Privacy Policy — Accrut Accounting, Billing, Invoicing, Inventory & Banking

Last updated: August 2026 · Version 1.1

This Privacy Policy explains how Accrut ("we", "us", "our") collects, uses, stores, and protects data in connection with the Accounting, Billing, Invoicing, Inventory, and Banking modules of the platform ("the Service"). It applies to the customer organisation and its authorised users ("you").

1. Who This Applies To

This policy covers the accounting, billing, invoicing, inventory, and banking-reconciliation portion of Accrut. It does not cover the HR/payroll module, which has its own separate Terms of Service and Privacy Policy.

2. Information We Collect

Account & Sign-In Information: name, email address, and organisation details, including information received via third-party sign-in (e.g. "Sign in with Google"). When you sign in with Google, we receive your basic Google profile information (name, email address, and profile photo if available) as authorised by you during the OAuth consent screen. We do not receive your Google password.

Business & Financial Data: invoices, purchase and sales records, GSTIN and other tax identifiers, vendor and customer records, inventory and stock data, ledgers, financial statements, and other accounting records entered or uploaded by the customer.

Banking Data: bank statement data uploaded or imported by the customer for reconciliation purposes (e.g. transaction descriptions, amounts, dates). We do not collect or store full card numbers, CVV, or online-banking login credentials.

Usage Data: log data such as IP address, browser type, device information, pages visited, and timestamps, collected automatically for security and service-improvement purposes.

Support Communications: information you provide when contacting us for support.

3. How We Use Information

We use collected information to: provide and operate the accounting, invoicing, inventory, and reconciliation features of the Service; authenticate users and secure accounts; generate reports and statutory-format documents for the customer's own use; respond to support requests; detect and prevent fraud, abuse, and security incidents; and improve and maintain the Service. We do not use customer financial data to train third-party AI models beyond what is strictly required to provide AI-assisted extraction features within the Service.

4. Google OAuth & Third-Party Sign-In

If you choose to sign in using Google, we access only the limited profile scopes you approve on the Google consent screen (typically name, email address, and profile picture) solely to create and authenticate your Accrut account. We do not access your Gmail, Google Drive, or other Google data unless a specific feature separately requests and discloses that scope with its own consent. You may revoke Accrut's access to your Google account at any time via your Google Account security settings.

5. Data Sharing & Disclosure

We do not sell or rent customer financial or business data. We may share data with: - Infrastructure/sub-processors (e.g. cloud hosting and database providers) strictly to operate the Service; - Government or regulatory authorities where required by law or a valid legal order; - Professional advisors of the customer (e.g. the customer's own Chartered Accountant), only at the customer's direction.

We do not share employee, vendor, customer, or banking data with third parties for their own marketing or commercial purposes.

6. Data Security

We use encryption for sensitive financial data, row-level security to isolate data between organisations, authentication controls, and audit logging of administrative actions. No system is 100% secure, and we cannot guarantee absolute security of data transmitted over the internet or stored on third-party infrastructure. You are responsible for keeping your account credentials confidential.

7. Data Retention

Accounting, invoicing, and GST-related records are retained for the duration of your active subscription and for a minimum period consistent with applicable law (generally a minimum of 6 years under GST law and 6–8 years under the Income Tax Act, 1961, depending on record type). Upon expiry of mandatory retention periods, data will be securely deleted upon written request. We cannot fulfil deletion requests during a mandatory statutory retention period.

8. Cross-Border Data Storage & Processing (DPDP Act, 2023)

Our infrastructure — including application hosting, databases, and authentication services — may store or process data on servers located outside India. Under Section 16 of the Digital Personal Data Protection Act, 2023, transfer of personal data outside India is permitted by default, except to any country or territory the Central Government specifically restricts by notification. As of the date of this policy, no such restricted list applies to our infrastructure providers. This is separate from, and does not override, any sector-specific data localisation requirement that may apply to particular data types (for example, RBI localisation requirements for payment system data, where applicable). We will update this policy if our cross-border processing arrangements change materially.

9. Your Rights & Grievance Redressal (DPDP Act, 2023)

Under the Digital Personal Data Protection Act, 2023, and its Rules, you have the right to access, correct, and request erasure of your personal data (outside mandatory statutory retention periods), the right to withdraw consent at any time (without affecting the lawfulness of processing carried out before withdrawal), and the right to nominate another individual to exercise these rights on your behalf in the event of death or incapacity.

Grievance Officer: If you have a complaint about how your personal data has been handled within this module, you may contact our Grievance Officer at anadib1010@gmail.com. We aim to acknowledge grievances within 7 days and resolve them within 30 days, in line with the DPDP Rules, 2025. Please include your organisation name and account email so we can verify and act on your request.

10. Cookies & Similar Technologies

We use essential cookies/local storage required for login sessions and basic functionality, and may use limited analytics to understand usage patterns and improve the Service. We do not use cookies for third-party advertising.

11. Children's Data

The Service is intended for business use by adult professionals and organisations. We do not knowingly collect personal data from individuals under 18.

12. International Data

The Service is operated from India and primarily serves Indian businesses. Data may be processed on infrastructure located outside India where our hosting providers operate; in such cases we require providers to maintain appropriate security safeguards.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email or in-app notification at least 14 days before taking effect. Continued use of the Service after that date constitutes acceptance of the updated policy.

14. Contact

For privacy questions, data access/deletion requests, or breach notifications, contact us at: anadib1010@gmail.com. We aim to respond within 5 business days.


This document was last reviewed in August 2026 (Version 1.1). This policy is specific to the Accounting, Billing, Invoicing, Inventory, and Banking portion of Accrut and is separate from the HR/payroll module's policy.