Privacy Policy
1. What Data We Collect
Account data:
- โWhatsApp number (for authentication)
- โName, email (optional)
- โBusiness name, GST registration details
Financial data (you provide):
- โInvoices, receipts, bank statements
- โPayroll, employee information
- โGST returns, TDS data
- โAll accounting entries
Usage data (automatic):
- โPages visited, features used
- โWhatsApp messages sent to OnGravy
- โError logs for debugging
- โDevice type, browser
2. How We Use Your Data
- โTo provide and improve OnGravy
- โTo auto-fill GST returns with your transaction data
- โTo send proactive alerts (GST deadlines, fraud alerts)
- โTo generate reports and insights
- โTo send billing notifications
- โWe do NOT use your data to train AI models
- โWe do NOT sell your data to any third party
3. Where Data Is Stored
All data is stored in India:
- โDatabase: Supabase, Mumbai (AWS ap-south-1)
- โCache: Upstash Redis, Mumbai
- โFiles: Supabase Storage, Mumbai
We do not transfer data outside India except for payment processing via Razorpay (India-based) and WhatsApp API via Meta (messages only, not financial data).
4. Data Sharing
We share data only with:
- โGST Portal (GSTN) โ only when you file returns
- โRazorpay โ only payment amounts, never full financial data
- โWhatsApp (Meta) โ only the messages you send to OnGravy
- โAWS Textract โ OCR processing (not stored by AWS)
We never share with: Advertisers ยท Data brokers ยท Other companies for marketing
5. Data Retention
- โActive accounts: data kept as long as subscription is active
- โCancelled accounts: 90-day export window, then permanently deleted
- โAudit logs: kept for 7 years (GST compliance requirement)
- โWhatsApp messages: not stored after processing
6. Your Rights (DPDP Act 2023)
You have the right to:
- โAccess all your data (export from Settings)
- โCorrect inaccurate data
- โDelete your account and all data
- โKnow who we share data with
- โWithdraw consent (will terminate service)
To exercise your rights: privacy@ongravy.in
7. Security
- โAES-256-GCM encryption for sensitive fields
- โHTTPS everywhere, TLS 1.3
- โWhatsApp OTP authentication โ no passwords
- โRow-level security: your data is completely isolated
- โRegular security audits
- โNo employee can access your financial data without your consent
8. Cookies
We use only essential cookies: authentication session and theme preference (dark/light). We do not use advertising or tracking cookies of any kind.
9. Children
OnGravy is not intended for users under 18. We do not knowingly collect data from minors.
10. Contact
Privacy Officer: Pratik Revankar
Email: privacy@ongravy.in
Address: OnGravy Technologies Pvt Ltd, Goa, India