Production-Ready Policy

Privacy Policy

Privacy policy for Baniya's (Baniyas AI), detailing how customer, vendor, SMS, contacts, and transactions are managed securely.

Effective Date: June 18, 2026Last Updated: August 18, 2026
Active Section

1. Introduction

1. Introduction

Welcome to Baniya's(“Baniyas”, “Baniyas AI”, “we”, “our”, or “us”). We are committed to protecting your business and transaction privacy.

Baniya's provides store owners, retailers, and kirana merchants with a digital price book, ledger book (“Khata”), wholesale/retail rate tracker, crop mandi rate search assistant, and voice-activated inventory manager.

This Privacy Policy describes how Baniya's handles information in connection with our mobile app (“Android Application”), the web portal located at https://baniyas.store, and the associated NestJS REST APIs. By using our application, you agree to the terms in this policy.

2. Information We Collect

We collect only the essential business and account information required to provide the core services of Baniya's. This is strictly divided into information you actively supply and the transactional catalog data you record during usage. We do not gather personal browsing histories or access sensitive device components beyond the explicitly approved features below.

3. Information You Provide

To use Baniya's, you actively provide us with:

  • Account Profile details: Store owner name, phone number, email address, and account password.
  • Custom Business lists: Custom item categories, product item catalogs (names, retail rates, wholesale rates, units, descriptions), and ledger contact profiles.
  • Voice Chat messages: Queries submitted in natural language to retrieve prices and stock updates.

4. Customer and Vendor Information

To manage your credit and balances (“Khata”), you can add customer and vendor (“Vyapari”) ledger records. When you add a ledger profile, we store:

  • The contact's display name (Required)
  • The contact's mobile phone number (Optional, used for SMS receipt sharing and verification)
  • The profile type classification (either CUSTOMER or VYAPARI)
  • Calculated ledger balance outstanding dues

5. Contacts Permission

To simplify adding parties to your ledger book, the Android Application requests permission to read your contacts (READ_CONTACTS permission).

Contacts Privacy Guarantee: The Contacts Permission is used solely on your Android device to open a list of your contacts so you can choose a specific customer or vendor. Only the specific contact you manually select (their name and phone number) is saved to the app database. We DO NOT upload your entire contact book, store it on our servers, or share it with third parties.

6. SMS Permission and Transaction Messages

Baniya's offers automatic notification sharing by requesting permission to send SMS text messages from your device (SEND_SMS permission).

When you record a transaction (“Gave” or “Got”) for a customer or vendor, Baniya's generates a transactional SMS message on-device. If the customer or vendor has a valid phone number, the app uses your carrier network to deliver the SMS message.

The SMS text message contains:

  • The customer or vendor's display name
  • The transaction details (credit or payment type, amount in Indian Rupees, and transaction date)
  • The total current outstanding balance
  • A unique, secure web history link for the contact to view their ledger online
  • Your business owner profile name

SMS Privacy Policy:The SMS capability is used strictly to send transactional alerts directly from your phone as configured by you. We do not read your inbox, access other text messages, or collect your phone's SMS history.

7. Khata / Transaction Data

Every ledger credit entry recorded includes the transaction type (GAVE or GOT), transaction amount (in INR), date and time of the entry, and optional notes (e.g., product item names, quantity details).

This transactional ledger is stored securely on our servers linked to your authenticated owner account and synchronized with your local device.

9. Product/Business Data

To manage pricing margins, you can register items in your product catalog, specifying:

  • Item name and description
  • Wholesaler rates, retail prices, and custom purchasing prices
  • Item measurement units (e.g., kg, dozen, packet, bottle)
  • Associated product category classifications

This catalog is protected by strict user isolation on the backend database. Owners cannot view, access, or edit products listed by other shop owners.

10. Account and Authentication Data

Owner account registration and login are validated securely on the backend server.

  • Passwords are hashed immediately using strong cryptographic algorithms (such as bcrypt) before storage. We do not store passwords in plaintext.
  • JWT Session Keys: Upon successful login, the API issues a secure JSON Web Token (JWT) Bearer token to authorize subsequent API requests.

11. How We Use Information

Baniya's uses collected data to run the application services, specifically to:

  • Maintain and authenticate your store owner account.
  • Synchronize catalog and ledger profiles between your phone and our databases.
  • Process monthly and yearly premium plans.
  • Resolve voice search requests and retrieve product info via the AI chatbot.
  • Provide shareable history receipt URLs for ledger transparency.
  • Deliver transactional SMS notifications and payment reminders via your carrier.

12. Local/Offline Data Storage

The Android Application saves catalog data, credit ledgers, and transaction jobs locally on your device in a secure SQLite database (via Room architecture). This ensures Baniya's functions correctly even without active internet connectivity.

13. Server Synchronization

When your device connects to the internet, local ledger edits and catalog items sync with our cloud server APIs to ensure your data is backed up and accessible in the event of device replacement or loss.

14. Third-Party Services

We coordinate with trusted technical partners to power our infrastructure:

  • MongoDB: Our primary database service for secure catalog and ledger cloud storage.
  • Render: Our server host hosting the REST NestJS APIs.
  • Razorpay: Our premium payment partner. Subscription flows are directed securely to Razorpay checkout portals.
  • Google Gemini / OpenAI APIs: Process natural voice commands and chat questions securely.
  • Cloudinary: Secure media/image asset storage.

15. AI Chatbot Integration

For active premium subscribers, the AI inventory assistant helps retrieve catalog data (e.g. “Sugar ka wholesale price detail search”).

  • To answer questions, the app sends your specific catalog search list (products, prices, units) and prompt text to Google Gemini or OpenAI LLM API endpoints.
  • Chat message history is saved securely in your private cloud account module.
  • Compliance: We do not submit customer phone numbers, credit ledgers, or account passwords to the AI interfaces. No business information is processed by the AI providers to train their baseline LLM models.

16. Payment and Subscription Details

Subscription payments are managed via Razorpay integration. When ordering monthly or yearly premium upgrades, we record:

  • Subscription state (TRIAL, ACTIVE, EXPIRED)
  • Payment details (Razorpay Order ID, Razorpay Payment ID, payment amount, currency)
  • Subscription period start and end dates

We do not collect, capture, or store your credit card, bank routing, UPI pin, or checkout credential details. All card checkouts are processed directly and securely by Razorpay.

17. Data Security Measures

We enforce security practices to safeguard your business ledgers:

  • Encryption in Transit: All requests and data synced between your mobile application, web page, and backend APIs are protected via HTTPS/SSL.
  • Authentication Keys: Operations require authentication via validated JWT session signatures.
  • Data Isolation: Catalog assets and Khata ledgers are partitioned based on owner `userId` tags, preventing other operators from intercepting your business accounts.
  • Password Hashing: Passwords are encrypted before database submission using modern hashing protocols.

Please note that while we use industry-standard security structures, no system is completely immune to security threats.

18. Data Retention Policies

We retain your catalog products, Khata ledgers, and profile credentials for as long as your Baniya's account remains active. If your premium subscription ends or expires, we preserve your information so you can access it again upon renewal.

19. Account and Data Deletion

You retain total control over your business catalog and ledger entries:

  • In-App Item Deletion: You can delete individual products, custom categories, transaction entries, and customer/vendor ledger cards directly in the app. Deleting a contact automatically purges all related credit records. Deleted items are permanently removed from our cloud servers.
  • Complete Account Deletion: You can request complete account deletion directly within the Baniya's Android App (navigate to Profile Settings → Delete Account). This will permanently purge your owner profile credentials, catalogs, all customer and vendor profiles, ledger transaction logs, shortage items, and shared web history links from both local storage and cloud databases.

Alternatively, you can request account deletion online via our public deletion page: /delete-account or by emailing us at support@baniyas.store.

20. Children's Privacy

Our services are directed to adults, business operators, and retail store merchants. We do not target or knowingly collect data from children under the age of 13. If we discover we have inadvertently collected information from a child, we will delete it immediately.

21. User Rights and Choices

Depending on your jurisdiction, you may have specific rights regarding your data:

  • Access and Export: You can review your transaction summaries and customer balance records inside the app.
  • Rectification: You can edit incorrect product descriptions, category names, customer/vendor names, and phone numbers directly.
  • Permission Control: You can revoke Contacts read access or SMS send permissions through your Android device settings at any time, though this will disable related auto-fill and receipt sharing features.

22. Changes to Privacy Policy

We may modify this Privacy Policy as our features evolve or compliance rules change. If we update the terms, we will update the “Last Updated” date at the top of the policy page. We encourage you to review this policy periodically.

23. Contact Us

If you have any questions, feedback, or data removal requests regarding this Privacy Policy, please reach out to us:

Email Support: support@baniyas.store
Official Site: https://baniyas.store