T2H BillMaster Privacy Policy
1. Introduction & Company Identity
Welcome to T2H BillMaster ("Application", "Service", or "Platform"). This Privacy Policy explains our practices regarding the collection, storage, use, and protection of personal and commercial data when you access our mobile applications (Android, iOS), desktop software (Windows), and web portal at https://bill.t2hbill.com.
The Application is developed, owned, and operated by Tech2Home Labs ("Company", "we", "us", or "our"), an Indian technology firm having its registered office at:
Shop No.27, 1st floor, The N.A.Dt. Ex.Servicemen, Co.op, Timber and Blacksmithy Workers & Service Ltd No.X.S.7, 14th East Cross Road, Gandhi Nagar, Vellore - 632006.
GSTIN: 33BZZPV0389L1Z9 • Email: [email protected]
2. Scope of Application
This Privacy Policy applies to all users of T2H BillMaster across all distributed channels:
- Web Application: Accessed via modern desktop and mobile web browsers.
- Android Mobile & Tablet Application: Distributed via Google Play Store and official signed APK package (
com.t2hbill.billmaster). - Windows Desktop POS Application: Standalone POS terminal installation.
- iOS Progressive Web Application (PWA): Full-screen mobile PWA experience for Apple devices.
3. Information We Collect
We collect information strictly necessary to provide robust business billing, Indian GST tax calculations, quotation lifecycles, and customer ledger accounting:
A. Account & Authentication Information
User full name, registered email address, optional contact phone number, securely hashed passwords (using industry-standard bcrypt), and OAuth authentication tokens (when signing in via Google or Firebase Authentication). We never store raw passwords in plain text.
B. Business Profile & Tax Details
Business trade name, legal entity name, owner name, business address, state code, GSTIN (Goods and Services Tax Identification Number), invoice numbering sequences, currency, and optional business logo image used for generating branded tax invoices and thermal receipts.
C. Customer Directory & Credit Ledgers
Customer names, contact numbers, email addresses, GSTIN numbers, billing/shipping addresses, opening balances, and running credit ledger transaction histories. Note: Business users are solely responsible for entering and lawfully handling their customers' records.
D. Billing, Invoices & Tax Computations
Product catalog items, HSN and SAC codes, item quantities, sale prices, line-item discounts, GST tax rate breakdowns (CGST, SGST, IGST), payment modes (Cash, UPI, Card, Bank), and generated PDF invoices.
E. Device & Hardware Permissions
- Camera (
android.permission.CAMERA): Used exclusively for live barcode and QR code scanning in POS counter mode. No photos or video recordings are saved or transmitted to our servers. - Bluetooth (
BLUETOOTH_CONNECT,BLUETOOTH_SCAN): Used exclusively to discover and communicate with ESC/POS 80mm wireless thermal receipt printers. - Network State (
INTERNET,ACCESS_NETWORK_STATE): Used to verify network connectivity and trigger automatic background cloud synchronization.
4. Data Flow Architecture & Offline Synchronization
T2H BillMaster is architected as an offline-first application to prevent retail counter freezing during network interruptions:
5. How We Use Collected Information
- Generating valid Indian GST Tax Invoices, Quotations, and Credit/Debit Notes.
- Executing real-time multi-device cloud synchronization between mobile phones, tablets, and desktop POS counters.
- Enabling 1-tap WhatsApp invoice delivery and thermal receipt printing.
- Maintaining customer ledger balances and generating sales performance analytics.
- Providing technical customer support, hardware printer troubleshooting, and account recovery.
6. Data Sharing & Third-Party Processors
We never sell, rent, trade, or monetize your commercial data or customer directories to advertisers or third-party data brokers. Data is shared strictly with verified infrastructure processors necessary to deliver the service:
- Razorpay Payment Gateway: For processing subscription payments. Payment card numbers, CVVs, and net banking credentials are handled directly by Razorpay under PCI-DSS Level 1 compliance. We only receive confirmation status and transaction reference IDs.
- Google & Firebase Authentication: For verifying user identities and issuing secure OAuth session tokens.
- Cloud Hosting & PostgreSQL Infrastructure: Encrypted cloud database servers hosted in secure data center environments.
7. Data Retention Policy
- Active Subscription Accounts: Account data, business profiles, customer ledgers, and invoice records are retained for as long as your account remains active.
- Statutory Tax Compliance: Invoices generated under Indian GST regulations may be retained in exportable format to assist businesses in meeting their statutory record-keeping obligations.
- Account Deletion: When an account deletion is requested, all cloud records are permanently purged within 48 hours.
8. Account & Data Deletion
In compliance with Google Play Store Developer policies and international data privacy laws, we provide a direct and accessible process for complete account and data deletion:
9. Security Safeguards
We implement comprehensive administrative, technical, and physical safeguards:
- All client-server communications use HTTPS with TLS 1.3 encryption.
- Passwords are cryptographically hashed using salted bcrypt.
- Authentication tokens on mobile devices are stored in hardware-backed keystores (
FlutterSecureStorage). - Databases are protected behind secure network firewalls with role-based access control.
10. Grievance Officer & Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or data handling practices, please contact our designated Privacy and Grievance Officer:
Email: [email protected]
Phone: +91 9047352593
GSTIN: 33BZZPV0389L1Z9
