Privacy Policy

Last updated:
1 October 2026
Policy version:
2026-10-01
Effective:
1 October 2026

1. Who we are and what this covers

BolHisab is provided by [LEGAL ENTITY NAME], [REGISTERED ADDRESS] (“BolHisab”, “we”, “us”). This Privacy Policy explains how we collect and use personal data when you use the BolHisab app, the CA Partner portal, the client portal, our website and the free tools.

We have two roles. For your own account data (your name, email, sign-in and billing) we decide why and how it is processed. For the business records you keep in BolHisab — including details of your customers, suppliers and staff — your business decides the purpose and we process that data on its behalf. Questions from your customers about their data should go to you first; we will help you respond. See also our DPDP Act notice.

2. Information we collect

Information you give us

  • Account details: your name, email address and password (stored only as a one-way hash), the business name you sign up with, your language preference, and two-factor settings if you enable them.
  • Business information: business name, legal name, address, state, GSTIN, PAN where you enter it, financial year, invoice settings, bank account names and the branches and team members you add.
  • Customers, suppliers and products: names, phone numbers, email and postal addresses, GSTINs and balances you record, and product details such as HSN/SAC codes and prices.
  • Accounting records: sales, purchases, expenses, receipts, payments, invoices, credit and debit notes, journals, inventory movements, GST data and the reports derived from them.
  • Uploaded documents: photos and PDFs of bills and receipts, bank statements (CSV/Excel), Tally and CSV import files, and documents uploaded to a CA firm's vault or the client portal.
  • Voice and text inputs: commands you type or speak to the assistant, voice recordings sent for transcription, and recent chat turns kept so the assistant understands follow-ups.
  • Support and requests: messages you send to support, privacy requests and grievances.

Information collected automatically

  • Security and device data: IP address and browser/user-agent recorded with sign-ins, sessions and audit-log entries; the time of each action.
  • Usage data: counts of AI commands, voice minutes and documents read, with timings and error codes, to enforce plan limits and keep the Service reliable. On the free tools we record which tool was used and whether it completed, with a random browser identifier — never the contents of your files.

Payment information

Subscription payments are made through Razorpay Checkout. Card, UPI and bank details are entered with Razorpay and are not received or stored by BolHisab. We receive the order and payment reference, amount and status.

We do not use third-party advertising or analytics trackers. See the Cookie Policy.

3. Why we use it

  • To provide the Service: keeping your books, creating invoices, calculating GST, producing reports, reconciling bank statements and running the CA and client portals.
  • To process documents and inputs you submit, including with AI providers (section 4).
  • To create and secure your account: verification, sign-in, two-factor authentication, fraud and abuse prevention, rate limiting and audit trails.
  • To bill for paid plans and enforce plan limits.
  • To send service emails you need: verification, password reset, invitations, security notices, receipts of requests, and the reminders and summaries you turn on.
  • To provide support and respond to privacy requests and grievances.
  • To improve reliability, using aggregated usage and error data, where permitted by law.
  • To send product updates and marketing — only if you opt in, and you can opt out at any time.
  • To comply with law, respond to lawful requests from authorities, and establish or defend legal claims.

4. AI processing

When you use AI features, the relevant input is sent to an AI provider configured for the Service (currently listed on our Subprocessors page) to produce a result:

  • Voice: your recording is sent for transcription; reply text may be sent for read-aloud audio.
  • Text commands: what you type, with recent turns of the conversation, is sent so the assistant can understand it.
  • Documents: bill and receipt images or PDFs you ask to be read are sent to a vision model.
  • Replies and summaries: finished reply sentences may be sent for translation into your language; CA summaries send the computed facts (figures and names) to be phrased.
  • Free AI tools: the uploaded document, or for spreadsheet tools only short descriptions with account numbers and similar identifiers removed.

Figures, balances and GST are calculated by our own software, not by the AI, and AI output is checked before it is shown. Nothing is posted to your books without your confirmation. Providers process data under their own terms and policies; we choose provider settings intended to limit use of submitted data, but we do not make claims about a provider's practices beyond what its published terms state. If no AI provider is configured for a feature, it falls back to built-in rules or manual entry and nothing is sent.

5. Uploaded documents

  • Why: to read a bill into a draft purchase or expense, import data, reconcile a bank statement, or share documents with your CA.
  • Who processes them: our servers and our hosting provider; for automatic reading, the configured AI provider receives the document.
  • Storage and security: files are checked by content, stored privately and only served to signed-in users with permission. Files in a CA firm's vault are encrypted at rest. Free tool uploads are processed in memory and not stored.
  • Retention and deletion: a bill stays with your business until you discard it; deleting it removes the stored file while keeping the accounting record. Copies may remain in backups for a limited period.

6. Who we share it with

  • Service providers (subprocessors): hosting, email, payments and AI providers listed on the Subprocessors page, each only for its stated purpose.
  • People you authorise: team members, your CA firm (only after the business owner approves access) and clients you invite to the client portal.
  • BolHisab staff: for support, a BolHisab administrator can enter a business only through a time-limited support session, which is logged.
  • Authorities: where required by law or a valid legal process.
  • Business transfers: if BolHisab is reorganised, merged or sold, subject to this Policy.

We do not sell personal data.

7. Transfers outside India

Some of our providers, including AI providers, may process data outside India. Where we transfer personal data outside India we do so in accordance with applicable Indian law, including any restrictions notified under the Digital Personal Data Protection Act, 2023. Provider locations are listed on the Subprocessors page where we have verified them.

8. How long we keep it

  • Account and business data: while your account is active.
  • Accounting records: businesses are often required to keep books for several years (for example under GST law). We keep your records while your account is active and, after closure, for as long as needed to meet legal obligations or resolve disputes, then delete or anonymise them.
  • Uploaded documents: until you delete them or your account is closed, subject to the above.
  • Security and audit logs: retained to protect the Service and to provide an audit trail; audit logs cannot be edited.
  • Backups: deleted data may persist in backups maintained by our hosting provider until they are overwritten in the normal cycle.
  • Free tools: uploaded files are not stored; usage events contain no file contents.

9. Your rights and choices

Subject to applicable law, you can ask for a summary of your personal data and how it is processed, ask us to correct, complete or update it, ask us to erase it where it is no longer needed and we are not required to keep it, withdraw consent where processing is based on consent, nominate another person to exercise your rights in the event of death or incapacity, and raise a grievance.

Signed-in users can do this from Settings → Privacy & data, which also shows your consent history and lets you change your marketing preference. You can also write to [email protected]. We may need to verify your identity. If your data was entered by a business (for example you are its customer), please contact that business; we will assist it.

Withdrawing consent does not affect processing already carried out, and withdrawing consent to these terms means we can no longer provide the Service to you.

10. Security

We use technical and organisational measures appropriate to accounting data, described on our Security page. No system is completely secure; if a breach affecting your personal data occurs, we will notify you and authorities as required by law.

11. Children

The Service is meant for businesses and professionals and is not directed at children. Accounts may not be created by anyone under 18.

12. Changes

We will post updates to this Policy here with a new version and effective date. For material changes, signed-in users are asked to review and accept the new version in the app.

13. Contact and grievances

Privacy questions: [email protected]. Grievance Officer: [GRIEVANCE OFFICER], [email protected]. See Grievance Redressal.