Legal
Privacy Policy
How Zetabooks (a Sabrixa product) collects, uses, stores, and shares your business and financial data.
- Effective
- 25 July 2026
- Last updated
- 25 July 2026
- Version
- 1.0
This Privacy Policy explains how Sabrixa (“Sabrixa”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects personal and business data when you use Zetabooks — our web application, Android/iOS apps, APIs, and related services (together, the “Service”).
Zetabooks is bookkeeping and invoicing software for businesses. It is designed so you upload bank statements and bills yourself — we do not ask for your live bank login or connect to your bank with aggregator credentials.
By creating an account, using the Service, or continuing after we post updates, you acknowledge this Policy. If you do not agree, please do not use the Service.
This Policy is written for clarity. It is not legal advice to you. For enterprise contracts or regulated industries, please ask your counsel to review it alongside our Terms of Service.
1. Who we are (data fiduciary)
For Indian data protection purposes, Sabrixa acts as the data fiduciary for personal data processed to operate Zetabooks, unless a written agreement says otherwise (for example, if we process data only as a processor for a larger enterprise).
Product: Zetabooks. Parent / operator: Sabrixa.
Contact for privacy requests: contact@sabrixa.com. Website: https://www.sabrixa.com.
If you need a postal address for notices, email us and we will provide the registered correspondence address on record for Sabrixa.
2. Scope — who and what this covers
This Policy applies worldwide to the extent you access the Service. Primary production hosting is in India (see Hosting).
- Business owners, staff, and invited team members who create or use a workspace
- People who visit our marketing website or contact us
- Customers who open payment or invoice links you send (limited data needed to show the invoice / payment page)
- Mobile app users (camera / photo library only when you choose to scan or upload)
3. Information we collect
3.1 Account & identity
- Name, email address, password (stored as a secure hash — we cannot read your password)
- Phone / WhatsApp number if you provide it for support or sharing
- Language preference and UI settings
- Business profile: business name, GSTIN (if you enter it), address, logo, UPI / payment details you configure
3.2 Financial & bookkeeping data (core of the product)
This may include sensitive commercial information and, incidentally, personal data of your customers, vendors, or workers that appears on documents you upload. You are responsible for having a lawful basis to upload that third-party data into your workspace.
- Bank / UPI statements you upload (PDF, CSV, images) and extracted transactions
- Invoices, quotations, credit notes, bills, purchase orders, products, categories
- Cash counts, contractor / payroll records you enter
- Payment status, matches between bank lines and invoices/bills
- GST-related exports and comparisons you run (for example GSTR-2B / GSTR-3B files you upload)
- Files and attachments you store for books (statements, bill PDFs, slips)
3.3 Mobile app permissions
We do not use these permissions for advertising. You can deny access in OS settings; scanning features will then be limited.
- Camera — only when you scan bills, receipts, or statements
- Photo library / media — only when you pick an image or file to upload
3.4 Technical & usage data
- IP address, device/browser type, approximate region derived from IP
- App version, crash/error diagnostics
- Pages or features used (product analytics / marketing visitor stats where enabled)
- Cookies or similar storage for session, language, theme, and referral attribution
3.5 Payments for your Zetabooks subscription
If you buy a paid plan, payment is processed by Razorpay (or another processor we name at checkout). We receive payment status, order identifiers, and limited billing metadata. We do not store your full card number on our servers.
3.6 Communications
- Messages you send to support (email, WhatsApp, in-app contact forms)
- Transactional emails we send (password reset, invites, reminders you enable)
4. What we deliberately do not collect
You stay in control of what statements and bills enter the Service by uploading or forwarding them.
- Live bank login credentials, netbanking passwords, or UPI PINs
- Direct API access to your bank account via account aggregators (unless we clearly introduce such a feature later and update this Policy)
- Your contacts list, SMS inbox, or call logs
- Precise GPS location for advertising
5. How we use information
We do not sell your financial books or statement contents to data brokers or advertisers.
- Provide bookkeeping, invoicing, reconciliation, reports, and related features you request
- Authenticate users, secure accounts, and enforce roles / permissions in your workspace
- Parse statements and bills (including with optional AI — see section 7)
- Send transactional messages (security alerts, invites, payment or reminder emails you enable)
- Process subscription payments and prevent fraud / abuse
- Improve reliability, debug errors, and understand feature usage in aggregate
- Comply with law, respond to lawful requests, and enforce our Terms
- Communicate product updates or support replies you initiate
6. Legal bases (including India DPDP)
Depending on context, we rely on one or more of: your consent (for example optional AI features, marketing cookies where required); performance of a contract (providing the Service you signed up for); legitimate uses permitted under applicable law for security, fraud prevention, and service improvement; and compliance with legal obligations.
Where India’s Digital Personal Data Protection Act, 2023 (DPDP) applies, we process personal data for the purposes described in this Policy and honour applicable rights of individuals (see Your rights).
7. Artificial intelligence (important)
Zetabooks may use machine-learning / large-language-model services to help with tasks such as: reading bank statement text or scanned statement images when local parsing is insufficient; extracting fields from vendor bills; answering questions in AI Coach / Ask using context from your live books; reading contractor paper slips from photos; and assisting with certain GST PDF comparisons or purchase-order match explanations.
When cloud AI is enabled for your workspace (via our environment configuration and/or your workspace AI settings), relevant excerpts — which may include transaction narrations, amounts, dates, GSTINs, vendor names, and, for vision features, page images — are sent to the AI provider solely to return structured results or answers for that request.
AI providers we may use include OpenAI, Google (Gemini), Anthropic, and/or a self-hosted/local model (for example Ollama) depending on configuration. Those providers process data as our processors / service providers under their terms and data-processing terms.
Cloud AI is not required for all features. Many statement formats parse locally. You can keep cloud AI off by not enabling API keys / turning AI settings off. When AI is off, AI-dependent extraction or Coach features will be limited or unavailable.
We do not use your books to train a public model for unrelated customers. Provider training/retention practices are governed by the provider’s API / enterprise terms in force at the time of processing — we recommend paid API usage with training opt-outs where available.
You should not upload data you are not allowed to process. AI output can be wrong — you remain responsible for reviewing books before filing taxes or paying vendors.
9. Hosting, security, and international transfers
Production runs on cloud infrastructure in India with encrypted transport (HTTPS). Data at rest is protected using platform-level disk encryption and application controls (hashed passwords, encrypted secrets for items such as statement PDF passwords and OAuth tokens where implemented).
No method of transmission or storage is 100% secure. We apply reasonable technical and organisational measures appropriate to a cloud bookkeeping product, including access controls, secrets management, and role-based permissions inside workspaces.
If you enable cloud AI or certain processors, data for that request may be processed in other countries (for example the United States) by that vendor. By enabling those features you instruct us to make that transfer for the stated purpose. We select reputable vendors and rely on appropriate contractual / legal mechanisms available under applicable law.
10. Retention
We keep account and bookkeeping data for as long as your workspace is active and as needed to provide the Service, resolve disputes, enforce agreements, and meet legal / tax record expectations you or we may have.
If you delete your business / account using in-product controls (where available) or submit a verified deletion request, we will delete or anonymise personal data within a reasonable period, except where we must retain information for legal compliance, fraud prevention, security, or backup integrity (backups are purged on a rolling schedule).
Uploaded statement files and derived transactions remain until you delete them or delete the workspace, subject to the same exceptions.
11. Your rights & choices
Subject to applicable law (including DPDP where it applies), you may request:
- Access to personal data we hold about you
- Correction of inaccurate personal data
- Deletion / erasure of personal data (with legal exceptions)
- Export / portability of your books where the product provides export tools
- Withdrawal of consent for optional processing (for example turning off AI or disconnecting Gmail)
- Grievance redressal via the contact below
How to exercise rights
Workspace owners can often export or wipe data from Settings → Data & privacy. For other requests, email contact@sabrixa.com with the subject “Privacy request”. We may need to verify your identity and authority over a business workspace before acting.
If you are a customer/vendor whose data appears only because a business uploaded it, contact that business first; we support the business as the primary controller of workspace contents.
12. Children
The Service is for business use and is not directed to children under 18. We do not knowingly create accounts for children. If you believe a child has provided personal data, contact us and we will take appropriate steps.
14. Third-party links and customer payment pages
The Service may link to third-party sites (banks, GST portal, Play Store, payment pages). Their privacy practices are their own. When your customer opens an invoice or payment link, they may see your business details and amounts you chose to share; payment card data is handled by the payment provider, not stored as full PAN on our servers.
15. Your responsibilities as a business user
- Upload only data you are allowed to process
- Configure team roles carefully; revoke access when staff leave
- Review AI-extracted or auto-matched data before relying on it for tax or payments
- Keep your password safe and enable organisational hygiene (unique emails per user)
- Provide your own privacy notice to your customers/employees where required
16. Changes to this Policy
We may update this Policy. The “Last updated” date at the top will change. Material changes may also be notified in-app or by email where appropriate. Continued use after the effective date means you accept the updated Policy, except where applicable law requires fresh consent.
17. Contact & grievance
Privacy / data requests: contact@sabrixa.com
General support: contact@sabrixa.com or WhatsApp via the contact details on https://www.sabrixa.com
Please allow a reasonable time for a response. If you are unsatisfied, you may also have rights to approach the Data Protection Board of India or other authorities under applicable law once those mechanisms are available for your case.
18. Google Play & mobile-specific note
This same Policy applies to the Zetabooks Android / iOS apps. The apps are primarily a client to our Service (including WebView-based experiences where used). Data practices for uploads, camera, and AI are as described above.
Play Store data-safety answers should be filled to match this Policy: financial info and personal info are collected for app functionality; data is encrypted in transit; optional cloud AI may process document contents when enabled; we do not sell user data.
Questions? Email contact@sabrixa.com. This page is provided for transparency; for high-stakes legal advice about your business, consult your own counsel.