BillMadi

Privacy Policy

In effect from 21 September 2026. This is version 1.0.

This policy explains what BillMadi collects, why we hold it, where it is kept and how you get it back or have it removed. SAOFAL PRIVATE LIMITED is the data fiduciary for the personal data described here, under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025.

Who we are

Legal name
SAOFAL PRIVATE LIMITED
CIN
U62011KA2026PTC223233
GSTIN
29ABUCS2103E1ZA
Udyam
UDYAM-KR-19-0060181
Registered office
3146, Commercial Space, Old Sante Maidan, Gandhinagar, Bangarpet, Kolar 563114, Karnataka, India
Phone
+91 63629 04463
Grievance contact
[email protected], or write to the registered office marked for the attention of the Grievance Officer

1. What stays on your device

BillMadi is built to keep working without a connection, so the bill you are ringing up, your day book, your settings and your text size all live on the device first, in its own browser storage. That copy stays on your device whether or not it has reached us. Clearing your browser data or uninstalling the app removes it, so export a backup before you do either.

2. What we collect

Your account. Your name, and whichever sign-in you choose: a phone number, an email address, or a passkey. For a passkey we hold a public key and a counter, never a password, a fingerprint or a face. For a phone or email sign-in we hold your passcode or password only as a scrypt hash with a per-account salt, which cannot be turned back into what you typed.

Your shop. The shop name, the mode you chose, and, only if you decide to issue GST invoices, your legal name, address, GSTIN and logo.

Your sales. Each sale you record: the lines, quantities, prices, any tax, the total, the day it belongs to, and which of your staff recorded it. If you write a customer name or a note on a credit entry, we hold that too, because it is part of the record you asked us to keep.

Your products. Names, prices, tax rates, barcodes and stock counts, in the modes that use them.

Security records. A log of significant account actions, such as sign-ins, invitations, voided sales and plan changes, with the time and the person. Counters used to slow down repeated failed sign-ins and abusive traffic.

3. What we do not collect

There are no advertising trackers, no analytics scripts and no third-party code of any kind in the app. Its content security policy allows scripts only from our own servers, so a tracker cannot be slipped in later without changing the app itself.

When you share a bill with a customer by link or QR code, the bill travels inside the fragment of the link, the part after the hash. Browsers do not send that part to any server, so the bill you share never reaches us. We cannot read it, and we do not store it.

We do not ask for your customers' phone numbers or identity documents, and nothing in BillMadi requires them.

4. Why we hold it, and on what basis

We process your account and shop data to give you the service you asked for, which is our contract with you. We process security records for the legitimate purpose of keeping accounts safe and preventing misuse. We process your sales data solely to store, sync and display it back to you and your staff. We do not profile you, and we take no automated decision that has any legal effect on you.

5. Where it is kept, including outside India

Our servers are hosted by Fly.io in Singapore, on an encrypted volume, so your account and sales data is stored outside India. Traffic to us passes through Cloudflare, which terminates TLS and filters attacks, and which operates from locations worldwide. We use both only to run the service, under their terms as our processors, and neither is permitted to use your data for its own purposes. The Digital Personal Data Protection Act permits transfer outside India except to a country the Central Government restricts, and we will move or restrict storage if that changes.

6. Who can see it

Inside your shop, the people you invite see what their role allows. Across shops, nothing is shared: an account is scoped to one business at a time and the server checks that on every request. Our own staff access production data only when it is needed to fix a fault or answer your request, and that access is logged.

We share data with nobody else, with two exceptions: the hosting and network providers named above, and a lawful order from a court or authority that we are obliged to follow. If we are ever required to hand over your data, we will tell you unless we are legally forbidden from doing so.

7. How long we keep it

We keep your sales and account data for as long as your account is open, because that is the record you are paying us to hold. When you ask us to delete your account, we remove your account, shop, sales and product data within 30 days, and it is gone from our backups within a further 30 days. Security logs are kept for 12 months and then deleted. Rate-limiting counters are cleared within an hour. If we are required by law to keep something longer, we will keep only that and tell you what it is.

8. Your rights

Under the Digital Personal Data Protection Act, 2023 you may ask us for a copy of the personal data we hold about you, ask us to correct or complete it, ask us to delete it, and nominate someone to exercise these rights if you die or become unable to. You may also withdraw consent where we relied on it, though we cannot run the service without the data needed to provide it.

You can export your own sales from inside the app at any time without asking us. For anything else, write to [email protected] or to the registered office. We will confirm your request within 7 working days and complete it within 30 days. If we cannot do what you ask, we will tell you why.

9. Complaints

If you are unhappy with how we have handled your data, contact our Grievance Officer at [email protected], by post at the registered office, or by phone on +91 63629 04463. We will acknowledge within 7 working days and respond within 30 days. If you are still not satisfied, you may complain to the Data Protection Board of India.

10. Children

BillMadi is for business use and we do not offer accounts to anyone under 18. We do not knowingly collect a child's personal data. If you believe a child has created an account, tell us and we will remove it.

11. Keeping it safe

Your data is encrypted while it travels to us and while it sits on our servers. If you sign in with a passkey, your device keeps the secret and we never hold one. If you sign in with a password or a passcode, we store only a one way hash of it, so it cannot be read back by us or by anyone who obtained a copy of our database. Accounts are protected against repeated guessing, and traffic is filtered before it reaches the service.

We do not publish the details of how these protections are built, because that information helps an attacker more than it helps you. If you are assessing BillMadi for your own business and need more, write to us and we will answer directly.

No system is perfectly safe. If a breach affects your personal data, we will tell you and the Data Protection Board of India without delay, describing what happened, what it affects and what you should do.

12. Changes

We may update this policy. If a change materially affects you, we will tell you in the app at least 30 days before it takes effect. Every version carries a number and a date.