Legal ยท Privacy

Privacy Policy

We are committed to protecting your data. Here is exactly what we collect, how we use it, and the rights you have.

Last updated: May 2026ยทEffective: May 1, 2026
๐Ÿ”’

End-to-end encrypted

TLS 1.2+ & AES-256 at rest

๐Ÿ‡ฎ๐Ÿ‡ณ

Stored in India

MongoDB Atlas, Mumbai region

๐Ÿšซ

Never sold

Your data stays yours

๐Ÿ“…

7-year retention

As per CGST Act Section 36

GSTR-2B AI Reconciliation Platform (โ€œweโ€, โ€œusโ€, โ€œourโ€) is committed to protecting the privacy of our users. This policy explains what information we collect, how we use it, and your rights under the Information Technology Act 2000 and applicable Indian data protection regulations.

Section 1

Information We Collect

Account Information

When you register, we collect your name, email address, firm name, and password (stored as a secure hash). For client accounts we also collect GSTIN, business name, contact details, and GST registration information.

Financial & Tax Data

To perform reconciliation we process GSTR-2B data and Purchase Register data you upload. This includes invoice numbers, supplier GSTINs, taxable values, tax amounts, and ITC eligibility flags. This data is stored encrypted and is never shared with third parties.

Usage Data

We collect standard server logs (IP address, browser type, pages visited, timestamps) to operate and improve the platform. We do not use third-party analytics trackers.

Section 2

How We Use Your Information

Service Delivery

Your data is used solely to provide reconciliation reports, ITC risk analysis, and related features you have subscribed to.

Communication

We send transactional emails (OTP verification, invoice notifications, critical security alerts). We do not send marketing emails without your explicit consent.

Platform Improvement

Aggregated, anonymised usage patterns help us improve matching accuracy and add new features. No personally identifiable information is used for this purpose.

Section 3

Data Storage & Security

Infrastructure

All data is stored on MongoDB Atlas clusters hosted in India (Mumbai region) with encryption at rest and in transit (TLS 1.2+).

Access Controls

Access to production data is restricted to authorised personnel. Role-based access controls (CA, Staff, Client, Admin) ensure each user can only access their own data.

Retention

Reconciliation records are retained for 7 years in line with GST record-keeping requirements under Section 36 of the CGST Act. You may request deletion of your account data at any time, subject to statutory retention obligations.

Section 4

Data Sharing

No Third-Party Sales

We do not sell, rent, or trade your personal or financial data to any third party.

Service Providers

We use a limited number of sub-processors (cloud hosting, email delivery) who are contractually bound to protect your data and may not use it for any other purpose.

Legal Requirements

We may disclose data if required by applicable Indian law, court order, or government authority.

Section 5

Your Rights

Access & Correction

You may access and update your account information at any time from your profile settings.

Data Portability

You can export your reconciliation data as Excel or PDF reports at any time from the Reports section.

Account Deletion

To permanently delete your account and associated data, contact us at support@gstr2bai.in. Deletion is processed within 30 days, subject to statutory retention requirements.

Section 6

Cookies

Session Cookies

We use a single httpOnly session cookie to maintain your authenticated session. This cookie is essential for the platform to function and cannot be disabled while you are logged in.

No Tracking Cookies

We do not use advertising cookies, cross-site tracking cookies, or any third-party marketing cookies.

Section 7

Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or applicable law. We will notify registered users by email at least 14 days before material changes take effect. Continued use of the platform after the effective date constitutes acceptance of the updated policy.

Section 8

Contact Us

For privacy-related queries, data requests, or complaints, please contact our Data Protection Officer at: support@gstr2bai.in. We will respond within 72 hours.

Questions about your privacy?

Contact our Data Protection Officer โ€” we respond within 72 hours.

support@gstr2bai.in