Privacy Policy
Last updated: April 2, 2026
1. Introduction
BillRaja ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the BillRaja mobile application and website (collectively, the "Service").
2. Information We Collect
Account Information
- Your name, email address, and phone number (via Google Sign-In or phone verification)
- Firebase User ID (UID) and profile photo
Business Profile Data
- Business name, address, GSTIN, UPI ID, and bank details
- Business logo images
- Store GPS coordinates (when provided)
Business Records
- Customer data including GSTIN and contact details
- Invoice and financial data
- Product catalog and inventory records
- Purchase order information
Subscription & Payment
- Subscription plan and billing cycle information
- Payment status records (we do NOT store card numbers or UPI PINs)
- Razorpay transaction references
Usage & Device Data
- FCM (Firebase Cloud Messaging) push notification tokens
- App usage patterns for analytics (no personally identifiable analytics)
Location Data
- GPS location is collected only when you enable the Geo-Attendance feature for your team
- Location is used solely for geo-fenced attendance verification
Team & Collaboration Data
- Team member profiles and roles
- Attendance logs with timestamps
- Audit logs for business operations
3. How We Use Your Information
We use the collected information to:
- Provide, operate, and improve the BillRaja Service
- Generate and manage your GST-compliant invoices
- Process subscription payments via Razorpay
- Send transactional notifications (invoice reminders, overdue alerts)
- Authenticate your identity and secure your account
- Enable team collaboration features
- Provide customer support and respond to inquiries
- Comply with applicable Indian laws and regulations
We do not sell your personal information or business data to third parties. We do not use your data for advertising.
4. Data Storage & Security
All data is stored securely on Google Firebase (Firestore) servers. Firebase provides enterprise-grade security including:
- Encryption at rest and in transit (TLS/SSL)
- Strict Firestore security rules — you can only access your own data
- Firebase App Check to prevent unauthorized API access
- Google Cloud infrastructure with SOC 2, ISO 27001 compliance
The app supports 100 MB offline cache for uninterrupted use without internet. This data is stored locally on your device.
5. Data Sharing
We may share your information only in the following limited circumstances:
- Service providers: Firebase (Google), Razorpay for payment processing
- Legal requirements: When required by Indian law, court order, or government authority
- Business transfers: In the event of a merger or acquisition, with appropriate notice
Your customer data, invoice data, and business records are never shared with other BillRaja users or third parties for commercial purposes.
6. Data Retention
We retain your data for as long as your account remains active. If you delete your account, we will delete your personal data within 30 days, except where retention is required by law (e.g., GST records may need to be retained for audit purposes).
Business data (invoices, GST records) that may be subject to statutory retention requirements under Indian law may be retained for up to 7 years even after account deletion.
7. Your Rights
You have the right to:
- Access: Request a copy of your personal data
- Correction: Update inaccurate information in the app settings
- Deletion: Request account and data deletion (see Account Deletion page)
- Portability: Export your business data (available on Pro and Enterprise plans)
- Withdrawal of consent: Disable location access via device settings
8. Children's Privacy
BillRaja is not intended for persons under the age of 18. We do not knowingly collect personal information from children. If you are a parent and believe your child has provided us with personal information, please contact us immediately.
9. Third-Party Services
The Service integrates with the following third-party services, each governed by their own privacy policies:
- Google Firebase (authentication, database, analytics)
- Google Sign-In
- Razorpay (payment processing)
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via in-app notification. Continued use of the Service after changes constitutes acceptance of the updated policy.
11. Contact & Grievance
For privacy-related questions or complaints, contact our Grievance Officer: