Skip to main content
OneBooks GST+ Logo

Privacy Policy

Background decoration
Background decoration
Background decoration
Background decoration
Background decoration
Background decoration

Last updated: March 21, 2026

This Privacy Policy ("Policy") applies to your use of the OneBooks GST+ platform available at onebooksgst.in and its web applications, operated by OneBooks GST+("Company", "we", "us", or "our").

By using the platform or availing our services, you agree to this Policy. If you do not agree, please stop using the platform. By using the platform, you also confirm that you are authorized to share any information you submit, and that doing so does not violate any applicable law or third-party rights.

1. Information We Collect

We collect the following categories of information when you use OneBooks GST+:

1.1 Account and Identity Information

Your name, email address, phone number, and password when you register an account. Your business name and GSTIN(s) associated with organizations you create on the platform.

1.2 GST and Marketplace Data

Marketplace sales files (Excel, CSV, JSON) you upload from platforms including Amazon, Flipkart, Meesho, and others. Invoice data, HSN codes, B2B/B2C transaction records, and GSTR-1 report data generated from your uploads. Tally XML mapping configurations you create for your organizations.

1.3 Bank Statement Data

Bank statement files you upload for processing. Parsed transaction records including dates, amounts, narrations, and credit/debit classifications. This data is used solely for the bank statement management features you use and is not shared with third parties for financial purposes.

1.4 Payment and Billing Information

Subscription payment records, Razorpay order IDs and payment IDs, transaction amounts, and payment status. Wallet top-up history and messaging credit balance. We do not store your full card number, CVV, or net banking credentials — these are handled directly by Razorpay.

1.5 WhatsApp Messaging Data

Message templates you create and submit to Meta for approval. Campaign configurations including audience selection, scheduling, and recurrence settings. Phone numbers of recipient organizations or users targeted by your campaigns. Message delivery logs including status (queued, sent, delivered, failed) and timestamps. WhatsApp Business Account ID and phone number ID obtained through your Meta OAuth connection.

1.6 Device, Session, and Security Data

IP addresses, browser type, operating system, and device identifiers associated with your login sessions. Session tokens and activity timestamps. Two-factor authentication (2FA) configuration status (we store only that 2FA is enabled and the encrypted TOTP secret — not your raw authenticator codes). Active session records that can be reviewed and revoked from your Security settings page.

1.7 Activity and Audit Log Data

Records of actions performed on the platform including file uploads, data exports, organization changes, user role updates, campaign launches, and account setting changes. These logs are used for security, dispute resolution, and platform integrity.

1.8 Support Ticket Data

Content of support tickets you raise including descriptions, attachments, and correspondence. This information is used to resolve your queries and improve platform reliability.

2. How We Use Your Information

We do not sell your personal or financial information to third parties. We use the information we collect for the following purposes:

2.1 Account management and service delivery: To create and maintain your account, authenticate logins (including 2FA), manage your organizations and subscriptions, process payments, and deliver all platform features you use.

2.2 GST processing and data management: To parse, reconcile, validate, and report on the GST and marketplace data you upload. To generate GSTR-1 reports, Tally XML exports, and other compliance documents on your behalf.

2.3 Bank statement management: To parse uploaded bank statement files, extract and display transactions, and support the manual and automated bank entry features.

2.4 WhatsApp messaging campaigns:To create and manage your message templates, build and execute campaigns, deliver messages through the Meta WhatsApp Business API, and provide delivery analytics. Phone numbers of recipients are used solely to route messages through the API and are not shared with any third party outside of Meta's messaging infrastructure.

2.5 Billing and wallet management: To process subscription payments and wallet top-ups via Razorpay, maintain your wallet balance and transaction history, and charge per-message costs against your wallet.

2.6 Security and fraud prevention: To monitor sessions, detect unauthorized access, maintain activity audit logs, and respond to security incidents. To conduct fraud audits on account activity where suspicious behavior is detected.

2.7 Support and communications: To respond to your support tickets and platform queries. To send transactional communications including email verification, password reset, payment receipts, template approval notifications, and platform security alerts. To contact you by email, phone, or WhatsApp for service-related and marketing communications (you may opt out of marketing communications at any time).

2.8 Product improvement and analytics: To monitor feature usage, measure performance, conduct data analysis, and improve the platform. Aggregated and anonymized data may be used for internal reporting and product development without identifying individual users.

2.9 Legal and regulatory compliance: To retain records as required by Indian tax law, GST regulations, and other applicable legal obligations. To respond to judicial, administrative, or regulatory requests for information where legally required.

2.10 Data retention: To store your account data, GST records, bank statement data, messaging logs, and activity logs in our servers or cloud infrastructure for as long as required by applicable law or as necessary to provide the services.

3. Information Sharing and Disclosure

We share your information only in the following circumstances:

3.1 Service providers: We engage trusted third-party vendors to operate the platform, including cloud hosting providers, payment gateway (Razorpay), email delivery services, and the Meta WhatsApp Business API. These providers are contractually bound to process your data only for the purposes we specify and to maintain confidentiality.

3.2 Meta (WhatsApp Business API):When you use the WhatsApp messaging feature, message content and recipient phone numbers are transmitted to Meta's infrastructure for delivery. This is governed by Meta's Privacy Policy and WhatsApp Business Terms.

3.3 Legal obligations: We may disclose your information to judicial, administrative, or regulatory authorities where required by applicable law, court order, or government directive.

3.4 Business transfers: In the event of a merger, acquisition, or sale of all or part of the Company, your data may be transferred to the successor entity subject to the same privacy protections described in this Policy.

3.5 We do not share your personal data, GST records, bank statement data, or client lists with advertising networks, data brokers, or any unaffiliated third parties for commercial purposes.

4. Cookie Policy

We use cookies and similar technologies including session tokens, local storage, and browser cache for authentication, 2FA state management, payment processing, and preference storage. For full details on the types of cookies used and how to manage them, please read our Cookie Policy.

5. Data Security

We implement industry-standard security measures to protect your data including:

  • SSL/TLS encryption for all data in transit
  • Encryption at rest for sensitive data including uploaded files and account credentials
  • Role-based access control — each user only accesses data for organizations they are authorized to manage
  • Two-factor authentication (2FA) available for all accounts
  • Session management with the ability to view and revoke active sessions
  • Activity audit logs for all significant account actions

While we employ strong security practices, no system is completely secure. You are responsible for keeping your account credentials and 2FA recovery codes confidential. If you suspect unauthorized access, contact us immediately at info@onebooksgst.in.

We will never ask for your password, full card details, or OTP via email or phone call. Treat any such request as a phishing attempt and report it to us immediately.

6. Data Retention

We retain your data for as long as your account is active and for the periods required by applicable Indian law including GST regulations (typically 6 years for GST records). After account deletion or subscription lapse, we may retain anonymized or aggregated data for internal analytics.

You may request deletion of your account and personal data by contacting our support team. Note that certain data may be retained for legal compliance purposes even after account deletion.

7. Your Rights

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete personal data
  • Request deletion of your personal data (subject to legal retention requirements)
  • Opt out of marketing communications at any time
  • Manage or disable cookies from your browser settings
  • Revoke active login sessions from the Security page in your account

To exercise any of these rights, contact us at info@onebooksgst.in.

8. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in law, technology, or our platform features. We will notify registered users of material changes via email or in-platform notice. The "Last updated" date at the top of this page always reflects the current version.

Continued use of the platform after an update is posted constitutes acceptance of the revised Policy.

9. Contact Us

If you have questions about this Privacy Policy, our data practices, or want to exercise your data rights, contact us:

Get in Touch

Company: OneBooks GST+

Email: info@onebooksgst.in

Website: onebooksgst.in