Billing data is the most sensitive thing your business keeps — what it sells, to whom, at what margin. Here is exactly how it is handled, in plain terms.
Database rules allow an account to read and write only its own tree. One shop cannot reach another's data, and the rules are enforced by the database itself rather than by the app asking politely.
Every connection between your device and our servers is over HTTPS. Passwords are stored only as a cryptographic hash — nobody here can read yours, including us.
Card numbers, CVV, UPI PIN and netbanking credentials go straight to the payment gateway, which is PCI-DSS compliant. We receive only the amount, the plan and a payment reference.
Subscription records live outside your account's tree and are writable only by our server. No app on any device — including one that has been tampered with — can extend its own coverage.
Full export as CSV and JSON, on demand, from inside the app. Stop paying and your account becomes read-only rather than closed — you can still open, print and export everything.
Every void, deletion, permission change and settings change is written to an activity log with the account that made it, so a disputed change has an answer.
No system is perfectly secure, and we would rather say so than print a badge. We hold no formal certification such as ISO 27001 or SOC 2 today. What we can tell you is precisely where your data sits — Google Firebase for the database and sign-in, Cloudflare R2 for images you upload — and that if a breach ever affects your records, we will tell you rather than hope you don’t notice.
If you believe you have found a security problem, please tell us before telling anyone else, and give us a reasonable chance to fix it. We will confirm receipt, keep you updated, and credit you if you would like. Please do not run tests that could affect other shops’ data or availability.
Read the privacy policy for the full detail, or ask us directly.
Contact us