🛡️ Privacy & Data Protection Policy

Privacy Policy for DueBook

Transparent information on how your data is handled, stored, and protected in DueBook.

Developer: TSR Mobile Solution (TSRMS)Effective Date: September 20, 2026Last Updated: September 20, 2026
App Classification & Regulatory Declaration

2. App Classification & Non-Lending Declaration

DueBook is strictly a Personal and Business Accounting & Record-Keeping Tool.

  • No Lending Services: DueBook is NOT a bank, Non-Banking Financial Company (NBFC), money lender, credit bureau, or lending institution.
  • No Loan Facilitation: DueBook does NOT provide, offer, facilitate, disburse, or service personal loans, business loans, payday loans, cash advances, micro-finance, peer-to-peer (P2P) lending, or debt recovery/collection services.
  • No Automated Financial Decisions: DueBook does not calculate credit scores, interest rates, or loan terms.
  • User-Controlled Data Entry: DueBook simply records completed credit/debit ledger entries and reminders manually entered by the user for internal record-keeping.

3. App Architecture & Offline-First Design

DueBook operates on an offline-first architecture:

  • Local Storage: All core business ledger records, customer/supplier names, transaction amounts, cash tallies, notes, and receipt photo attachments are stored locally on your device in a secure SQLite database (managed via Android Room). The app functions completely without an internet connection for all day-to-day ledger operations.
  • Internet Connectivity: Internet access is required only for:
    1. Authenticating your identity via Google Sign-In.
    2. Cloud Firestore device registration and single-device security gate.
    3. Business profile cloud synchronization.
    4. User-initiated, client-side encrypted Google Drive backups and restores.
    5. Firebase Remote Config for app versioning and service notices.

4. Information We Collect and How We Use It

A. User & Account Information (Cloud Firestore)

When you sign in using Google Sign-In (via Google Credential Manager and Firebase Authentication), we collect and store the following account metadata in Google Cloud Firestore (users/{uid}):

  • Email address, Display name, and Profile photo URL (from Google account)
  • Active device ID (hardware ANDROID_ID) & Active organization ID pointer
  • Account creation and last login timestamps

💡 Note: DueBook never collects or stores your Google account password. Authentication is handled entirely and securely by Google OAuth.

B. Device Information & Single-Device Gate

To enforce our single-device security gate and prevent unauthorized concurrent logins, we collect device hardware metadata stored in Cloud Firestore (users/{uid}/devices/{androidId}):

  • Device model & manufacturer (e.g. "Samsung Galaxy M34")
  • Hardware ANDROID_ID (Settings.Secure.ANDROID_ID)
  • Android OS SDK version, App version name & code
  • Registration and last active timestamps

C. Business Profile Data (Cloud Synchronization)

To enable cross-device restore of your business setup, non-financial identity fields are stored in Cloud Firestore (organizations/{organizationId}):

  • Business / Shop name, Owner name, Contact phone number, Shop address, Category
  • Default currency and language preferences
  • Merchant UPI ID (VPA) & Merchant Display Name (for UPI QR code generation)
  • Backup settings metadata (last backup timestamp, backup file name, contact/transaction count summary)

5. Google Drive Backup & Restore (Optional Feature)

  • Isolated App Scope: DueBook requests only the restricted Google Drive scope https://www.googleapis.com/auth/drive.appdata. This scope is restricted strictly to a private, hidden app data folder. DueBook cannot view, read, modify, or delete any personal documents, photos, or files in your Google Drive.
  • Client-Side AES-256-GCM Encryption: Backup archives containing your ledger records are encrypted on your device using AES-256-GCM before upload. The encryption key is derived on-device with PBKDF2 (65,536 iterations) and is never transmitted to or stored on our servers.
  • Google API Policy Compliance: DueBook's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

6. Android Permissions Requested

DueBook requests only the minimal Android permissions necessary for declared features:

PermissionDeclared Purpose
INTERNETGoogle Sign-In, Firestore single-device gate, Google Drive backup, Remote Config.
ACCESS_NETWORK_STATEVerifies network availability before attempting cloud sync or backup.
CAMERACapturing bill & receipt photo attachments (stored in private sandboxed internal storage).
POST_NOTIFICATIONSDelivering local payment due reminders and backup alerts.
RECEIVE_BOOT_COMPLETEDRescheduling local payment reminder alarms after device restart.
SCHEDULE_EXACT_ALARMPrecise payment reminder notifications at specified dates/times (Android 12 & below).
USE_EXACT_ALARMExact payment reminder notifications on Android 13+ with graceful WorkManager fallback.

7. Data Sharing, Advertising & Third-Party Services

  • No Data Sale: We do NOT sell, rent, monetize, or trade your personal information or business ledger records to any third party.
  • No Advertising SDKs: DueBook does not embed third-party advertising SDKs or tracking networks.
  • Infrastructure Processors: We use Google Firebase (Auth, Firestore, Remote Config), Google Drive (optional backup), and Cloudflare (website CDN).
Google Play Policy Compliance · Data Deletion

8. Data Retention & Account Deletion

Local Data Deletion: You can erase all local ledger records instantly via Settings → Reset / Delete Local Data inside the app, or by uninstalling the app.

Cloud Account Deletion: You may request complete deletion of your account and all associated cloud records at any time.

  • How to Request: Submit a deletion request via our contact form at https://duebook.tsrms.in/contact?topic=delete-account or email tsrmobilesolution@gmail.com directly with the subject "Account Deletion Request - DueBook".
  • Deletion Action: Upon verification of your request, all associated cloud records are permanently and irreversibly deleted, including your Firebase Authentication identity, Cloud Firestore user profile, device registry, organization profile, backup settings metadata, and any associated backup tracking records. This process is completed within 30 calendar days of request verification.

9. Children's Privacy

DueBook is designed and intended strictly for business owners, merchants, traders, and individual adults managing financial ledgers. We do not knowingly collect or solicit personal information from children under the age of 13, or the applicable minimum age in their jurisdiction. If we become aware that a child has provided us with personal data, we will take immediate steps to delete such information.

10. Regulatory Compliance & Grievance Redressal (India)

In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the Digital Personal Data Protection Act, 2023:

Application Name: DueBook
Developer / Legal Entity: TSR Mobile Solution (TSRMS)
Grievance & Support Email: tsrmobilesolution@gmail.com
WhatsApp Support: +91 8016227323
Grievance Timeline: Grievances are acknowledged within 48 hours and resolved within 15 days from receipt.