Privacy policy
What we collect, why, who sees it, and how you stay in control.
Amit Singh Rawat, trading as The Openn Group (“we”), runs Openn Invoice. This policy explains what personal data we handle and your rights over it. It is written for India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and the other privacy laws named under Country-specific information.
Who is responsible
Amit Singh Rawat, trading as The Openn Group, B-2908, Nikoo Homes 4, Bhartiya City, Thanisandra, Bengaluru 560064, Karnataka, India. Email hello@theopenngroup.com. Amit Singh Rawat is the person responsible for privacy. Our grievance officers are Deepali Pandey and Pooja Rawat.
At a glance
- For your account and billing, we are the controller (data fiduciary).
- For the records you keep about your own customers, you are the controller and we are your processor. Our data processing addendum covers that data.
- We do not sell personal data, show ads, or use your customers’ data for anything other than serving you.
- Google Analytics runs only on our public pages, and only if you accept it. Never inside the app.
What we collect
- Account: your name, email, a hashed password, whether your email is confirmed, your email preferences, and when you agreed to our terms.
- Team: the emails of people you invite, their names and roles once they join.
- Business details: business name, tax registration number (GSTIN, VAT number or similar), address, phone, email, payment details such as a bank account, a payment link or (in India) a UPI ID, a Udyam (MSME) number if you add one in India, and your logo or signature image.
- Your records: customers, items, invoices, quotations, credit notes, payments (including payment proof photos or PDFs you upload) and bank statement lines you upload.
- Payments: order and payment status from Cashfree and, if you turn on auto-renew, the mandate’s status, limit and a masked payment method (such as a UPI ID’s first letters or a card’s last four digits). We never receive full card numbers, UPI PINs or bank log-ins.
- Checkout evidence: when you pay, your IP address (stored truncated), browser, device, the terms version you accepted, your confirmation that you are buying for a business, the result of any tax number check, and the card network, type, issuing country and bank that Cashfree reports.
- Support: the messages and feature requests you send us.
- Location: we don’t use GPS and don’t look up where you are from your IP address. Your browser tells the page its time zone and languages, and we use them to guess your country: to show prices in your currency, to fill in the country when you set up, and to ask “You seem to be in …” when your device is in another country than your business. That guess stays in your browser. We store a country only when you choose one: your business’s country, state and address, your customers’ countries and addresses, and the countries you told us not to ask about again. Cashfree tells us the country that issued the card you pay with, and Google Analytics (only if you accept) records an approximate location.
- Invoice links: when your customer first opens an invoice link, we record the time so you can see it was viewed. We don’t record who opened it or from where.
- Security: sign-in and verification codes (stored hashed, valid for minutes), a device cookie and a device label such as “Chrome on macOS”, your IP address for rate limits and new sign-in alerts, a log of the emails we sent you, and an audit log of sensitive account changes.
- Analytics (with consent): pages viewed on our public site, the Start buttons clicked, browser and approximate location, collected by Google Analytics. See the cookie policy.
IP addresses are used in full only for rate limits and security checks, which last no more than two days. Anything we keep longer holds the IP address truncated.
Why we use it, and on what basis
- To provide the service you signed up for: create and share documents, match payments, produce reports, run your team. (Contract; under the DPDP Act, the purpose you gave us the data for.)
- To bill you and issue tax invoices for your subscription (GST invoices, as we are registered in India), and keep them as tax law requires. (Legal obligation.)
- To keep accounts secure and prevent payment fraud: sign-in codes, device limits, new-device alerts, rate limits, checkout checks and answering chargebacks. A checkout that looks risky may be paused until a person reviews it. (Legitimate interests; security is part of the service.)
- To email you about your account: sign-in codes, receipts, renewal reminders, and important changes. (Contract.)
- To send onboarding tips, a weekly summary and news about Openn Invoice to you as a customer. (Legitimate interests, or where the law requires it, the “soft opt-in” for existing customers.) You can switch these off any time in the Account page or from the link in each email. We don’t send promotional email about other companies.
- To understand our public pages with Google Analytics. (Consent, which you can withdraw any time.)
We make no automated decisions about you that have legal or similarly significant effects.
International transfers
Our servers are in India. Google processes email and analytics data in the United States and elsewhere, and Hostinger’s delivery network may handle requests in other countries. Where the GDPR, UK GDPR or Swiss law applies, transfers rely on the European Commission’s Standard Contractual Clauses (with the UK Addendum and Swiss amendments), and for Google also on its certification under the EU-US Data Privacy Framework. We do not transfer data to any country the Indian government has restricted under the DPDP Act.
How long we keep it
- Your account, business details and records
- While your account exists. When you delete your account they are removed from the live service at once, and from our rolling backups (including payment proof files) within 30 days.
- Our own billing records
- Tax invoices for your subscription, orders and payment records: 8 years, as Indian GST and income tax law requires.
- Checkout evidence
- Truncated IP address, browser, device, terms version, the business confirmation and card details from the processor (network, type, issuing country and bank): 3 years from the payment, to answer chargebacks and fraud checks.
- Security and access logs
- Sign-ins, new-device alerts and the audit log of sensitive account changes: at least 1 year, as India’s DPDP Rules require, and no more than 2 years.
- Email log
- A record of the emails we sent you: 400 days.
- Support messages
- 2 years after the last message in the conversation.
- Error log
- 180 days.
- Sign-in codes, reset links and sessions
- Codes and links work for minutes to hours. Sessions last up to 30 days.
- Google Analytics
- Up to 14 months, then Google deletes it.
Cookies
We use a few essential cookies to keep you signed in and secure, and Google Analytics cookies only on our public pages and only if you accept. If your browser sends a Global Privacy Control (GPC) signal, we treat it as Decline. The cookie policy lists each cookie, and you can change your choice from Cookie settings at the foot of any page.
Security and breaches
Passwords are hashed with scrypt, sessions use secure http-only cookies, connections are encrypted, two-step sign-in is available, and every query is scoped to your business so one business can never read another’s records. Our security page has the details.
If a personal data breach happens, we tell the Data Protection Board of India without delay, with a full report within 72 hours, and, where the GDPR or UK GDPR applies, the relevant supervisory authority within 72 hours of becoming aware of it. We tell the people affected without undue delay. If the breach affects records you keep about your customers, we tell you as our data processing addendum sets out.
Your rights
- Everyone: you can see, correct and export your data in the app (CSV export), and delete your account from the Account page. You can withdraw consent to analytics at any time.
- India (DPDP Act): you may ask for a summary of your data and who we shared it with, correction, completion, updating or erasure, have your grievance redressed, and nominate someone to exercise these rights if you die or become unable to.
Rights under other laws are listed under Country-specific information. Write to hello@theopenngroup.com from your account email. We may ask you to confirm who you are, we reply within 30 days, and we never take longer than 90 days. If your data is in another business’s records (you are their customer), we will pass your request to that business, since they control it.
Children
Openn Invoice is for businesses and people aged 18 or over. We don’t knowingly collect data from children. If you think a child has given us data, tell us and we will delete it.
Country-specific information
EU, EEA, UK and Switzerland
The legal bases we rely on are listed above. You have the right to access, correct and erase your data, to restrict or object to its use (including an absolute right to object to direct marketing), to data portability, and to withdraw consent at any time. You may complain to the data protection authority where you live or work, such as the ICO in the UK or the FDPIC in Switzerland. We are based in India, which has no adequacy decision, so transfers to us rely on Standard Contractual Clauses. We have not yet appointed a representative in the EU or UK; please contact us directly at hello@theopenngroup.com.
United States
Depending on your state, you have the right to know and access the personal data we hold about you, to correct it, to delete it, to get a copy in a portable format, and to opt out of its sale, of sharing for cross-context behavioural advertising, of targeted advertising and of profiling. We do not sell or share personal data for those purposes, and we treat a GPC signal as an opt-out. You may use an authorised agent. If we refuse a request, you may appeal by replying to our answer; if we refuse the appeal, you may contact your state attorney general. We will not treat you differently for using these rights.
Canada and Quebec
The person in charge of the protection of personal information is Amit Singh Rawat (hello@theopenngroup.com). Your data is stored outside Canada, in India and the United States, and may be accessible to courts and authorities there. You may ask to access or correct your data, and complain to the Office of the Privacy Commissioner of Canada or, in Quebec, the Commission d’accès à l’information.
Brazil
Under the LGPD, our Encarregado (data protection officer) is Amit Singh Rawat (hello@theopenngroup.com). You may ask us to confirm that we process your data, give you access, correct it, anonymise, block or delete data that is unnecessary or excessive, port it, and tell you which public and private entities we share it with (listed above). Where we rely on consent, you may refuse it, which only means we won’t run analytics, and revoke it at any time. You may complain to the ANPD.
Australia
We handle your data in line with the Australian Privacy Principles. Overseas recipients are in India (our hosting) and the United States (Google), and Hostinger’s delivery network may pass requests through other countries. Please contact us first; if you are not satisfied, you may complain to the Office of the Australian Information Commissioner (OAIC).
New Zealand
Under the Privacy Act 2020 you may ask to access and correct your data. We send data to India and the United States with safeguards comparable to New Zealand law. You may complain to the Office of the Privacy Commissioner.
Singapore
Under the PDPA you may ask to access and correct your data and withdraw consent. We protect data sent outside Singapore to a standard comparable to the PDPA through contracts with our providers. Our data protection contact is Amit Singh Rawat (hello@theopenngroup.com). You may complain to the Personal Data Protection Commission.
Japan
Under the APPI, your data is provided to recipients in India (us and our hosting) and the United States (Google). India protects personal data under the DPDP Act, 2023; the United States has no single federal privacy law but has sector and state laws. Our providers are bound by contract to protect the data. You may ask us to disclose, correct, stop using or delete your data, and complain to the Personal Information Protection Commission.
South Korea
Your data is transferred abroad to the providers, countries and for the purposes listed on our sub-processors page, over the internet as you use the service, and kept for the periods above. You may ask to access, correct, delete or suspend the processing of your data, and complain to the Personal Information Protection Commission.
United Arab Emirates and Saudi Arabia
Under the UAE and Saudi Personal Data Protection Laws, you may ask to access, correct and erase your data, and to restrict or object to its use. Data sent outside your country is protected by contract. In Saudi Arabia you may complain to the Saudi Data and AI Authority (SDAIA); in the UAE, to the UAE Data Office.
South Africa
Under POPIA, our information officer is Amit Singh Rawat (hello@theopenngroup.com). You may ask to access, correct or delete your data and object to its use. Data sent outside South Africa is protected by binding agreements. You may complain to the Information Regulator.
Nigeria
Under the Nigeria Data Protection Act 2023, you may ask to access, correct, erase or port your data, and object to its use. Data sent outside Nigeria is protected by contract. You may complain to the Nigeria Data Protection Commission.
China
Openn Invoice is not offered to, or aimed at, people in mainland China.
Changes to this policy
We will post any change here with a new date, and email you at least 15 days before a material change applies.
Grievance officers and contact
Grievance officers: Deepali Pandey and Pooja Rawat, The Openn Group, B-2908, Nikoo Homes 4, Bhartiya City, Thanisandra, Bengaluru 560064, Karnataka, India. Email hello@theopenngroup.com. We acknowledge a grievance within 24 hours and resolve it within 15 days, and in any case within 90 days. If you are unhappy with our answer, you may complain to the Data Protection Board of India, or to the authority named for your country above.