We are committed to protecting your data. Here is exactly what we collect, how we use it, and the rights you have.
End-to-end encrypted
TLS 1.2+ & AES-256 at rest
Stored in India
MongoDB Atlas, Mumbai region
Never sold
Your data stays yours
7-year retention
As per CGST Act Section 36
GSTR-2B AI Reconciliation Platform (โweโ, โusโ, โourโ) is committed to protecting the privacy of our users. This policy explains what information we collect, how we use it, and your rights under the Information Technology Act 2000 and applicable Indian data protection regulations.
Section 1
Account Information
When you register, we collect your name, email address, firm name, and password (stored as a secure hash). For client accounts we also collect GSTIN, business name, contact details, and GST registration information.
Financial & Tax Data
To perform reconciliation we process GSTR-2B data and Purchase Register data you upload. This includes invoice numbers, supplier GSTINs, taxable values, tax amounts, and ITC eligibility flags. This data is stored encrypted and is never shared with third parties.
Usage Data
We collect standard server logs (IP address, browser type, pages visited, timestamps) to operate and improve the platform. We do not use third-party analytics trackers.
Section 2
Service Delivery
Your data is used solely to provide reconciliation reports, ITC risk analysis, and related features you have subscribed to.
Communication
We send transactional emails (OTP verification, invoice notifications, critical security alerts). We do not send marketing emails without your explicit consent.
Platform Improvement
Aggregated, anonymised usage patterns help us improve matching accuracy and add new features. No personally identifiable information is used for this purpose.
Section 3
Infrastructure
All data is stored on MongoDB Atlas clusters hosted in India (Mumbai region) with encryption at rest and in transit (TLS 1.2+).
Access Controls
Access to production data is restricted to authorised personnel. Role-based access controls (CA, Staff, Client, Admin) ensure each user can only access their own data.
Retention
Reconciliation records are retained for 7 years in line with GST record-keeping requirements under Section 36 of the CGST Act. You may request deletion of your account data at any time, subject to statutory retention obligations.
Section 5
Access & Correction
You may access and update your account information at any time from your profile settings.
Data Portability
You can export your reconciliation data as Excel or PDF reports at any time from the Reports section.
Account Deletion
To permanently delete your account and associated data, contact us at support@gstr2bai.in. Deletion is processed within 30 days, subject to statutory retention requirements.
Section 7
We may update this Privacy Policy to reflect changes in our practices or applicable law. We will notify registered users by email at least 14 days before material changes take effect. Continued use of the platform after the effective date constitutes acceptance of the updated policy.
Section 8
For privacy-related queries, data requests, or complaints, please contact our Data Protection Officer at: support@gstr2bai.in. We will respond within 72 hours.
Questions about your privacy?
Contact our Data Protection Officer โ we respond within 72 hours.