Privacy Policy & Data Security
How OpenBill Pro collects, encrypts, and protects your business and customer information in compliance with Indian IT Rules and the DPDP Act 2023.
1. Commitment to Business Confidentiality
OpenBill Pro (an initiative by OpenSoz) is deeply committed to protecting the privacy, commercial confidentiality, and data sovereignty of Indian shop owners, MSMEs, and their respective customers. This Privacy Policy outlines our data governance standards under the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection (DPDP) Act, 2023.
2. Information We Collect & Why
We collect only the essential information strictly necessary to deliver billing, tax calculation, and automated messaging capabilities:
Registered business name, proprietor name, mobile number, verified email address, shop physical address, GSTIN (optional), and UPI ID used to generate customer payment QR codes.
Item descriptions, HSN/SAC codes, quantities, rates, tax calculations (SGST, CGST, IGST), payment status (Draft, Paid, Overdue), and unique invoice sequence numbers.
Customer contact names and mobile numbers inputted by you strictly for dispatching requested invoice PDF attachments and ledger balance notifications.
Session tokens, IP address, device telemetry, and authentication timestamps recorded to detect malicious intrusion and protect against brute-force attacks.
3. Absolute Zero-Monetization & No-Sale Guarantee
We never sell, rent, monetize, or trade your data. Your trade turnover metrics, customer directory, invoice line items, and financial summaries belong solely to you. OpenBill Pro does not syndicate your customer contacts to third-party telemarketers, credit card issuers, lending agents, or advertising networks.
4. Bank-Grade Cryptography & Cloud Infrastructure
- 256-Bit TLS 1.3 In-Flight Encryption: All communications between your mobile device or web browser and our cloud servers are encrypted using modern Transport Layer Security standards.
- Salted Cryptographic Hashing: Passwords, verification OTPs, and authentication keys are salted and hashed using bcrypt and SHA-256 algorithms. They are never recorded or visible in plain text.
- Encrypted Daily Cloud Backups: Database snapshots are captured and stored in geographically redundant, encrypted enterprise vaults with point-in-time recovery capabilities.
5. Data Sovereignty & 7-Day Account Deletion Grace Period
You maintain full sovereignty over your digital records. You may export your entire billing archive as GSTR-1 JSON or CSV spreadsheets at any time. If you wish to delete your account, you can initiate a permanent account purge from Shop Settings > Delete Account:
- Your account enters an automatic 7-Day Safety Grace Period during which you can instantly cancel the deletion request if initiated accidentally.
- Upon expiry of the 7-day period, all shop profiles, invoice records, customer ledger entries, and stored documents are permanently and irrecoverably purged from our live production databases.
6. Statutory Grievance Redressal & Data Protection Officer
In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the DPDP Act 2023, if you have any questions, concerns, or grievances regarding your personal data or this Privacy Policy, you may contact our designated Grievance Officer: