Legal · Privacy
Privacy Policy
Effective 1 June 2026 · Last updated 24 August 2026
SnapBooks Technologies Pvt Ltd ("SnapBooks", "we", "us") operates the SnapBooks platform — an AI-powered accounting assistant for Indian businesses. This policy explains what personal data we collect, why we collect it, how we use and store it, and your rights under the Digital Personal Data Protection Act, 2023 (DPDPA).
1. What we collect
We collect the minimum data needed to run the service:
- Account data: your name, email address, and optionally your mobile number when you register.
- Company / accounting data: ledger entries, vouchers, invoices, GST numbers, party names, and other financial records you sync from Tally, Zoho, QuickBooks, Xero, or enter directly.
- WhatsApp messages: the text, voice notes, and documents you send to the SnapBooks WhatsApp number. These are processed to generate responses and not retained beyond what is needed for conversation context.
- Usage data: the pages you visit on our website, the features you use, and error logs, collected automatically to improve the service. For website visits we record the page path (never the query string), the referring site, and a first-party visitor identifier described in section 7.
- Device / connection data: IP address, browser type, operating system, and the approximate country and city your network provider maps that address to.
- Sign-in records: the time, method, IP address and outcome of each attempt to sign in to your account — including failed attempts. We keep these to let you and us tell your own sign-ins apart from someone else's, and to detect attacks on your account.
We do not collect Aadhaar numbers, PAN numbers, or bank credentials.
2. How we use your data
- Providing and operating the SnapBooks service, including answering questions, generating invoices, and producing GST filings.
- Processing your accounting queries through our AI system (powered by Anthropic Claude). Your data is sent to Anthropic's API solely to generate responses and is not used to train Anthropic's models under their API terms.
- Sending transactional emails (OTPs, invoice confirmations, service alerts). We do not send marketing emails without your consent.
- Detecting and preventing fraud, errors, and abuse.
- Complying with applicable Indian law, including GST regulations.
3. Where your data is stored
All data is stored in Indian data centres (Mumbai / ap-south-1 region) operated by Supabase (our database provider). Data is encrypted at rest (AES-256) and in transit (TLS 1.2+). We do not transfer your personal data outside India except where explicitly needed to provide the service (e.g., Anthropic's API for AI processing), and only under contractual safeguards.
4. Third-party services
We share your data with the following sub-processors only to the extent necessary:
- Anthropic — AI processing (your accounting queries are sent here to generate answers).
- Meta / WhatsApp — message delivery for the WhatsApp channel.
- Supabase — database and authentication infrastructure.
- Vercel — hosting of the web application, and aggregate, cookieless traffic measurement (Vercel Web Analytics and Speed Insights). These report counts by page, country and device; they do not identify you and do not receive your IP address in a form we can query.
- Resend — transactional email delivery.
We do not sell your data to any third party, ever.
5. Data retention
We retain your account and company data for as long as your account is active. If you delete your account, we delete your personal data within 30 days, except where retention is required by law (e.g., GST records must be kept for 8 years under Indian tax law — you remain responsible for your own statutory obligations).
Two categories expire on their own schedule, enforced by an automated daily job rather than by request:
- Website visit records — the IP address and browser string attached to a page view are erased 90 days after the visit. The visit itself remains as an anonymous count.
- Sign-in records — deleted after 365 days. They are kept longer than visit data because they are a security record of access to your account.
6. Your rights (DPDPA 2023)
Under the Digital Personal Data Protection Act, 2023, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to correct inaccurate data.
- Erasure — request deletion of your personal data (subject to legal retention obligations).
- Grievance redressal — raise a complaint with our Data Protection Officer.
To exercise these rights, email team@snapbooks.co.in. We will respond within 30 days.
7. Cookies
We use two kinds of cookie, both first-party. We do not use advertising cookies, and we do not allow third parties to set tracking cookies or pixels on our site.
- Essential session cookies — required to keep you signed in. Without these the service cannot work.
- An analytics cookie (
sb_vid) — a random identifier, set by our own server and readable only by it, that lets us tell a returning visitor from a new one. It expires after 180 days. It is not derived from your IP address or your device, is not shared with anyone, and is not used to build a profile or to target advertising.
Our aggregate traffic measurement (Vercel Web Analytics, section 4) sets no cookie at all.
8. Children
SnapBooks is not directed at children under 18. We do not knowingly collect personal data from minors.
9. Changes to this policy
We will notify you of material changes by email or in-app notice at least 14 days before they take effect. Continued use of the service after the effective date constitutes acceptance.
10. Contact
SnapBooks Technologies Pvt Ltd
Mumbai, Maharashtra, India
Email: team@snapbooks.co.in