RReceipto
Privacy Policy.
Last updated: 26 September 2026
Receipto ("we") helps shop owners run their stores. Your business data is the heart of the app, so here is exactly what we collect, why, and what we never touch.
1. What we collect
- Account details: your name, email address and/or mobile number, and login credentials (passwords are stored only as one-way hashes — we cannot read them).
- Shop profile: shop name, address, GSTIN, UPI ID, and billing preferences you enter.
- Business data you create: products, bills, customers, suppliers, purchases, expenses, coupons, khata/ledger entries, staff accounts, and audit logs.
- Subscription records: plan, status, and payment references from Razorpay.
- Technical data: basic device and error logs needed to keep the service running.
2. What we never collect
- Your UPI PIN, bank passwords, or card details — card/UPI payments are processed entirely by Razorpay on their secure pages.
- Money you receive through the billing QR goes directly to your own UPI ID; it never passes through us.
- Website tracking cookies — our public website only counts anonymous visits and button taps (no cookies, no IP addresses stored, no advertising profiles).
3. Why we use your data
- To run the Service: syncing your shop's data across your devices and keeping it available.
- Automatic server backups of active shops for disaster recovery.
- Subscription billing, receipts, and support.
- We do not sell your data, and we do not use your business data for advertising.
4. Where your data lives
Data is stored on your device (for offline use) and on our secured PostgreSQL database. Payment processing is handled by Razorpay under their own privacy policy.
5. Sharing
We share data only with the providers needed to run the Service, and only what each needs. These are currently:
- Render — hosts our servers.
- Neon — hosts our PostgreSQL database.
- Razorpay — processes subscription payments (card/UPI details go to Razorpay directly, never to us).
- Cloudflare Turnstile — bot protection on login/signup.
- Gmail (Google) — delivers transactional emails like password resets.
- Brevo / Resend — backup email delivery, used only if Gmail delivery fails.
- Google Sign-In — lets you log in with your Google account (only your verified name and email are received).
- Google Gemini — identifies products from photos you choose to scan (the photo is sent to Google's AI service only when you use this feature).
- OpenStreetMap Nominatim & BigDataCloud — turn your location coordinates into a readable address when you use the "use my location" feature.
- OpenFoodFacts — looks up product names from barcodes using this open product database.
We disclose data to authorities only when required by law.
6. Your rights
- Export: download a full backup of your shop anytime from Settings.
- Correct: edit your profile and records directly in the app.
- Delete: delete your shop and all its data yourself from Settings → Danger Zone → "Delete my shop" (owner only), or write to receipto.support@gmail.com from your registered email/phone and we will delete your account and shop data (backups age out within our retention window).
7. Security
We use encrypted connections (HTTPS), hashed passwords, per-shop data isolation, and role-based access (staff cannot reach owner-only areas). No system is perfect — if you suspect a breach, tell us immediately at the address above.
8. Children
Receipto is a business tool and is not intended for children under 18.
9. Changes
We may update this policy; material changes will be announced in the app. Continued use means you accept the updated policy.
10. Contact
Rahul Kumar
Abadganj, Mission School Road, Near Shiv Temple, Daltonganj, 822101
Questions about privacy: receipto.support@gmail.com.
11. Grievance Officer (DPDP Act, 2023)
Under India's Digital Personal Data Protection Act, 2023, you can contact our Grievance Officer about how your personal data is handled:
Name: Rahul Kumar
Email: rahulkumaryadav7090@gmail.com
We will acknowledge your grievance within the timelines required by law.