Privacy policy
Effective May 26, 2026
399apps ("we", "us") helps Indian businesses run accounting, GST and inventory operations. This page explains what data we collect, why, and how it's looked after.
1. What we collect
Account details (name, email, mobile, organisation name and GSTIN), transactional data you enter (customers, vendors, invoices, payments, line items), and operational telemetry (request logs, error traces, sign-in events) used to keep the service running and secure.
2. Why we collect it
To deliver the bookkeeping, invoicing, tax-return and reporting features you signed up for; to enforce statutory record-keeping requirements under Indian GST and the Income-tax Act; and to investigate abuse, fraud and security incidents.
3. Where data lives
Customer data is hosted in AWS Asia Pacific (Mumbai / ap-south-1). Backups are encrypted and retained for 30 days. We do not sell personal data to third parties.
4. Who can see it
Only the organisation members you invite, and a small number of 399apps engineers acting under audited break-glass procedures during incident response. Accounts are authenticated in-house with encrypted passwords; payment links are routed through Razorpay; transactional email goes through Amazon SES — see those providers' own privacy notices for sub-processor detail.
5. Your rights
You can export every record we hold about your organisation as JSON from Settings → Export data. You can permanently delete the organisation and all its records from Settings → Close organisation. Both flows are self-serve and require no support ticket.
6. Contact
Privacy questions, deletion requests and complaints: email [email protected]. We aim to respond within 5 working days.