Last updated · 1 May 2026
Privacy Policy
This is the plain-English version. The legal-language version is available on request. If the two ever conflict, the plain-English version is what we intended.
Who we are
TatvaBooks is a product of Tatva Fintech Private Limited, an Indian private limited company with CIN U66190PN2025PTC250051, registered at Office No. 1, Mayfair Towers - II, Shivajinagar, Pune 411005, Maharashtra, India.
Our Data Protection Officer (DPO) can be reached at support@tatvabooks.com.
What we collect
Account data
- Your name, email, phone number, and password (hashed).
- Business name, GSTIN, PAN, address.
- Billing address and payment method (we store only the last 4 digits of cards; the full card lives with our PCI-DSS Level 1 payment processor).
Business data
- The books, invoices, vendor bills, expenses, payroll and tax filings that you create or upload in TatvaBooks.
- Documents you attach to transactions (invoices, receipts, contracts).
- Bank statements you connect via account aggregator or upload.
Usage data
- Pages you visit, features you use, errors you encounter.
- Device, browser, IP address (for security and rate-limiting).
- Email opens and link clicks for emails we send you.
How we use it
- To run the product.Your books, your tax filings, your payroll — TatvaBooks couldn't exist if we didn't process this data.
- To bill you. Subscription invoices, payment reconciliation.
- To support you. When you write to us, we look up your account to help you faster.
- To improve the product. Aggregate, anonymous usage statistics. Never identifiable to an individual or business.
- To comply with law. GST law, Companies Act and Income Tax law all require us to keep certain records.
What we don't do
- Sell your data. Ever. To anyone. For any reason. This is in our Articles of Association.
- Read your books for marketing.Your invoices, vendors, P&L — we don't mine them for ads, partnerships, or lead generation.
- Send your data outside India. All TatvaBooks data is hosted in India (AWS Mumbai, with hot standby in AWS Hyderabad). We comply with the DPDP Act 2023 by default.
Who sees your data inside TatvaBooks
Almost no one. Our engineering team does not have direct access to your books. Production access requires four levels of approval, MFA, a recorded session, and a documented reason — typically a support ticket where you've asked us to look at something specific. Access is logged in an immutable audit trail you can request.
Sub-processors
We use a small number of trusted vendors to run TatvaBooks. As of this writing:
- AWS (Mumbai + Hyderabad) — infrastructure hosting.
- Razorpay / Cashfree — subscription payments.
- Postmark / SES — transactional email.
- Karix / MSG91 — SMS and WhatsApp.
- NIC IRP, GSTN, MCA21, TRACES — government systems for filings.
A complete, current list is at our DPA, section 4. Any new sub-processor will be announced with 30 days' notice via email.
Your rights under the DPDP Act 2023
You have the right to:
- Access the personal data we hold about you.
- Correct any inaccurate or incomplete data.
- Erase your data (subject to legal retention requirements — e.g., GST records must be kept for 6 years).
- Withdraw consent for processing not required by law.
- Nominate a person to exercise rights on your behalf.
- File a grievance with our DPO or the Data Protection Board of India.
To exercise any of these, email support@tatvabooks.com. We respond within 7 working days, in line with the DPDP Act's requirement.
Cookies
TatvaBooks uses essential cookies (to keep you logged in) and a small number of analytics cookies (to understand which features are used, anonymously). No advertising or tracking cookies. Details in our Cookie Notice.
Data retention
We keep your books for as long as your account is active, plus 90 days after closure (to allow accidental-closure recovery). After that, books are permanently deleted, except for records we're legally required to retain (GST: 6 years; ITR: 7 years; PF/ESI: 7 years).
Children
TatvaBooks is not intended for use by anyone under 18. We do not knowingly collect data about minors.
Changes to this policy
We'll email account holders at least 30 days before any material change. The current version is always at this URL, with a "last updated" date at the top.
Contact
Questions? support@tatvabooks.com. Complaints? Same address — your complaint will be acknowledged within 24 hours and addressed within 7 working days.