Privacy Policy
This policy explains what Trip Munshi, operated by [[ legal entity name ]] ("we", "us"), collects, why, and what you can do about it. It covers the Trip Munshi website and application.
1. What we collect
- Account details — name, email address, contact number and password (stored hashed, never in readable form).
- Business records you enter — firms, companies, fleet owners, orders, consignments, invoices, payments and the documents you attach. This is your operational data; we treat it as confidential.
- Billing records — the plan you chose, the amount and reference of a payment you report, and its confirmation status.
- Usage and security logs — an activity log of significant changes inside your account, plus standard server logs (IP address, browser, timestamps) used to run and secure the Service.
We do not run advertising or third-party tracking on the application. [[ update this line if you add website analytics ]]
2. What we do not collect
We never see or store card, UPI PIN, or bank credentials. Payment is made directly by you through your own UPI or banking app; we only record the amount and reference you report so we can confirm it.
3. Why we use it
- To provide the Service — storing your records and producing your ledgers, invoices and reports.
- To authenticate you and keep accounts secure, including verifying your email address.
- To bill you and confirm payments you report.
- To support you when you contact us, and to send service notices (renewals, changes, incidents).
- To debug and improve the Service.
We do not sell your data, and we do not use your business records to train models or build products for anyone else.
4. Separation between customers
Each organisation's records are scoped to that organisation and are not visible to any other customer. Within your account, access is limited to the users you invite and the roles you give them.
5. Who else touches your data
We use a small number of service providers to run Trip Munshi — hosting, database, email delivery. They process data only on our instructions.
Current providers: [[ list your hosting, mail and backup providers ]]. Data is hosted in [[ region / country ]].
We may also disclose data where required by law or valid legal process.
6. How long we keep it
We keep your records for as long as your account is active. After cancellation: [[ retention window before deletion, e.g. 90 days ]]. Backups are retained for [[ backup retention, e.g. 30 days ]] and then overwritten. Security and billing logs may be kept longer where the law requires it.
7. Security
Access is protected by password authentication with email verification, per-organisation scoping, and role-based permissions. Traffic is served over HTTPS and passwords are stored hashed. No system is perfectly secure; if a breach affects your data we will notify you promptly. [[ add encryption-at-rest and backup specifics once confirmed ]]
8. Your choices
- Export — download your organisation's data as CSV at any time from Data Export in the app.
- Correct — edit your account and business records directly in the app.
- Delete — ask us to delete your account and data by writing to tripmunshi@gmail.com.
- Service email — notices about billing, security and availability are part of the Service and cannot be opted out of while your account is open.
9. Cookies
We set only the cookies needed to run the application: a session cookie to keep you signed in and a CSRF token to protect forms. No advertising or cross-site tracking cookies are used.
10. Children
Trip Munshi is a business tool and is not directed at anyone under 18.
11. Changes
We may update this policy. Material changes will be notified by email or in the app before they take effect.
12. Contact
Questions, or a request about your data: tripmunshi@gmail.com, [[ registered address ]].