Security & Privacy

Privacy Policy

Effective Date: 18 July 2026 | Last Updated: 18 July 2026

Provider details

Sanshray IT Solutions LLP ("Aarthic", "we", "us", "our")

  • LLP Identification Number (LLPIN): ABZ-0784
  • Registered office: Navdurga Society, Patan, Gujarat, India – 384265
  • Customer care email: support@aarthic.com
  • Customer care telephone: +91 7016272752
  • Customer care hours: Monday–Friday, 10:00–18:00 IST

This Privacy Policy explains how Sanshray IT Solutions LLP ("Aarthic", "we", "us", "our") collects, uses, stores, processes, protects, shares and retains Personal Data and Business Data when you access or use the Aarthic platform, including our website, mobile applications, web application, APIs and related services (the "Services").

We process Personal Data in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 and rules made thereunder, and other applicable Indian law.

1. Scope

This Policy applies to all users of Aarthic, including individual business owners, sole proprietors, partnerships, companies, organisations, employees authorised to use an Account, Authorised Third Parties such as accountants, website visitors, and customers on free or paid plans. It applies whenever you visit our website, register an Account, use our applications, subscribe to a plan, contact support, participate in surveys or promotions, or otherwise interact with the Services.

This Policy does not apply to third-party websites, applications or services governed by their own privacy policies.

2. Our Role: Data Fiduciary and Data Processor

Aarthic acts in two distinct capacities:

(a) As Data Fiduciary

For Personal Data we collect directly to operate our business — your Account registration details, billing and subscription information, support communications, and technical and usage data — Sanshray IT Solutions LLP is the Data Fiduciary and determines the purposes and means of processing. This Policy describes that processing.

(b) As Data Processor

For Personal Data contained within Business Data that you upload or create — including information about your customers, suppliers and employees — you are the Data Fiduciary and Aarthic is a Data Processor acting on your instructions. We process that data only to provide, secure, support and maintain the Services, under the Data Processing Terms in Schedule A to our Terms & Conditions.

If you are an individual whose personal data was uploaded to Aarthic by a business using our Services (for example, if you are a customer or employee of that business), your rights are exercised in the first instance against that business as the Data Fiduciary. We will assist that business in responding to you, and you may also contact our Grievance Officer, who will direct your request appropriately.

3. Information We Collect

3.1 Account information

Full name, business or shop name, email address, mobile number, login credentials, subscription information and account preferences. Passwords are never stored in plain text; they are hashed using industry-standard cryptographic algorithms.

3.2 Business Data

Sales and purchase invoices, quotations, estimates, credit and debit notes, inventory records, product catalogues, barcode information, customer and supplier information, employee information where you use payroll features, expense and payment records, accounting entries, cashbook records, GST and tax records, financial reports, business documents, attachments, images and notes.

Your Business Data remains your property. Aarthic does not acquire ownership of it. We process it as a Data Processor in accordance with Clause 2(b).

3.3 Payment information

Payments are processed by authorised payment service providers such as Razorpay. We do not store complete card numbers, CVV, UPI PIN, net banking credentials or payment authentication credentials. We retain transaction references, amounts, dates and status for accounting, tax and dispute-resolution purposes.

3.4 Technical information

IP address, device type and model, operating system, browser type and version, application version, device identifiers, language preferences, login and logout timestamps, session information, crash reports, error logs, diagnostic information, network information and usage statistics.

3.5 Communications and usage

Information you provide when contacting support, submitting feedback, reporting bugs, requesting features, participating in surveys or responding to emails; and information about how the Services are used, including features accessed, frequency of use, navigation behaviour, subscription usage, device sessions and login history.

4. How We Use Your Information

We use the information we collect to: create and manage your Account; provide access to the Services; process subscriptions and payments; deliver requested features; manage invoices, inventory, accounting and business records; synchronise information across devices; provide customer support; improve the performance, stability and usability of the Services; detect, prevent and investigate fraud, abuse, security incidents and unauthorised access; maintain audit logs and operational records; comply with legal, taxation, GST, accounting and regulatory obligations; and send account-related communications including security alerts, payment confirmations, pre-debit notifications, subscription notices, maintenance notifications and legal updates.

With your consent, we may also send product updates, feature announcements, educational content and promotional communications. You may withdraw that consent at any time without affecting essential service-related notifications.

We use data to improve the Services only in aggregated and de-identified form from which no individual and no customer account can reasonably be re-identified. We do not use your Business Data to train artificial intelligence or machine-learning models, and we do not sell, rent or trade Personal Data or Business Data.

5. Legal Basis for Processing

Under the DPDP Act we process Personal Data on the following bases:

(a) Consent — section 6

Where you provide Personal Data to create an Account, subscribe, or opt in to promotional communications, we process it on the basis of your consent, given by a clear affirmative action. Our consent notice describes the Personal Data collected and the purpose of processing, and is available in English and in such other languages as required under the DPDP Act. You may withdraw consent at any time as described in Clause 12.

(b) Certain legitimate uses — section 7

We process Personal Data without separate consent only where a specified legitimate use applies, including:

  • where you have voluntarily provided Personal Data to us for a specified purpose and have not indicated that you object to its use for that purpose — for example, information you supply when contacting support;
  • for compliance with any judgment, decree or order, or with any law in force in India, including taxation, GST, accounting and record-keeping obligations;
  • for the performance of any function under law, or the provision of any service or benefit, where required.

Where we rely on your consent, withdrawing it may affect our ability to provide some or all of the Services. Where processing is required to comply with a legal obligation, we may continue that processing after withdrawal to the extent the law requires.

Processing of Personal Data contained in Business Data is carried out on the instructions of the Customer, who is responsible for establishing the lawful basis for it.

6. How We Share Your Information

We do not sell, rent, trade or otherwise commercially exploit Personal Data or Business Data. We share information only as described below.

6.1 Service providers (Data Processors)

We engage service providers to assist with cloud infrastructure and hosting, payment processing, email and SMS delivery, push notifications, customer support, security and system monitoring, error reporting, backup and disaster recovery, and analytics necessary to improve the Services. Each is contractually required to process data only on our instructions, implement appropriate security measures, maintain confidentiality, and comply with applicable data protection obligations.

6.2 Payment service providers

Payments are processed by authorised providers including Razorpay. Payment information is transmitted directly to the provider. We do not receive or store complete card numbers, CVV, UPI PIN, net banking passwords or authentication credentials.

6.3 Legal compliance

We may disclose information where necessary to comply with applicable law; respond to lawful requests from courts or government authorities; comply with tax or GST requirements; protect our legal rights; enforce our agreements; investigate fraud or unlawful activity; or protect the safety, rights or property of Aarthic, our users or the public.

6.4 Business transfers

If Aarthic undergoes a merger, acquisition, restructuring, investment transaction, sale of assets or similar transaction, information may be transferred to the successor entity subject to applicable law. Any successor will remain bound by obligations substantially consistent with this Policy.

6.5 Professional advisors

Where reasonably necessary, information may be shared with legal counsel, auditors, accountants, tax advisors and insurers, subject to confidentiality obligations.

7. Where Your Data Is Stored, and Cross-Border Transfers

Personal Data and Business Data are stored on servers located in Hostinger.

Certain sub-processors may process limited data outside India. Where Personal Data is transferred outside India, we do so in accordance with section 16 of the DPDP Act and do not transfer Personal Data to any country restricted by the Central Government by notification.

We require appropriate contractual protections for any cross-border processing.

8. Cookies and Similar Technologies

Our website and web application use cookies and similar technologies to remember login sessions, maintain authenticated sessions, remember preferences, improve performance, analyse usage patterns, detect security threats and prevent fraud.

Aarthic does not use third-party advertising cookies for behavioural advertising. You may manage or disable cookies through your browser settings; disabling certain cookies may affect the functionality of parts of the Services.

9. Data Security

We implement commercially reasonable administrative, technical and organisational safeguards designed to protect Personal Data and Business Data against unauthorised access, disclosure, alteration, destruction or misuse. These include:

  • HTTPS/TLS encryption for data transmitted over public networks;
  • secure password hashing using industry-standard cryptographic algorithms;
  • role-based access control and least-privilege access;
  • tenant isolation, so that each business's data is segregated from every other business's data;
  • authentication and authorisation controls, including scoped access for Authorised Third Parties;
  • audit logging of access and changes, attributable to the acting user and business;
  • encrypted backups where applicable, infrastructure monitoring, firewalling and server hardening;
  • secure development practices, security testing and periodic assessment;
  • monitoring for suspicious activity.

No method of transmission or electronic storage can guarantee absolute security. You are responsible for maintaining the confidentiality of your credentials, using strong passwords, protecting the devices you use, granting third-party access only where appropriate, and promptly notifying us of suspected unauthorised access.

10. Security Incidents and Breach Notification

If we become aware of a personal data breach we will promptly investigate, take containment and remedial measures, and assess the impact on affected individuals.

In accordance with the DPDP Act, we will notify the Data Protection Board of India and each affected Data Principal of any personal data breach, in the form and within the time prescribed. No minimum severity threshold applies to this obligation.

Where an incident falls within the categories specified by the Indian Computer Emergency Response Team (CERT-In), we will report it to CERT-In within six (6) hours of becoming aware of it, as required by the CERT-In Directions dated 28 April 2022.

We maintain logs of our information and communication technology systems for a rolling period of 180 days within India, as required by those Directions, and will make them available to CERT-In when lawfully directed.

Where we act as Data Processor for Business Data, we will notify the affected Customer without undue delay and in any event within seventy-two (72) hours of becoming aware of a breach affecting their data, so that the Customer can meet its own obligations.

11. Data Retention

We retain Personal Data and Business Data only for as long as necessary for the purposes for which it was collected. Specifically:

  • Business Data: retained for the life of your Account, and for at least thirty (30) days after termination to allow export, after which it is deleted;
  • Account and profile data: deleted or anonymised within 90 days of a verified deletion request, subject to the exceptions below;
  • Financial, invoicing, GST and taxation records: retained for 8 years, as required under the Companies Act, 2013, the Central Goods and Services Tax Act, 2017 and the Income-tax Act, 1961;
  • Security and audit logs: retained for 180 days in accordance with the CERT-In Directions, and longer where required for an ongoing investigation;
  • Support communications: retained for 1 months;
  • Backups: purged on a rolling cycle, with deleted data removed from backups within 30 days.

Retention after Subscription expiry

If your paid Subscription expires or is cancelled, your Business Data is not deleted. We continue to store it so that you can reactivate your Subscription and resume use, and to meet our own legal and record-keeping obligations, for the periods set out above. Continued retention of Business Data does not itself entitle you to continued access to premium features; your ability to export your Business Data following expiry is governed by Clause 20 of our Terms & Conditions, which provides an export period of at least seven (7) days after expiry and an open route to obtain your data at any time thereafter where you need it to meet an obligation under applicable law.

Where information is retained beyond the periods above, it is retained only where required by applicable law, to perform or enforce a contract, for the resolution of a dispute or legal claim, for the prevention or investigation of fraud or a security incident, or for another purpose expressly permitted under applicable law. It is processed only for that purpose until the applicable period expires, after which it is securely deleted or anonymised.

12. Your Rights

Subject to the DPDP Act and other applicable law, you have the right to:

  • obtain a summary of the Personal Data we process about you and the processing activities undertaken;
  • request correction, completion or updating of inaccurate or incomplete Personal Data;
  • request erasure of your Personal Data, subject to our legal retention obligations;
  • withdraw consent where processing is based on consent;
  • nominate another individual to exercise your rights in the event of your death or incapacity;
  • obtain redressal of grievances, and to escalate to the Data Protection Board of India if unsatisfied with our response.

To exercise any right, contact our Grievance Officer using the details in Clause 14. We may request reasonable information to verify your identity before acting. We will respond within the timelines set out in Clause 14.

Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal, and may affect our ability to provide some or all of the Services.

13. Account Deletion

You may request deletion of your Account by contacting support. Before doing so, export any Business Data you wish to retain. Upon a verified deletion request, your access will be disabled and your Personal Data and Business Data deleted or anonymised in accordance with Clause 11, except where retention is required for legal compliance, taxation and GST obligations, accounting, fraud prevention, dispute resolution, enforcement of legal rights, security investigations or audit.

14. Grievance Officer and Response Timelines

If you have a concern about how we collect, process, store, use, disclose or protect your Personal Data, you may contact our Grievance Officer:

  • Name: Harsh Shah
  • Designation: Grievance Officer, Sanshray IT Solutions LLP
  • Email: support@aarthic.com
  • Telephone: +91 7016272752
  • Address: Navdurga Society, Patan, Gujarat, India

Please include your registered email address, contact information, a description of your concern, and any supporting documents.

Our timelines

  • We will acknowledge your grievance within twenty-four (24) hours of receipt.
  • We will resolve it within fifteen (15) days of receipt, in accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
  • For consumer complaints under the Consumer Protection (E-Commerce) Rules, 2020, we will acknowledge within forty-eight (48) hours and redress within one (1) month.

If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India.

15. Children's Privacy

The Services are intended for business users aged 18 and over and are not directed at children. We do not knowingly collect Personal Data of a child. If we become aware that we have collected such data without verifiable consent of a parent or lawful guardian, we will delete it in accordance with the DPDP Act. Parents or guardians may contact our Grievance Officer.

16. Records of Consent

We maintain records of the consent you provide, including the version of this Policy and the Terms & Conditions accepted, the date and time of acceptance, and the identifier of the Account through which acceptance was given.

17. Changes to this Policy

We may update this Policy to reflect changes in applicable law, the Services, security practices or business requirements. The updated Policy will be published with a revised "Last Updated" date. Where changes materially affect your rights, we will give at least thirty (30) days' notice through the Services or by email before they take effect.

18. Governing Law and Jurisdiction

This Policy is governed by the laws of India. Subject to the dispute resolution provisions of our Terms & Conditions, the courts at Patan, Gujarat, India shall have exclusive jurisdiction. Nothing in this Policy limits any non-waivable statutory right, including the right to approach the Data Protection Board of India or a Consumer Commission.

19. Interpretation and Severability

Headings are for convenience only. Words in the singular include the plural and vice versa; references to any law include amendments and successor legislation. If any provision is held invalid, illegal or unenforceable, the remaining provisions continue in full force and effect.

20. Contact Us

Sanshray IT Solutions LLP — Navdurga Society, Patan, Gujarat, India

General enquiries: support@aarthic.com

This Policy should be read together with our Terms & Conditions (including Schedule A — Data Processing Terms) and our Refund & Cancellation Policy. Where this Policy conflicts with applicable law, applicable law prevails.