Effective Date: 18 July 2026 | Last Updated: 18 July 2026
Provider details
Sanshray IT Solutions LLP ("Aarthic", "we", "us", "our")
This Privacy Policy explains how Sanshray IT Solutions LLP ("Aarthic", "we", "us", "our") collects, uses, stores, processes, protects, shares and retains Personal Data and Business Data when you access or use the Aarthic platform, including our website, mobile applications, web application, APIs and related services (the "Services").
We process Personal Data in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 and rules made thereunder, and other applicable Indian law.
This Policy applies to all users of Aarthic, including individual business owners, sole proprietors, partnerships, companies, organisations, employees authorised to use an Account, Authorised Third Parties such as accountants, website visitors, and customers on free or paid plans. It applies whenever you visit our website, register an Account, use our applications, subscribe to a plan, contact support, participate in surveys or promotions, or otherwise interact with the Services.
This Policy does not apply to third-party websites, applications or services governed by their own privacy policies.
Aarthic acts in two distinct capacities:
(a) As Data Fiduciary
For Personal Data we collect directly to operate our business — your Account registration details, billing and subscription information, support communications, and technical and usage data — Sanshray IT Solutions LLP is the Data Fiduciary and determines the purposes and means of processing. This Policy describes that processing.
(b) As Data Processor
For Personal Data contained within Business Data that you upload or create — including information about your customers, suppliers and employees — you are the Data Fiduciary and Aarthic is a Data Processor acting on your instructions. We process that data only to provide, secure, support and maintain the Services, under the Data Processing Terms in Schedule A to our Terms & Conditions.
If you are an individual whose personal data was uploaded to Aarthic by a business using our Services (for example, if you are a customer or employee of that business), your rights are exercised in the first instance against that business as the Data Fiduciary. We will assist that business in responding to you, and you may also contact our Grievance Officer, who will direct your request appropriately.
3.1 Account information
Full name, business or shop name, email address, mobile number, login credentials, subscription information and account preferences. Passwords are never stored in plain text; they are hashed using industry-standard cryptographic algorithms.
3.2 Business Data
Sales and purchase invoices, quotations, estimates, credit and debit notes, inventory records, product catalogues, barcode information, customer and supplier information, employee information where you use payroll features, expense and payment records, accounting entries, cashbook records, GST and tax records, financial reports, business documents, attachments, images and notes.
Your Business Data remains your property. Aarthic does not acquire ownership of it. We process it as a Data Processor in accordance with Clause 2(b).
3.3 Payment information
Payments are processed by authorised payment service providers such as Razorpay. We do not store complete card numbers, CVV, UPI PIN, net banking credentials or payment authentication credentials. We retain transaction references, amounts, dates and status for accounting, tax and dispute-resolution purposes.
3.4 Technical information
IP address, device type and model, operating system, browser type and version, application version, device identifiers, language preferences, login and logout timestamps, session information, crash reports, error logs, diagnostic information, network information and usage statistics.
3.5 Communications and usage
Information you provide when contacting support, submitting feedback, reporting bugs, requesting features, participating in surveys or responding to emails; and information about how the Services are used, including features accessed, frequency of use, navigation behaviour, subscription usage, device sessions and login history.
We use the information we collect to: create and manage your Account; provide access to the Services; process subscriptions and payments; deliver requested features; manage invoices, inventory, accounting and business records; synchronise information across devices; provide customer support; improve the performance, stability and usability of the Services; detect, prevent and investigate fraud, abuse, security incidents and unauthorised access; maintain audit logs and operational records; comply with legal, taxation, GST, accounting and regulatory obligations; and send account-related communications including security alerts, payment confirmations, pre-debit notifications, subscription notices, maintenance notifications and legal updates.
With your consent, we may also send product updates, feature announcements, educational content and promotional communications. You may withdraw that consent at any time without affecting essential service-related notifications.
We use data to improve the Services only in aggregated and de-identified form from which no individual and no customer account can reasonably be re-identified. We do not use your Business Data to train artificial intelligence or machine-learning models, and we do not sell, rent or trade Personal Data or Business Data.
Under the DPDP Act we process Personal Data on the following bases:
(a) Consent — section 6
Where you provide Personal Data to create an Account, subscribe, or opt in to promotional communications, we process it on the basis of your consent, given by a clear affirmative action. Our consent notice describes the Personal Data collected and the purpose of processing, and is available in English and in such other languages as required under the DPDP Act. You may withdraw consent at any time as described in Clause 12.
(b) Certain legitimate uses — section 7
We process Personal Data without separate consent only where a specified legitimate use applies, including:
Where we rely on your consent, withdrawing it may affect our ability to provide some or all of the Services. Where processing is required to comply with a legal obligation, we may continue that processing after withdrawal to the extent the law requires.
Processing of Personal Data contained in Business Data is carried out on the instructions of the Customer, who is responsible for establishing the lawful basis for it.
We do not sell, rent, trade or otherwise commercially exploit Personal Data or Business Data. We share information only as described below.
6.1 Service providers (Data Processors)
We engage service providers to assist with cloud infrastructure and hosting, payment processing, email and SMS delivery, push notifications, customer support, security and system monitoring, error reporting, backup and disaster recovery, and analytics necessary to improve the Services. Each is contractually required to process data only on our instructions, implement appropriate security measures, maintain confidentiality, and comply with applicable data protection obligations.
6.2 Payment service providers
Payments are processed by authorised providers including Razorpay. Payment information is transmitted directly to the provider. We do not receive or store complete card numbers, CVV, UPI PIN, net banking passwords or authentication credentials.
6.3 Legal compliance
We may disclose information where necessary to comply with applicable law; respond to lawful requests from courts or government authorities; comply with tax or GST requirements; protect our legal rights; enforce our agreements; investigate fraud or unlawful activity; or protect the safety, rights or property of Aarthic, our users or the public.
6.4 Business transfers
If Aarthic undergoes a merger, acquisition, restructuring, investment transaction, sale of assets or similar transaction, information may be transferred to the successor entity subject to applicable law. Any successor will remain bound by obligations substantially consistent with this Policy.
6.5 Professional advisors
Where reasonably necessary, information may be shared with legal counsel, auditors, accountants, tax advisors and insurers, subject to confidentiality obligations.
Personal Data and Business Data are stored on servers located in Hostinger.
Certain sub-processors may process limited data outside India. Where Personal Data is transferred outside India, we do so in accordance with section 16 of the DPDP Act and do not transfer Personal Data to any country restricted by the Central Government by notification.
We require appropriate contractual protections for any cross-border processing.
Our website and web application use cookies and similar technologies to remember login sessions, maintain authenticated sessions, remember preferences, improve performance, analyse usage patterns, detect security threats and prevent fraud.
Aarthic does not use third-party advertising cookies for behavioural advertising. You may manage or disable cookies through your browser settings; disabling certain cookies may affect the functionality of parts of the Services.
We implement commercially reasonable administrative, technical and organisational safeguards designed to protect Personal Data and Business Data against unauthorised access, disclosure, alteration, destruction or misuse. These include:
No method of transmission or electronic storage can guarantee absolute security. You are responsible for maintaining the confidentiality of your credentials, using strong passwords, protecting the devices you use, granting third-party access only where appropriate, and promptly notifying us of suspected unauthorised access.
If we become aware of a personal data breach we will promptly investigate, take containment and remedial measures, and assess the impact on affected individuals.
In accordance with the DPDP Act, we will notify the Data Protection Board of India and each affected Data Principal of any personal data breach, in the form and within the time prescribed. No minimum severity threshold applies to this obligation.
Where an incident falls within the categories specified by the Indian Computer Emergency Response Team (CERT-In), we will report it to CERT-In within six (6) hours of becoming aware of it, as required by the CERT-In Directions dated 28 April 2022.
We maintain logs of our information and communication technology systems for a rolling period of 180 days within India, as required by those Directions, and will make them available to CERT-In when lawfully directed.
Where we act as Data Processor for Business Data, we will notify the affected Customer without undue delay and in any event within seventy-two (72) hours of becoming aware of a breach affecting their data, so that the Customer can meet its own obligations.
We retain Personal Data and Business Data only for as long as necessary for the purposes for which it was collected. Specifically:
Retention after Subscription expiry
If your paid Subscription expires or is cancelled, your Business Data is not deleted. We continue to store it so that you can reactivate your Subscription and resume use, and to meet our own legal and record-keeping obligations, for the periods set out above. Continued retention of Business Data does not itself entitle you to continued access to premium features; your ability to export your Business Data following expiry is governed by Clause 20 of our Terms & Conditions, which provides an export period of at least seven (7) days after expiry and an open route to obtain your data at any time thereafter where you need it to meet an obligation under applicable law.
Where information is retained beyond the periods above, it is retained only where required by applicable law, to perform or enforce a contract, for the resolution of a dispute or legal claim, for the prevention or investigation of fraud or a security incident, or for another purpose expressly permitted under applicable law. It is processed only for that purpose until the applicable period expires, after which it is securely deleted or anonymised.
Subject to the DPDP Act and other applicable law, you have the right to:
To exercise any right, contact our Grievance Officer using the details in Clause 14. We may request reasonable information to verify your identity before acting. We will respond within the timelines set out in Clause 14.
Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal, and may affect our ability to provide some or all of the Services.
You may request deletion of your Account by contacting support. Before doing so, export any Business Data you wish to retain. Upon a verified deletion request, your access will be disabled and your Personal Data and Business Data deleted or anonymised in accordance with Clause 11, except where retention is required for legal compliance, taxation and GST obligations, accounting, fraud prevention, dispute resolution, enforcement of legal rights, security investigations or audit.
If you have a concern about how we collect, process, store, use, disclose or protect your Personal Data, you may contact our Grievance Officer:
Please include your registered email address, contact information, a description of your concern, and any supporting documents.
Our timelines
If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India.
The Services are intended for business users aged 18 and over and are not directed at children. We do not knowingly collect Personal Data of a child. If we become aware that we have collected such data without verifiable consent of a parent or lawful guardian, we will delete it in accordance with the DPDP Act. Parents or guardians may contact our Grievance Officer.
We maintain records of the consent you provide, including the version of this Policy and the Terms & Conditions accepted, the date and time of acceptance, and the identifier of the Account through which acceptance was given.
We may update this Policy to reflect changes in applicable law, the Services, security practices or business requirements. The updated Policy will be published with a revised "Last Updated" date. Where changes materially affect your rights, we will give at least thirty (30) days' notice through the Services or by email before they take effect.
This Policy is governed by the laws of India. Subject to the dispute resolution provisions of our Terms & Conditions, the courts at Patan, Gujarat, India shall have exclusive jurisdiction. Nothing in this Policy limits any non-waivable statutory right, including the right to approach the Data Protection Board of India or a Consumer Commission.
Headings are for convenience only. Words in the singular include the plural and vice versa; references to any law include amendments and successor legislation. If any provision is held invalid, illegal or unenforceable, the remaining provisions continue in full force and effect.
Sanshray IT Solutions LLP — Navdurga Society, Patan, Gujarat, India
General enquiries: support@aarthic.com
This Policy should be read together with our Terms & Conditions (including Schedule A — Data Processing Terms) and our Refund & Cancellation Policy. Where this Policy conflicts with applicable law, applicable law prevails.