Privacy Policy
This Privacy Policy describes how Paper Billing (“we”, “us”, “our”) collects, uses, stores, and shares personal data when you use our website and application (the “Service”). It is intended for users in India and is drafted with reference to the Digital Personal Data Protection Act, 2023 (DPDP Act).
1. Who we are
Paper Billing is a multi-tenant software product that helps organizations manage product forms, stock, suppliers, buyers, and invoices. We host the Service and store data you and your organization submit on our servers (including backups and object storage).
2. Roles under data protection law
- Your organization (shop) typically decides why supplier, buyer, and related identity data is collected for its business. For that data, the organization is generally the Data Fiduciary.
- We process that organization data on their behalf as a Data Processor when providing the Service, and we are a Data Fiduciary for account data of people who sign up for Paper Billing (for example username, email, and login activity).
3. Personal data we collect
Depending on how the Service is used, we may process:
- Account data: name/username, email, password (hashed), organization membership and role.
- Organization profile data: business name, contact details, address, logo, government ID details if you enter them in settings.
- Supplier / seller data submitted via share links or product records: name, business name, phone, email, address, government ID type/number, and ID card images.
- Customer data on invoices or buy requests: similar contact and identity fields when required.
- Product and transaction data: SKUs, IMEI, prices, invoice contents, and related uploads (images/videos).
- Technical data: basic logs, device/browser information, and analytics events if enabled (for example PostHog), needed to run and secure the Service.
4. Why we process personal data
- To create and manage accounts and organizations.
- To provide templates, stock, sales, invoices, share links, and related features.
- To store submissions and files so the requesting organization can review and use them.
- To secure the Service, prevent abuse, and comply with law.
- To improve reliability of the product (aggregated or technical diagnostics).
We process account data with your consent and/or as needed to provide the Service you request. Organization-collected supplier/buyer data is processed to deliver the Service to that organization and under that organization’s instructions and purposes.
5. Public forms and share links
When you submit a supplier form or buy request through a public link, you are sending personal data to the named organization via Paper Billing. We store that submission so the organization can review it. Please only submit information you are comfortable sharing with that organization for the stated purpose.
6. Government ID and Aadhaar-related information
Some workflows ask for government ID type, number, and/or an image of an ID document (which may include Aadhaar, Voter ID, or PAN). This information is sensitive.
- It should be collected only when needed for the organization’s stated purpose (for example verifying a party on a sale or stock intake).
- We store it securely with the organization’s records and do not sell it.
- We do not use it to perform UIDAI Aadhaar authentication unless we expressly say so and are authorized to do so.
- Organizations should prefer the minimum identity information necessary and avoid collecting full Aadhaar details when another ID will do.
7. Sharing
We may share personal data with:
- The organization that owns the workspace / requested the form submission.
- Infrastructure providers that host the Service (for example cloud compute, object storage, and backups), under contractual safeguards.
- Authorities when required by applicable law.
We do not sell personal data.
8. Retention
We retain personal data while your organization account is active and as needed to provide the Service, resolve disputes, and meet legal obligations. Organizations may delete or ask us to delete records they control through the product (where available) or by contacting us. Backups may persist for a limited period after deletion.
9. Security
We use reasonable technical and organizational measures appropriate to the nature of the data, including access controls, encrypted transit where configured, and restricted access to production systems. No method of transmission or storage is completely secure.
10. Your rights
Subject to the DPDP Act and applicable rules, individuals may have rights to access, correct, and erase personal data, and to withdraw consent where processing is based on consent. If your data was submitted for an organization (for example as a supplier), contact that organization first; you may also contact us and we will help route the request.
11. Children
The Service is intended for business use by adults. Do not submit personal data of children under 18 unless you are a lawful guardian and the collection is permitted by law.
12. Changes
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change. Continued use of the Service after updates constitutes notice of the revised policy where permitted by law.
13. Contact
For privacy questions or requests related to Paper Billing, contact the organization that runs your workspace, or reach us through the contact channel published on the Service / your deployment operator.