Privacy Policy
Last updated: 23 August 2026
1. What we collect
- Account data: your name and email address from Google Sign-In.
- Business data you provide: business/client names, GSTINs, purchase register rows, GSTR-2B extracts, vendor names and WhatsApp numbers, and reconciliation results.
- Usage data: reconciliation run summaries, credit transactions, and notification delivery logs.
2. What we do NOT collect
We never store your GST portal password. GST portal access works through a one-time OTP sent to your registered mobile number via an authorised GST Suvidha Provider (GSP); the resulting session token is short-lived, stored encrypted at rest on our servers, and never shared with your browser or third parties. We never see or store your UPI PIN, card, or bank details; payments are handled entirely by Razorpay.
3. How we use data
Solely to provide the Service: running reconciliations you request, showing your history back to you, sending the vendor notifications you trigger, and processing your credit top-ups. We never sell your data, and we never use your invoices, vendors or GST figures for advertising. We share them only with the processors listed below.
Google Ads conversion tracking runs across the website, including while you are signed in, so we can tell which adverts lead to a sign-up. The Google tag sets cookies and receives the page address, your IP address and your browser, plus a one-off signal when an account is created. It never receives your name, email, GSTIN, invoices, vendors or any figure from your reconciliation. You can opt out at google.com/settings/ads or by blocking third-party cookies.
4. Where data lives
Your data is stored and processed in India (AWS Mumbai region) with these processors:
- Supabase: primary database (Postgres, Mumbai).
- Vercel: application hosting.
- Amazon Web Services: reconciliation compute (Mumbai).
- Twilio: WhatsApp message delivery (message content and recipient number only).
- Razorpay: payment processing for credit top-ups.
- Sandbox (sandbox.co.in): authorised GSP channel to the GST system.
- Google (Google Ads): advertising measurement on the website. Receives page addresses and cookie identifiers only, never invoice, vendor or GST data.
5. Isolation and security
Every account's data is isolated: your clients, vendors, runs, and notifications are visible only to you. All traffic is encrypted in transit (TLS) and at rest. Sessions automatically expire 24 hours after sign-in. Database-level row security is enabled as an additional layer.
6. Vendor phone numbers
WhatsApp numbers you add for your vendors are used only to deliver the specific alerts you trigger. You are responsible for having consent to contact those numbers; recipients can opt out by replying STOP, and we honour opt-outs.
7. Retention and deletion
Data is retained while your account is active. Email support@2bmatch.com from your registered address to export or permanently delete your account and all associated data.
8. Contact
Questions or grievances: support@2bmatch.com.