Privacy Policy
At Cashtro, your privacy is not an afterthought β it is foundational to how we build our financial operating system. This policy details exactly what data we collect, why we collect it, and the comprehensive measures we take to protect it.
1Definitions
Throughout this policy, the following terms carry the meanings described below:
- "Cashtro", "we", "our", "us" β Cashtro and its parent company, operators, and affiliates offering the Cashtro platform.
- "Platform" β The Cashtro mobile application (Android & iOS), web application, admin portal, and associated APIs.
- "User", "you" β Any individual who creates an account or uses the Platform.
- "Personal Data" β Any information that directly or indirectly identifies you as an individual.
- "Financial Data" β Transactions, cashbooks, budgets, goals, invoices, receipts, and other financial records you enter into the Platform.
- "Processing" β Any operation performed on data including collection, storage, analysis, sharing, or deletion.
- "Consent" β A freely given, specific, informed, and unambiguous indication of your agreement to data processing.
- "DPDP Act" β India's Digital Personal Data Protection Act, 2023.
2Information We Collect
A. Account & Identity Information
- Full name, email address, phone number (for OTP verification)
- Hashed & salted passwords (we never store plaintext passwords)
- Profile photo (optional, uploaded by you)
- Business name, GSTIN, PAN number (optional, for GST invoicing features)
- Registered address (for invoice generation)
B. Financial Records (Entered by You)
- Transactions β amounts, dates, notes, categories, payment modes
- Cashbook titles, descriptions, and member invitations
- Budget limits, goal names, target amounts, and deadlines
- Invoice details β items, quantities, tax rates, client information
- Receipt images and documents (encrypted in your private vault)
- Notes and comments attached to transactions
- Chat messages within shared cashbooks
- Scheduler rules and automation configurations
C. Usage & Technical Data
- Device type, operating system, app version
- Browser type and version (web users)
- IP address (for authentication security)
- Push notification tokens (FCM/APNs)
- Session identifiers and JWT tokens
- Crash logs and error reports (stripped of financial content)
- Feature usage analytics (which features are used, frequency)
D. Cookies & Local Storage
We use cookies and browser local storage to maintain your session, remember your preferences (theme, language, dashboard layout), and for analytics. See our Cookie Policy for full details.
E. AI & Receipt Scanning Data
When you use AI-powered features (receipt scanning, smart categorization, financial insights), receipt images and transaction context are temporarily processed by AI services. Images are processed ephemerally unless you explicitly save them to your account. See Section 5 for full AI data safety details.
3Why We Collect Your Data
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Account creation & authentication | Name, email, phone, password | Contract performance |
| Cloud sync & cross-device access | All user-entered data | Contract performance |
| Invoice & GST report generation | PAN, GSTIN, business info | Contract performance |
| AI-powered financial insights | Anonymized transaction patterns | Consent |
| Push notifications & email alerts | Notification tokens, email | Consent |
| Fraud prevention & security | IP, device, session data | Legitimate interest |
| Scheduler & automation | Scheduler rules, timing data | Contract performance |
| Customer support | Account info, support ticket content | Contract performance |
| Product improvement & analytics | Anonymized usage data | Legitimate interest |
| Legal compliance | Identity, financial records (if ordered) | Legal obligation |
4What Cashtro Does Not Do
- β We do NOT sell, rent, or auction your personal information to third parties.
- β We do NOT sell your financial transaction data to advertisers, data brokers, or analytics firms.
- β We do NOT publicly expose your private transactions, cashbooks, or financial records.
- β We do NOT use your private financial records to train public AI models.
- β We do NOT share your data with third parties except as strictly necessary to provide the services you requested, or where required by law.
- β We do NOT allow advertising networks to track you across the Platform.
- β We do NOT share your data with government agencies without a valid court order or legal mandate, except as required under applicable Indian law.
5AI Features & Data Safety
Cashtro uses AI to power receipt scanning, smart categorization, financial insights, and chat assistant features. Here is exactly how your data is handled in AI workflows:
Receipt & Document Scanning
- Images are transmitted via encrypted TLS connections to AI processing services (e.g., Google Gemini Vision API).
- Ephemeral Processing: Images are analyzed only to extract structured fields (merchant, date, amount, tax). They are discarded immediately after extraction unless you explicitly choose to save them.
- No Model Training: Your private receipts and financial documents are NEVER used to train, fine-tune, or improve any public AI model.
Financial Insights & Smart Categorization
- Transaction patterns are analyzed to generate personalized insights, budget alerts, and spending summaries.
- AI insights are informational only β they do not constitute financial advice.
- Aggregated, anonymized data may be used to improve our own internal categorization models.
AI Chat Assistant
- Conversations with the AI assistant are processed to provide responses. Conversation history is stored in your account for continuity.
- AI providers process queries under their own privacy policies (see Section 6) with data processing agreements in place.
6Third-Party Services & Data Sharing
We use trusted sub-processors to provide our services. Each receives only the minimum data necessary for their function:
| Service | Purpose | Data Shared |
|---|---|---|
| Cloud Infrastructure (AWS/Hetzner) | Hosting encrypted databases & storage | All encrypted user data |
| Email Provider (SendGrid/AWS SES) | Transactional emails, OTPs, reports | Email address, notification content |
| Push Notifications (FCM/APNs) | Mobile push notifications | Device token, notification payload |
| AI Services (Google Gemini API) | Receipt scanning, insights | Receipt images (ephemeral), anonymized patterns |
| Payment Gateway (Razorpay) | Subscription payments | Name, email, phone, transaction amount |
| Analytics (Internal) | Product improvement | Anonymized usage metrics only |
7Your Rights Under DPDP Act 2023
Under India's Digital Personal Data Protection Act 2023 and principles of data sovereignty, you have the following rights:
π View Your Data
Access all personal and financial data stored in your account at any time.
βοΈ Correct Information
Update incorrect personal information directly from your Profile Settings.
π₯ Download & Export
Export transactions as CSV/PDF, download invoices, and request a full data copy.
ποΈ Delete Account
Permanently delete your account and all associated data from Settings > Account > Delete.
π Withdraw Consent
Opt out of non-essential data processing such as analytics and AI features.
π΅ Manage Notifications
Control all push, email, and in-app notification preferences granularly.
πͺ Manage Cookies
Accept or decline non-essential cookies from our Cookie Preference Center.
π Nominate a Representative
Under DPDP, you may nominate a person to exercise rights on your behalf.
To exercise any right, email us at legal@cashtro.in. We will respond within 30 days as required by applicable law. Account deletion requests are processed within 30 days, after which personal identifiers are permanently purged.
8Data Security Measures
We implement industry-standard technical and organizational security measures to protect your data:
π AES-256 Encryption
All sensitive data fields (passwords, PAN, GSTIN, financial records) are encrypted at rest.
π TLS 1.3 in Transit
All data transmitted between your device and our servers is protected by TLS 1.3 encryption.
π Secure Authentication
JWT-based session tokens, refresh token rotation, and optional two-factor authentication.
π¦ Rate Limiting
Brute-force protection on all authentication endpoints with automated lockout.
π Audit Logging
All administrative access and sensitive operations are logged with immutable audit trails.
ποΈ Access Controls
Strict role-based access controls (RBAC) ensure staff can only access data necessary for their function.
πΎ Automated Backups
Encrypted daily backups with point-in-time recovery capabilities.
π Monitoring
Continuous infrastructure monitoring for anomalies, intrusions, and unauthorized access attempts.
9Data Retention
We retain your data only as long as necessary to provide our services or as required by law. See our full Data Retention Policy for complete details.
| Data Category | Retention Period | Reason |
|---|---|---|
| Account & identity info | Until account deletion + 30 days | Service provision |
| Financial records & transactions | Until deletion request or 7 years (GST) | Legal compliance (GST Act) |
| Invoices & GST records | 7 years from invoice date | Indian tax law requirement |
| Chat messages | Until deletion request | User preference |
| Crash logs & technical data | 90 days | Debugging & quality |
| Support tickets | 3 years after closure | Dispute resolution |
| Anonymized analytics | Indefinitely (not personal data) | Product improvement |
10Children's Privacy
Cashtro is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that a minor has created an account, we will take steps to delete the account and associated data promptly. If you believe a minor's data has been collected, contact us at legal@cashtro.in.
11Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page.
- Send an in-app notification and/or email to registered users.
- In cases of significant changes affecting your rights, seek your renewed consent.
Continued use of the Platform after changes take effect constitutes acceptance of the revised policy.
12Contact Our Privacy Officer
For privacy-related inquiries, data requests, or complaints:
Cashtro Privacy & Grievance Officer
π§ Privacy Requests: legal@cashtro.in
π Security Concerns: legal@cashtro.in
βοΈ Legal & Compliance: legal@cashtro.in
π Support: support@cashtro.in
β±οΈ Response Time: Within 30 days for formal data requests; within 72 hours for security incidents.
If you are not satisfied with our response, you may approach the appropriate Data Protection Board as constituted under the DPDP Act 2023 once operational.