Legal

Privacy policy

What we collect, where it sits, who touches it and how long it stays. Your invoices are not a product we sell.

Last updated: 16 August 2026 · Covers this website, the web app at app.bahisathi.com and the Android app (com.appsyoda.business). They are one product on one account, so one policy covers all three.

The short version

BahiSathi needs an account, and your business data — invoices, quotations, customers, items — is stored in it so you can reach it from your phone and from the web. We store it for you. We do not sell it, we show no advertising, we do not use it to train anything, and we never see your card number. You can export it or erase it whenever you want.

1. Who is responsible for your data

Mohit Sehgal, an individual sole proprietor trading as AppsYoda, of 19-C, Palm Enclave, Sidhwan Canal Road, NH-5, Ludhiana, Punjab, 141122, India. For anything to do with this policy or your data, write to appsyoda@gmail.com.

2. Your account

Using BahiSathi requires an account. Against it we hold:

  • your email address, and your name if you give one;
  • a password, handled by Google Firebase Authentication. We never see it and cannot recover it — we can only send you a reset link;
  • if you sign in with Google, the email address, name and profile picture URL Google passes us. We never receive your Google password.

3. Your business data

Stored in your account in Google Cloud Firestore, in the asia-south1 (Mumbai) region, and cached on your device so the app works offline:

  • Your business profile — name, phone, address, GSTIN, PAN, bank details, logo, default terms.
  • Your customers — name, phone, email, GSTIN, billing and shipping addresses.
  • Your items — names, descriptions, units, rates, GST rates, HSN/SAC codes.
  • Your documents — invoices, quotations, credit and debit notes, with their lines, tax and totals.
  • PDFs, which are generated on your device and are not uploaded.

We do not sell this, share it with advertisers, or use it to train anything. We access it only where running the service requires it — investigating a fault you have reported, for instance. Staff you invite to a business can see that business's data to the extent their role allows.

4. Payments

When you buy Pro, the payment is taken by a third-party payment gateway on their own page or widget. Your card number, CVV, UPI PIN and net-banking credentials go to them and never to us — we have no way to see or store them, and nothing of that sort is written to our database.

What we do receive and keep is the record of the transaction:

  • that a payment of a given amount succeeded or failed, and when;
  • the gateway's payment and order reference;
  • the method used in general terms (card, UPI, net banking) and, for a card, the last four digits and the network, as the gateway reports them;
  • the billing name and email address you gave.

This is what lets us match a payment to an account, activate Pro, issue a receipt, and process a refund. The gateway is a separate data controller for what it collects, under its own privacy policy.

5. Usage and crash reporting

Two Firebase services tell us whether the app works and where people get stuck, and this website separately runs Google Analytics. All three collect data about how something is used — never what you type into the app.

  • Firebase Analytics (the Android and web app) — anonymous events (a business was set up, a quotation saved, a PDF generated, a document shared and by which method), screens opened, a randomly generated app-instance identifier, device model, OS version, language, and an approximate country or region derived from your IP address.
  • Firebase Crashlytics (the Android and web app) — crash stack traces, app version, device model, OS version, the screen that was open, and general device state such as free memory.
  • Google Analytics (this website, bahisathi.com, only — never the app where your business data lives) — pages viewed, the referring site, an approximate location derived from your IP address, device and browser type, and a randomly generated identifier stored in a first-party cookie so a repeat visit is recognised as the same visitor. Google Signals, which would let Google use this for ad personalisation or link it across your devices, is switched off.

What is structurally excluded. The app is built so your business content cannot be sent even by accident. Customer names, business names, phone numbers, email addresses, GSTINs, addresses, item names, document numbers and every monetary amount are incapable of appearing in an analytics or crash report. Screen names are recorded without the identifier of the record being viewed. The website carries no login and no business data, so there is nothing of that kind for its analytics to capture in the first place.

6. Advertising

There is none. We do not collect the Android Advertising ID — the permission that would allow it is removed from the app — we build no advertising profiles, and we run no personalised advertising.

7. When you share a document

Tapping Share, Email or Save hands the PDF to another app you pick — WhatsApp, your mail app, your file storage. That transfer happens on your device, is started by you, and we receive no copy. Once the file is in another app, that app's privacy policy governs it.

8. Who else touches it

We do not sell your data or share it with third parties for their own purposes. Two categories of processor act on our instructions:

  • Google, for Firebase Authentication, Cloud Firestore, Cloud Functions, Analytics and Crashlytics, and for Google Analytics on this website, under the Firebase Privacy and Security terms and the Google Privacy Policy.
  • Our payment gateway, for taking payments and issuing refunds, as described in section 4.

Business data is stored in the Mumbai region. Some processing — analytics aggregation in particular — may happen on servers outside India. We also disclose data where the law requires it of us.

9. How long it is kept

WhatHow long
Your business data (documents, customers, items)Until you delete it or delete your account
Account details (email, name)Until you delete your account
Encrypted backupsUp to 30 days, then overwritten on a rolling cycle
Analytics events (app and website)Up to 14 months, then deleted automatically
Crash reportsUp to 90 days
Server logs30 days. They record requests, not document contents
Payment and billing recordsEight years, because Indian tax law requires us to keep our own books

The billing record that outlives a deleted account is our own invoice to you, which we are required to keep. It is never the documents you created in the app.

10. Your choices and rights

  • Export — the Reports screen exports your documents as JSON and CSV, and any document can be shared as a PDF.
  • Delete your account — do it yourself in Settings, or email us. The deletion page sets out exactly what goes and what stays.
  • Stop collection — uninstall the Android app, or sign out of the web app and stop using it. Nothing further is sent.
  • Clear the local cache — uninstall, or Settings › Apps › BahiSathi › Storage on Android; clear site data for app.bahisathi.com in your browser.
  • Ask us to delete analytics records — email us. The analytics identifier is random and not tied to your account, so include roughly when you used the app and we will find them.

You may have further rights of access, correction, erasure and grievance redressal under India's Digital Personal Data Protection Act, 2023, or the GDPR where it applies to you. Write to appsyoda@gmail.com and we will act within 30 days. Complaints go to the same address — see the contact page for how they are escalated.

11. Children

BahiSathi is a tool for running a business. It is not directed at children and we do not knowingly collect data from anyone under 18.

12. Security

Data in transit is encrypted. Data on your device sits in the app's private storage, which Android isolates from other apps. Data in your account is held in Google Cloud Firestore, protected by security rules that scope every read and write to the account it belongs to, and those rules are covered by an automated test suite. We hold no card data at all, which removes the most attractive thing on the shelf.

No system is perfectly secure. If you think an account has been accessed by someone else, tell us at once and we will act the same day.

13. Changes to this policy

When this policy changes materially we update this page, change the date at the top, and email the address on your account if the change affects you directly.

Who you are dealing with

BahiSathi is owned and operated by Mohit Sehgal, an individual trading as AppsYoda. There is no separate company: the person named here is the person you contract with, the person who answers support, and the person the payment is made to.

Address
19-C, Palm Enclave
Sidhwan Canal Road, NH-5
Ludhiana, Punjab 141122
India
Phone
+91 79735 81745 — also on WhatsApp
Hours
Monday to Saturday, 10:00 – 19:00 IST

Every policy is on the contact page too, with the other ways to reach us.