Your Privacy Matters

Privacy Policy

This policy explains what data Billify collects, why it is collected, how it is stored, and your rights — including your right to permanently delete your account and all associated data.

Android App
Web Dashboard
IT Act 2000 Compliant
📅 Effective Date: June 15, 2026  |  Last Updated: June 15, 2026  |  Version: 1.0
🤖 Android Mobile App 🌐 Web Dashboard
1
Information We Collect

Account & Business Information:

  • Business name, GSTIN, address, and contact details
  • Owner and staff names, mobile numbers, and login credentials
  • Outlet names, locations, and operating configurations
  • Tenant branding information (logo, colors, display name)

Transactional Data:

  • Sales orders, invoices, and payment records (Cash / QR)
  • Product names, SKUs, HSN codes, batch numbers, and stock levels
  • Service records, customer names, and service completion status
  • GST-applicable amounts per transaction (CGST, SGST breakdown)

Device & Technical Data (Mobile App):

  • Device model and Android version
  • App version and crash/error logs
  • Camera usage for barcode scanning (not stored)
2
How We Use Your Data

Data collected by Billify is used exclusively for the following purposes:

  • Providing core POS and business management functionality
  • Generating GST-compliant invoices and E-Receipts
  • Enabling multi-outlet operations with isolated stock and sales data
  • Delivering role-based access (Admin vs. Staff) to appropriate features
  • Generating sales, service, payment, and stock reports
  • Sending E-Receipts via WhatsApp or QR code sharing
  • Improving platform reliability and performance through error tracking
Billify does not use your data for advertising, profiling, or any purpose outside direct business service delivery.
3
Data Storage & Security

All Billify data is stored on secured cloud servers. We implement the following security measures:

  • All API communication encrypted via HTTPS/TLS
  • Passwords stored as salted cryptographic hashes — never in plaintext
  • Access tokens expire periodically and require re-authentication
  • Server-side validation on all data inputs to prevent injection attacks
  • Regular security audits and monitoring of backend infrastructure
⚠️ While Billify applies industry-standard security practices, no digital system can guarantee absolute security. Users are advised to use strong, unique passwords and report any suspicious activity immediately.
4
Multi-Tenant Architecture

Billify operates a multi-tenant model where each business ("tenant") has completely isolated data storage. This means:

  • No business can access another business's data, staff, or records
  • Outlet-level data is scoped within your business account only
  • Tenant-specific branding (logo, name, color) is applied dynamically and stored separately
  • Admin and Staff access is restricted within your own tenant boundary
5
App Permissions (Mobile)

The Billify Android application requests the following device permissions:

  • Camera: Required for barcode/QR scanning during product lookup and stock entry. Images are not stored.
  • Storage (Read/Write): Required for saving generated PDF receipts to device for WhatsApp sharing
  • Internet: Required for all API communication with Billify servers
  • Vibration: Used for barcode scan feedback (haptic)

No permission is requested beyond what is functionally necessary. You may revoke permissions through Android device settings; this may limit certain features.

6
Data Sharing

Billify does not sell, trade, or rent your personal or business data. Data may be shared only in limited circumstances:

  • Service Providers: Infrastructure providers (cloud hosting, CDN) who process data on our behalf under strict confidentiality agreements
  • TinyURL API: Used on mobile to shorten E-Receipt share links; only the receipt URL is passed — no personal data
  • WhatsApp Sharing: PDF receipts are shared via Android FileProvider; Billify does not access or store WhatsApp data
  • Legal Requirements: We may disclose data if required by law, court order, or governmental authority in India
7
E-Receipts & QR Sharing

Billify generates digital E-Receipts that can be shared with customers. Please note:

  • E-Receipts are accessible via a public URL hosted at /api/receipt/public/{id}
  • Receipt links on mobile use TinyURL for shortened QR code sharing links
  • Receipt data includes: business name, items purchased, GST breakdown, payment mode, and date
  • Customer-facing receipt pages do not require login and are accessible by anyone with the link
  • Contact support to deactivate a specific receipt link if required
Share receipt links only with intended customers. Anyone with the receipt link can view the bill details.
8
Cookies & Web Storage

The Billify web dashboard uses the following browser technologies:

  • Session Cookies: Used to maintain your login session securely
  • Local Storage: Used to cache outlet selections and user preferences for performance
  • React Query Cache: Temporary in-memory cache for API responses; cleared on session end

Billify does not use third-party advertising cookies, tracking pixels, or analytics SDKs that share data externally. You may clear cookies through your browser settings; this will log you out of the dashboard.

9
Data Retention

Billify retains your data according to the following policy:

  • Active account data is retained for as long as your subscription is active
  • Transaction records are retained for a minimum of 7 years as required under Indian GST law
  • After account termination, data is retained for 90 days before permanent deletion
  • Deleted staff accounts are anonymized; their transaction records remain for audit purposes
  • Backup copies may persist for up to 30 additional days after deletion
10
Your Rights

As a Billify user, you have the following rights regarding your personal and business data:

  • Right to Access: Request a copy of all data Billify holds about your business
  • Right to Correction: Request correction of inaccurate or outdated information
  • Right to Deletion: Request permanent deletion of your account and all associated data (see Section 11)
  • Right to Export: Download your business data in a portable format via the Admin dashboard
  • Right to Restrict Processing: Request that we limit processing of your data in specific circumstances

To exercise any of these rights, contact us at nexlifylabs.dev@gmail.com. We will respond within 30 business days.

12
Children's Privacy

Billify is a B2B business management platform intended for use by adults operating retail businesses. We do not knowingly collect personal information from individuals under the age of 18.

If you believe a minor has provided us with personal information, please contact us immediately at nexlifylabs.dev@gmail.com and we will take steps to remove such information promptly.

13
Policy Changes

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make changes:

  • The updated policy will be published within the app and on the web dashboard
  • The "Last Updated" date at the top will be revised accordingly
  • Significant changes will be communicated via in-app notification
  • Continued use of Billify after updates constitutes acceptance of the revised policy
14
Contact & Grievance Officer

For privacy concerns, data requests, or grievances related to this policy, please reach out to our designated contact. We will respond within 30 business days.

Privacy Officer – Nexlify Labs

Krishnagiri, Tamil Nadu, India

Response time: within 30 business days