Privacy policy
Last updated 9 August 2026
Ragxen Technologies operates Ragxen Books, billing and bookkeeping software for shops in India. This policy explains what we collect, why, and what we never do with it.
The short version
We collect what is needed to run your billing and nothing else. We do not sell your data, we do not share it with advertisers, and there is no advertising or tracking identifier in our app or website.
What we collect
Your account. Your name, email address, mobile number, business name, GSTIN and a hashed password. Passwords are stored as bcrypt hashes and are never readable by us.
What you enter. Invoices, quotations, credit and debit notes, purchases, payments, products and the customer or supplier records you create. That includes names, phone numbers, email addresses and GSTINs that you enter about your own customers.
Technical data. IP address and timestamps for sign-in attempts, used only to block brute-force attacks and to keep an audit trail of licence changes.
We do not collect location, contacts, photos, device identifiers or advertising IDs.
Data about your customers
When you record a customer, you are the controller of that data and we process it on your behalf. We use it only to produce your documents and to send them where you ask us to. We never contact your customers for our own purposes.
Why we process it
- To provide the service: creating, storing, printing and sending your documents.
- To meet legal obligations: GST law requires issued tax invoices to be retained.
- To secure the service: rate limiting, CAPTCHA on public forms, and audit records.
- To take payment for your subscription and to tell you when it is due.
Who we share it with
Only the providers needed to run the service, each handling a narrow slice:
- Hosting and database: servers located in India, holding your account and documents.
- Ragxen Pay: subscription payments. Card and bank details go to the payment provider and never reach our servers.
- Email delivery: our own mail server, used to send invoices, password resets and staff invitations.
- Cloudflare Turnstile: bot protection on the signup and password-reset forms.
We do not sell, rent or trade personal data. We disclose it otherwise only where the law requires it.
How long we keep it
Your data stays while your account is open. If you close it, we delete your login and personal contact details, but tax invoices and the records supporting them are retained for 72 months as GST law requires. Those retained records are locked to statutory access only and are not used for anything else.
Unpaid signups that never issue an invoice are deleted automatically after seven days.
Security
- All traffic is encrypted with HTTPS.
- Passwords are hashed with bcrypt; nobody at our company can read them.
- Every shop’s data is isolated by organisation on every query.
- Sign-in, signup and password-reset endpoints are rate limited against brute force.
- On phones, your session token is held in the device keystore rather than ordinary storage.
Your rights
You can view and correct your details in the app at any time, export your registers as CSV, and request deletion. Write to privacy@ragxen.com and we will respond within 30 days. See deleting your account for what deletion does and does not remove.
Children
Ragxen Books is business software and is not directed at anyone under 18.
Changes and contact
If we change this policy we will update the date above and notify account owners by email where the change is material.
Ragxen Technologies, [Registered address]. Email privacy@ragxen.com.