At BaniyaDesk, your financial privacy is fundamental. We utilize zero-knowledge principles, passwordless OTP architecture, and end-to-end data encryption so your records remain exclusively yours.
Last Modified: September 24, 2026256-Bit SSL EnforcedGDPR & CCPA Compliant
1. Overview & Commitment
Welcome to BaniyaDesk (“we”, “our”, or “us”). This Privacy Policy explains in straightforward terms how we collect, handle, protect, and safeguard the data generated when you visit our website, utilize our web-based invoice builder, and interact with our services.
We believe that financial information deserves the highest echelon of security. We never monetize your client lists, line items, or billing figures, and we do not sell or lease your private data to advertising networks.
2. Information We Collect
To provide our frictionless invoicing platform, we collect only the essential elements necessary to authenticate your workspace and render your invoices:
A. Account Credentials
Your registered email address, name, and temporary one-time password (OTP) verification hashes. We never ask for or store static account passwords.
B. Business & Invoicing Data
Company name, business address, tax ID/GSTIN/VAT identifiers, logos, client contact entries, line item descriptions, totals, bank details, and UPI/QR payment payloads.
C. Technical & Diagnostic Telemetry
IP address, browser type, operating system metadata, and error diagnostics to safeguard against automated spam attacks and brute force OTP abuse.
3. How We Use Your Data
Your information is strictly utilized to:
Generate, render, format, and export high-resolution PDF invoices and shareable receipts.
Deliver single-use OTP verification codes to your inbox via Amazon Simple Email Service (SES).
Maintain your client directory, recurring templates, and tax preference configurations.
Conventional password databases represent the single greatest vulnerability for web platforms. BaniyaDesk operates on a 100% passwordless authentication model:
Ephemerality
All verification codes expire strictly after 5 minutes and become invalid immediately upon use.
Rate-Limiting & Lockouts
Brute-force attempts are thwarted with automated IP and identifier cooldowns after 5 incorrect inputs.
Cryptographic Hashing
OTP values are transformed via secure cryptographic one-way hashing before database writes.
Encrypted Transport
All browser-server communication is encrypted with TLS 1.3 / 256-bit SSL protocols.
5. Data Ownership & Non-Disclosure
You maintain 100% intellectual property and commercial ownership of every invoice, client contact, logo asset, and price quote created inside your workspace.
BaniyaDesk will never disclose, sublicense, aggregate for third-party resale, or distribute your financial records to competitors or advertisers under any circumstance, unless strictly compelled by a lawful and verified court order.
6. Cookies & Tracking Policy
We maintain a lean cookie footprint. We do NOT use invasive cross-site advertising cookies, Facebook Pixels, or third-party behavioral trackers.
Essential Session Cookies: Used strictly to authenticate your active workspace session and maintain invoice builder state between pages.
Local Storage: Utilized on your client browser to store invoice draft caches, user preferences (e.g. selected currency, template choice), and UI themes for lightning-fast performance.
7. Third-Party Service Providers
We collaborate only with tier-1 enterprise infrastructure providers that guarantee industry-leading data protection standards:
Amazon Web Services (AWS SES & S3): Dispatches transactional OTP emails and stores encrypted logo assets with high durability and security.
MongoDB Atlas: Enterprise-managed cloud database operating with encryption-at-rest and strict VPC network isolation.
Vercel & Cloudflare: Edge compute and CDN caching infrastructure guaranteeing DDoS mitigation and fast worldwide SSL routing.
8. Your Privacy Rights (GDPR & CCPA)
Regardless of your geographic location, we extend comprehensive privacy controls to all BaniyaDesk users:
Right to Access & PortabilityExport your invoice history, templates, and client contacts in PDF or JSON format anytime.
Right to Erasure (“Right to be Forgotten”)Request complete and irreversible deletion of your account and all associated billing data.
Right to RectificationUpdate company addresses, tax registrations, or contact emails via Account Settings at any point.
Right to Object / RestrictOpt out of non-critical system updates or product announcements with one click.
9. Data Retention & Account Deletion
We retain your invoicing records for as long as your account remains active so you can maintain audit-ready tax histories and client ledger books.
When you submit an account closure or deletion request, your personally identifiable information and workspace entries are permanently purged from our active clusters within 30 days, following standard backup rotation cycles.
10. Contact Our Data Protection Officer
If you have any questions, clarifications, or data erasure requests concerning this Privacy Policy, please reach out directly: