OpenBill Pro
🛡️ Open Privacy Charter • DPDP Act 2023 Compliant

Privacy Policy & Data Protection Charter

Formulated by the OpenBill Pro Open-Source Platform Initiative • Protecting Indian Merchants

An Open-Source Initiative You Can Trust

Unlike proprietary corporate billing softwares that quietly track user behavior and sell merchant trade insights, OpenBill Pro is built on open modern web standards. Our architecture is transparent, privacy-centric by design, and contains zero advertising spyware.

1. Scope of Privacy Protection

This Privacy Charter governs the processing of merchant and transaction data by the OpenBill Pro platform. We adhere strictly to the Information Technology Act, 2000, the IT Rules 2011 (Reasonable Security Practices), and the Digital Personal Data Protection (DPDP) Act, 2023 of the Republic of India.

2. Categorization of Data Collected

We collect only the bare essential technical data required to render invoices and execute payment settlement:

  • Merchant Profile: Shop Name, Proprietor Name, Registered Mobile Number, Verified Email Address, Shop Physical Address, State, and GSTIN.
  • UPI Settlement VPA: Your Shop UPI ID (e.g. `shop@okhdfcbank`) used exclusively to generate scannable dynamic UPI QR codes. We do not store or ask for net-banking passwords, UPI PINs, or debit card CVVs.
  • Invoice Ledger Data: Serial numbers, line item names, HSN/SAC codes, quantities, prices, CGST, SGST, IGST calculations, and payment status (Paid, Unpaid, Draft).
  • Customer Khata Ledger: Customer contact names and numbers provided by you solely for invoice dispatch and balance tracking.

3. Absolute Zero Data Monetization Pledge

🛡️ 100% Anti-Monetization & Privacy Guarantee:

As an open platform initiative, we have zero corporate incentive to exploit merchant data:

  • We NEVER sell, rent, license, or trade your shop records, billing amounts, or customer contacts to advertising networks, third-party data brokers, or commercial syndicates.
  • We NEVER share your customer phone numbers with unauthorized marketing agencies or telemarketers.
  • Your financial turnover, sales metrics, and customer ledgers remain your confidential, proprietary asset.

4. Bank-Grade Encryption & Cloud Architecture

All data transmitted between your device and our hosted servers is encrypted using 256-bit TLS 1.3 encryption. Passwords and authentication OTPs are hashed using salted cryptographic algorithms (bcrypt and SHA-256). All database records are hosted on enterprise cloud servers located in the Mumbai, India (ap-south-1) region, ensuring full Indian data residency compliance.

5. Data Retention & 7-Day Purge Grace Period

If you initiate account termination through Shop Settings, your account enters a mandatory 7-Day Grace Period. During this window, you may restore your account with 1-click. After 7 days, our automated purge engine executes a permanent cascade deletion of your profile, invoices, customer khata, and associated notification logs.

6. Grievance Redressal Desk

In accordance with the Information Technology Rules, 2021, queries or grievances regarding data privacy can be directed to our designated Grievance Desk at grievance@openbillpro.in. Formal grievances are acknowledged within 24 hours.