Legal
Privacy Policy
Effective: 2026-06-01 · Last updated: 2026-06-06
This Privacy Policy explains how MarBill (“we”, “us”, “the app”) collects, uses, stores, and shares information when you use the MarBill mobile application on iOS and Android. MarBill is owned and operated by Too Loud Communications (proprietor: Shobhit Jitendra Johari), GSTIN 24AYVPJ7014J1Z3, registered at 402, Shree Murlidhar Appartment, Opposite Agrasen Bhavan, Surat, Gujarat – 395007, India.
Contact: privacy@marbill.in
1. Information we collect
1.1 Information you provide
- Account identity — your mobile phone number, used for one-time-password (OTP) sign-in via Firebase Authentication.
- Business profile — business name, GSTIN, state of registration, invoice number prefix, financial-year start month.
- Party (customer) records — party name, phone, GSTIN (optional), state code, address, opening balance.
- Inventory data — varieties (name, grade, HSN, GST %, default rate), stock receive / adjust transactions, available sq.ft.
- Quotations and invoices — line items (variety, dimensions, pcs, rate, GST), totals, payment records, ledger entries.
1.2 Information collected automatically
None. MarBill v1.0 ships no analytics SDKs and no crash-reporting SDKs. We do not track which screens you visit, which features you use, or how long you spend in the app. Production crash reports are reviewed only through the platform-built-in services (Apple TestFlight crash reports, Google Play crash dashboards) and contain no user-identifying business data.
1.3 What we do NOT collect
- We do not access your contacts, photos (except an invoice image you explicitly pick for autofill, which is processed on-device and discarded), microphone, or location.
- We do not embed third-party advertising or tracking SDKs.
- We do not collect payment-card information (any pricing is collected via external payment gateways with their own policies).
2. How we use information
We use the data above to:
- Provide the billing and inventory service you signed up for.
- Authenticate you via Firebase Authentication (phone OTP).
- Generate PDFs of your quotes and invoices and let you share them via your device's share sheet.
- Respond to support requests at support@marbill.in.
We do not sell, rent, or share your personal or business data with third parties for marketing purposes. Ever.
3. Where your data is stored
- On-device SQLite — every record (parties, varieties, invoices, payments, settings) is first written to a SQLite database inside the app's private container on your phone. This is the primary data store; it works offline.
- MySQL database (Hostinger, India) — for multi-device sync and cloud backup we mirror your records to a MySQL database hosted by Hostinger on Indian infrastructure.
- Firebase Authentication — phone-number-to-user-ID mapping is stored by Google Firebase Authentication. Google may process this data in multiple regions per its own infrastructure.
We do not transfer your business data outside India.
4. Sub-processors
We rely on a minimal set of sub-processors:
| Sub-processor | Purpose | Region |
|---|---|---|
| Google Firebase Authentication | Phone-OTP sign-in | Multi-region (Google) |
| Hostinger | API hosting + MySQL database | India (Mumbai) |
| Let's Encrypt | TLS certificates | Global edge |
We will update this list if it changes.
5. Your rights (DPDP Act, 2023)
Under India's Digital Personal Data Protection Act, 2023 you have the right to:
- Access your personal data and a summary of how it is processed.
- Correct inaccurate or outdated data — most fields are editable in-app.
- Delete your account and all associated business data.
5.1 In-app account deletion
Go to More → Settings → Delete my account. On confirmation we will:
- Immediately sign you out and mark your tenant for deletion.
- Hide your data from all access.
- Hard-delete all records after 7 days (a brief grace window to recover from accidental deletion via support).
You can also request deletion by emailing privacy@marbill.in from the phone number on the account.
6. Data retention
While your account is active, we retain your business data so the app works (you wouldn't want last month's invoices to disappear). When you delete your account, we hard-delete the data after the 7-day grace window described above.
7. Security
- All API traffic is TLS-encrypted (HTTPS) end-to-end.
- Database access is restricted to the MarBill API; no public network exposure.
- Firebase ID tokens are verified on every API call; expired or revoked tokens are rejected.
- Passwords are not used (phone OTP via Firebase); we therefore cannot leak passwords we never had.
No system is perfectly secure. If we detect a personal-data breach affecting you, we will notify you in-app and by email within 72 hours of becoming aware, as required by the DPDP Act.
8. Children
MarBill is a business-to-business application for stone traders. It is not directed to anyone under the age of 18 and we do not knowingly collect data from minors.
9. Changes to this policy
If we materially change this policy we will (a) update the “Last updated” date above, (b) show an in-app notice on next launch, and (c) email account holders. Continued use after the change constitutes acceptance.
10. Contact
| For | |
|---|---|
| Privacy questions | privacy@marbill.in |
| Data deletion request | privacy@marbill.in |
| General support | support@marbill.in |
Postal: Too Loud Communications, 402, Shree Murlidhar Appartment, Opposite Agrasen Bhavan, Surat, Gujarat – 395007, India.