Privacy Policy
Version 1.1 — last updated 23 Aug 2026
1. Who we are
TaxOn Edge™ is a workbench for Indian Chartered Accountants managing GST and Income Tax compliance for their client firms. In DPDP (Digital Personal Data Protection Act, 2023) terms we are the Data Fiduciary for the CA firm's own account data and a Data Processor for the CA firm's clients' data uploaded to the platform.
This policy explains what personal and client data we collect, how we use it, where we keep it, how long we retain it, and how you can exercise your rights under the DPDP Act, 2023.
2. What we collect
CA-firm account data — ICAI membership number, member name, city and state (currently captured via operator-assisted onboarding; a third-party verification API may be integrated later, with prior notice via this policy), your email, WhatsApp number, and login credentials. Payment records: Razorpay order/payment ids, invoice line items, GSTIN of the paying entity.
Client tax data uploaded by the CA — GST notices and correspondence, Tally exports, AIS/Form 26AS snapshots, response drafts, portal credentials (encrypted at rest with AES-256-GCM), and supporting documents. This is your clients' personal + financial data; you are the controller for it and we process it on your instructions.
Operational telemetry — audit-trail rows for every mutating action (who did what, when, from which IP), Sentry error events (stack traces, request context, minus PAN/GSTIN/OTP/card numbers), and infrastructure logs. Telemetry is retained for security, debugging, and legal-defensibility purposes only.
3. Why we collect it
We use CA-firm account data to authenticate you, provision your workspace, issue payment receipts and (once our GST registration is in effect) tax invoices, and contact you about your account and service updates (email is the primary channel; WhatsApp is used only for account-related notices, not marketing).
We use client tax data solely to run the workflows you configure — notice extraction, draft generation, GSTR-2B reconciliation against your Tally exports, and bundle assembly. The AIS / 26AS snapshots you upload are read and listed per client; they are not compared against your Tally books. We do not use client data to train any model, we do not profile clients, and we do not derive analytics you have not requested.
We use operational telemetry to keep the platform available, investigate incidents, satisfy audit obligations, and defend the platform against abuse. Telemetry is scoped to the minimum needed for that purpose.
4. Where the data lives
Primary database — Supabase (managed Postgres) in the ap-south-1 Mumbai region. Cross-firm isolation is layered. The primary control is application-layer scoping: every authenticated request resolves to exactly one ca_firm_id, and every query the platform issues is filtered by it before it reaches the database. Row-level security in Postgres sits underneath that as defence-in-depth and is enforced on the most sensitive tables — it is a second line, not a blanket database-layer guarantee across every table, and it does not substitute for the application-layer check.
Document vault — Cloudflare R2 (encrypted at rest, SigV4-signed transport). Every read/write emits an audit row before the object is touched. Sensitive credential fields on the row (portal passwords, GST-portal session tokens, MFA secrets) are wrapped in AES-256-GCM using a per-deployment encryption key held in Railway secret storage.
Ephemeral state — Redis (Upstash) holds queue jobs and rate-limit counters. Redis is never used as a system of record; a Redis wipe never loses tax data.
Primary data storage stays in India (Supabase ap-south-1 Mumbai region). For draft generation and notice extraction we send scoped, purpose-limited payloads to two AI processors outside India: (a) Anthropic PBC (United States) for the Claude Sonnet family and (b) Google LLC (United States) for the Gemini family. We have not executed separate data-processing agreements with these processors; their handling of the data we send is governed by their own published terms of service, which you should review if that matters to you. The United States is not among the countries the Central Government has restricted transfers to under Section 16 of the DPDP Act as of the date of this policy. Sub-processors handling infrastructure only (Cloudflare, Upstash) do NOT process personal or client data as the primary purpose of their engagement. Vercel hosts the web application and also runs page-view analytics on it, so it is listed separately in Section 7.
5. Retention
Active CA-firm accounts — data is retained while the account is active. On account closure we delete personal identifiers within 90 days, retaining only the anonymised audit spine required for legal defensibility (invoice history, security events).
Client tax data — retained until the CA firm either deletes the client from the workspace or closes the firm account. Deleting a client takes effect immediately and cannot be undone: the notices, documents, drafts, computations and portal credentials are destroyed, and so are the underlying files in our document storage. Where a client is attached to a payment record we are required to keep, the client record itself is retained but stripped of every personal identifier. The audit trail keeps a tombstone noting who deleted it and when, but not the content.
Sentry error events — 90 days. Operational logs — 30 days. Payment records — 8 financial years, matching statutory record-keeping obligations under the GST Act.
6. Your rights under the DPDP Act, 2023
As a Data Principal you have the right to (a) confirm we process your personal data, (b) access a summary of the personal data we hold about you, (c) correct inaccurate or out-of-date entries, (d) erase your personal data where retention is no longer justified by a lawful purpose, (e) nominate another individual to exercise your rights in the event you are incapacitated or deceased, and (f) withdraw consent (except where retention is required by law).
For CA firms exercising these rights on behalf of their own client firms — we honour the request from the CA firm as the controller for the client's data on our platform. If a Data Principal contacts us directly about data held on their CA firm's workspace, we will route the request to the CA firm and confirm resolution.
To exercise any of these rights, write to info@taxonedge.net with the subject line "DPDP request — <right>". We will acknowledge within 72 hours and respond substantively within 30 days.
7. No third-party sale
We do not sell, rent, or share your personal data or your clients' tax data for advertising, profiling, or any commercial purpose outside the workflows you have configured on the platform.
Third parties that necessarily process data on our behalf: Razorpay (payments), SendGrid (email delivery), Supabase, Cloudflare, Upstash and Railway (infrastructure), Vercel (hosting for the web application, and page-view analytics — it receives the address of each page you open together with the request metadata any web host sees), Sentry (error tracking), and — for draft generation and notice extraction — Anthropic PBC (United States, Claude Sonnet family) and Google LLC (United States, Gemini family). Each processes the data we send under its own published terms of service. We send each of them only what that specific task requires. A current sub-processor list is available on request from info@taxonedge.net.
8. Security posture
TLS 1.2+ for all transport. AES-256-GCM for secrets at rest. Application-layer tenant scoping on every query, with row-level security in the database as a second line on the most sensitive tables. Multi-factor authentication (TOTP) is supported for CA and operator accounts and can be switched on per account; it is not enforced by default. Every mutating request writes an audit-trail row. Vault reads/writes are logged separately with SHA-256 content hashes for tamper detection.
We publish a set of production runbooks (docs/runbooks/) that classify every high-impact failure as Group A (mechanical, auto-fixable) or Group B (human-only, touching data / money / credentials). Group B events always page the founder — no automation writes to the DB except the migrations you have approved.
9. Grievance contact
Grievance Officer: Pankaj Sinha, Founder. For any privacy concern, DPDP request, or data-security incident, contact the Grievance Officer at info@taxonedge.net. We will acknowledge within 72 hours and resolve within 30 days, in line with the DPDP Act's response-time expectations.
If you are a client of a CA firm and your concern is about tax data that firm uploaded, please raise it with your CA firm in the first instance: they are the Data Fiduciary for that data and we act on their instructions.
If you are not satisfied with our resolution, you may escalate to the Data Protection Board of India in accordance with the DPDP Act, 2023.
10. Data Protection Officer
One person is accountable for this policy's implementation and is the point of contact for regulators and Data Principals: Pankaj Sinha, Founder. This is the same person named as Grievance Officer in Section 9.
Contact: info@taxonedge.net.
Section 10 of the DPDP Act, 2023 requires a designated Data Protection Officer only of Significant Data Fiduciaries. We do not hold ourselves out as one. The accountability described here is ours by choice; the statutory Grievance Officer duty under Section 13 is discharged as set out in Section 9.
Raise a grievance with us before escalating to the Data Protection Board of India.
11. Age and children's data
TaxOn Edge is intended for adults (18+) — practising Chartered Accountants and their business clients. We do not knowingly collect personal data from anyone under 18. If you become aware that a person under 18 has provided personal data through the platform, contact the DPO immediately and we will delete it.
Our client-facing scan app confirms adult status on first launch. Where a business client is legally represented by a person under 18 (rare — a family business), the CA firm is responsible for obtaining verifiable parental consent under Section 9 of the DPDP Act, 2023 before uploading that client's data.
12. Changes to this policy
We may update this policy from time to time. Substantive changes bump the version number recorded at the bottom of this page. We will notify existing CAs by email at least 14 days before any change that materially affects your rights or our obligations takes effect.
If you do not accept the updated policy, you may close your account and export your data.
Version 1.1. Substantive changes are announced by email at least 14 days ahead. Prior versions and change summaries are available on request via info@taxonedge.net. See also the Terms of Service.