LedgerLink · Legal

Privacy Policy

Effective date: 21 August 2026Last updated: 21 August 2026App name: LedgerLinkService provider: Ctoryteller ("we," "us," "our")Contact email: ledgerlink@ctoryteller.comGrievance Officer: Faroze War (grievance@ctoryteller.com)
Draft notice: highlighted values are placeholders that have not been filled in yet. This document takes effect once they are completed.

This Privacy Policy explains how Ctoryteller ("LedgerLink", "we", "us", or "our"), the owner and operator of the LedgerLink mobile application and related services (the "App" or "Service"), collects, uses, shares, stores, and protects your information.

We are committed to protecting your privacy in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules), and other applicable Indian laws.

By creating an account or using the App, you acknowledge that you have read and understood this Privacy Policy.

1. Who we are (Data Fiduciary)

For the purposes of the DPDP Act, Ctoryteller is the Data Fiduciary that determines the purpose and means of processing your personal data.

  • Registered office: Ctoryteller, 7th Floor, Skyline Icon, Andheri East, Mumbai 400059, India
  • Entity type / registration: [ENTITY TYPE — e.g. Private Limited / LLP / Proprietorship], [CIN / LLPIN / Registration No.]
  • GSTIN (if applicable): [GSTIN]
  • Contact: ledgerlink@ctoryteller.com | ctoryteller.com/ledgerlink/

Details of our Grievance Officer are in Section 13.

2. Scope

This Policy applies to personal data we process when you use the App to keep a digital ledger, manage contacts and inventory, record transactions that the other party can confirm or dispute, issue GST tax invoices, generate bills and reports, send reminders, and purchase a subscription.

3. The information we collect

3.1 Identity and account data

Your name, business/shop name, mobile phone number, email address (if you sign in with email, Google, or Apple), business address, and your chosen app language.

3.2 Contact data you enter

Names, phone numbers, and labels of the customers, suppliers, and other parties ("Contacts") you add to your ledger — including Contacts imported from your device's address book (only with your permission, and only the entries you select) and Contacts who are not on the app. Where you use GST features, this also includes a Contact's GSTIN and place of supply (state).

3.3 Ledger and transaction data

Transaction amounts, item descriptions, rates and quantities, dates, payment and settlement details, notes, the confirmation / dispute / withdrawal status of each entry, edit history, reminders, and records of bills you have sent.

3.4 Inventory data

Item names, units, categories, prices, per-Contact rate overrides and rate history, and — for GST users — each item's GST rate and HSN code.

3.5 GST registration and tax data (only if you enable GST billing)

If you choose to enable GST billing, we collect and store:

  • the GSTIN you submit, together with the legal name, trade name, business type, state, and address you submit with it;
  • the response we receive from the GSTIN verification provider — registration status, legal and trade name, business and taxpayer type, state, address, and registration date — which is stored in full and is what your tax invoices are headed with;
  • the date GST billing was first verified and the date it was last verified;
  • for every taxable entry, a tax invoice record: invoice number, invoice date, financial year, taxable value, GST rate, CGST/SGST/IGST amounts, place of supply, your state, whether the supply is inter-state, and the Contact's GSTIN; and
  • the periods you mark as settled, and any voids or adjustments.

3.6 Subscription and payment data

Your plan, billing cycle, subscription status and dates, and the payment/subscription references returned by our payment gateway.

3.7 Support communications

The content of support tickets and messages you send us.

3.8 Information collected automatically

  • Device and technical data: device model, operating system and version, app version, language and region settings.
  • Server and log data: requests made to our backend, including IP address and timestamps, and error and diagnostic logs generated by our hosting and database provider.

3.9 Information from third parties

  • Payment data: when you subscribe, our payment gateway Razorpay processes your payment. We receive transaction status, a subscription/payment reference, and billing metadata. We do not collect or store your full card number, CVV, UPI PIN, or bank credentials.
  • Phone verification: one-time passwords (OTPs) for phone verification are delivered via our SMS provider (MSG91).
  • Sign-in providers: if you sign in with Google or Apple, we receive the basic account identifiers those services return (such as your email address and, where provided, your name).
  • GSTIN verification: if you enable GST billing, your GSTIN is submitted to [GSTIN VERIFICATION PROVIDER], and the registration details returned are stored as described in Section 3.5.

3.10 Information stored only on your device

  • App Lock PIN and biometric settings: if you enable App Lock, your PIN is stored only on your device in the platform secure store, as a salted cryptographic hash — never in plain text and never transmitted to our servers. Biometric authentication is performed entirely by your device's operating system; we never receive your fingerprint or face data.
  • Entries you record while offline: transactions you create with no working connection are held on your device until they can be sent to our servers. Until they sync they exist nowhere else — so uninstalling the App, clearing its data, or signing in on a different device will lose them.
  • Preferences and session: your language and theme choice, and your sign-in session token.

4. What the other party can see

LedgerLink is a two-party ledger. This is the most important thing to understand about how your data moves:

  • When you record an entry against a Contact who is a LedgerLink user, that entry is shared with them. They can see the amount, the items, the date, your notes, and your name and business name, and they can confirm, dispute, or wait.
  • The entry sits in your book from the moment you create it, and enters their book only when they confirm it. Until then, either side can see it as pending. Entries do not expire.
  • If you withdraw an unconfirmed entry, it is deleted for both parties.
  • Once an entry is confirmed, it forms part of the other party's own business records, and we cannot remove it from their book at your request.
  • Bills, statements, and reminders you send leave the App and go to the recipient through your own messaging apps or email.

5. Contacts you add about other people

The App is a record-keeping tool. When you add a Contact or record a transaction involving another person (including persons "not on the app"), you decide what data to enter.

  • You confirm that you have a lawful basis to record and process that person's information for your legitimate business/accounting purposes, and that you will handle it responsibly.
  • With respect to Contact data you enter, we act largely as a Data Processor processing that data on your behalf and under your instructions, while you act as the Data Fiduciary for your own business records.
  • Placeholder profiles: adding a Contact by phone number creates a placeholder record for that person even if they have never used LedgerLink. If they later register with the same phone number, that placeholder becomes their account — and the entries you share with them become visible to them, as described in Section 4.
  • Download invitation SMS: when you record a transaction for a Contact who is not yet on the App, we may send that Contact one SMS inviting them to download LedgerLink, identifying you by the name on your profile. We send it using a DLT-registered template, no more than once every 14 days per phone number. You are responsible for having a lawful basis to give us that person's number; if you do not want the invitation sent, do not add the Contact.
  • If a person whose data you have entered wishes to exercise their rights, they may contact our Grievance Officer (Section 13), and we will assist and, where appropriate, direct the request to you.

6. How we use your information (purposes)

We process personal data to:

  1. Create and manage your account and verify your phone number;
  2. Provide core features — ledgers, contacts, transactions, confirmations and disputes, inventory, bills, reports, and reminders;
  3. Verify a GSTIN you submit, and generate, number, store, and present the tax invoices and GST summaries that follow from it;
  4. Determine and enforce what your subscription plan entitles you to (such as contact and daily-transaction limits, and which features are available);
  5. Process subscriptions, payments, invoices, renewals, and cancellations;
  6. Send transactional and service communications (e.g., OTPs, in-app notifications about entries awaiting your response, payment notices, and important announcements);
  7. Send, at your instruction, the download invitation described in Section 5;
  8. Provide customer support and resolve disputes and grievances;
  9. Maintain security, prevent fraud and abuse, and debug and improve the App;
  10. Comply with legal, regulatory, tax, and accounting obligations.

7. Legal basis for processing

Under the DPDP Act, we process your personal data on the basis of:

  • Your consent, which you provide when you register and use features (and which you may withdraw — see Section 10); and/or
  • Certain legitimate uses permitted by law, including where you voluntarily provide data for a specified purpose, and to comply with law.

Where SMS, WhatsApp, or other messages are sent to your Contacts at your request, you are responsible for having the necessary consent and for complying with TRAI regulations and Do-Not-Disturb (DND) requirements — except for the download invitation in Section 5, which we send under our own DLT registration.

8. How we share information

We do not sell your personal data. We share it only as described below:

  • The other party to a transaction — see Section 4. This is a core function of the Service.
  • Service providers (Data Processors):

    • Supabase — cloud database, authentication, storage, and hosting;
    • Razorpay — payment processing and subscription billing;
    • MSG91 — SMS delivery for OTPs and for the download invitation in Section 5;
    • [GSTIN VERIFICATION PROVIDER] — GSTIN verification, if you enable GST billing;
    • Google and Apple — if you use their sign-in.

    These providers are permitted to process data only for the purposes we specify and under appropriate safeguards.

  • Legal and regulatory: to comply with applicable law, a lawful request from a court or authority, or to protect our rights, users, and the public.

  • Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.

Messages you send are sent by you. When you share a bill, statement, or reminder over WhatsApp, the App opens WhatsApp on your device with the message prepared; it is sent from your WhatsApp account, and its contents do not pass through our servers. The same applies to any message you choose to send by SMS or email from your device.

9. Data storage, location, security, and retention

  • Your data is hosted on Supabase infrastructure located in Mumbai, India (ap-south-1). Some service providers may process data outside India; where they do, we take steps to ensure protection consistent with applicable law and any restrictions notified by the Government of India under the DPDP Act.
  • Security measures: encryption in transit; row-level security so each tenant's queries can reach only their own data; server-side enforcement of who may read and write what, so access rules cannot be bypassed by a modified client; write access to sensitive fields such as ledger balances withheld from the App entirely; provider credentials held in an encrypted vault; App Lock PINs stored only on your device as a salted hash; and access controls on our administrative tools, whose actions are recorded in an audit log.
  • One-time passwords are stored on our servers only for the few minutes they remain valid, are not returned to the App in an API response, and are readable only by our backend.
  • No method of transmission or storage is 100% secure, but we maintain reasonable security practices as required by the SPDI Rules.
  • Retention: we retain personal data for as long as your account is active and as needed to provide the Service, and thereafter only as required to comply with legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. When no longer required, data is deleted or anonymised.
  • Tax records are retained longer, and are not editable. Once a tax invoice record exists it is not deleted or rewritten; a correction is recorded as a void and reissue or as a separate adjustment entry, so the history stays auditable. Records covered by a period you have marked as settled are not altered. We retain GST records for the period required by GST law72 months (six years) from the due date of furnishing the annual return for the financial year the record belongs to, as prescribed by section 36 of the Central Goods and Services Tax Act, 2017 — regardless of account closure.
  • Confirmed entries form part of the other party's business records and are retained in their account even if you close yours.

10. Your rights

Subject to the DPDP Act, you have the right to:

  • Access a summary of the personal data we process about you;
  • Correct, complete, or update inaccurate or incomplete data;
  • Erase your personal data where it is no longer necessary for the purpose it was collected (subject to the retention rules in Section 9);
  • Withdraw consent at any time (this will not affect processing done before withdrawal, and may limit your ability to use the Service);
  • Nominate another individual to exercise your rights in the event of death or incapacity; and
  • Grievance redressal — raise a complaint with our Grievance Officer, and escalate to the Data Protection Board of India if unresolved.

To exercise any right, contact us at ledgerlink@ctoryteller.com or via the in-App Help & Support section. We may need to verify your identity before acting.

Account deletion is handled by request. Email ledgerlink@ctoryteller.com from your registered address, or contact us through in-App Help & Support. Deleting your account permanently removes your business data and cannot be undone. It does not remove entries the other party has already confirmed into their own book (Section 4), and it does not shorten the statutory retention of tax records (Section 9).

Getting your data out: on plans that include it, the App can produce a PDF report of your transactions for a chosen period, and a statement for any Contact. If you need a copy of your data beyond what the App exports, ask us.

11. Children

The App is available to users aged 13 and over. It is a bookkeeping tool, not a social or entertainment product, and it is not directed at children — but a young person keeping a record of their own small trade is a use we allow rather than shut out.

Under the DPDP Act, 2023, anyone under 18 is a Child. Where a user is under 18:

  • we process their personal data only with the verifiable consent of a parent or legal guardian, obtained before processing begins;
  • we do not carry out tracking or behavioural monitoring of them, and we do not direct advertising at them — we do neither of these for any user (Section 12), so there is nothing to switch off; and
  • the parent or guardian may exercise every right in Section 10 on the Child's behalf, including access, correction, and deletion.

We do not knowingly process a Child's personal data without that consent. If you believe a child has provided us data without it, contact our Grievance Officer (Section 13) and we will delete it.

12. Analytics and third-party links

  • We do not currently embed third-party analytics or advertising SDKs in the App, and we do not use your data for advertising or profiling. What we know about usage comes from the server-side logs described in Section 3.8. If we introduce analytics or crash reporting later, we will update this Policy and its "Last updated" date before doing so.
  • The App and our communications may link to third-party services (for example Razorpay checkout, or WhatsApp). Their use of your data is governed by their own privacy policies, and we are not responsible for their practices.

13. Grievance Officer

In accordance with the IT Act, the SPDI Rules, and the DPDP Act:

  • Name: Faroze War
  • Designation: Grievance Officer / Data Protection point of contact
  • Email: grievance@ctoryteller.com
  • Phone: +91-9970983661
  • Address: Ctoryteller, 7th Floor, Skyline Icon, Andheri East, Mumbai 400059, India
  • Response time: we aim to acknowledge complaints within 48 hours and resolve them within the timelines prescribed by law (and in any case within 30 days).

14. Changes to this Policy

We may update this Policy from time to time. Material changes will be notified in the App or by other reasonable means, and the "Last updated" date above will change. Your continued use after an update constitutes acceptance of the revised Policy.

15. Contact us

Questions about this Policy or your data: Email: ledgerlink@ctoryteller.com Address: Ctoryteller, 7th Floor, Skyline Icon, Andheri East, Mumbai 400059, India

16. Governing law

This Policy is governed by the laws of India. Disputes are subject to the exclusive jurisdiction of the courts at Mumbai, Maharashtra.


This document is a template and does not constitute legal advice. Please have it reviewed by a qualified Indian legal professional before publishing.