Privacy & Cookie Policy
Last Updated: January 2025
Your privacy is important to us. This policy explains how InvoiceKaro collects, uses, and protects your personal and business information.
1. Introduction
FINALDOC TECHNOLOGIES PRIVATE LIMITED ("we", "us", "our") is committed to protecting your privacy. This Privacy & Cookie Policy explains how we collect, use, disclose, and safeguard your information when you use InvoiceKaro, our GST billing and invoicing platform.
This policy applies to information collected through our website, mobile application, and any related services (collectively, the "Service"). By using InvoiceKaro, you consent to the practices described in this policy.
2. Information We Collect
We collect information that you provide directly and information collected automatically:
Information You Provide:
• Account Information: Name, email address, phone number, business name, GSTIN
• Business Information: Address, bank details, business type, industry
• Financial Data: Invoice details, customer information, payment records, transaction history
• Profile Information: Logo, digital signature, preferences
• Communication: Support requests, feedback, correspondence
Automatically Collected Information:
• Device Information: Device type, operating system, browser type
• Usage Data: Features used, pages visited, time spent, actions taken
• Log Data: IP address, access times, referring URLs
• Location Data: General location based on IP address (not precise GPS)
3. How We Use Your Information
We use collected information for the following purposes:
Service Delivery:
• Create and manage your account
• Process invoices and financial transactions
• Generate GST-compliant reports and documents
• Provide customer support and respond to inquiries
Service Improvement:
• Analyze usage patterns to improve features
• Develop new functionality based on user needs
• Fix bugs and optimize performance
• Conduct research and analytics
Communication:
• Send transactional emails (invoices, receipts, alerts)
• Provide important service updates and announcements
• Send marketing communications (with your consent)
• Respond to your requests and inquiries
Legal and Security:
• Comply with legal obligations and regulations
• Enforce our Terms and Conditions
• Prevent fraud, abuse, and security threats
• Protect our rights and the rights of our users
4. Data Storage and Security
Data Storage:
• Your data is stored on secure cloud servers located in India
• We use industry-standard encryption for data in transit (TLS 1.3) and at rest (AES-256)
• Regular backups are performed to prevent data loss
• Data is retained as long as your account is active or as required by law
Security Measures:
• Multi-factor authentication options
• Regular security audits and vulnerability assessments
• Access controls and employee training
• Intrusion detection and monitoring systems
• Secure development practices
While we implement robust security measures, no system is completely secure. We encourage you to use strong passwords and protect your account credentials.
5. Data Sharing and Disclosure
We do not sell your personal or business data. We may share information in these circumstances:
Service Providers:
• Cloud hosting and infrastructure providers
• Payment processors for subscription billing
• Email and communication services
• Analytics and monitoring tools
All service providers are bound by confidentiality agreements and data protection requirements.
Legal Requirements:
• Compliance with court orders, subpoenas, or legal process
• Response to government or regulatory requests
• Protection of our legal rights and enforcement of our terms
• Investigation of potential violations or fraud
Business Transfers:
• In the event of a merger, acquisition, or sale of assets
• We will notify you of any such change and your options
With Your Consent:
• When you explicitly authorize sharing
• Integration with third-party services you connect
6. Your Rights and Choices
You have the following rights regarding your data:
Access and Portability:
• View your personal information in account settings
• Export your data in standard formats (PDF, Excel, CSV)
• Request a copy of all data we hold about you
Correction and Update:
• Update your account information at any time
• Request correction of inaccurate data
• Modify your preferences and settings
Deletion:
• Delete specific invoices or customer records
• Request account deletion (subject to legal retention requirements)
• We will delete or anonymize data within 30 days of verified request
Communication Preferences:
• Opt out of marketing emails
• Manage notification preferences
• Transactional communications cannot be opted out
To exercise these rights, contact us at privacy@invoicekaro.com or through your account settings.
7. Cookie Policy
We use cookies and similar technologies to enhance your experience:
Essential Cookies:
• Session management and authentication
• Security and fraud prevention
• Load balancing and performance
• These cannot be disabled as they are necessary for the Service
Functional Cookies:
• Remember your preferences and settings
• Language and regional preferences
• Previously entered information
Analytics Cookies:
• Understand how users interact with the Service
• Identify popular features and areas for improvement
• Track performance metrics
• We use Google Analytics with IP anonymization
Marketing Cookies (optional):
• Deliver relevant advertisements
• Measure ad campaign effectiveness
• These require your consent
Managing Cookies:
• Browser settings allow you to block or delete cookies
• Some features may not function properly without cookies
• You can withdraw cookie consent at any time through settings
8. Third-Party Services
InvoiceKaro may integrate with third-party services:
Payment Processors:
• Razorpay for payment processing
• Subject to Razorpay's privacy policy
Cloud Services:
• AWS/Google Cloud for infrastructure
• Industry-standard security certifications
Analytics:
• Google Analytics for usage insights
• Data is anonymized and aggregated
Communication:
• Email delivery services
• SMS notification providers
These third parties have their own privacy policies. We encourage you to review them. We only share data necessary for the specific service and require confidentiality agreements.
9. Data Retention
We retain your data based on the following criteria:
Active Accounts:
• Account data retained while your account is active
• Financial records retained for 8 years (as per Indian tax laws)
• Invoice data retained indefinitely unless you delete it
Deleted Accounts:
• Personal data deleted within 30 days of account deletion
• Financial records may be retained for legal compliance
• Anonymized data may be retained for analytics
Legal Requirements:
• GST records: Minimum 6 years from the end of the relevant financial year
• Tax-related documents: As per Income Tax Act requirements
• Dispute-related data: Until resolution plus statute of limitations
10. Children's Privacy
InvoiceKaro is designed for business use and is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.
If we become aware that we have collected data from a child under 18, we will take steps to delete such information promptly. If you believe a child has provided us with personal information, please contact us immediately.
11. International Users
InvoiceKaro is primarily designed for businesses operating in India. If you access the Service from outside India:
• Your data will be transferred to and processed in India
• Indian data protection laws will apply
• By using the Service, you consent to this transfer
• We implement appropriate safeguards for international data transfers
We comply with applicable Indian data protection regulations, including the Information Technology Act, 2000 and related rules.
12. Changes to This Policy
We may update this Privacy & Cookie Policy periodically. When we make changes:
• We will update the "Last Updated" date at the top
• Material changes will be notified via email or in-app notification
• Continued use after changes constitutes acceptance
• Previous versions will be archived and available upon request
We encourage you to review this policy regularly to stay informed about our data practices.
13. Grievance Officer
In accordance with Information Technology Act, 2000 and rules made thereunder, the contact details of the Grievance Officer are provided below:
Grievance Officer: Privacy Team
Email: grievance@invoicekaro.com
Phone: +91-8093712301
Address:
FINALDOC TECHNOLOGIES PRIVATE LIMITED
Bangalore, Karnataka, India
We will acknowledge your grievance within 48 hours and aim to resolve it within 30 days.
14. Contact Us
For privacy-related questions, concerns, or requests:
Email: privacy@invoicekaro.com
General Support: support@invoicekaro.com
Phone: +91-8093712301
Mailing Address:
FINALDOC TECHNOLOGIES PRIVATE LIMITED
Attn: Privacy Team
Bangalore, Karnataka, India
Business Hours: Monday to Saturday, 9:00 AM to 6:00 PM IST
We take your privacy seriously and will respond to all inquiries within 5 business days.
By using InvoiceKaro, you acknowledge that you have read and understood this Privacy & Cookie Policy.