Privacy Policy

Version 1.0  ·  Effective date: 30 August 2026  ·  Last updated: 30 August 2026
Application: Somoney (Android & iOS)  ·  Operated by Shubh Arvind Somani, an individual sole proprietor based in India (the “Data Fiduciary”, “we”, “us”).

In plain words

If you read nothing else, read this:

  • Your khata stays on your phone. Somoney works fully offline. Your customers, balances, bills and stock are saved on your device — they do not go to the internet unless you switch on cloud backup.
  • Cloud backup is your choice. Only if you turn on Cloud Backup & Sync does your data copy to our secure servers in India (Mumbai), so you can use Somoney on more than one phone and recover after a lost device.
  • Only you can read your data in the cloud. Each shop’s data is locked to its own account. A different account cannot read your khata, and an unauthenticated request reads nothing.
  • Your secret PIN never leaves your phone. It is irreversibly scrambled (hashed) and stored only on your device. We never send it anywhere and never sync it.
  • Extras are off by default. Crash reports are off unless you allow them, and we strip out personal details (names, phone numbers, amounts) before anything is sent.
  • Other people’s information. When you save a customer’s or worker’s name, phone or photo, you are responsible for having their consent. Somoney stores it for you on your instruction.
  • You are in control. You can change these choices any time in Settings, export or delete your data, and ask us to erase your cloud data by emailing us.

Version history:

VersionDateSummary of changes
1.030 August 2026Initial published version. Consolidated and hardened master (explicit retention periods, per-purpose legal basis, sub-processor table with links, defined terms, rights-exercise timelines).

Legal framework

This Policy is issued in compliance with, and is to be read alongside:

Where any term used here is defined in the DPDP Act, it carries that meaning.

Definitions

“Personal data”
any data about an individual who is identifiable by or in relation to such data.
“Data Principal”
the individual to whom personal data relates (for example, you, or a customer or staff member whose details you enter).
“Data Fiduciary”
the person who, alone or with others, determines the purpose and means of processing personal data.
“Data Processor”
a person who processes personal data on behalf of a Data Fiduciary.
“Processing”
any operation on personal data — collection, storage, use, sharing, or erasure.
“Cloud Backup & Sync”
the optional feature that copies your data to our cloud so you can sync across devices and recover after device loss.
“khata”
your business records kept in the app (ledger, parties, bills, stock, and the like).
“the app”, “Somoney”
the Somoney mobile application (package com.shubhtech.ledger).

1. Who we are and how to contact us

Somoney is a mobile bookkeeping (bahi-khata), billing and business-management application for Indian shopkeepers and small businesses.

Under the DPDP Act, the roles differ depending on whose data is in question:

2. The core idea: Somoney is local-first

Somoney is built to work on your phone, offline, by default. Your business records live in your phone’s own storage. Nothing is transmitted to the internet unless you choose to turn on a cloud feature (Section 8) or to share or back up a file yourself (Section 9).

This means:

3. What information Somoney handles

3.1 Your account & business

3.2 Your business records (your khata)

Everything you create in the app, including:

3.3 Information about other people (third-party data)

When you add a customer or a staff member, you are entering their personal information — names, phone numbers, addresses, GSTIN, balances, and sometimes photographs. Somoney stores this for you as your Data Processor. Your responsibilities as their Data Fiduciary are explained in Section 12.

3.4 Photographs

You may attach photographs — a customer’s photo, a staff photo, a bill/receipt photo, an expense photo, or your business logo. Photographs are kept on your device. If you turn on cloud backup, they are also copied to our private cloud storage (Section 8.4). Captured photos are compressed and size-limited before storage.

3.5 Camera

The app requests camera access only so you can scan product barcodes (for inventory) and capture the photographs described above. The camera is used only while you are actively performing one of those actions.

3.6 On-device notifications

With your permission, the app may show local notifications generated on your phone — for example a daily digest, low-stock alerts, and birthday or payment reminders. These are produced on your device from your own data; we do not operate a push-notification server that receives your data for this purpose.

3.7 Crash & diagnostic data (optional, off by default)

If, and only if, you allow Usage Analytics, Somoney sends crash and error reports so we can find and fix problems. Personal details are removed first. See Section 11.

3.8 Technical data

Standard data needed to run the service — for example the app version and basic device/operating-system information attached to a crash report (only if analytics is on). Somoney does not use advertising identifiers, does not collect your location, does not show advertisements, does not track you across other apps or websites, and does not sell your data.

4. Why we use your information, and our legal basis

The table below maps each purpose to the personal data used and to the ground for processing under the DPDP Act (consent under Section 6, or a specific legitimate use under Section 7).

PurposePersonal data usedLegal basis (DPDP Act)
Run the app (save/show your khata, bills, stock, reports on your device)Your account + business records; third-party data you enterProcessing you direct us to perform as part of the service you requested (Section 6 consent at setup; and, for data about others, on your instruction as Data Fiduciary).
Cloud backup & multi-device (opt-in)Your business records + photographsYour consent (Section 6) — the Cloud Backup & Sync switch.
Account login & recovery (opt-in)Google account (email, basic profile)Your consent (Section 6) — you choose to sign in with Google for Cloud Backup & Sync.
Improve the app (opt-in)Crash/error reports (personal details removed); app version; device/OSYour consent (Section 6) — the Usage Analytics switch.
Notifications (opt-in)Your own data, on your deviceYour consent (Section 6) — notification permission.
Legal & safetyThe minimum necessaryCompliance with law and the legitimate uses recognised under Section 7.

We do not rely on any general “legitimate interests” balancing basis — the DPDP Act permits processing without consent only for the specific “certain legitimate uses” listed in its Section 7. Optional features rely on your consent, which you may withdraw at any time (Section 6).

When you first set up Somoney, and again in Settings, you control these switches. All optional switches are OFF by default.

SwitchDefaultWhat turning it ON does
Essential (required)OnLets the app run on your device. Cannot be turned off while you use the app.
Cloud Backup & SyncOffCopies your data to our secure cloud in India so you can sync and recover (Section 8).
Usage AnalyticsOffSends crash/error reports (personal details removed) to help us fix bugs (Section 11).

Consent obtained through the app is free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, limited to the purpose described, and accompanied by this notice — consistent with Section 6 of the DPDP Act and the DPDP Rules, 2025.

6. Consent withdrawal

You may withdraw any consent at any time from Settingswithdrawing consent is as easy as giving it.

Withdrawing consent does not affect the lawfulness of anything done on the basis of your consent before you withdrew it. Where you withdraw consent and the data is no longer needed for a purpose you chose, we will erase it as described in Section 14 (Section 8(7), DPDP Act).

7. Your rights under the DPDP Act, and how to exercise them

As a Data Principal you have the right to:

How to exercise these rights:

Identity verification and timelines. We may need to verify your identity (for example, via the email address on your Google account) before acting, to protect your account from unauthorised requests. As required by the DPDP Rules, 2025, we publish the timelines within which we respond: we aim to acknowledge a request or complaint within 3 working days, and to resolve it within 30 days (or sooner where the DPDP Act or the DPDP Rules prescribe a shorter period), extending only where reasonably necessary and permitted, in which case we will tell you.

8. When your data leaves your device — Cloud Backup & Sync (opt-in)

This Section applies only if you turn on Cloud Backup & Sync.

8.1 Where it is stored

Your data is stored with our cloud infrastructure provider Supabase, hosted in the Mumbai region (ap-south-1) — i.e. within India.

8.2 Only you can read it

Each business’s data is isolated to its own account using database Row-Level Security (RLS). Access is tied to your authenticated account (auth.uid()) through a membership table, and every read and write is checked against it. A different account cannot read or change your data, and an unauthenticated request reads nothing.

8.3 What syncs (and what never does)

8.4 Photographs in the cloud

If cloud backup is on, attached photographs are uploaded to a private storage bucket (not public). They are shown back to you through short-lived signed links (valid for approximately one hour) that only your authenticated account can generate. When you are offline or not using the cloud, photographs remain on your device.

8.5 In transit

All communication with our cloud is over encrypted connections (HTTPS/TLS). The app is configured to refuse cleartext (unencrypted) network traffic.

8.6 Multi-device conflicts and deletions

Somoney uses a last-write-wins model with tombstones (deletion markers) so a deletion on one device is honoured on your others and deleted items do not reappear. Deletion markers are retained for approximately 90 days so that all your devices can catch up, and are then purged.

9. Backups and exports you make yourself

10. Who else processes your data (sub-processors) & cross-border note

We use a small number of trusted service providers (“Data Processors”) strictly to run Somoney. We do not sell your data or share it for advertising. Each processor acts on our behalf and is bound to protect your data.

Sub-processorWhat they do for SomoneyWhenWhere data may be processedTheir privacy policy
SupabaseCloud database, authentication, and file (photo) storageOnly if Cloud Backup & Sync is onIndia (Mumbai, ap-south-1)supabase.com/privacy
Google (Sign-In)Authenticates your login and provides your Google email + basic profile so we can create your accountOnly if you turn on Cloud Backup & SyncMay process limited sign-in information outside Indiapolicies.google.com/privacy
Sentry (crash reporting)Receives crash/error reports with personal details removedOnly if Usage Analytics is onMay process outside Indiasentry.io/privacy

A note on UPI QR codes. Where an invoice displays a UPI QR code, that QR is generated entirely on your device — it is not fetched from, and no invoice or payment detail is sent to, any third-party QR service.

Cross-border processing. Your khata data is stored in India. Certain supporting services above — authenticating your sign-in and, if enabled, optional crash reports — may process limited information outside India. Any such transfer is only to operate the features you have chosen, and only to the extent permitted by the DPDP Act and the DPDP Rules, 2025. We do not transfer personal data to any country or territory in respect of which such transfer is restricted by the Central Government under Section 16 of the DPDP Act.

11. Crash & diagnostic reporting (opt-in)

If, and only if, you allow Usage Analytics, Somoney sends crash and error reports (via Sentry) so we can find and fix problems.

12. Your responsibility for your customers’ and staff’s data

Because you decide what customer and staff information to store, under the DPDP Act you are the Data Fiduciary for that information, and Somoney is your Data Processor acting on your instructions under the Terms of Service. In plain words:

We will help you meet these duties (for example, by erasing cloud data on your instruction), but the relationship with your own customers and staff is yours.

13. Children’s data

Somoney is a business application intended for shopkeepers and business owners, who are adults. It is not directed at children, and we do not knowingly collect the personal data of a child for our own purposes. Consistent with Section 9 of the DPDP Act and the DPDP Rules, 2025, we do not undertake tracking, behavioural monitoring, profiling, or targeted advertising directed at children. Where you add a staff member, you must confirm that they are 18 years or older, or that you have obtained verifiable parental/guardian consent, as stated in Section 12.

14. Data retention & deletion

We keep personal data only for as long as needed for the purpose it was collected for, or as the law requires. The specific periods are:

Data categoryRetention period
Your data on your deviceKept until you delete it. Settings → Delete My Data removes all business data from that device immediately and permanently.
Your data in the cloud (if Cloud Backup & Sync is on)Kept while your account is active and cloud sync is on. Erased on a verified deletion request; and — where you withdraw cloud consent and the data is no longer needed, or after prolonged account inactivity — erased or de-identified, unless the law requires us to keep it (Section 8(7), DPDP Act).
Photographs in the cloudSame as your cloud data; deleted from cloud storage on erasure.
Login / authentication identity (Google-based account)Deleted on a verified account-deletion request, so your Google account can be used to register afresh.
Deletion markers (tombstones)Retained for approximately 90 days so the deletion propagates across your devices, then purged.
Crash / diagnostic reports (if analytics on)Retained only as long as needed to diagnose and fix defects — up to approximately 90 days — then deleted or aggregated.
Records we must keep by law (e.g. to comply with a legal obligation, resolve a dispute, or prevent abuse)Retained only for as long as, and to the extent, the law requires; then deleted.

How to delete:

15. How we protect your data

We implement reasonable security safeguards as required by Section 8(5) of the DPDP Act and the DPDP Rules, 2025, and reasonable security practices and procedures as contemplated by Section 43A of the IT Act and the SPDI Rules.

Honest limits (so you can decide with full information):

16. Grievance redressal

If you have a question or complaint about your privacy or how Somoney handles data, contact our Grievance Officer:

We will acknowledge and respond within the timelines published in Section 7 and required by the DPDP Act and the DPDP Rules, 2025. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.

17. Personal data breaches

If a personal-data breach occurs, we will take steps to contain and remedy it and will notify the Data Protection Board of India and each affected Data Principal in the manner and within the timelines required by Section 8(6) of the DPDP Act and the DPDP Rules, 2025 — which require intimating affected Data Principals without delay and giving the Board a detailed report within 72 hours of becoming aware of the breach (or such longer period as the Board may allow on request).

18. Changes to this Policy

We may update this Policy as the app evolves or the law changes. The version number and version-history table at the top will be updated, and the version is tied to the app’s in-app consent version. If we make a significant change to how we use your personal data, we will show you the updated notice in the app and, where the law requires, ask for your consent again before the change affects you.

19. Governing law & jurisdiction

This Policy is governed by and construed in accordance with the laws of India, including the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. Subject to the statutory grievance and Data Protection Board process described above, the courts of competent jurisdiction in India shall have jurisdiction.

20. Languages

This Policy is published in English and in हिन्दी (Hindi) and मराठी (Marathi); ગુજરાતી (Gujarati), தமிழ் (Tamil) and తెలుగు (Telugu) versions are being prepared. We have endeavoured to make every version say the same thing in plain language. In the event of any inconsistency, the English version governs for legal interpretation; if you relied in good faith on your own-language version, we will honour the meaning you could reasonably have understood from it.

21. Contact