Legal
Privacy Policy
Last updated: 31 July 2026
BillMate is a GST invoicing tool for Indian businesses. This policy explains what the service stores, why it stores it, and how you get it removed. It applies to the web application at https://tunirsaha.com/projects/billmate.
What We Collect
Account information. Your name, email address and password are collected when you sign up. Passwords are stored only as a one-way hash - they are never readable, by us or by anyone with a copy of the database. Sign-in issues a session token stored in your browser. Email verification, password reset and team invitation links are stored only as hashes, so a leaked copy cannot be replayed. Sign-in attempts are logged with a timestamp and IP address for a short period to rate-limit brute-force attacks.
Business data you enter. Everything you type into the app: business profile (name, address, GSTIN, PAN, state, bank account and IFSC, UPI ID), uploaded logo and signature images, your clients and their GSTINs and addresses, invoices, proforma invoices, payment receipts, saved line items, and the members you invite to a business. This is your accounting data. It is stored so the application can show it back to you and print it onto documents.
BillMate has no advertising and no third-party trackers. Anonymous usage analytics load only after you accept them on the cookie banner; decline and no analytics cookies are set. It does not read your contacts, location or device storage.
How We Use It
Data is used only to run the service you signed up for: authenticating you, keeping your businesses and documents, generating GST-compliant invoice numbers and tax splits, producing printable invoices, proforma invoices and receipts, sending verification, password-reset and team-invite emails, and protecting the service against abuse.
We do not sell your data and we do not share it for marketing. Two categories of provider necessarily process it on our behalf: the hosting provider that runs the server and database, and the mail service that delivers verification, reset and invite emails. Data is disclosed beyond that only where the law requires it.
Who Can See Your Data
Every request is scoped to the signed-in account. You see a business only if you own it or have been invited to it as a team member. Bank details, UPI details, signature and team management are restricted further, to the owner of the business alone. Removing a team member ends their access immediately.
Retention and Deletion
Your records are kept as long as your account is active, because they are accounting documents you are likely to need again. You can ask for your account and its data to be deleted at any time - see the Data Deletion page for how to request it and what is removed.
Some records may be retained after a deletion request where Indian tax or company law, an unresolved dispute, or fraud prevention requires it. Copies inside routine backups age out with the backup cycle rather than disappearing the same day.
Security
Traffic is served over HTTPS. Passwords are hashed with a per-password salt, and changing your password signs out every other session. Emailed tokens are stored hashed and expire. No system is perfectly secure, but if a breach affects your data we will tell you.
Your Choices
- Correct your name from the profile page, and your business or client details from their edit screens.
- Export your invoices, proforma invoices and receipts to CSV from the list screens at any time.
- Request deletion of your account and its data - see Data Deletion.
Changes
If this policy changes, the date at the top of this page changes with it. Continuing to use BillMate after that means you accept the updated policy.
Contact
Privacy questions: sahatunir@gmail.com.