Privacy Policy
DRAFT. This document has not been reviewed by a lawyer and is awaiting the founder's approval. It is written to describe what Dukaaan actually does today, but it is not final, and its wording may change before it is.
Last updated: Draft — pending founder approval · legal position reviewed 1 September 2026
Dukaaan is billing software for Indian small businesses. This policy explains what we store, why, and how you get it back or have it deleted. It is written to the standard the Digital Personal Data Protection Act, 2023 sets — and the first section says plainly how much of that Act is actually switched on today, because most of it is not yet.
Which law applies, and from when
The Digital Personal Data Protection Act, 2023 is law, but it arrives in stages. The Government notified the Act's commencement and the Digital Personal Data Protection Rules, 2025 together on 14 November 2025, and set three dates. From that date: the Data Protection Board, the definitions, and the Government's own powers. From November 2026: the consent-manager provisions. From May 2027, eighteen months on: the duties this policy is mostly about — the notice we owe you, consent, your rights, security safeguards, breach reporting and erasure. Until that last date arrives, the older rules made under the Information Technology Act, 2000 are the ones that bind us. We have written to the newer standard now anyway, because your data is already here.
Who we are
Dukaaan is operated from India. For DPDP purposes we act as a Data Fiduciary for your account details, and as a Data Processor for the customer and supplier records you enter into your books. One person builds and runs it, and that person is also the one who answers questions about how your data is processed and who handles complaints about it. The address is printed at the foot of this page.
What we collect
Account details you give us: your name, email address and/or phone number, and your business name and GSTIN. Business data you enter: customers, suppliers, products, invoices, payments, expenses and stock. Technical logs: request timestamps, routes, response times and error traces, identified by account and business IDs only — never by name, phone number or invoice value. Once subscription billing is switched on, also the record of what you pay us: whether each payment succeeded, its amount and date, and the payment provider's reference for it.
Why we use it
To run the service you signed up for: creating and storing your invoices, computing GST, showing what your customers owe you, and producing your exports and reports. We do not sell your data, we do not use it to train models, and we do not show advertising.
The notice you are entitled to
When you create an account, one line beside the button asks for your consent and links here. This section is the notice behind that line, and it is meant to be readable on its own. Here is every item we ask for and what each one is for. Your name: so your account has a name on it and a reply from us is addressed to a person. Your email address and/or phone number: to sign you in, to send you the documents and reminders you ask us to send, and to reach you about your account. Your business name and GSTIN: to print them on the invoices, credit notes and other documents the law requires them on, and to work out the right tax. The customers, suppliers, products, invoices, payments, expenses and stock you enter: to keep the books you came here to keep, and to produce your GST returns, reports and exports from them. Files you attach to a record: to show them back to you against that record. Technical logs: to keep the service running and to find faults — they carry account and business IDs, never a name, a phone number or an invoice value. Once subscription billing is switched on, the record of what you pay us: to run your subscription, to account for what you paid, and to refund it if that is owed. That list is the whole of it: nothing here is collected for a purpose that is not named in it, and no purpose named in it is anything but running the service you are signing up to. We do not sell your data, we do not use it to train models, and we do not show advertising. You can withdraw your consent as easily as you gave it, from Settings → Privacy and data — the same screen you export and delete from. Withdrawing it ends your use of the service; the records GST law requires us to keep stay, and "How long we keep it" below says which and for how long. "Your rights" below says how to do everything else, and "Complaints" says how to raise one with us or with the Data Protection Board. From May 2027 the Act gives you the right to read this notice in English or in any language listed in the Eighth Schedule to the Constitution; ask for the one you want and we will send it.
Where it lives
Your business records — invoices, customers, payments, stock, expenses and everything else you enter — are stored in Google Cloud's Mumbai region (asia-south1). They are encrypted in transit and at rest, and backups are taken daily and held in the same region. Signing in is handled by Google's identity service, which stores your email address, phone number, password and sign-in metadata on servers outside India; it holds none of your business records.
Payments
We never see or store card, UPI or bank credentials. Payments you record in Dukaaan are just entries in your books, not money movement. Subscription billing is not switched on yet. When it is, paying for Dukaaan itself will go through Razorpay: you will enter your card or UPI details on Razorpay's own payment pages, not ours, and we will receive only what we need to run your subscription — whether a payment succeeded, its amount and date, and Razorpay's reference for it.
How long we keep it
Your books — invoices, credit notes, payments, stock movements and the accounting entries behind them — are kept for at least 8 years and are never deleted. GST law requires it: records must survive 72 months from the due date of that year's annual return, which works out at close to eight years for an invoice dated early in the year. Finalized documents cannot be edited or deleted by you or by us; corrections happen through credit notes and cancellations, which leave both the original and the correction on the record.
What does get deleted, and when
Files we can regenerate do not need keeping forever, so they expire. Exports, downloaded reports and list CSVs are removed after 90 days — press the button again and you get a fresh one. A file you upload for an import is removed after 30 days if you never complete the import. Older versions of a file you replaced go after 30 days. Anything you delete yourself — a customer, a product, a supplier — sits in your recycle bin for 30 days where you can restore it, and is then removed permanently, unless one of your documents still refers to it, in which case we keep it and tell you why. Files you attached to a record are never deleted.
Your rights, and how to use them
You can export everything you have entered, at any time, as CSV files in one ZIP, from Settings → Privacy and data. You can ask us to delete your account from the same screen; we act on it within 30 days, except for the records GST law requires us to retain for 8 years — which, for a business that has issued invoices, is most of the books. You can also ask us to correct your account details. If you cannot sign in, write to the address at the foot of this page from the email address your account uses, or quote the phone number it uses; that is what we need in order to find you. The Act also lets you nominate someone to exercise these rights for you. There is no screen for that yet — write to us and we will honour it.
If you do not have an account
Two things here take information from people who never signed up. The first is an invoice link. If a business sends you one, the page it opens is public — anyone holding the link can read that one invoice — and it carries a form for telling the seller you have paid. That form keeps the amount you say you sent, the date you say you sent it, and the note you write. The note is stored exactly as typed, so if a name or a payment reference is in it, that is because you put it there. Your IP address is turned into a one-way hash so the form cannot be flooded; the address itself is neither stored nor logged. The message goes to the seller, who checks their own bank. It never marks anything paid by itself, and we never write to you about it. On that data the seller is the Data Fiduciary and we are their Data Processor, so the decision to erase it is theirs and not ours. Ask them if you can — the invoice page carries their name, GSTIN and city, but no phone number or email address — and if you cannot reach them, write to us and we will relay your request to them. The second is the help button, on every public page. It asks for your name, your email address, a subject and your message so somebody can reply, and it records which page you were on, your browser's user-agent string, and the same one-way hash of your IP. A message sent from a public page is never attached to any business's account; a database rule refuses the write. For those messages we are the Data Fiduciary — write to the address at the foot of this page and we will delete yours.
Sharing
We share data only with the infrastructure providers that run the service (Google Cloud, for hosting, storage and sign-in). Once subscription billing is switched on, Razorpay will also process the payments you make to us, as described under Payments. We disclose data to authorities only where the law requires it.
If your data is ever breached
If personal data we hold is breached, we will tell the people affected — through their account, or the contact details they registered with us — without delay, and in plain words: what happened, what it means for them, what we have done about it, what they can do themselves, and who to write to. We will also report it to the Data Protection Board: an opening description without delay, and the detailed account within 72 hours. That is what Rule 7 of the DPDP Rules, 2025 sets out. Rule 7 does not bind us until May 2027, and we intend to work to it before then.
Complaints, and who answers them
Write to the address at the foot of this page about anything to do with your data: a request that has not been actioned, a correction, a deletion, or a complaint about how we handled one. It reaches a person and it needs no account — which matters, because an earlier version of this page named a link inside the app and printed no address at all, and a data request should never depend on being able to sign in. The rules that bind us today give us one month to resolve a grievance, and the DPDP Rules will allow ninety days; we do not intend to use either in full. Above us, the Act gives you a route to the Data Protection Board of India. The Board is established in law, but its Chairperson and Members were still being appointed when this page was written, and the provisions that let you take a complaint to it fall in the stage beginning May 2027. So bring it to us first. The grievance officer is Shubhankar Kalra, and the address at the foot of this page is the way to reach that officer; the contact page carries the same two details. A registered business address will be published there once the entity details are finalized.
Did this answer it?
If it did not, write to the person who built Dukaaan. You get a reply from someone who can change the product.
support@dukaaan.in