Privacy Policy
Last Updated: February 22, 2026 · Effective: February 22, 2026
InvoiceCheck.in ("we", "our", or "us") is committed to protecting the privacy of businesses and individuals who use our GST invoice validation service. This Privacy Policy explains what data we collect, how we use it, and the choices you have.
1. Information We Collect
1a. Data You Enter
When you validate an invoice, you provide invoice details such as GSTIN, invoice number, date, line items, tax amounts, HSN/SAC codes, and Place of Supply. This information is used solely to perform the GST compliance check.
1b. Account Information
If you create an account, we collect your email address and, optionally, your name and business GSTIN. Passwords are never stored in plain text — we use Supabase Auth (which follows bcrypt hashing standards).
1c. Payment Information
Payments are processed by Razorpay. We do not store your card number, CVV, or bank credentials on our servers. Razorpay provides us with a transaction ID and payment status only.
1d. Usage and Analytics
We collect anonymous usage data (pages visited, features used) to improve the product. This data cannot be used to identify you individually. We also collect UTM parameters and referral codes to attribute traffic sources.
1e. Technical Data
Standard server logs include your IP address, browser type, and timestamps. These are retained for security and debugging purposes for up to 90 days.
2. How We Use Your Data
- To perform GST invoice validation and generate the compliance report.
- To process payments and issue receipts via Razorpay.
- To send transactional emails (payment confirmation, report delivery).
- To send filing deadline reminders if you have opted in.
- To improve our 15-rule validation engine based on aggregated, anonymised data.
- To detect fraud, abuse, or misuse of the service.
We do not use your invoice data to train AI/ML models.
3. Data Retention
- Guest users: Invoice input data is cached for up to 1 hour for idempotency (to prevent duplicate charges) and then permanently deleted.
- Registered users: Validation results are stored in your dashboard history for as long as your account is active. You can delete individual checks or your entire account at any time from Settings.
- Payment records: Required by law to be retained for 7 years under Indian accounting regulations.
4. Data Sharing
We do not sell, rent, or trade your personal information. We share data only with the following trusted sub-processors:
- Supabase — database and authentication (servers in AWS ap-south-1, India)
- Razorpay — payment processing (RBI-regulated)
- Resend / Nodemailer — transactional email delivery
- Vercel — application hosting
We may disclose data if required by Indian law (e.g., a valid court order or regulatory direction from GSTN/CBIC).
5. Cookies
We use strict-necessity cookies for session authentication and a localStorage key (gst_free_checks_used) to track your free check usage. We do not use third-party advertising cookies.
6. Security
All data is transmitted over HTTPS (TLS 1.3). Database access is protected by Row Level Security (Supabase RLS policies) so users can only access their own data. We undergo periodic security reviews.
7. Your Rights
Under India's Digital Personal Data Protection Act, 2023 (DPDPA), you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate personal data.
- Request erasure of your data (right to be forgotten).
- Withdraw consent at any time.
- Nominate a representative in the event of your death or incapacity.
To exercise any of these rights, email us at privacy@invoicecheck.in. We will respond within 30 days.
8. Children's Privacy
Our service is intended for businesses and is not directed at individuals under 18. We do not knowingly collect data from minors.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via email (for registered users) or a notice on the website at least 7 days before they take effect.
10. Contact Us
If you have any questions about this Privacy Policy, please contact us:
- Email: privacy@invoicecheck.in
- Website: invoicecheck.in/contact