Data We Process
GSTRecon360 processes account details, organisation membership, uploaded GSTR-2B files, purchase-register rows, reconciliation results, freeze snapshots, exports, audit logs, and payment metadata needed to operate the service.
How We Use Data
We use data to authenticate users, run GSTR-2B vs books reconciliation, retain month-wise workspaces, generate reports, maintain audit history, process billing, secure tenant access, and provide support.
Sign-in can use Google OAuth where configured. Email sign-in stores a one-way password hash and never stores plaintext passwords.
Data Isolation
Application queries are tenant-scoped. Users can access only the organisations and records attached to their signed-in workspace, except platform administrators performing audited support or operations tasks.
Payments
Paid checkout is processed through Razorpay. GSTRecon360 stores order IDs, payment IDs, plan, amount, tax split, status, and webhook evidence. We do not store card, UPI, net-banking, or wallet credentials.
Sub-processors
We share the minimum data needed to operate the service with: Razorpay (payment processing), Google (OAuth sign-in), Resend (transactional email, including contact-form and account emails), Sentry (error and performance monitoring), our S3-compatible object storage provider (uploaded GSTR-2B and purchase-register files), and our hosting platform, Vercel. Resend and Sentry may process data outside India. Data is retained for as long as your account is active, plus a reasonable period after account closure for legal, billing, and security purposes.
Security
Workspace access requires authentication. Passwords are stored as a one-way hash, never in plain text. All traffic is served over HTTPS. Application queries are tenant-scoped, so a signed-in user can only reach their own workspace's data. Sensitive actions such as uploads, freeze, admin changes, matching-rule edits, and payment webhooks are recorded in a chained-hash, tamper-evident audit log. Uploaded files are held in private object storage, never publicly readable.
Contact & Deletion Requests
Signed-in users can create a deletion request from Settings. Submitting a request records it for identity, ownership, retention, and legal-hold review by our support team. Submission does not automatically erase data or guarantee completion within 30 days; we will confirm the applicable handling and timeline after review. For privacy enquiries, e-mail taxoneadvisory@gmail.com with your account email and organisation name.
Legal Entity & Grievances
GSTRecon360 is operated by Tax One Advisory (OPC) Private Limited, GSTIN 37AAMCT7977Q1ZX, registered in Vijayawada, Andhra Pradesh, India.
Send privacy questions, data-access requests and grievances to taxoneadvisory@gmail.com.