Privacy Policy
This Privacy Policy explains how Invoral ("we", "us", "our"), a sole proprietorship based in Chennai, Tamil Nadu, India, collects, uses, stores, and protects your information when you use our invoicing application at invoral.com (the "Service"). By using the Service, you agree to this policy. This policy complies with applicable Indian data-protection law, including the Digital Personal Data Protection Act, 2023 (DPDP Act).
1. Information we collect
| Category | What we collect |
|---|---|
| Account information | Your name, email address, and a securely hashed password. |
| Business profile | Business name, address, GSTIN, PAN, phone, email, logo, signature, seal, and bank/UPI payment details you choose to add. |
| Client data | The clients you create — name, email, phone, address, GSTIN, PAN. Sensitive fields are encrypted at rest (see Section 5). |
| Invoice & document data | Invoices, proformas, and quotations you create, including line items, amounts, tax details, and discounts. |
| Technical data | Login token and theme preference stored in your browser's local storage. We do not use third-party analytics or tracking cookies. |
We do not collect data beyond what is necessary to operate the Service.
2. How we use your information
- To provide the Service — create and store your invoices, generate PDFs and payment QR codes, and show your dashboard.
- To authenticate you and keep your account secure (passwords hashed with bcrypt, sessions verified via JWT).
- To send transactional emails — such as password-reset codes — from admin@invoral.com.
- To improve the Service — understand usage patterns (aggregate, not individual) to fix bugs and plan features.
3. Legal basis for processing
Under the DPDP Act and applicable law, we process your data on the following bases:
- Consent — you provide consent when you create an account and agree to these policies.
- Contract performance — processing necessary to provide the Service you signed up for.
- Legitimate interest — securing the Service, preventing fraud, and improving functionality.
- Legal obligation — where required by Indian law (e.g., data retention, responding to lawful requests).
4. Your clients' data
Invoices contain information about your clients that you enter. You are the data fiduciary (controller) of that data; we process it on your behalf solely to provide the Service. You are responsible for:
- Having a lawful basis to store and process your clients' information.
- Informing your clients about how their data is used.
- Responding to your clients' data access or deletion requests relating to data you hold about them.
5. How we store & protect data
- Passwords are hashed with bcrypt and never stored in plain text.
- Sessions use signed tokens (JWT); every request is verified against your account.
- Client sensitive fields (email, phone, address, GSTIN, PAN) are encrypted at rest using AES-256.
- Data isolation — you can only access records that belong to your account; strict per-user scoping is enforced at the database query level.
- Parameterized queries prevent SQL injection.
- Admin access to user management is protected by a separate admin authentication with a two-password system for account deletions.
No method of transmission or storage is 100% secure, but we take reasonable technical and organisational measures to protect your data.
6. Cookies & local storage
Invoral does not use cookies. We use your browser's localStorage to store:
- Your authentication token (to keep you signed in).
- Your theme preference (light/dark).
These are essential for the Service to function and are not used for tracking or advertising. No data from localStorage is sent to third parties.
7. Third-party services
We use a limited number of third-party services:
- Email delivery (SMTP provider) — to send transactional emails such as password-reset codes. Only your email address and the message content are shared with the email provider.
- Razorpay — for subscription payment processing (when subscriptions are enabled). Razorpay receives payment information you provide at checkout under their own privacy policy and PCI-DSS compliance.
- UPI QR codes — generated locally from your UPI ID so your clients can pay you directly. No data is sent to a third party for QR generation.
We do not use Google Analytics, Facebook Pixel, or any third-party tracking or advertising services.
8. Data retention & deletion
We keep your data for as long as your account is active. You can:
- Delete individual clients and draft invoices within the app.
- Request full deletion of your account and all associated data by emailing admin@invoral.com.
Upon account deletion, all your data (business profile, clients, invoices, documents) is permanently removed from our database. We may retain minimal data where required by law (e.g., tax records, legal obligations).
9. Your rights
Under the DPDP Act and applicable law, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — request correction of inaccurate or incomplete data.
- Erasure — request deletion of your personal data (subject to legal retention requirements).
- Withdraw consent — withdraw your consent to data processing at any time (which may require account closure).
- Grievance redressal — file a complaint with us or, if unresolved, with the Data Protection Board of India.
To exercise any of these rights, contact us at admin@invoral.com. We will respond within a reasonable time as required by law.
10. Children
The Service is intended for businesses and professionals and is not directed to individuals under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with their data, please contact us for removal.
11. Data breach notification
In the event of a personal data breach that is likely to cause harm, we will:
- Notify the Data Protection Board of India as required under the DPDP Act.
- Notify affected users by email within a reasonable time, describing the nature of the breach and the steps we are taking.
12. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date at the top of this page. For significant changes, we will notify you by reasonable means (e.g., in-app notification or email). Continued use of the Service after changes take effect constitutes acceptance.
13. Contact & grievance officer
For any questions, privacy requests, or grievances under this policy or applicable IT rules:
Invoral
Email: admin@invoral.com
We aim to acknowledge grievances within a reasonable time as required by law. If your grievance is not resolved satisfactorily, you may approach the Data Protection Board of India.