Privacy Policy
This policy explains what data Billify collects, why it is collected, how it is stored, and your rights — including your right to permanently delete your account and all associated data.
Account & Business Information:
- Business name, GSTIN, address, and contact details
- Owner and staff names, mobile numbers, and login credentials
- Outlet names, locations, and operating configurations
- Tenant branding information (logo, colors, display name)
Transactional Data:
- Sales orders, invoices, and payment records (Cash / QR)
- Product names, SKUs, HSN codes, batch numbers, and stock levels
- Service records, customer names, and service completion status
- GST-applicable amounts per transaction (CGST, SGST breakdown)
Device & Technical Data (Mobile App):
- Device model and Android version
- App version and crash/error logs
- Camera usage for barcode scanning (not stored)
Data collected by Billify is used exclusively for the following purposes:
- Providing core POS and business management functionality
- Generating GST-compliant invoices and E-Receipts
- Enabling multi-outlet operations with isolated stock and sales data
- Delivering role-based access (Admin vs. Staff) to appropriate features
- Generating sales, service, payment, and stock reports
- Sending E-Receipts via WhatsApp or QR code sharing
- Improving platform reliability and performance through error tracking
All Billify data is stored on secured cloud servers. We implement the following security measures:
- All API communication encrypted via HTTPS/TLS
- Passwords stored as salted cryptographic hashes — never in plaintext
- Access tokens expire periodically and require re-authentication
- Server-side validation on all data inputs to prevent injection attacks
- Regular security audits and monitoring of backend infrastructure
Billify operates a multi-tenant model where each business ("tenant") has completely isolated data storage. This means:
- No business can access another business's data, staff, or records
- Outlet-level data is scoped within your business account only
- Tenant-specific branding (logo, name, color) is applied dynamically and stored separately
- Admin and Staff access is restricted within your own tenant boundary
The Billify Android application requests the following device permissions:
- Camera: Required for barcode/QR scanning during product lookup and stock entry. Images are not stored.
- Storage (Read/Write): Required for saving generated PDF receipts to device for WhatsApp sharing
- Internet: Required for all API communication with Billify servers
- Vibration: Used for barcode scan feedback (haptic)
No permission is requested beyond what is functionally necessary. You may revoke permissions through Android device settings; this may limit certain features.
Billify does not sell, trade, or rent your personal or business data. Data may be shared only in limited circumstances:
- Service Providers: Infrastructure providers (cloud hosting, CDN) who process data on our behalf under strict confidentiality agreements
- TinyURL API: Used on mobile to shorten E-Receipt share links; only the receipt URL is passed — no personal data
- WhatsApp Sharing: PDF receipts are shared via Android FileProvider; Billify does not access or store WhatsApp data
- Legal Requirements: We may disclose data if required by law, court order, or governmental authority in India
Billify generates digital E-Receipts that can be shared with customers. Please note:
- E-Receipts are accessible via a public URL hosted at
/api/receipt/public/{id} - Receipt links on mobile use TinyURL for shortened QR code sharing links
- Receipt data includes: business name, items purchased, GST breakdown, payment mode, and date
- Customer-facing receipt pages do not require login and are accessible by anyone with the link
- Contact support to deactivate a specific receipt link if required
The Billify web dashboard uses the following browser technologies:
- Session Cookies: Used to maintain your login session securely
- Local Storage: Used to cache outlet selections and user preferences for performance
- React Query Cache: Temporary in-memory cache for API responses; cleared on session end
Billify does not use third-party advertising cookies, tracking pixels, or analytics SDKs that share data externally. You may clear cookies through your browser settings; this will log you out of the dashboard.
Billify retains your data according to the following policy:
- Active account data is retained for as long as your subscription is active
- Transaction records are retained for a minimum of 7 years as required under Indian GST law
- After account termination, data is retained for 90 days before permanent deletion
- Deleted staff accounts are anonymized; their transaction records remain for audit purposes
- Backup copies may persist for up to 30 additional days after deletion
As a Billify user, you have the following rights regarding your personal and business data:
- Right to Access: Request a copy of all data Billify holds about your business
- Right to Correction: Request correction of inaccurate or outdated information
- Right to Deletion: Request permanent deletion of your account and all associated data (see Section 11)
- Right to Export: Download your business data in a portable format via the Admin dashboard
- Right to Restrict Processing: Request that we limit processing of your data in specific circumstances
To exercise any of these rights, contact us at nexlifylabs.dev@gmail.com. We will respond within 30 business days.
🗑️ Your Right to Delete
You have the right to request the deletion of your account and all associated personal data at any time. We are committed to processing your request promptly and transparently.
How to request account deletion:
🗑️ What Gets Deleted
- Your business profile and account credentials
- Staff accounts and role assignments
- Sales orders and transaction history
- Service records and customer data
- Product, batch, and stock data
- Outlet configurations and branding
- E-Receipts and generated invoices
- All personally identifiable information
📋 What May Be Retained
- Anonymised or aggregated data not linked to your identity
- Transaction records required under Indian GST law (up to 7 years)
- Backup copies for up to 30 days post-deletion
- Records required by court order or law enforcement
Billify is a B2B business management platform intended for use by adults operating retail businesses. We do not knowingly collect personal information from individuals under the age of 18.
If you believe a minor has provided us with personal information, please contact us immediately at nexlifylabs.dev@gmail.com and we will take steps to remove such information promptly.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make changes:
- The updated policy will be published within the app and on the web dashboard
- The "Last Updated" date at the top will be revised accordingly
- Significant changes will be communicated via in-app notification
- Continued use of Billify after updates constitutes acceptance of the revised policy
For privacy concerns, data requests, or grievances related to this policy, please reach out to our designated contact. We will respond within 30 business days.
Privacy Officer – Nexlify Labs
Krishnagiri, Tamil Nadu, India
Response time: within 30 business days