceBhai platform ("Service").

This Privacy Policy explains how we collect, use, store, share, and protect your personal data and business information in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000 (IT Act), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules), and other applicable Indian laws.

Data Fiduciary: InvoiceBhai Technologies Pvt Ltd acts as a Data Fiduciary under the DPDP Act with respect to the personal data processed through the Service.

2. Data We Collect

2.1 Information You Provide Directly

  • Business Information: Trade name, legal entity name, GSTIN, PAN, business address, state of registration, bank details, and nature of business.
  • Contact Information: Mobile phone number (WhatsApp), email address, and name of the authorised representative.
  • Transaction Data: Invoice details including client names, addresses, GSTINs, descriptions of goods/services, HSN/SAC codes, quantities, unit prices, tax rates, and amounts.
  • Payment Information: Subscription and payment transaction records. We do not store credit/debit card numbers or UPI PINs; payments are processed by third-party gateways.

2.2 Information Collected Automatically

  • Usage Data: Frequency and patterns of Service usage, features accessed, invoices generated, and interaction timestamps.
  • Device and Technical Data: Device type, operating system, WhatsApp version, IP address (where applicable), and unique device identifiers.
  • Log Data: Server logs recording API calls, errors, and system events for operational and diagnostic purposes.

2.3 Information from Third Parties

We may receive information from WhatsApp (Meta Platforms) as part of the WhatsApp Business API, including message delivery status and user profile information made publicly available on WhatsApp.

3. Purpose of Data Processing

Under Section 4 of the DPDP Act, we process your personal data only for lawful purposes for which you have given consent or which are deemed legitimate. Specifically, we process your data for the following purposes:

  • To provide, operate, and maintain the InvoiceBhai Service, including generating GST-compliant invoices based on your instructions.
  • To create and manage your account on the platform.
  • To process payments, subscriptions, and billing.
  • To communicate with you regarding service updates, new features, support requests, and transactional notifications.
  • To comply with legal obligations, including record-keeping requirements under GST law, the IT Act, and other applicable regulations.
  • To detect and prevent fraud, unauthorised access, and misuse of the Service.
  • To improve, personalise, and optimise the Service through aggregated and anonymised analytics.
  • To respond to legal requests from government authorities and law enforcement, where required by law.

5. Data Sharing and Disclosure

We do not sell your personal data. We may share your data with the following categories of recipients:

  • Service Providers: Third-party vendors who assist in operating the Service, including WhatsApp/Meta (messaging infrastructure), payment gateway providers (Razorpay, Cashfree, or similar), cloud hosting providers, and analytics services. These providers are bound by contractual obligations to protect your data.
  • Professional Advisors: Auditors, legal counsel, and accountants as necessary for business operations and compliance.
  • Government Authorities: GST authorities, tax departments, law enforcement agencies, or other government bodies when required by law, regulation, legal process, or enforceable governmental request.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, subject to this Privacy Policy.

We require all third parties to whom we disclose data to implement appropriate security measures and to process data only in accordance with our instructions and applicable law.

6. Data Storage and Retention

Your data is stored on secure servers located in India. We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law.

  • Active Account Data: Retained for the duration of your account and active subscription.
  • Invoice Records: Retained for a minimum period as required under GST law (currently 6 years from the due date of filing the Annual Return for the relevant year) and the Income Tax Act, 1961.
  • Post-Termination: Upon account termination, we retain data for 90 days to allow for account recovery. After this period, data is deleted or anonymised, except where longer retention is required by law.
  • Anonymised/Aggregated Data: Data that has been irreversibly anonymised may be retained indefinitely for analytical and product improvement purposes.

7. Data Principal Rights (Under DPDP Act)

As a Data Principal under the DPDP Act, you have the following rights:

  • Right to Access (Section 11): You have the right to obtain a summary of your personal data being processed by us and the processing activities undertaken.
  • Right to Correction and Erasure (Section 12): You have the right to request correction of inaccurate or misleading personal data, completion of incomplete data, and erasure of personal data that is no longer necessary for the purpose for which it was processed.
  • Right to Grievance Redressal (Section 13): You have the right to have your grievances addressed by our Grievance Officer within the timelines specified by law.
  • Right to Nominate (Section 14): You have the right to nominate another individual who may exercise your rights in the event of your death or incapacity.

To exercise any of these rights, please contact our Grievance Officer at help@invoicebhai.com or call +91 63877 68346. We will respond to your request within 30 days.

8. Data Security

We implement appropriate technical and organisational security measures to protect your personal data, including:

  • Encryption of data in transit (TLS/SSL) and at rest.
  • Access controls limiting data access to authorised personnel on a need-to-know basis.
  • Regular security assessments and vulnerability testing.
  • Secure software development practices.
  • Incident response procedures for data breaches.

In the event of a personal data breach that is likely to cause harm to you, we will notify you and the Data Protection Board of India as required under Section 8 of the DPDP Act.

9. Cross-Border Data Transfer

Your personal data is primarily stored and processed in India. If any data is transferred outside India, such transfers will only be made to countries or territories permitted by the Central Government under Section 16 of the DPDP Act, and we will ensure appropriate safeguards are in place.

10. Children's Data

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly. Under Section 9 of the DPDP Act, processing of children's data requires verifiable consent from a parent or guardian.

11. Cookies and Tracking

Our website (if applicable) may use cookies and similar technologies. Please refer to our separate Cookie Policy for detailed information.

13. Grievance Officer

In compliance with the IT Act, SPDI Rules, and the DPDP Act, we have appointed a Grievance Officer:

  • Name: Husain Kazim
  • Designation: Grievance Officer
  • Email: help@invoicebhai.com
  • Phone: +91 63877 68346
  • Address: 1 Shivaji Marg, Hewett Road, Lucknow - 226018, Uttar Pradesh, India

The Grievance Officer shall acknowledge your complaint within 24 hours and resolve it within 15 days from the date of receipt, or within such timeframe as prescribed by applicable law.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Material changes will be communicated to you via WhatsApp, email, or a prominent notice on our website (www.invoicebhai.com) at least 15 days before they take effect.

Your continued use of the Service after the updated Privacy Policy takes effect constitutes your acceptance of the changes.

15. Contact Us

InvoiceBhai Technologies Pvt Ltd

Registered Address: 1 Shivaji Marg, Hewett Road, Lucknow - 226018, Uttar Pradesh, India

Email: help@invoicebhai.com

Phone: +91 63877 68346

Website: www.invoicebhai.com