Legal
Privacy Policy
Effective 12 Aug 2026 · Last updated 12 Aug 2026
MeriRaseed holds a business's books. This explains exactly what we collect, why we need it, who else it reaches, and what you can ask us to do with it.
This policy explains how [registered entity name] (“we”, “us”), which operates MeriRaseed at meriraseed.online, handles personal data. It is written to meet the Digital Personal Data Protection Act, 2023 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
Two kinds of data, and two different roles
MeriRaseed sits in an unusual position, and the distinction matters for your rights and for your own obligations:
- Your data. Information about you and your business — your name, email, mobile number, GSTIN. For this we are the Data Fiduciary: we decide why and how it is processed, and this policy governs it.
- Your customers' data. The parties you bill — their names, phone numbers, addresses and GSTINs — which you enter and control. For this you are the Data Fiduciary and we are your Data Processor: we hold and process it on your instructions, and we do not use it for our own purposes.
What we collect
When you create an account
- Your name, email address and Google account identifier, received from Google when you sign in.
- Your mobile number, and the date and time you verified it.
- Your chosen language.
- The IP address from which a one-time code was requested, kept as an anti-abuse measure.
About your business
- Business name, address, and the state you supply from.
- Whether you are registered under GST, and your GSTIN if you are.
- Your UPI ID, if you choose to print a payment QR on your receipts.
The records you create
- Items, with their names in each language you enter, HSN or SAC codes and prices.
- Parties you bill or buy from, including their name, mobile number, email, GSTIN and address.
- Invoices, credit and debit notes, payments and ledger entries.
- Delivery records — which channel an invoice was sent on, and whether it arrived.
Technical and audit records
- An append-only audit log of significant actions — who did what, and when. It exists so that you can see changes to your own books, and because tax records must be traceable. It cannot be edited or deleted, by you or by us.
- Ordinary server logs: request times, error traces, and the pages that produced them.
What we do not collect
- No bank or card details. A UPI ID is a public payment address, not a credential. We never see your bank login, card number or UPI PIN.
- No Google data beyond name and email. We do not request access to your Gmail, Drive, Contacts or Calendar, and could not read them if we wanted to.
- No location tracking. We do not collect GPS or device location.
- No advertising profiles. We do not sell personal data, and we do not share it with advertising networks or data brokers. There is no third-party ad or analytics tracker on our pages.
Why we process it, and on what basis
| Purpose | Data used | Basis |
|---|---|---|
| Creating and securing your account | Name, email, Google id, mobile, IP | Consent; performance of our agreement with you |
| Verifying your mobile number | Mobile number, one-time code | Consent |
| Producing GST-correct invoices | Business details, items, parties, invoices | Performance of our agreement; legal obligation |
| Delivering invoices you ask us to send | Party mobile or email, invoice and PDF | Your instruction, as your processor |
| Keeping an audit trail | Action, actor, timestamp | Legal obligation; legitimate use |
| Preventing abuse of one-time codes | Mobile number, IP, send counts | Legitimate use |
| Support you ask us for | Whatever the issue concerns | Consent |
We do not use your business records to train machine-learning models, and we do not read them except when you ask us to help with a specific problem, or where we are legally compelled to.
Sign in with Google
We ask Google for three things only: your basic profile, your email address, and an identifier that lets us recognise you next time. We use them to create your account and to address you by name. We do not ask for, receive or store any other Google user data, and we do not transfer Google user data to anyone except the infrastructure providers listed below who store it on our behalf.
You can disconnect MeriRaseed from your Google account at any time from your Google account permissions page. Doing so stops future sign-ins; it does not by itself delete the records already in your books.
Who else sees it
We share personal data only with the service providers we need to run MeriRaseed. Each one is bound by contract to process it only on our instructions. The full current list, with what each receives, is on our sub-processors page.
Beyond those providers, we disclose personal data only:
- when you tell us to — for example, by sending an invoice to a customer on WhatsApp;
- when a law, a court, or a lawful order of a government authority requires it;
- to establish, exercise or defend a legal claim; or
- to a buyer, if the business is sold — in which case this policy continues to apply until you are given notice of any change.
We never sell personal data.
Where it is stored
Your books — accounts, parties, invoices and PDFs — are stored in India, in Amazon Web Services' Mumbai region. Two of our providers process limited data outside India: Google, for sign-in, and Meta, for WhatsApp delivery. In both cases the data involved is narrow (your name and email for Google; a recipient's mobile number and the invoice details for WhatsApp) and is transferred under those providers' own contractual safeguards.
How long we keep it
- Tax records — 72 months. Invoices, ledger entries and the parties they refer to are retained for 72 months from the due date of the annual return for the relevant year, because section 36 of the CGST Act, 2017 requires it. We cannot delete them earlier, even at your request.
- One-time codes — 30 days. Only the hash of a code is ever stored, and the record is purged after 30 days.
- Audit log — 365 days.
- Closed accounts — 30 days. If you close your account we delete your personal profile after 30 days, keeping only what the retention rule above obliges us to keep. Export your data before you close it.
Your rights
Under the DPDP Act, 2023 you may:
- Ask what we hold — a summary of your personal data and who it has been shared with.
- Correct it — most fields you can edit yourself; write to us for the rest.
- Erase it — subject to the tax-record retention above.
- Withdraw consent — as easily as you gave it. Withdrawing consent to phone verification means you can no longer sign in.
- Nominate someone — to exercise your rights if you die or become incapacitated.
- Complain — to our Grievance Officer, and then to the Data Protection Board of India if we do not resolve it.
Write to contact@meriraseed.online from your registered email address. We will respond within 15 days.
How we protect it
- All traffic is encrypted in transit over TLS.
- One-time codes are stored only as hashes — nobody, including us, can read a code back out.
- Access tokens for connected services are encrypted at rest.
- Every business's records are isolated at the database query layer, and that isolation fails closed: if the system cannot establish which business a request belongs to, it returns nothing rather than everything. This is enforced by automated tests that run on every change.
- Within a business, access is role-based. A cashier's screen is never sent purchase prices or margins — the data is removed before it leaves the server, not merely hidden in the browser.
- Sensitive actions require re-verification by one-time code.
No system is perfectly secure. If a breach affects your personal data we will notify you and the Data Protection Board of India as the law requires.
Cookies
We set two cookies, both strictly necessary: one to keep you signed in, and one to protect forms against cross-site request forgery. We do not use advertising, profiling or third-party analytics cookies, so there is nothing here for you to opt out of.
Children
MeriRaseed is for running a business and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, write to us and we will delete it.
Changes to this policy
If we change this policy we will update the date at the top of this page. For changes that materially affect your rights we will also notify you by email or in the app before they take effect.
Contact
[registered entity name]
[registered address]
Pune, Maharashtra, India
Privacy enquiries: contact@meriraseed.online
Grievance Officer: [officer name]
,
contact@meriraseed.online
Questions about this document? Write to contact@meriraseed.online, or see our grievance redressal process.