Privacy Policy
Last updated: 22 August 2026
VANIJ (“VANIJ”, “we”, “us”, “our”) is a multi-tenant point-of-sale and ERP platform (billing, inventory, GST compliance, purchase, payroll and related modules) offered as a web console, an offline-capable desktop billing counter, and a mobile app to registered businesses (“Customer”, “you”, “your company”) and used by their staff (“Users”). This Privacy Policy explains what data we collect, why, how it is stored and secured, who it is shared with, and the choices you have — including under the WhatsApp Business Platform integration provided by Meta Platforms, Inc. (“Meta”).
By creating a VANIJ account or using VANIJ on behalf of a business, you agree to the collection and use of information as described here. If you do not agree, please do not use the service.
1. Who this policy covers
VANIJ is business software: a Customer (a shop, pharmacy, restaurant, distributor, etc.) subscribes to VANIJ and its own staff sign in as Users. This policy covers (a) data about the Customer company itself, (b) data about that company's own end customers and vendors which the Customer stores inside VANIJ to run their business, and (c) data about individual Users who sign in. Where the Customer is the controller of its end-customers' data and VANIJ acts as a processor/service provider, this is noted in Section 4.
2. Information we collect
2.1 Account & company information
- Business/company name, GSTIN, PAN, registered address, business vertical and plan/subscription details.
- User full name, email address, mobile number, role (owner/manager/cashier/accountant, etc.) and login credentials (passwords are stored as salted hashes; we never store your plaintext password).
- Optional biometric/passkey (WebAuthn) public-key credentials for passwordless sign-in — the underlying biometric data never leaves your device.
2.2 Business data you store in VANIJ
- Customers & vendors — names, phone numbers, email addresses, GSTIN, billing/shipping addresses, credit terms and outstanding balances that your business records against its own customers and suppliers.
- Invoices, credit/debit notes & orders — items billed, quantities, prices, taxes (CGST/SGST/IGST/UTGST/cess), HSN/SAC codes, e-invoice IRNs and e-way bill numbers.
- Payments & accounting — receipts, payment methods and references, bank statements you import for reconciliation, ledgers, vouchers and financial statements generated from your transactions.
- Inventory & purchase — item catalogue, stock levels, batches/serials/expiry, purchase orders, GRNs and supplier bills.
- Payroll & HR (if enabled) — employee records, attendance, salary structures and payslips for your own staff.
- Documents & attachments — PDFs, scanned bills and receipts you upload, stored in access-controlled storage buckets scoped to your company.
2.3 WhatsApp / messaging data
If you connect the WhatsApp Business Platform (or another supported messaging channel) to send invoices, payment reminders, payslips or marketing messages, VANIJ processes:
- The recipient's phone number and the message content/template (e.g. an invoice PDF, an amount due, a payslip) that your business chooses to send.
- Delivery status callbacks (sent/delivered/read/failed) returned by the messaging provider, so we can show you whether a message reached the recipient and retry failed sends.
- We do not read, sell or use the content of your WhatsApp messages for advertising, and we do not access your end customers' personal WhatsApp account or their other conversations. Messages are sent through Meta's WhatsApp Cloud API using credentials your business (or its VANIJ administrator) configures and controls.
2.4 Device, usage & log data
- IP address, browser/device type, operating system and approximate location (derived from IP), used for security (rate-limiting, fraud/login-abuse prevention) and diagnostics.
- Audit logs of actions taken in the app (who created/edited/voided what, and when) — required for financial accountability and shown back to your company's own admins.
- Crash/error diagnostics to help us fix bugs.
2.5 Cookies & similar technologies
VANIJ's web console uses strictly necessary cookies/local storage to keep you signed in (session tokens), remember your workspace/theme preference, and protect against cross-site request forgery. We do not use third-party advertising or cross-site tracking cookies. Where analytics cookies are used, they are limited to understanding product usage and can be disabled in your browser without breaking core billing functionality.
3. How we use information
- To provide the core service — billing, inventory, tax computation, accounting posting, reports and the WhatsApp/email notifications your business configures.
- To authenticate Users and enforce role-based, company-scoped access to your data.
- To generate statutory documents (GST returns, e-invoices, e-way bills) and file them with government systems on your instruction.
- To detect, investigate and prevent fraud, abuse, security incidents and service outages.
- To provide customer support and respond to requests you or your Users raise with us.
- To improve the product (aggregated, de-identified usage patterns) — never by reading the content of your invoices or messages for purposes unrelated to running your business.
4. Your role vs. ours (controller / processor)
For your own account information, VANIJ is the data controller. For data about your customers and vendors that you enter into VANIJ to run your business (their names, phone numbers, invoices, dues, WhatsApp messages sent to them), your company is the data controller and VANIJ acts as a data processor / service provider, processing that data solely on your instructions to deliver the service. You are responsible for having a lawful basis (e.g. an existing customer relationship, consent where required) to store and message your own customers through VANIJ.
5. Who we share data with
We share data only as needed to run the service, never for third-party advertising:
| Category | Purpose |
|---|---|
| Meta / WhatsApp Business Platform | Delivering invoice, payment-reminder, payslip and marketing WhatsApp messages you initiate. |
| Email & SMS/OTP providers | Delivering invoices/statements by email, and OTP-based login/verification. |
| Payment gateways | Processing your VANIJ subscription payments and, where enabled, payment links you send to your customers. |
| GST Suvidha Provider (GSP) / IRP / e-way bill systems | Filing GST returns, generating e-invoices (IRNs) and e-way bills on your instruction. |
| Cloud infrastructure (Supabase — managed PostgreSQL, authentication, storage) | Hosting the database, files and authentication that power VANIJ. |
| Law enforcement / regulators | Only where legally compelled (e.g. a valid court order or statutory demand). |
We do not sell personal data, and we do not share your business data with other tenants — every company's data is isolated by row-level security in our database.
6. Data security
- Encryption in transit (TLS) for all traffic between your devices and our servers, and encryption at rest for the underlying database and file storage.
- Row-Level Security enforced in the database so every query is scoped to the signed-in user's own company — no tenant can read another tenant's data.
- Role-based access control inside your company (owner/admin/manager/cashier permissions) and a full audit trail of sensitive actions.
- Server-side credentials (e.g. WhatsApp/email/payment provider access tokens) are held only in secured backend functions and are never shipped to the browser or mobile app.
- Passwords are hashed (never stored in plaintext); optional passkey/biometric and OTP-based login further reduce password-related risk.
7. Data retention
We retain business records (invoices, ledgers, tax filings) for as long as your account is active and, thereafter, for the period required under applicable Indian tax and accounting law (generally up to 8 years for GST-related records). Account and profile data is retained until you request deletion (see our Data Deletion page) or your subscription is terminated and the applicable retention/grace period has elapsed. WhatsApp message logs and delivery statuses are retained only as long as needed for delivery troubleshooting and your own message history, subject to the same deletion rights.
8. Your rights
- Access, correct or export the data your company holds in VANIJ, using the in-app tools available to your account's admins, or by contacting us.
- Request deletion of your account and associated personal data, subject to statutory retention obligations — see Data Deletion Instructions.
- Withdraw consent for optional communications (e.g. marketing WhatsApp/email campaigns) at any time; this does not affect transactional messages required to deliver invoices you have billed.
- Raise a complaint with us, or with your local data protection authority, if you believe your data has been mishandled.
9. International data transfer
VANIJ is built for Indian businesses and primarily stores data in infrastructure serving the Indian region. Some sub-processors (e.g. Meta's WhatsApp Cloud API, global cloud infrastructure) may process data outside India in the course of delivering the service; where this happens, we rely on those providers' own security and compliance commitments.
10. Children's privacy
VANIJ is business software intended for use by adults operating or employed by a registered business. It is not directed at children, and we do not knowingly collect data from anyone under 18.
11. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Material changes will be highlighted in the product or communicated to your registered account email. Continued use of VANIJ after an update constitutes acceptance of the revised policy.
12. Contact us
For privacy questions, access/export requests, or complaints, contact us at privacy@erp.creativedox.com. For account or data deletion requests specifically, see Data Deletion Instructions.