In plain words
If you read nothing else, read this:
- Your khata stays on your phone. Somoney works fully offline. Your customers, balances, bills and stock are saved on your device — they do not go to the internet unless you switch on cloud backup.
- Cloud backup is your choice. Only if you turn on Cloud Backup & Sync does your data copy to our secure servers in India (Mumbai), so you can use Somoney on more than one phone and recover after a lost device.
- Only you can read your data in the cloud. Each shop’s data is locked to its own account. A different account cannot read your khata, and an unauthenticated request reads nothing.
- Your secret PIN never leaves your phone. It is irreversibly scrambled (hashed) and stored only on your device. We never send it anywhere and never sync it.
- Extras are off by default. Crash reports are off unless you allow them, and we strip out personal details (names, phone numbers, amounts) before anything is sent.
- Other people’s information. When you save a customer’s or worker’s name, phone or photo, you are responsible for having their consent. Somoney stores it for you on your instruction.
- You are in control. You can change these choices any time in Settings, export or delete your data, and ask us to erase your cloud data by emailing us.
Version history:
| Version | Date | Summary of changes |
|---|---|---|
| 1.0 | 30 August 2026 | Initial published version. Consolidated and hardened master (explicit retention periods, per-purpose legal basis, sub-processor table with links, defined terms, rights-exercise timelines). |
Legal framework
This Policy is issued in compliance with, and is to be read alongside:
- the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (notified 13 November 2025) made thereunder;
- the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), to the extent applicable; and
- the constitutional right to privacy recognised by the Supreme Court of India in Justice K.S. Puttaswamy (Retd.) & Anr. v. Union of India & Ors., (2017) 10 SCC 1.
Where any term used here is defined in the DPDP Act, it carries that meaning.
Definitions
- “Personal data”
- any data about an individual who is identifiable by or in relation to such data.
- “Data Principal”
- the individual to whom personal data relates (for example, you, or a customer or staff member whose details you enter).
- “Data Fiduciary”
- the person who, alone or with others, determines the purpose and means of processing personal data.
- “Data Processor”
- a person who processes personal data on behalf of a Data Fiduciary.
- “Processing”
- any operation on personal data — collection, storage, use, sharing, or erasure.
- “Cloud Backup & Sync”
- the optional feature that copies your data to our cloud so you can sync across devices and recover after device loss.
- “khata”
- your business records kept in the app (ledger, parties, bills, stock, and the like).
- “the app”, “Somoney”
- the Somoney mobile application (package
com.shubhtech.ledger).
1. Who we are and how to contact us
Somoney is a mobile bookkeeping (bahi-khata), billing and business-management application for Indian shopkeepers and small businesses.
- Data Fiduciary: Shubh Arvind Somani, an individual sole proprietor operating the Somoney application from India. We have not been notified as a Significant Data Fiduciary under the DPDP Act, and are therefore not required to appoint a Data Protection Officer; the contacts below are the persons authorised to answer questions about our processing.
- Privacy / data-protection contact: privacy@somoney.in
- Grievance Officer: Shubh Arvind Somani — grievance@somoney.in (see Section 16).
Under the DPDP Act, the roles differ depending on whose data is in question:
- For your own account information (your phone number, your name, your business profile), we are the Data Fiduciary and you are the Data Principal.
- For information you enter about other people — your customers and your staff — you are the Data Fiduciary, and Somoney acts as a Data Processor that stores and syncs that information on your behalf and under your instructions, under the terms of our Terms of Service (which constitute the processor contract required by Section 8(2) of the DPDP Act). See Section 12.
2. The core idea: Somoney is local-first
Somoney is built to work on your phone, offline, by default. Your business records live in your phone’s own storage. Nothing is transmitted to the internet unless you choose to turn on a cloud feature (Section 8) or to share or back up a file yourself (Section 9).
This means:
- If you never turn on Cloud Backup & Sync, your data never leaves your device through Somoney — except the optional, personal-detail-removed diagnostic items in Section 11, which are also off until you allow them.
- You can use the entire app — entries, bills, stock, reports — with no account and no internet connection.
3. What information Somoney handles
3.1 Your account & business
- Google account (email & basic profile) — if you turn on Cloud Backup & Sync, you sign in with Google. We receive your Google email address and basic profile (such as your name) to create and secure your account. We do not receive your Google password.
- Phone number — optional. Kept in your business profile and used only for features you choose (e.g. WhatsApp reminders); it is not used to log you in. Stored in the standard international (E.164) format, e.g.
+91XXXXXXXXXX. - Owner name and business profile — business name, address, and GSTIN (if you add it).
- Your secret PIN — used to unlock the app. It is irreversibly hashed (PBKDF2-HMAC-SHA256, 600,000 iterations) and kept only on your device. It is never transmitted to our servers and is never included in cloud sync.
3.2 Your business records (your khata)
Everything you create in the app, including:
- ledger entries (udhar/jama), customer and supplier balances, and full transaction history;
- parties (customers/suppliers): names, phone numbers, addresses, GSTIN, notes, opening balances;
- invoices, estimates, proforma invoices, credit/debit notes, sale & purchase orders, delivery challans, payment receipts, sale/purchase returns, purchase vouchers;
- inventory items, stock, batches, warehouses, price lists, barcodes;
- expenses; bank accounts (we store only the last four digits of an account number) and cheques;
- staff profiles, roles and permissions; employees, attendance and payroll; loyalty programmes; appointments.
3.3 Information about other people (third-party data)
When you add a customer or a staff member, you are entering their personal information — names, phone numbers, addresses, GSTIN, balances, and sometimes photographs. Somoney stores this for you as your Data Processor. Your responsibilities as their Data Fiduciary are explained in Section 12.
3.4 Photographs
You may attach photographs — a customer’s photo, a staff photo, a bill/receipt photo, an expense photo, or your business logo. Photographs are kept on your device. If you turn on cloud backup, they are also copied to our private cloud storage (Section 8.4). Captured photos are compressed and size-limited before storage.
3.5 Camera
The app requests camera access only so you can scan product barcodes (for inventory) and capture the photographs described above. The camera is used only while you are actively performing one of those actions.
3.6 On-device notifications
With your permission, the app may show local notifications generated on your phone — for example a daily digest, low-stock alerts, and birthday or payment reminders. These are produced on your device from your own data; we do not operate a push-notification server that receives your data for this purpose.
3.7 Crash & diagnostic data (optional, off by default)
If, and only if, you allow Usage Analytics, Somoney sends crash and error reports so we can find and fix problems. Personal details are removed first. See Section 11.
3.8 Technical data
Standard data needed to run the service — for example the app version and basic device/operating-system information attached to a crash report (only if analytics is on). Somoney does not use advertising identifiers, does not collect your location, does not show advertisements, does not track you across other apps or websites, and does not sell your data.
4. Why we use your information, and our legal basis
The table below maps each purpose to the personal data used and to the ground for processing under the DPDP Act (consent under Section 6, or a specific legitimate use under Section 7).
| Purpose | Personal data used | Legal basis (DPDP Act) |
|---|---|---|
| Run the app (save/show your khata, bills, stock, reports on your device) | Your account + business records; third-party data you enter | Processing you direct us to perform as part of the service you requested (Section 6 consent at setup; and, for data about others, on your instruction as Data Fiduciary). |
| Cloud backup & multi-device (opt-in) | Your business records + photographs | Your consent (Section 6) — the Cloud Backup & Sync switch. |
| Account login & recovery (opt-in) | Google account (email, basic profile) | Your consent (Section 6) — you choose to sign in with Google for Cloud Backup & Sync. |
| Improve the app (opt-in) | Crash/error reports (personal details removed); app version; device/OS | Your consent (Section 6) — the Usage Analytics switch. |
| Notifications (opt-in) | Your own data, on your device | Your consent (Section 6) — notification permission. |
| Legal & safety | The minimum necessary | Compliance with law and the legitimate uses recognised under Section 7. |
We do not rely on any general “legitimate interests” balancing basis — the DPDP Act permits processing without consent only for the specific “certain legitimate uses” listed in its Section 7. Optional features rely on your consent, which you may withdraw at any time (Section 6).
5. Your choices & consent
When you first set up Somoney, and again in Settings, you control these switches. All optional switches are OFF by default.
| Switch | Default | What turning it ON does |
|---|---|---|
| Essential (required) | On | Lets the app run on your device. Cannot be turned off while you use the app. |
| Cloud Backup & Sync | Off | Copies your data to our secure cloud in India so you can sync and recover (Section 8). |
| Usage Analytics | Off | Sends crash/error reports (personal details removed) to help us fix bugs (Section 11). |
Consent obtained through the app is free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, limited to the purpose described, and accompanied by this notice — consistent with Section 6 of the DPDP Act and the DPDP Rules, 2025.
6. Consent withdrawal
You may withdraw any consent at any time from Settings — withdrawing consent is as easy as giving it.
- Turning off Cloud Backup & Sync immediately stops live syncing and disconnects the real-time cloud connection. Data already in the cloud remains until you ask us to erase it (Section 14).
- Turning off Usage Analytics immediately stops those uploads.
Withdrawing consent does not affect the lawfulness of anything done on the basis of your consent before you withdrew it. Where you withdraw consent and the data is no longer needed for a purpose you chose, we will erase it as described in Section 14 (Section 8(7), DPDP Act).
7. Your rights under the DPDP Act, and how to exercise them
As a Data Principal you have the right to:
- Access — obtain a summary of the personal data we process about you and the processing activities (Section 11, DPDP Act).
- Correction, completion & updating — correct or update your data (Section 12; you can edit most of it directly in the app).
- Erasure — have your personal data deleted (Section 12; see Section 14 of this Policy).
- Grievance redressal — raise a complaint and receive a response (Section 13; see Section 16 of this Policy).
- Nomination — nominate another individual to exercise your rights in the event of your death or incapacity (Section 14, DPDP Act).
- Complain to the Board — if you are not satisfied with our response, complain to the Data Protection Board of India, whose grievance process is operated through a dedicated digital portal under the DPDP Rules, 2025.
How to exercise these rights:
- In the app: edit your records directly; use Settings → Delete My Data to wipe this device; use the in-app account-deletion / Request Cloud Data Erasure option to erase your cloud data.
- By email: write to privacy@somoney.in (or grievance@somoney.in for complaints). To nominate someone, email us their name and contact details.
Identity verification and timelines. We may need to verify your identity (for example, via the email address on your Google account) before acting, to protect your account from unauthorised requests. As required by the DPDP Rules, 2025, we publish the timelines within which we respond: we aim to acknowledge a request or complaint within 3 working days, and to resolve it within 30 days (or sooner where the DPDP Act or the DPDP Rules prescribe a shorter period), extending only where reasonably necessary and permitted, in which case we will tell you.
8. When your data leaves your device — Cloud Backup & Sync (opt-in)
This Section applies only if you turn on Cloud Backup & Sync.
8.1 Where it is stored
Your data is stored with our cloud infrastructure provider Supabase, hosted in the Mumbai region (ap-south-1) — i.e. within India.
8.2 Only you can read it
Each business’s data is isolated to its own account using database Row-Level Security (RLS). Access is tied to your authenticated account (auth.uid()) through a membership table, and every read and write is checked against it. A different account cannot read or change your data, and an unauthenticated request reads nothing.
8.3 What syncs (and what never does)
- Syncs (when enabled): your business records — ledger entries, parties, invoices, estimates, expenses, inventory, orders, bank accounts, cheques, recurring transactions, payroll/employees/attendance, loyalty, party notes, opening balances, and similar records listed in Section 3.2.
- Never syncs: your staff list and PIN hashes are deliberately excluded from sync. Your PIN stays on your device only.
8.4 Photographs in the cloud
If cloud backup is on, attached photographs are uploaded to a private storage bucket (not public). They are shown back to you through short-lived signed links (valid for approximately one hour) that only your authenticated account can generate. When you are offline or not using the cloud, photographs remain on your device.
8.5 In transit
All communication with our cloud is over encrypted connections (HTTPS/TLS). The app is configured to refuse cleartext (unencrypted) network traffic.
8.6 Multi-device conflicts and deletions
Somoney uses a last-write-wins model with tombstones (deletion markers) so a deletion on one device is honoured on your others and deleted items do not reappear. Deletion markers are retained for approximately 90 days so that all your devices can catch up, and are then purged.
9. Backups and exports you make yourself
- Encrypted backup (
.sph) is the default, primary backup. It is encrypted with a password you set, using strong encryption (AES-256-GCM with PBKDF2 key strengthening). Keep your password safe — without it the file cannot be opened, and we cannot recover it for you. - Plain JSON backup is available as a secondary option. It is not encrypted and contains your records in readable form. The app labels it as unencrypted and warns you before you share it. Share it only through trusted apps and storage.
- Automatic off-device backup. To protect you from losing data if the app is uninstalled or cleared, Somoney can write a daily backup file to your device’s Documents folder. This file is unencrypted by design (so it can still be restored after the app’s on-device keys are wiped). Treat any exported file as sensitive; once a file leaves Somoney, securing it is your responsibility.
10. Who else processes your data (sub-processors) & cross-border note
We use a small number of trusted service providers (“Data Processors”) strictly to run Somoney. We do not sell your data or share it for advertising. Each processor acts on our behalf and is bound to protect your data.
| Sub-processor | What they do for Somoney | When | Where data may be processed | Their privacy policy |
|---|---|---|---|---|
| Supabase | Cloud database, authentication, and file (photo) storage | Only if Cloud Backup & Sync is on | India (Mumbai, ap-south-1) | supabase.com/privacy |
| Google (Sign-In) | Authenticates your login and provides your Google email + basic profile so we can create your account | Only if you turn on Cloud Backup & Sync | May process limited sign-in information outside India | policies.google.com/privacy |
| Sentry (crash reporting) | Receives crash/error reports with personal details removed | Only if Usage Analytics is on | May process outside India | sentry.io/privacy |
A note on UPI QR codes. Where an invoice displays a UPI QR code, that QR is generated entirely on your device — it is not fetched from, and no invoice or payment detail is sent to, any third-party QR service.
Cross-border processing. Your khata data is stored in India. Certain supporting services above — authenticating your sign-in and, if enabled, optional crash reports — may process limited information outside India. Any such transfer is only to operate the features you have chosen, and only to the extent permitted by the DPDP Act and the DPDP Rules, 2025. We do not transfer personal data to any country or territory in respect of which such transfer is restricted by the Central Government under Section 16 of the DPDP Act.
11. Crash & diagnostic reporting (opt-in)
If, and only if, you allow Usage Analytics, Somoney sends crash and error reports (via Sentry) so we can find and fix problems.
- Consent is checked for every report — turning analytics off stops reporting immediately.
- Personal details are removed first: messages and logs are passed through a redactor that masks GSTIN/PAN, phone numbers, amounts, and likely names across all supported scripts. On-screen text and tapped-element labels are dropped entirely. Your IP address and request headers are not sent.
- What a report does contain: the technical error and stack trace (program-code locations), the app version, and basic device/operating-system information — the minimum needed to fix the defect.
- If no crash-reporting key is configured in a build, crash reporting is fully disabled.
12. Your responsibility for your customers’ and staff’s data
Because you decide what customer and staff information to store, under the DPDP Act you are the Data Fiduciary for that information, and Somoney is your Data Processor acting on your instructions under the Terms of Service. In plain words:
- Store only information about a person that you genuinely need for your business (data minimisation).
- Ensure the person is content for you to store their details. The app reminds you of this — for example: “Ensure you have consent from this person to store their information.”
- Respond to that person if they ask to see, correct, or delete what you hold about them. You can edit or delete their records in the app, and request cloud erasure from us.
- For staff, confirm they are adults or that you have verifiable parental consent — the app asks you to confirm: “I confirm this staff member is 18 years or older, or I have obtained verifiable parental consent.”
We will help you meet these duties (for example, by erasing cloud data on your instruction), but the relationship with your own customers and staff is yours.
13. Children’s data
Somoney is a business application intended for shopkeepers and business owners, who are adults. It is not directed at children, and we do not knowingly collect the personal data of a child for our own purposes. Consistent with Section 9 of the DPDP Act and the DPDP Rules, 2025, we do not undertake tracking, behavioural monitoring, profiling, or targeted advertising directed at children. Where you add a staff member, you must confirm that they are 18 years or older, or that you have obtained verifiable parental/guardian consent, as stated in Section 12.
14. Data retention & deletion
We keep personal data only for as long as needed for the purpose it was collected for, or as the law requires. The specific periods are:
| Data category | Retention period |
|---|---|
| Your data on your device | Kept until you delete it. Settings → Delete My Data removes all business data from that device immediately and permanently. |
| Your data in the cloud (if Cloud Backup & Sync is on) | Kept while your account is active and cloud sync is on. Erased on a verified deletion request; and — where you withdraw cloud consent and the data is no longer needed, or after prolonged account inactivity — erased or de-identified, unless the law requires us to keep it (Section 8(7), DPDP Act). |
| Photographs in the cloud | Same as your cloud data; deleted from cloud storage on erasure. |
| Login / authentication identity (Google-based account) | Deleted on a verified account-deletion request, so your Google account can be used to register afresh. |
| Deletion markers (tombstones) | Retained for approximately 90 days so the deletion propagates across your devices, then purged. |
| Crash / diagnostic reports (if analytics on) | Retained only as long as needed to diagnose and fix defects — up to approximately 90 days — then deleted or aggregated. |
| Records we must keep by law (e.g. to comply with a legal obligation, resolve a dispute, or prevent abuse) | Retained only for as long as, and to the extent, the law requires; then deleted. |
How to delete:
- On your device: Settings → Delete My Data (cloud data, if any, is not removed by this action).
- In the cloud: use the in-app account-deletion / Request Cloud Data Erasure option, or email privacy@somoney.in. On a verified request, we erase your business’s cloud records and stored photographs and delete your login/authentication identity. Full instructions are on our account & data deletion page.
15. How we protect your data
- Isolation: per-business Row-Level Security in the cloud; an unauthenticated request reads nothing.
- In transit: HTTPS/TLS for all cloud communication; the app refuses cleartext traffic.
- On device: your PIN is hashed (PBKDF2-HMAC-SHA256, 600,000 iterations) and never leaves the device; the operating system’s automatic app-data backup is disabled for the app; encrypted
.sphbackups use AES-256-GCM. - Minimisation: we store only the last four digits of bank accounts; we do not collect advertising identifiers or location; we scrub personal details from optional crash data.
We implement reasonable security safeguards as required by Section 8(5) of the DPDP Act and the DPDP Rules, 2025, and reasonable security practices and procedures as contemplated by Section 43A of the IT Act and the SPDI Rules.
Honest limits (so you can decide with full information):
- Cloud database fields are protected by access control (RLS), not by client-side encryption at rest — we (and our cloud provider, under contract) operate the database, while RLS prevents cross-account access.
- The plain JSON backup and the automatic off-device backup file are unencrypted by design; secure any exported file yourself, and prefer the encrypted
.sphbackup. - Sign-in is handled by Google — we do not run our own login rate-limiting; the security of the sign-in step itself depends on your Google account's own protections.
- No method of storage or transmission is 100% secure. We work to protect your data but cannot guarantee absolute security.
16. Grievance redressal
If you have a question or complaint about your privacy or how Somoney handles data, contact our Grievance Officer:
- Name: Shubh Arvind Somani
- Email: grievance@somoney.in
We will acknowledge and respond within the timelines published in Section 7 and required by the DPDP Act and the DPDP Rules, 2025. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.
17. Personal data breaches
If a personal-data breach occurs, we will take steps to contain and remedy it and will notify the Data Protection Board of India and each affected Data Principal in the manner and within the timelines required by Section 8(6) of the DPDP Act and the DPDP Rules, 2025 — which require intimating affected Data Principals without delay and giving the Board a detailed report within 72 hours of becoming aware of the breach (or such longer period as the Board may allow on request).
18. Changes to this Policy
We may update this Policy as the app evolves or the law changes. The version number and version-history table at the top will be updated, and the version is tied to the app’s in-app consent version. If we make a significant change to how we use your personal data, we will show you the updated notice in the app and, where the law requires, ask for your consent again before the change affects you.
19. Governing law & jurisdiction
This Policy is governed by and construed in accordance with the laws of India, including the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. Subject to the statutory grievance and Data Protection Board process described above, the courts of competent jurisdiction in India shall have jurisdiction.
20. Languages
This Policy is published in English and in हिन्दी (Hindi) and मराठी (Marathi); ગુજરાતી (Gujarati), தமிழ் (Tamil) and తెలుగు (Telugu) versions are being prepared. We have endeavoured to make every version say the same thing in plain language. In the event of any inconsistency, the English version governs for legal interpretation; if you relied in good faith on your own-language version, we will honour the meaning you could reasonably have understood from it.
21. Contact
- Privacy / data-protection: privacy@somoney.in
- Grievance Officer: grievance@somoney.in (see Section 16)
- Operator: Somoney, operated by an individual sole proprietor in India.