This Privacy Policy explains how Ketpy Book (operated by Ketpy) collects, uses, stores, and protects information when you use our invoicing & accounting SaaS platform at ketpybook.com (the "Service").
1. Information we collect
- Account & identity: name, email, mobile number, business name, GSTIN, PAN, state, address.
- Business data: customers, vendors, items, invoices, bills, payments, accounting entries you create inside the Service.
- Payment metadata: Razorpay subscription IDs, payment success/failure events. We never see or store your card / UPI / bank credentials.
- Telemetry: IP address, browser, device type, page paths visited, login timestamps — for security & product improvement only.
- Cookies: a session cookie, a remember-me cookie if you opt in, a CSRF token, and a dark-mode preference. No third-party advertising cookies. See Cookie Policy.
2. How we use your information
- To provide the Service — render your books, generate PDFs, send invoices, file GST returns.
- To send transactional emails (OTPs, payment receipts, reminders) and operational notices.
- To detect & prevent abuse (rate limiting, audit logs, suspicious-login alerts).
- To improve the product (aggregated, de-identified usage trends only).
We do not sell your data, share it with advertisers, or use it for behavioural ad targeting.
3. Where your data lives
All production data is stored in India (Hostinger Mumbai region). Daily encrypted backups are retained for 14 days, also in-region. Sub-processors are limited to: Razorpay (payments), Hostinger (hosting + email relay), and AWS Mumbai (object storage for attachments only).
4. Your rights under the DPDP Act 2023
- Right to access: see what data we hold about you. Use Settings → Data export.
- Right to correction: edit any of your business profile / accounting data inline.
- Right to erasure: request account closure + data deletion at team@ketpy.com. Honoured within 30 days, subject to legal retention obligations (audit, GST records — 7 years).
- Right to grievance redressal: contact our Data Protection Officer at team@ketpy.com. Response within 7 working days.
- Right to nominate: as per DPDP §14, you can nominate someone to exercise your rights in case of incapacity.
5. Retention
Active accounts: data retained while the subscription is alive. After cancellation: 90 days for restoration, then anonymised. Audit logs & financial records retained 7 years per GST & Companies Act requirements.
6. Security
AES-256 encryption at rest, TLS 1.3 in transit, daily backups, role-based access, audit log of every privileged action. Read more on the security page.
7. Children
Ketpy Book is not directed at users under 18. We do not knowingly collect data from minors.
8. Changes to this policy
Material changes are notified via in-app banner and email at least 30 days in advance. The "Last updated" date above always reflects the most recent revision.