Privacy Policy
Updated 30 September 2026
How VyajPay handles personal data in our Android and iPhone apps and on vyajpay.com, including information about people recorded in a ledger.
Who is responsible
VyajPay is operated by Vijaysinh Zala, sole proprietor, Ahmedabad, Gujarat, India. Vijaysinh Zala is also the Grievance Officer. Contact contact@vyajpay.com or +91 9274730603. See grievance redressal.
What we collect and why
| Category | Information | Purpose |
|---|---|---|
| Account and profile | Name, phone, email, sign-in identifiers and profile photo; optional age, occupation and region. | Sign-in, recovery, profile display and record linking. |
| Business profile | Business name, contact details, address, GSTIN, logo and document branding. | Display your business details on receipts and reports. |
| Bookkeeping records | Customer/borrower names, numbers, notes, amounts, interest, dates, payments, penalties, collateral and shared records. | Calculate and sync your ledger, prepare reports and provide sharing features. |
| Photos and documents | Selected contact photos, scans, ID proofs, agreements, signatures, receipts and payment proofs. | Attach documents, process scans and share selected proofs. Use masked IDs and collect only what is necessary. |
| Device and diagnostics | Installation IDs, push tokens, device/app version, language, region, timezone, crash reports and performance events. | Notifications, device sessions, anti-abuse and failure investigation. |
| App analytics and ads | Account-linked usage, screen and purchase events, device/ad identifiers and amount ranges. Android Meta matching can include hashed email and name. | Feature use, subscription measurement, ad attribution and campaign performance. These events are not all anonymous. |
| Subscriptions and referrals | Store purchase tokens, transaction IDs, entitlement, trial status, invite codes and referral progress. | Verify access, resolve billing and administer referrals. Referrers can see a friend’s first name and progress. |
| Support and website requests | Name, email, optional phone, subject/message, consent text, browser details and a hash of your network address. | Reply to requests, verify authority and limit spam. Requests are stored in Firebase and exported to Google Sheets. |
| Website browsing | IP address and request logs at our host; optional cookie/device identifiers and browsing events after consent. | Serve and protect the website; with permission, measure visits, session replay and ads. |
Information comes from you, selected device features, linked counterparties, staff submissions and providers. The contact picker selects an individual contact; this does not upload your whole address book. Biometric templates stay with the operating system. App-lock PIN protection is local to the device.
Information about borrowers, customers and staff
You must have authority to record, upload and share someone else’s information. Explain the purpose and obtain any consent required for storage, AI processing and messaging. Do not upload unmasked identity numbers, unnecessary sensitive information or documents you are not entitled to use.
Linked users, assigned staff and recipients of shared documents receive records relevant to that relationship. Profile and contact information may appear in linking requests. Shared download links and exports can be copied; treat them as confidential.
If someone recorded your information, you can request access, correction or deletion without an account. We may need to identify the record owner and verify your identity. We cannot erase another person’s independent copy or decide whether a debt is valid.
Smart Scan, OCR and voice features
Smart Scan sends your selected image, including visible names, numbers and amounts, to Google Gemini and/or OpenAI for extraction. This is cloud processing and can take place outside India. Check every extracted entry before saving.
The current workflow also retains submitted images and extraction results in VyajPay’s scan archive for quality review and training. That archive does not currently have a verified automatic deletion period. Only submit scans you are authorized to share; contact us to request deletion. Provider retention follows their terms, and requests may not immediately remove their security or abuse-monitoring records.
On-device OCR uses Google ML Kit where supported. Voice entry uses the device’s speech service where offered and may be processed by its provider. Review device permissions and provider settings. Scan and document access is used when you choose these features.
Providers and international processing
- Google / Firebase: Authentication, storage, sync, notifications, App Check, Crashlytics, performance and analytics.
- Google AdMob / Ads / Analytics: In-app ads and usage/ad measurement; optional website tags.
- Meta: App Events, ad attribution and WhatsApp messages; optional website Pixel.
- Google Gemini: Cloud processing of Smart Scan ledger images and extraction requests.
- OpenAI: Cloud processing of Smart Scan images and extraction requests.
- MSG91: Phone verification and SMS delivery, including number and message content.
- Apple / Google Play: Sign-in, in-app billing and subscription verification.
- Microsoft Clarity: Optional website session replay on public marketing pages.
- Netlify: Website hosting and request/security logs.
Relevant core Firebase storage is configured in India, but authentication, analytics, advertising, AI and support providers can process data elsewhere, including the United States. We do not promise all processing stays in India.
We do not sell your ledger as a dataset. App analytics and ad events nevertheless include account/device identifiers and amount ranges, and Android sends hashed matching information to Meta. Legal, regulatory and security requests may also require disclosure.
WhatsApp, SMS and notifications
A Pro daily due-list can go to the account holder. Separate record-update and due-reminder settings can cause messages to customers or borrowers: eligible app users may receive WhatsApp updates and other recipients may receive SMS. A lender’s switch is not the recipient’s consent. Obtain permission before enabling messages.
For unexpected messages, corrections or requests to stop, see Messages from VyajPay or email us with the recipient number. Do not rely solely on a reply to an SMS header or an automatic WhatsApp STOP reply; contact support for confirmation.
Retention and deletion
Active account records are kept while your account is in use. In-app deletion starts a 30-day recovery window. That window is not a guarantee that every cloud copy is permanently erased at its end. Some backups, reset archives, scan images, support submissions and analytics exports currently lack a verified automatic expiry.
Billing, security and dispute records may require retention for legal obligations or claims. Linked counterparties and people receiving exports hold independent copies. We will explain retained categories and reasons when handling a request; we do not promise all data disappears within 30 days.
Use Delete account or Your data rights to request removal of an account, selected records, scans or support data. Ask for written confirmation of the outcome and any remaining retention period.
Security
We use HTTPS for transmission and cloud-provider storage safeguards. App Lock restricts access on your device. The local ledger database is not encrypted by VyajPay, and cloud sync is not end-to-end encryption. No measure guarantees protection against every incident. See security information.
Rights, consent and complaints
Request a copy, correction or deletion of personal data, withdraw optional processing permission, or complain through the request form or email. We verify identity and authority before disclosing or changing account data. Never send an OTP, password, PIN, full card details or unmasked ID.
Accounts and paid services are intended for adults aged 18 or over. Contact us if a child’s data has been collected. Revisions appear with their updated date; new optional processing requires the relevant choice.