Legal
Privacy Policy
This version replaces version 1.0 dated 26 May 2026, which was published inside the app during the pilot.
1. In short
Arthace is accounting software for Indian businesses. To run it, we hold some information about you, and we hold the accounting records you create.
Three things are worth saying plainly at the top:
- Your books belong to you. We do not sell your data, we do not show you advertisements, and we do not use your accounting records to train any AI model.
- You can take your data out whenever you want, and you can ask us to delete it.
- AI document reading is switched on by you, not by us. Until the business owner turns it on, no document leaves our systems for AI processing.
This policy is written to meet India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000 and rules made under it.
2. Who we are
1109, International Wealth Centre, Vesu, Surat, Gujarat, India – 395007
Phone: 79841 67514
WhatsApp: 93136 45986
Website: arthace.com · Software: app.arthace.com
Email: arthaceindia@gmail.com
For the purposes of the DPDP Act, Arthace is the Data Fiduciary for the personal data we hold about you — your account, your login, your billing details. For the personal data of your customers, suppliers and staff that sits inside the accounting records you create, you are the Data Fiduciary and we act as your Data Processor: we process that data only to run the service for you and only on your instructions. Section 9 explains this in more detail.
3. What we collect
3.1 Information you give us
| What | Examples |
|---|---|
| Account identity | Your name, email address, mobile number, business name, and your GSTIN if you choose to enter it |
| Login and security data | Your password (stored only as a one-way hash — nobody at Arthace can read it), two-factor authentication secret (encrypted), backup codes (hashed), device and IP address you sign in from, session timestamps |
| Billing details | Billing name, address, GSTIN and state (needed to raise a correct GST invoice), plan chosen, payment reference numbers |
| Your business records | Company profile, staff accounts, ledgers, invoices, vouchers, stock, bank entries and every other accounting entry you record |
| Documents you send us | Photos, scans, PDFs, Excel and CSV files, bank statements, and — if you use the WhatsApp channel — WhatsApp messages and voice notes |
| What you write to us | Support messages, demo requests, grievance and data-rights requests |
3.2 Information we generate
| What | Why it exists |
|---|---|
| Operational and audit logs | Logins, password changes, staff changes, licence and plan events, and what was posted to your books and by whom — so you have an audit trail and so we can investigate suspected misuse |
| Usage counters | AI scan credits used, WhatsApp and voice units used, number of users and companies — to apply your plan's allowances and to bill correctly |
| Technical logs | Error logs, request logs and security logs used to keep the service running and safe |
3.3 Payment information
Card numbers, UPI IDs, CVV and bank credentials are never stored on Arthace systems. Online payments are handled entirely by our payment gateway (see section 8). We receive only the outcome of a payment, the amount, the plan and a payment reference.
3.4 Website information
On arthace.com we use standard web analytics and advertising measurement tags so we know which pages and campaigns are working. What is in use, and whether a cookie consent banner is shown, is set out in section 12.
We do not buy personal data about you from data brokers, and we do not build advertising profiles.
4. Why we use it
We use your information only for these purposes:
- To provide the service you signed up for — running your books, reading your documents, answering your questions, generating your reports and returns.
- To operate your account — verifying your email or mobile, resetting passwords, inviting staff, applying your plan's limits.
- To take payment and raise a valid tax invoice — including the GST details the law requires us to record.
- To keep your account safe — spotting repeated wrong-password attempts, alerting you to a sign-in from a new device, recovering access when you are locked out.
- To support you — replying to your messages and investigating problems you report.
- To improve the product — using aggregated and statistical information about how features are used. We do not use the content of your books for this.
- To meet our own legal obligations — tax, accounting and record-keeping law that applies to us as a business.
Under the DPDP Act, we process this data on the basis of the consent you give when you create an account, and on the legitimate uses the Act allows — for example where you have voluntarily given us data for a purpose, and where we must comply with a law.
What we do not do: we do not sell your data, we do not rent or share it with advertisers or data brokers, and we do not use your accounting records to train AI models.
5. AI features — how they work and what you control
Arthace uses AI for three things: reading documents (photo and PDF entry), understanding voice notes, and answering questions about your own books.
AI is opt-in. The business owner must switch AI features on in Settings → AI Consent before any of your content is sent to an AI provider. Consent can be withdrawn at any time, and both the switch-on and the switch-off are recorded in your audit trail. Excel, CSV and typed entry never involve an AI provider.
When an AI feature runs, we send only what is needed for that task — the document page, the voice note, or the question you asked, plus a small amount of context such as the names of your own ledgers so the result can be matched to your books. We do not send your whole database.
Nothing an AI produces is posted to your books on its own. Every entry is shown to you first and is saved only when you approve it. This is a design rule of the product, not a preference.
Our AI providers process this content under business terms which state that content sent through their business APIs is not used to train their models. We keep those terms under review, and if a provider changes, this policy is updated and you are told.
The exact list of AI providers in use today is in section 8.
6. The WhatsApp channel
If you link a WhatsApp number to your Arthace account (Team plan and above):
- Messages, photos, PDFs and voice notes you send on that number are processed to create the entry you asked for, and for nothing else.
- The message travels through WhatsApp and through our WhatsApp service provider (section 8) before it reaches us. Their handling of the message in transit is governed by their own terms.
- Voice notes are converted to text by a speech-to-text provider so the instruction can be understood.
- Send STOP at any time to remove that number from the service immediately.
- Only a number you have linked from inside the app can transact on your account.
7. How we protect your data
- Passwords are stored only as a one-way bcrypt hash. They are never stored, logged or displayed in readable form.
- Two-factor secrets and any external API keys you save are encrypted at rest (AES-256-GCM).
- All traffic between your browser and our servers uses HTTPS.
- Every business gets its own isolated workspace. One customer cannot see another customer's data.
- Sessions are tracked server-side. If a session is ended — by a password change, by you signing a device out, or by an administrator — it stops working on the very next request.
- Access by Arthace staff to a customer's data is restricted, logged, and the log of what was viewed and why is retained (section 10).
- Security logs are retained for at least 180 days, in line with the CERT-In directions of 28 April 2022.
No system is perfectly secure, and we do not claim otherwise. If a personal data breach happens, we will inform the Data Protection Board of India and the affected users, in the manner and within the time the law requires, and we will tell you what happened and what we are doing about it.
8. Who else processes your data
We keep the list short and we name everyone. Each provider is bound to protect the data we pass to them and to use it only to perform their service for us.
| Purpose | Provider | What they receive |
|---|---|---|
| Reading documents (photo / PDF extraction) | Google (Gemini) | The document page or image you submitted |
| Answering questions about your books | Anthropic (Claude) | Your question plus the limited context needed to answer it |
| Converting voice notes to text | Sarvam AI | The voice note audio |
| Transactional email (verification, alerts, invoices) | Resend | Your email address and the content of that email |
| Online payments (card, UPI, netbanking) | Razorpay | Your name, contact details, billing details and the amount. Card and bank credentials go to them, never to us |
| WhatsApp message delivery | Our WhatsApp Business Solution Provider (11za), and WhatsApp itself as the underlying channel | The messages, documents and voice notes exchanged on the linked number |
| Application hosting and database | Railway | All service data, stored and processed |
| Backups | Amazon Web Services (AWS) | Encrypted backups of your service data |
This list was checked against our production configuration on 12 August 2026. An earlier version of this policy named OpenAI as an optional provider; OpenAI is not in use and has been removed.
Other than the providers above, we share your data only:
- when you ask us to (for example, when you invite your chartered accountant into your workspace);
- when we are required by law — a valid order from a court, tax authority or other competent authority. Where we are permitted to tell you, we will;
- to protect our rights or someone's safety, where there is no reasonable alternative;
- if the business is ever sold or merged, in which case the acquirer is bound by this policy and you will be told before anything moves.
9. Your accounting data — who owns what
- Your accounting records are yours. We claim no ownership over them.
- Your books contain personal data about other people — your customers, suppliers and staff. You decide what goes in and why. For that data you are the Data Fiduciary and we are your Data Processor: we handle it only to deliver the service to you, we do not use it for our own purposes, and we return or delete it when you tell us to, subject to section 10.
- If one of your customers or suppliers writes to us directly about data held inside your books, we will point them to you, and let you know.
- You are responsible for making sure you are allowed to put that data into Arthace in the first place, and for giving whatever notices your own customers and staff are entitled to.
10. Where your data is stored, and how long we keep it
10.1 Where
Your data is hosted on Railway (application and database) and backed up to Amazon Web Services (AWS). The storage regions will be named here once confirmed. We make no claim about the country your data is stored in until we can state it accurately.
Some of the providers listed in section 8 process data outside India. The DPDP Act permits the transfer of personal data outside India except to countries the Central Government restricts, and we comply with that.
10.2 How long
| Data | Retention |
|---|---|
| While your account is active | For as long as you use the service |
| After you close your account | You can sign in for 30 days to download your data. After that you cannot sign in |
| Deletion after closure | On request. We delete after verifying who you are, except for records Indian tax, GST and company law require us or you to keep for a minimum period |
| Security logs | At least 180 days (CERT-In directions) |
| Data-access logs (what an Arthace administrator looked at, and why) | 24 months |
| Billing and tax records | For the minimum period Indian tax law requires us to keep our own books |
Documents you send for AI processing are retained as part of the entry they created, so you have the source document against the voucher. If you want a source document removed, delete it in the app or ask us.
11. Your rights under the DPDP Act, 2023
You can, at any time:
- See what we hold — a summary of your personal data and who we have shared it with. Use Settings → Backup & Restore → Download my data, or write to us.
- Correct or update it — ask us to fix anything wrong, incomplete or out of date.
- Erase it — ask us to delete your personal data, subject to the minimum retention Indian law requires.
- Withdraw consent — as easily as you gave it. Withdrawing consent to AI features switches those features off. Withdrawing consent altogether means we close your account at the next cut-off and keep only what the law requires.
- Nominate someone — name a person to exercise these rights on your behalf if you die or become unable to act.
- Complain — to our Grievance Officer first, and if you are not satisfied, to the Data Protection Board of India.
How to exercise them: use the Privacy & Data Rights request form at app.arthace.com/grievance (no account needed, so a closed-account customer can still use it), or write to arthaceindia@gmail.com, or post to the address in section 2.
We acknowledge requests within 3 working days and respond within 30 days. We may need to verify who you are before we act — that protects you.
There is no charge for exercising these rights.
12. Cookies and tracking
Inside the software (app.arthace.com) we use only strictly-necessary cookies:
| Cookie | Purpose |
|---|---|
access_token | Keeps you signed in |
refresh_token | Renews your session without making you sign in again |
arthace_csrf | Protects against cross-site request forgery |
There are no advertising or profiling cookies inside the software.
On this website (arthace.com) we use analytics and advertising measurement so we can see which pages and campaigns bring us enquiries. These tools may set cookies in your browser. You can block or delete cookies in your browser settings; the software will still work, the website may lose some measurement.
13. Marketing and communications
- Transactional messages — verification codes, password resets, new-device alerts, invoices, renewal reminders and service notices — are part of the service and are not marketing. You cannot opt out of these while you have an account.
- Marketing emails or messages, if we send any, always carry an unsubscribe option, and you can also tell us to stop by writing to us.
- WhatsApp — reply STOP to remove your number.
14. Children
Arthace is a business product, sold to businesses and to adults. It is not directed at children, and we do not knowingly collect the personal data of a child. If you believe a child's data has reached us, write to us and we will remove it.
15. Changes to this policy
If we change this policy in a way that materially affects you, we will email you and publish the new version here with a new version number and date. The version you accepted is recorded against your account, and you can see it in your data export. Continuing to use Arthace after a change means you accept the updated policy.
16. Contact and grievance redressal
Grievance Officer (appointed under the Information Technology Act, 2000 and the rules made under it, and acting as our contact for DPDP Act queries):
- Email: arthaceindia@gmail.com
- Post: Grievance Officer, Arthace, 1109, International Wealth Centre, Vesu, Surat, Gujarat, India – 395007
- Phone: 79841 67514
General support: arthaceindia@gmail.com · Phone 79841 67514 · WhatsApp 93136 45986
See also: Terms of Service · Cancellation Policy · Contact