GSTRecon360 ("we") provides GST reconciliation software. This page describes the public beta's current data handling. It is not a claim of certification or a completed compliance audit. DPDP operational notices and grievance details will be completed before a broad paid launch.
What we collect
- Account data: your email address and organisation name.
- Uploaded data: GSTR-2B files and purchase registers you upload, and the reconciliation results computed from them. These contain supplier GSTINs and invoice details.
- Billing data: plan and payment status. Card/UPI details are handled by Razorpay and never touch our servers.
- Operational data: security, error and request records needed to run and protect the service.
How we use it
- To run reconciliations and store results for your account — that is the product.
- We do not sell uploaded invoice data or use uploads to train AI models.
- Service providers process data only to host, authenticate, bill and operate the service.
Storage & security
- Application data is hosted with Supabase/PostgreSQL and the deployment provider; billing is handled by Razorpay.
- Organisation-scoped database policies and private storage are used to separate customer workspaces.
- The beta has not yet completed an independent penetration test or security certification.
- A fixed automatic retention schedule is not yet enforced. Do not use the beta as the only copy of a statutory record; retain your source files and final working papers separately.
Your rights
- Download available source files and reconciliation reports from your workspace.
- Use available in-product deletion controls for source files and clients.
- Request account-level access, correction or erasure through support; completion may require identity verification and is not instant.
Contact
Data and privacy questions: support@gstrecon360.com. A named grievance contact and legal operator details must be published before the public paid launch.