Last updated 6 August 2026
1. Scope
This policy explains how [[REGISTERED ENTITY NAME]] handles personal information when you use GSTPilot. It is written to comply with the Information Technology Act 2000, the SPDI Rules 2011, and the Digital Personal Data Protection Act 2023.
2. What we collect
We collect only what the Service needs to function.
- Account details: your name, email address and password (stored only as a cryptographic hash — we cannot read it).
- GSTIN profiles: the GSTINs, legal and trade names, state and nature of business you enter.
- Uploaded reports: the marketplace files you submit for conversion, processed to produce your return.
- Conversion history: metadata about each generated return — period, totals, platforms, status.
- Wallet and transaction records: recharges, credit deductions, bonuses and referral rewards.
- Support messages: anything you send through the contact or support forms.
- Technical logs: IP address, browser type and timestamps, kept for security and debugging.
3. What we never collect
- Card numbers, CVV, UPI PINs or net-banking credentials. Payments go directly to Razorpay; those details never reach our servers.
- Your GST portal username or password. We do not log in to the portal on your behalf.
4. Why we process it
- To provide the Service — parsing your files and generating returns.
- To operate your wallet and process payments.
- To keep a filing history you can return to.
- To answer support requests.
- To detect fraud, abuse and security incidents.
- To meet legal and tax record-keeping obligations.
5. Who we share it with
We do not sell your data. We do not share it for advertising. We share it only with processors that make the Service work:
- Razorpay — payment processing. Governed by Razorpay's own privacy policy.
- Our hosting and database providers — infrastructure on which the Service runs.
- Law enforcement or regulators, where we are legally required to do so.
6. How long we keep it
Account and GSTIN profile data is kept while your account is open.
Conversion history and wallet ledgers are retained for the period required by Indian tax record-keeping rules, which can be several years, because they evidence transactions.
Uploaded source files are processed to produce your return and are not retained as long-term archives.
Technical logs are kept for a limited period for security and debugging.
7. Security
Data is encrypted in transit using TLS. Passwords are hashed. Administrative access is role-based and re-checked on every request rather than trusted from a session.
No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant authority as required by law.
8. Your rights
You may ask us to:
- Give you a copy of the personal data we hold about you.
- Correct anything inaccurate.
- Delete your account and associated personal data, subject to records we must retain by law.
- Withdraw consent for processing that relies on it.
9. Cookies
We use only what the Service needs: a session cookie to keep you signed in, and a preference cookie remembering your theme and sidebar state. We do not use advertising or cross-site tracking cookies.
Blocking the session cookie will prevent you from signing in.
10. Grievance officer
In accordance with the Information Technology Act 2000 and the rules made under it, the contact details of our Grievance Officer are:
[[GRIEVANCE OFFICER NAME]]
Email: grievance@gstpilot.in
[[REGISTERED ADDRESS, CITY, STATE, PIN]]
We aim to acknowledge grievances within 24 hours and resolve them within 15 days.
Related policies

