Privacy Policy
SlipSmart is built for salaried users in India. This policy explains, in plain terms, what salary data we process and how we protect it. It forms part of our full legal bundle (Terms, Privacy and Refund policy).
1. Overview
This Privacy Policy explains how SlipSmart collects, uses, stores, shares, and protects personal data when you use the Service. We process data in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000, and applicable rules thereunder.
This Policy should be read with our Terms and Refund & Cancellation Policy.
2. Data fiduciary and contact
Suhas Chadha, an individual sole proprietor based in India doing business as "SlipSmart", is the data fiduciary for personal data processed through the Service.
Privacy requests: slipsmart.support@gmail.com
Grievance / DPDP complaints: slipsmart.support@gmail.com. As a sole proprietor, Suhas Chadha is the contact person for data-protection grievances. We aim to acknowledge grievances within 24–48 hours and resolve within timelines prescribed under the DPDP Act where applicable.
3. Personal data we process
Account data: name, email address, authentication identifiers (e.g. Firebase/Google), profile preferences (city, trade, tax regime preference), subscription status.
Financial/salary-related data you provide: payslip PDFs or images (processed on our servers), extracted salary components (encrypted at rest), tax declarations (rent, 80C, 80D, NPS, income gaps), Form 16 text, and derived analytics such as estimated tax.
Technical data: device/browser type, IP address, app and security/audit logs (recording security-sensitive actions such as sign-ins, consent changes, and data access, export, or deletion), crash diagnostics, and — only if you opt in inside the authenticated app — aggregated usage analytics.
Public marketing analytics: On our public website pages only (homepage, about, sign-in/sign-up, privacy and terms, and free calculator/learn articles), and only while you are not signed in, we may load Google Analytics to measure traffic and improve the site. Google Analytics does not run on any page after you sign in, including onboarding and the salary/tax tools. IP addresses are anonymized in that configuration.
Payment metadata: transaction IDs, plan, amount, and status from our payment partner (we do not receive or store full card credentials).
We do not store raw payslip PDF files. Common personal identifiers (such as PAN, bank account numbers, email, phone, and detected names) are automatically scrubbed before salary figures are encrypted and saved; any residual extracted text is stored only in encrypted form.
4. Purposes and legal bases
We process data to: provide and secure the Service; sync encrypted backups; run parsers and tax tools you request; process subscriptions; comply with law; prevent fraud; and improve features (with opt-in analytics only).
Under the DPDP Act, processing is based on your consent (sign-up legal bundle, onboarding data-storage consent, optional co-pilot and analytics toggles), performance of contract (providing the Service you signed up for), and legitimate uses permitted by law (security, fraud prevention, compliance).
5. Consent (how we record it)
Legal bundle (Terms + Privacy + Refund): You agree once at account creation via an explicit checkbox. We store the bundle version identifier and timestamp on your account record. Re-acceptance may be requested if we publish a material update.
Salary data storage & processing: During onboarding you provide separate opt-in consent to store and process salary-related data on our encrypted servers. You may withdraw by deleting data or your account.
Optional salary co-pilot: Off by default. The co-pilot answers common salary and tax questions using rule-based logic applied to your own salary figures in your browser; it does not use any third-party AI and does not send your questions or salary details to an AI service. When enabled, a question counter is stored on your account to apply free-plan limits. You may disable it anytime.
Optional analytics: Off by default. Enabling it constitutes consent to aggregated, non-sale usage measurement. You may disable it anytime.
Payslip PDF upload: Covered by your sign-up legal bundle and onboarding consent. PDFs are sent over HTTPS for text extraction only, processed in memory, scrubbed for identifiers, not stored as files, and salary figures are encrypted at rest. You may use Take photo instead for on-device OCR only.
Withdrawal of consent does not affect lawfulness of prior processing. Some processing may continue where required by law or for legitimate security purposes.
7. Retention
Payslip ciphertext/metadata: retained for up to three (3) years from the payslip month to support multi-year tax planning, year-over-year comparisons, and record-keeping, unless you delete sooner.
Chat history (if used): up to thirty (30) days on device-oriented flows as described in-app.
Tax planner inputs: retained per financial year while your account is active.
Account and consent records: retained while your account exists and for a reasonable period thereafter for legal, tax, and dispute resolution (typically up to three (3) years unless a longer period is required by law).
Security and audit logs (e.g. sign-ins, consent changes, and data access, export, or deletion events — including IP address and device/browser info): retained for up to twelve (12) months for security, fraud prevention, and compliance, then purged.
On account deletion or 'Delete all data', we purge user content within timelines stated in Settings, subject to backup lag and legal holds.
8. Your rights (DPDP Act)
Subject to applicable law, you may: access a summary of your data; request correction; withdraw consent for optional processing; request erasure via in-app deletion tools or email; and nominate a person to exercise rights in the event of death or incapacity (as per DPDP rules).
Exercise rights via Settings or slipsmart.support@gmail.com. We respond within statutory timelines (generally within one month, extendable where permitted).
If unsatisfied, you may escalate to the Data Protection Board of India when constituted and operational under the DPDP framework.
9. Security
We use encryption in transit (HTTPS/TLS), authenticated access (Firebase), rate limiting, audit logging of security-sensitive events (such as sign-ins, consent changes, data exports, deletions, and administrative actions), and AES-256-GCM encryption at rest for salary payloads. When configured, data keys are wrapped with Google Cloud KMS (customer-managed keys). Raw payslip PDFs are not retained.
You are responsible for your Google account security. Do not share payslip screenshots containing PAN, bank, or employer identifiers in unsecured channels.
10. Children
The Service is not directed to persons under 18. We do not knowingly collect children's data. Contact us to request deletion if you believe a minor has registered.
11. Cross-border processing
Processors may store or process data on servers located outside India subject to applicable law and contractual safeguards. By using the Service you acknowledge such transfers where permitted.
12. Changes to this Policy
We will update this Policy when practices or law change. The 'Last updated' date and legal bundle version will change accordingly. Material changes will be communicated in-app or by email where appropriate.
Minor clarifications (such as 5 June 2026 — public marketing analytics disclosure) may be published without a blocking re-consent step when they do not change how salary data itself is processed.
Questions about your data? See how to contact us or email slipsmart.support@gmail.com.