Privacy Policy for DueBook
Transparent information on how your data is handled, stored, and protected in DueBook.
1. Introduction & Overview
Welcome to DueBook, a digital ledger and bookkeeping application developed and operated by TSR Mobile Solution ("we", "us", "our"). DueBook is designed primarily for Indian shop owners, merchants, traders, and small businesses to record and manage day-to-day customer and supplier dues, transactions, payment reminders, cash calculator tallies, and business reports.
We respect your privacy and are committed to protecting the information you entrust to us. This Privacy Policy explains what data we collect, how it is stored and processed, where it is kept, and your rights regarding your information under applicable Indian laws, including the Digital Personal Data Protection Act (DPDPA), 2023 and the Information Technology Act, 2000.
2. App Classification & Non-Lending Declaration
DueBook is strictly a Personal and Business Accounting & Record-Keeping Tool.
- No Lending Services: DueBook is NOT a bank, Non-Banking Financial Company (NBFC), money lender, credit bureau, or lending institution.
- No Loan Facilitation: DueBook does NOT provide, offer, facilitate, disburse, or service personal loans, business loans, payday loans, cash advances, micro-finance, peer-to-peer (P2P) lending, or debt recovery/collection services.
- No Automated Financial Decisions: DueBook does not calculate credit scores, interest rates, or loan terms.
- User-Controlled Data Entry: DueBook simply records completed credit/debit ledger entries and reminders manually entered by the user for internal record-keeping.
3. App Architecture & Offline-First Design
DueBook operates on an offline-first architecture:
- Local Storage: All core business ledger records, customer/supplier names, transaction amounts, cash tallies, notes, and receipt photo attachments are stored locally on your device in a secure SQLite database (managed via Android Room). The app functions completely without an internet connection for all day-to-day ledger operations.
- Internet Connectivity: Internet access is required only for:
- Authenticating your identity via Google Sign-In.
- Cloud Firestore device registration and single-device security gate.
- Business profile cloud synchronization.
- User-initiated, client-side encrypted Google Drive backups and restores.
- Firebase Remote Config for app versioning and service notices.
4. Information We Collect and How We Use It
A. User & Account Information (Cloud Firestore)
When you sign in using Google Sign-In (via Google Credential Manager and Firebase Authentication), we collect and store the following account metadata in Google Cloud Firestore (users/{uid}):
- Email address, Display name, and Profile photo URL (from Google account)
- Active device ID (hardware
ANDROID_ID) & Active organization ID pointer - Account creation and last login timestamps
💡 Note: DueBook never collects or stores your Google account password. Authentication is handled entirely and securely by Google OAuth.
B. Device Information & Single-Device Gate
To enforce our single-device security gate and prevent unauthorized concurrent logins, we collect device hardware metadata stored in Cloud Firestore (users/{uid}/devices/{androidId}):
- Device model & manufacturer (e.g. "Samsung Galaxy M34")
- Hardware
ANDROID_ID(Settings.Secure.ANDROID_ID) - Android OS SDK version, App version name & code
- Registration and last active timestamps
C. Business Profile Data (Cloud Synchronization)
To enable cross-device restore of your business setup, non-financial identity fields are stored in Cloud Firestore (organizations/{organizationId}):
- Business / Shop name, Owner name, Contact phone number, Shop address, Category
- Default currency and language preferences
- Merchant UPI ID (VPA) & Merchant Display Name (for UPI QR code generation)
- Backup settings metadata (last backup timestamp, backup file name, contact/transaction count summary)
5. Google Drive Backup & Restore (Optional Feature)
- Isolated App Scope: DueBook requests only the restricted Google Drive scope
https://www.googleapis.com/auth/drive.appdata. This scope is restricted strictly to a private, hidden app data folder. DueBook cannot view, read, modify, or delete any personal documents, photos, or files in your Google Drive. - Client-Side AES-256-GCM Encryption: Backup archives containing your ledger records are encrypted on your device using AES-256-GCM before upload. The encryption key is derived on-device with PBKDF2 (65,536 iterations) and is never transmitted to or stored on our servers.
- Google API Policy Compliance: DueBook's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Android Permissions Requested
DueBook requests only the minimal Android permissions necessary for declared features:
| Permission | Declared Purpose |
|---|---|
| INTERNET | Google Sign-In, Firestore single-device gate, Google Drive backup, Remote Config. |
| ACCESS_NETWORK_STATE | Verifies network availability before attempting cloud sync or backup. |
| CAMERA | Capturing bill & receipt photo attachments (stored in private sandboxed internal storage). |
| POST_NOTIFICATIONS | Delivering local payment due reminders and backup alerts. |
| RECEIVE_BOOT_COMPLETED | Rescheduling local payment reminder alarms after device restart. |
| SCHEDULE_EXACT_ALARM | Precise payment reminder notifications at specified dates/times (Android 12 & below). |
| USE_EXACT_ALARM | Exact payment reminder notifications on Android 13+ with graceful WorkManager fallback. |
7. Data Sharing, Advertising & Third-Party Services
- No Data Sale: We do NOT sell, rent, monetize, or trade your personal information or business ledger records to any third party.
- No Advertising SDKs: DueBook does not embed third-party advertising SDKs or tracking networks.
- Infrastructure Processors: We use Google Firebase (Auth, Firestore, Remote Config), Google Drive (optional backup), and Cloudflare (website CDN).
8. Data Retention & Account Deletion
Local Data Deletion: You can erase all local ledger records instantly via Settings → Reset / Delete Local Data inside the app, or by uninstalling the app.
Cloud Account Deletion: You may request complete deletion of your account and all associated cloud records at any time.
- How to Request: Submit a deletion request via our contact form at https://duebook.tsrms.in/contact?topic=delete-account or email tsrmobilesolution@gmail.com directly with the subject "Account Deletion Request - DueBook".
- Deletion Action: Upon verification of your request, all associated cloud records are permanently and irreversibly deleted, including your Firebase Authentication identity, Cloud Firestore user profile, device registry, organization profile, backup settings metadata, and any associated backup tracking records. This process is completed within 30 calendar days of request verification.
9. Children's Privacy
DueBook is designed and intended strictly for business owners, merchants, traders, and individual adults managing financial ledgers. We do not knowingly collect or solicit personal information from children under the age of 13, or the applicable minimum age in their jurisdiction. If we become aware that a child has provided us with personal data, we will take immediate steps to delete such information.
10. Regulatory Compliance & Grievance Redressal (India)
In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the Digital Personal Data Protection Act, 2023: