What we collect, why we collect it, and the control you have over it.
What we collect
Account details — your name, email address, business name, GSTIN, state and the IP address you signed up from. We need these to create your account, isolate your data and issue compliant invoices.
Business data you enter — customers, products, invoices, payments and the settings around them. This is yours; we hold it to run the Service for you.
Payment information — when you buy a plan you are redirected to our payment partner. Card, UPI and bank details go to them directly and never reach or get stored on our servers. We keep only the order reference, the amount and whether it succeeded.
Technical logs — request logs and error traces, kept briefly, to keep the platform secure and working.
What we do not do
We do not sell your data. We do not share it with advertisers. We do not use your customer list or invoices to market anything to anyone.
Data you hold about others
Your customers' names, addresses and GSTINs belong to you, not to us. We process them on your instructions, only to provide the Service. You are responsible for having a lawful basis to hold them, and for what you send to your customers using the Service.
How your data is separated
The platform is multi-tenant: every record carries a company identifier, and every database query is scoped to the signed-in account at the framework level. One business cannot read another's data — not through the app, not through the API.
AI processing
If you use an AI feature, the specific content needed for that request — for example the photograph of a bill, or a summary of your figures — is sent to the AI provider configured by the platform operator to generate the answer. Nothing is sent automatically: an AI request only happens when you ask for one.
We do not send your full customer list or complete ledger. AI requests are not used to train third-party models where the provider offers that setting, and the platform operator can switch AI off entirely, or run a self-hosted model so that nothing leaves the server.
Who else sees it
We share data only with the service providers needed to run the Service:
- Payment gateway — to process plan purchases.
- Email provider — to send invoices, reminders and account emails you trigger.
- Hosting provider — where the application and database run.
- AI provider — only for the specific requests described above.
Each of these receives only what is required to do its job. We may also disclose data where the law requires it.
Security
Passwords are stored hashed, never in plain text. Sessions use bearer tokens with server-side revocation. Sign-in is rate limited and locks out after repeated failures. Uploaded files are stored outside the web-readable application directory. We recommend running the Service over HTTPS.
No system is perfectly secure, but we take this seriously and fix reported issues quickly.
How long we keep it
Your data is kept for as long as your account exists. If you close your account we delete your business data, other than records we must keep to meet legal or tax obligations. You can export everything as CSV before you go.
Your rights
You can:
- See and correct your data, from inside the app;
- Export your customers, products and invoices as CSV at any time;
- Ask for deletion of your account and its data;
- Object to any processing you think is unfair.
Write to help@simpliweb.in and we will act on it.
Cookies and local storage
We store your login session and display preferences in your browser. These are necessary for the app to work — there are no advertising or third-party tracking cookies.
Changes
If this policy changes we will update this page and the "last updated" date, and tell account holders about anything material.
Please note: this is a good-faith starting template, not legal advice. Add your registered entity details and have it reviewed before going live.