Privacy Policy
This policy describes what Techkaro Private Limited collects through taxifo.com and the Taxifo application, why, and what happens to it. It is written to describe what the software actually does.
1. This website collects almost nothing
taxifo.com loads no analytics, no advertising tag, no tag manager, no third-party fonts and no CDN. Every file it needs comes from taxifo.com itself, which means reading about accounting software does not tell anybody else that you did. There are no tracking cookies. This is verifiable from the page source.
If you fill in the callback form
We store only what you type, plus one derived value:
- Your phone number — the only required field, because it is how we call you back.
- Name, city, type of business, and any note — only if you choose to give them.
- A coarsened form of your IP address — the first three octets only, for example
203.0.113.0/24. It exists to detect automated abuse of the form and is deliberately too imprecise to locate a person.
We use this to call you back about accounting, and to introduce you to a CA firm if you ask. Nothing else, and it is not sold or passed to advertisers.
2. What the application holds
When you use Taxifo to bill, the records you create — invoices, parties, GSTINs, addresses, items, payments — are held on the installation belonging to your CA firm, in that firm's own database. One firm's data is not in the same place as another's.
For that data, your CA firm decides the purposes and Techkaro processes it on their instructions in order to run the software.
3. How it is protected
- Passwords are hashed with
argon2id, which is deliberately slow and memory-hard. Nobody can read your password back out, including us. - Every change records the row as it was and as it became, with who changed it and when.
- Each installation signs its own sessions with its own key, so a login from one firm is not valid at another.
- All traffic is encrypted in transit (TLS).
- Backups are taken and are proven by restoring them into a working database and checking the counts match — an unrestored backup is a file, not a backup.
4. Payments
Payments are handled by a payment aggregator regulated by the Reserve Bank of India. We never receive your full card number, CVV, UPI PIN or net-banking password. We keep only the fact of a payment — amount, date, reference and status — for accounting and statutory record-keeping.
5. Who else sees anything
- The CA firm you bill into, or the one we introduce you to.
- Infrastructure and payment providers strictly as needed to run the service.
- Authorities, where the law requires it.
We do not sell personal data. We do not use your business records to train machine-learning models.
6. How long it is kept
Callback enquiries are kept while we are still following them up, and for no more than 24 months after the last contact. Business records are kept for as long as your CA firm requires them and as long as tax law requires — GST records generally have to be preserved for six years. Ask us and we will delete an enquiry sooner.
7. Your rights
You may ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it where we are not required to keep it. Write to privacy@taxifo.com. If the data sits in your CA firm's installation we will route the request to that firm, because it is theirs to decide.
8. Children
Taxifo is for businesses. It is not directed at anyone under 18 and we do not knowingly collect their data.
9. Grievances
Our grievance officer is listed on the contact page, as required by the Information Technology Act, 2000. Complaints are acknowledged within 48 hours and resolved within 30 days.
10. Changes
If this policy changes, the date at the top changes with it, and anything material is notified before it takes effect.