Trust & Data Protection

Privacy Policy

At BaniyaDesk, your financial privacy is fundamental. We utilize zero-knowledge principles, passwordless OTP architecture, and end-to-end data encryption so your records remain exclusively yours.

Last Modified: September 24, 2026256-Bit SSL EnforcedGDPR & CCPA Compliant

1. Overview & Commitment

Welcome to BaniyaDesk (“we”, “our”, or “us”). This Privacy Policy explains in straightforward terms how we collect, handle, protect, and safeguard the data generated when you visit our website, utilize our web-based invoice builder, and interact with our services.

We believe that financial information deserves the highest echelon of security. We never monetize your client lists, line items, or billing figures, and we do not sell or lease your private data to advertising networks.

2. Information We Collect

To provide our frictionless invoicing platform, we collect only the essential elements necessary to authenticate your workspace and render your invoices:

A. Account Credentials

Your registered email address, name, and temporary one-time password (OTP) verification hashes. We never ask for or store static account passwords.

B. Business & Invoicing Data

Company name, business address, tax ID/GSTIN/VAT identifiers, logos, client contact entries, line item descriptions, totals, bank details, and UPI/QR payment payloads.

C. Technical & Diagnostic Telemetry

IP address, browser type, operating system metadata, and error diagnostics to safeguard against automated spam attacks and brute force OTP abuse.

3. How We Use Your Data

Your information is strictly utilized to:

  • Generate, render, format, and export high-resolution PDF invoices and shareable receipts.
  • Deliver single-use OTP verification codes to your inbox via Amazon Simple Email Service (SES).
  • Maintain your client directory, recurring templates, and tax preference configurations.
  • Enforce platform security, detect rate-limit breaches, and prevent unauthorized account access.

4. Passwordless OTP & Security Architecture

Conventional password databases represent the single greatest vulnerability for web platforms. BaniyaDesk operates on a 100% passwordless authentication model:

Ephemerality

All verification codes expire strictly after 5 minutes and become invalid immediately upon use.

Rate-Limiting & Lockouts

Brute-force attempts are thwarted with automated IP and identifier cooldowns after 5 incorrect inputs.

Cryptographic Hashing

OTP values are transformed via secure cryptographic one-way hashing before database writes.

Encrypted Transport

All browser-server communication is encrypted with TLS 1.3 / 256-bit SSL protocols.

5. Data Ownership & Non-Disclosure

You maintain 100% intellectual property and commercial ownership of every invoice, client contact, logo asset, and price quote created inside your workspace.

BaniyaDesk will never disclose, sublicense, aggregate for third-party resale, or distribute your financial records to competitors or advertisers under any circumstance, unless strictly compelled by a lawful and verified court order.

6. Cookies & Tracking Policy

We maintain a lean cookie footprint. We do NOT use invasive cross-site advertising cookies, Facebook Pixels, or third-party behavioral trackers.

Essential Session Cookies: Used strictly to authenticate your active workspace session and maintain invoice builder state between pages.

Local Storage: Utilized on your client browser to store invoice draft caches, user preferences (e.g. selected currency, template choice), and UI themes for lightning-fast performance.

7. Third-Party Service Providers

We collaborate only with tier-1 enterprise infrastructure providers that guarantee industry-leading data protection standards:

  • Amazon Web Services (AWS SES & S3): Dispatches transactional OTP emails and stores encrypted logo assets with high durability and security.
  • MongoDB Atlas: Enterprise-managed cloud database operating with encryption-at-rest and strict VPC network isolation.
  • Vercel & Cloudflare: Edge compute and CDN caching infrastructure guaranteeing DDoS mitigation and fast worldwide SSL routing.

8. Your Privacy Rights (GDPR & CCPA)

Regardless of your geographic location, we extend comprehensive privacy controls to all BaniyaDesk users:

Right to Access & PortabilityExport your invoice history, templates, and client contacts in PDF or JSON format anytime.
Right to Erasure (“Right to be Forgotten”)Request complete and irreversible deletion of your account and all associated billing data.
Right to RectificationUpdate company addresses, tax registrations, or contact emails via Account Settings at any point.
Right to Object / RestrictOpt out of non-critical system updates or product announcements with one click.

9. Data Retention & Account Deletion

We retain your invoicing records for as long as your account remains active so you can maintain audit-ready tax histories and client ledger books.

When you submit an account closure or deletion request, your personally identifiable information and workspace entries are permanently purged from our active clusters within 30 days, following standard backup rotation cycles.