[ GST Send · Legal ]

Privacy
Policy

Effective date 6 August 2026

01

Overview

GST Send is a GST invoicing app for Indian businesses, available on iOS and Android. This Privacy Policy explains what the app and its servers collect, why, how long it is kept, and the choices you have. It does not cover how Apple or Google handle your data when you buy a subscription through their stores.

02

Who we are

GST Send is provided by Aier Labs. For privacy questions, contact us at gstsend@aierlabs.com.

03

Working offline and as a guest

GST Send is offline-first. If you use the app as a guest, your business, customer, product, and invoice records stay on your device only. Nothing is sent to our servers until you sign in and your local data is migrated to your account.

Finalising an invoice and emailing it require an account, because both are performed on our servers.

04

Information you provide

  • Email address — used to sign you in with a one-time code and to contact you about your account
  • Business details — business name, GSTIN, address, and state code, which appear on invoices you issue
  • Customer and product records — names, and where you enter them, GSTIN, address, email, and phone
  • Invoice contents — line items, amounts, tax treatment, notes, and totals
05

Information created by using the app

  • Device identifier — a random internal identifier used for sessions, synchronisation, rate limiting, and error context. It is not an advertising identifier and is not shared with advertisers.
  • Authentication records — sign-in provider subject identifiers from Apple or Google when you use those methods, plus session and refresh token records
  • Subscription records — store transaction identifiers and purchase tokens, used to verify access. Sensitive tokens are encrypted at rest. We never receive your card or bank details.
  • Error metadata — app and build version, platform, operating system, the screen you were on, and a safe error category and message
  • Email delivery metadata — the status of invoice emails you ask us to send
  • Product analytics — a limited, allow-listed set of usage events, described below
06

What we never send to analytics

Invoice numbers and contents, GSTINs, customer and business names, addresses, email addresses, phone numbers, payment data, authentication tokens, one-time codes, free-form text, and raw error messages are excluded from analytics and from operational logs. This exclusion is enforced in code and covered by automated tests.

07

Analytics

We use Mixpanel as our product-analytics system and mirror the same allow-listed events to Google Analytics. Events are delivered through our own servers; no third-party analytics SDK runs inside the app, and the app does not contain an analytics project token.

Analytics uses a one-way internal identity derived from your internal user or device identifier. Your email address is never used as an analytics identity.

Analytics is enabled by default outside regulated regions. In the EU, EEA, UK, Switzerland, and California we ask for your explicit consent first. You can turn analytics off at any time from More → Product analytics.

08

Why we use your information

  • To provide invoicing, calculation, and PDF generation — performance of a contract
  • To sign you in and keep your session secure — performance of a contract
  • To synchronise your data across devices — performance of a contract
  • To email invoices you choose to send — performance of a contract
  • To verify and maintain your subscription — performance of a contract
  • To keep the service reliable and secure — legitimate interests
  • To improve the product — consent where required, otherwise legitimate interests
09

Who we share with

We do not sell your data and we do not run ads. We share it only with providers that operate the service:

  • Cloudflare — hosting, database, object storage, PDF rendering, and email delivery
  • Apple and Google — subscription purchase verification, and identity verification if you sign in with Apple or Google
  • Mixpanel and Google Analytics — allow-listed, privacy-safe product events only

Each of these providers operates under its own data processing terms, which form part of our agreement with them. Your data is stored on Cloudflare's global network and may be processed outside India, including in the United States and the European Union, under those terms.

10

How long we keep it

  • Canonical invoices and finalised snapshots: seven financial years after the applicable financial year
  • Account metadata and active business records: while your account is active
  • Soft-deleted operational records: 30 days, except records covered by invoice retention
  • Data exports: seven days
  • Authentication challenges: ten minutes
  • Revoked or expired sessions and refresh tokens: 35 days
  • Failure metadata and failed-job records: 90 days
  • Email delivery metadata: 13 months
  • Rate-limit violation records: 90 days
  • Backups: 35 days for daily, 13 months for monthly, at least 90 days for pre-migration backups
11

Your choices and rights

  • Export your data — request a structured archive from More → Export your data. The download link is authenticated and expires after seven days.
  • Turn off analytics — More → Product analytics
  • Delete your account — contact gstsend@aierlabs.com. We delete data that is not subject to legal retention within 30 days. Invoice and tax records are retained only for the applicable statutory retention period, restricted to legal and operational use during that time, and deleted when it ends.
  • Access, correction, objection, and portability — where the law gives you these rights, contact gstsend@aierlabs.com. We respond within 30 days.

If you are in the EU, EEA, or UK and are not satisfied with our response, you may complain to your local data protection supervisory authority.

12

Children

GST Send is a business tool intended for people aged 18 or over who are registering or running a business. It is not directed at children, and we do not knowingly collect data from anyone under 18. If you believe a child has given us data, contact gstsend@aierlabs.com and we will delete it.

13

Security

Access tokens are short-lived and signed. Refresh tokens are opaque, hashed before storage, and rotated on use. Every server query is scoped to your account. Sensitive billing tokens are encrypted at rest.

14

Changes

We will update this page when the service changes and will revise the effective date above. For material changes we will tell you in the app or by email.

15

Contact

Questions about this policy or your data: gstsend@aierlabs.com.