Last updated:
1. Who we are and scope
This Privacy Policy explains how NXTKRAFT SOLUTIONS (OPC) PRIVATE LIMITED ("we", "us") collects, uses, shares and protects personal data when you visit our website or use the Go2Invoice application (the "Service"). It is published in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (the "DPDP Act").
For personal data about your account and use of the Service, we act as a data fiduciary. For personal data that you enter about your own customers, vendors and employees ("Customer Data"), we process it on your behalf and under your instructions; you are responsible for having a lawful basis and giving any notices required to those individuals.
2. Information we collect
- Account information: your name, email address, profile picture (optional), and, if you use Google sign-in, your Google account identifier, name and email.
- Business information: organization name, address, state, GSTIN, PAN, logo, contact details, bank details you choose to print on invoices, and settings.
- Customer Data and transactions: customers, vendors, items, quotes, invoices, bills, expenses, payments, bank transactions, journals and other records you create.
- Payment information: subscription payments are processed by Razorpay. We receive payment status, amount, method type and reference identifiers, but not your full card number, CVV, UPI PIN or bank credentials.
- Integration credentials: if you connect your own Razorpay account or mail server, we store the keys and passwords you provide in encrypted form. API keys you create are stored only as a one-way hash.
- Usage and technical data: IP address, browser and device information, pages and features used, sign-in times, API usage and logs needed for security, troubleshooting and fraud prevention.
- Communications: messages you send to our support team and emails sent through the Service (recipient, subject, delivery status).
3. How we use information
- to create and manage your account, authenticate you and provide the Service;
- to process subscription payments, send invoices and receipts, and manage trials, renewals and cancellations;
- to send service emails such as sign-in codes, invitations, invoice and reminder emails you trigger, and important notices about your account or these policies;
- to provide support and respond to your requests;
- to maintain security, prevent fraud and abuse, enforce rate limits and investigate incidents;
- to improve and develop the Service using aggregated or de-identified information; and
- to comply with legal obligations and respond to lawful requests from authorities.
We process personal data on the basis of your consent, which you give by using the Service and which you may withdraw at any time, and for legitimate uses permitted under the DPDP Act, such as complying with law. We do not sell personal data, and we do not use Customer Data for advertising.
6. Data security
We use reasonable security practices, including encrypted connections (HTTPS), passwordless sign-in with expiring one-time codes, encryption of stored integration secrets, hashing of API keys, role-based access control, separation of each organization's data, audit logs and restricted internal access. No method of transmission or storage is completely secure; if we become aware of a personal data breach, we will notify affected users and authorities as required by law.
7. Data retention
We keep your account and Customer Data for as long as your account is active. You can ask us to delete your account; we will then delete or anonymise personal data within 90 days, except where we must keep it longer to comply with law (for example, tax and accounting records), resolve disputes or enforce our agreements. Security logs are kept for a limited period. Please export any records you need to keep before requesting deletion.
8. Your rights
Subject to applicable law, including the DPDP Act, you have the right to:
- access a summary of your personal data and how it is processed;
- correct, complete or update inaccurate or incomplete personal data;
- request erasure of personal data that is no longer needed, and withdraw consent (which may mean we can no longer provide the Service);
- have grievances redressed by our Grievance Officer; and
- nominate another person to exercise your rights in the event of death or incapacity.
You can update most account and business information in the application. For other requests, email [email protected] from your registered email address. If you are not satisfied with our response, you may approach the Data Protection Board of India.
9. Children
The Service is intended for businesses and is not directed at anyone under 18. We do not knowingly collect personal data of children.
10. Where data is processed
Your data may be stored and processed on servers operated by our service providers in India or other countries, subject to appropriate safeguards and to any restrictions notified under Indian law.
11. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page with a new "Last updated" date and, for material changes, notify account administrators by email or in the application.
12. Grievance Officer and contact
If you have questions or complaints about this Policy or your personal data, contact our Grievance Officer:
Sai Areti
NXTKRAFT SOLUTIONS (OPC) PRIVATE LIMITED
Bhimavaram, West Godavari, Andhra Pradesh 534201, India
Email: [email protected]
We acknowledge complaints within 24 hours and aim to resolve them within 15 days of receipt.