← Back to home

Legal & Privacy

Last updated: 10 June 2026 - DPDP Act 2023 + DPDP Rules 2025 aligned

Privacy Policy Terms of Service Refund Policy Data Security
Privacy Notice under the Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025 · Effective: 10 June 2026 · Applies to all Caledger users in India

Plain English summary: We collect only what we need to run your account, with your consent. We never sell your data or use it for advertising. Your clients' data belongs to your firm - we only store and process it on your instructions. You can withdraw consent, export, or delete everything at any time, as easily as you gave it.

1. Who We Are

Caledger is a product operated by Ledgerstack Technologies LLP ("we", "us"). Ledgerstack Technologies LLP is the Data Fiduciary for the personal data of registered account holders. Registered office: Bengaluru, Karnataka, India. For the client records your firm enters into Caledger, your firm is the Data Fiduciary and Ledgerstack Technologies LLP (through Caledger) acts as a Data Processor on your firm's instructions - we never use that data for our own purposes.

2. What Personal Data We Collect, and Why

Account information (you, as our customer)

Collected: name, firm name, email address, WhatsApp number, city, plan and payment references, and a one-way hashed password.
Purpose: creating and operating your account, billing, sending account and security notifications, and support. We never store your password in readable form.

Client data your firm enters (processed on your behalf)

Stored: client names, GSTIN, contact details, filing statuses, notes.
Purpose: only to provide the service to your firm. This data is yours; we are the secure storage and processing layer.

Client GST portal credentials (only if your firm connects a client's login)

Stored: the client's GST portal username and password, encrypted at rest with AES-256-GCM. The password is never returned to the browser, never displayed in any report, and never written to logs.
Purpose: solely to log in to the GST portal on that client's behalf to fetch their own filing status, returns and notices - the same task your firm would otherwise do manually. Credentials are decrypted only in server memory at the moment of a fetch, and every decryption is recorded in an access log. We store a credential only when your firm confirms it holds the client's authorisation to access their GST account; that confirmation is recorded with the staff member's name and the date. Your firm, as Data Fiduciary, is responsible for obtaining and retaining written authorisation from each client (an authorisation template is available on request).

Contact / enquiry forms

Collected: name, email, phone and your message, with your explicit consent at the point of submission.
Purpose: responding to your enquiry. Not used for marketing without separate consent.

Usage and security logs

Collected: login times and security-relevant events.
Purpose: security monitoring, fraud prevention and legal compliance. Logs are retained for one year as required by the DPDP Rules, 2025. No advertising, profiling or tracking.

3. Consent, and Withdrawing It

We process your personal data on the basis of the consent you give at signup or on a form, for the specific purposes stated there. You may withdraw consent at any time, with the same ease you gave it:

  • In the app: Settings → Data & Privacy → Withdraw consent / Delete my account
  • By email: info@caledger.in with the subject "Withdraw consent"

On withdrawal we stop processing and delete your personal data (see Retention below), except where retention is required by law. Withdrawal does not affect the lawfulness of processing already done.

On request, we will provide this notice in any language listed in the Eighth Schedule to the Constitution of India.

4. Your Rights as a Data Principal

  • Access - a summary of the personal data we hold about you and the processing activities
  • Correction and updation - fix inaccurate or incomplete data, in-app or by email
  • Erasure - deletion of your personal data when no longer necessary or on consent withdrawal
  • Grievance redressal - a working, time-bound complaints channel (below)
  • Nomination - nominate a person to exercise your rights in case of death or incapacity

We respond to rights requests within 7 working days. If you are unsatisfied with our response, you have the right to complain to the Data Protection Board of India.

5. Data Sharing and Transfers

We do not sell, rent, or share personal data with any third party for their own use. Limited sharing happens only with:

  • Hosting infrastructure - servers located in Mumbai, India. Your data does not leave India.
  • GST data services - when you use GST sync, the client GSTIN you request is sent to a government-authorised GST API provider solely to retrieve public filing status.
  • Legal compliance - where required by Indian law, court order, or a regulator. We notify you where legally permitted.

6. Security Safeguards

In line with Rule 6 of the DPDP Rules, 2025: encryption in transit (TLS) everywhere, hashed credentials (bcrypt), strict access controls with per-firm isolation, encrypted recycle-bin storage, security logging with one-year retention, automated daily backups, and server-side rate limiting and intrusion protection. Core infrastructure and client data are hosted in India. A few operational sub-processors (captcha-solving, transactional email and web-push delivery) may process limited data outside India.

7. Personal Data Breach

If a personal data breach affects you, we will inform you without delay in plain language - what happened, what data was involved, what we are doing, and what you can do - and report it to the Data Protection Board of India within the timelines prescribed by the DPDP Rules, 2025 (72 hours).

8. Data Retention and Erasure

  • Your data is retained while your account is active.
  • You can export all data (Excel/PDF) at any time, including before closing your account.
  • On account closure or consent withdrawal: personal data is deleted from live systems within 30 days, and from backups within 60 days.
  • Security logs are kept for one year, then deleted.
  • We will give you at least 48 hours' notice before erasing data due to prolonged inactivity.

9. Cookies

Caledger uses only essential cookies and local storage required for the application to function (session management, security tokens). No tracking cookies, no advertising cookies, no third-party analytics.

10. Grievance Officer and Contact

Grievance Officer: Himanshu Daga
Email: info@caledger.in
Address: Ledgerstack Technologies LLP, Bengaluru, Karnataka, India

We acknowledge grievances within 48 hours and resolve them within 7 working days. If unresolved, you may escalate to the Data Protection Board of India.

Effective: 10 June 2026

1. Acceptance of Terms

Caledger is a product operated by Ledgerstack Technologies LLP ("we", "us", "Caledger"). By creating an account on Caledger, you agree to these Terms of Service with Ledgerstack Technologies LLP. If you do not agree, do not use the service. These terms apply to all users - firm owners, CAs, and staff members.

2. Service Description

Caledger is a practice management software for Indian CA firms. It provides client management, compliance tracking, staff management, and secure credential storage. Caledger is a tool to help you manage your practice - it does not provide legal, tax, or accounting advice.

3. Account Responsibilities

  • You are responsible for maintaining the confidentiality of your login credentials
  • You are responsible for all activity that occurs under your account
  • You must notify us immediately of any unauthorised access at info@caledger.in
  • Each firm must register with accurate information
  • One account per CA firm. Multiple staff members can be added as team members.

4. Acceptable Use

You agree not to:

  • Use Caledger for any unlawful purpose or in violation of ICAI regulations
  • Attempt to gain unauthorised access to other firms' data
  • Reverse engineer, copy, or resell any part of Caledger
  • Upload malicious code, viruses, or harmful content
  • Use Caledger to store data unrelated to your CA practice

5. Subscription and Payment

  • All paid plans require UPI payment at checkout
  • Plans are billed monthly or annually as selected at checkout
  • All prices are in Indian Rupees (INR) and inclusive of GST where applicable
  • Payments are processed via UPI. We do not store card details.
  • Subscriptions renew automatically unless cancelled before the renewal date

6. Service Availability

We aim for 99.5% uptime. Planned maintenance will be notified 24 hours in advance. We are not liable for losses resulting from downtime beyond our reasonable control.

7. Limitation of Liability

Caledger is a practice management tool. We are not responsible for compliance failures, missed deadlines, or financial losses arising from use or non-use of the software. Users are responsible for verifying all compliance deadlines independently with official GSTN and Income Tax portals.

8. Governing Law

These terms are governed by the laws of India and constitute an agreement with Ledgerstack Technologies LLP. Any disputes shall be subject to the jurisdiction of courts in Bengaluru, Karnataka, India.

9. Changes to Terms

We may update these terms. We will notify you by email at least 14 days before material changes take effect. Continued use after that date constitutes acceptance.

Effective: 10 June 2026

Short version: We offer a 7-day refund window from the date of first payment. Annual plans get a prorated refund within 30 days. Contact info@caledger.in to request a refund.

7-Day Refund Policy

Payments for Caledger are collected by Ledgerstack Technologies LLP. If you are not satisfied within 7 days of your first payment, contact us at info@caledger.in and we will issue a full refund. No questions asked. Annual plans are eligible for a prorated refund within 30 days.

Monthly Plans

If you are not satisfied after your first payment on a monthly plan, contact us within 7 days of the payment date and we will refund the full amount - no questions asked.

After 7 days from payment, monthly plan payments are non-refundable. You can cancel anytime to stop future charges.

Annual Plans

Annual plan payments are eligible for a prorated refund within 30 days of payment. After 30 days, annual plan payments are non-refundable but your access continues until the plan expiry date.

How to Request a Refund

Email info@caledger.in with your firm name, registered email, and payment date. We process all refunds within 5 working days back to your original UPI account.

Technical security overview - June 2025

Our commitment: Your client data is treated with the same care an Indian bank applies to financial records. Here is exactly how we protect it.

Encryption

Data at Rest
All sensitive data including GST passwords encrypted with AES-256-GCM before storage. The encryption key is never stored in the database.
Data in Transit
All communication between your browser and our servers is encrypted in transit over HTTPS/TLS. No data ever travels unencrypted.
Passwords
User passwords are stored only as salted bcrypt hashes - never in plain text. Even we cannot reverse your password. Ever.
🎫
Sessions
Short-lived JWT tokens (15 min). Refresh tokens stored hashed. Automatic logout on inactivity. Account locks after 5 failed logins.

Data Isolation

Every query to our database includes a mandatory firm ID filter. It is technically impossible - not just policy - for one CA firm to access another firm's data. This is enforced at the database query level, not just the application level.

Within your firm, staff members only see clients assigned to them. Your admin/CA staff see all clients. This access control is enforced at every API endpoint.

Infrastructure

  • Hosted on enterprise-grade cloud servers in India
  • Automatic daily backups with 30-day retention
  • SSL certificate from a trusted CA with auto-renewal
  • DDoS protection and rate limiting on all endpoints
  • Login attempts: max 10 per minute per IP. Brute force protection active at all times.

GST Password Vault - Technical Detail

When you save a GST portal password:

  • It travels to our server over HTTPS (encrypted in transit)
  • It is immediately encrypted with AES-256-GCM using a unique random IV
  • The encrypted version is stored in the database - the plaintext is immediately discarded
  • The encryption key is stored only in environment variables - never in the database
  • Every access to a decrypted password is logged with timestamp and user ID
  • Only 5 password decryption requests are allowed per minute (rate limited)

Reporting a Security Issue

If you discover a security vulnerability, please report it responsibly to info@caledger.in with subject line "Security Report". We will acknowledge within 24 hours and aim to resolve critical issues within 72 hours. We do not pursue legal action against good-faith security researchers.