Privacy policy
This policy explains what information Ledgeree collects when you install and use the app, why, who it is shared with, and how to exercise your rights over it. Last updated 29 August 2026.
Who this policy covers
Ledgeree is operated by Bytefacts Software Solutions, Tamil Nadu, India (“Ledgeree,” “we,” “us”). This policy applies to the Ledgeree Shopify app, Ledgeree Books, the ledgeree.com website, and the Windows relay agent used to connect to Tally Prime.
Information we collect
We collect only what the configured workflow needs to post correct, GST-compliant vouchers:
- From your Shopify store, via webhooks and the Admin API: fulfillment and order identifiers, line items (SKU, title, quantity, price, discount), shipping province and country, payment gateway name, tracking carrier, and -- only where you configure a GSTIN source -- a B2B buyer’s GSTIN from an order note, metafield, or Shopify B2B company record. Ledgeree deliberately does not store the buyer’s name, email, phone number, or full address -- place-of-supply and B2B invoicing only need the state, country, and (for B2B orders) the GSTIN.
- Configuration you enter directly: product-to-ERP mappings (SKU, HSN code, GST rate), ledger names, warehouse/state mappings, LUT number and financial year, voucher numbering rules, and (for Zoho Books) OAuth authorization.
- From your connected accounting system: ledger and Stock Item names read back from Tally Prime (via your local relay agent) or Zoho Books, used only to validate mappings and avoid posting against a name that doesn’t exist.
- Operational data: sync status, retry counts, error messages, and relay-agent heartbeat/connectivity logs, used to show you what succeeded, failed, or is pending.
- Support correspondence: anything you send us directly, e.g. via the contact form or email.
We do not collect payment card details. Subscription billing runs entirely through Shopify’s own Billing API -- Ledgeree never receives or stores your card number.
How we use this information
- To capture shipped/fulfilled orders and generate GST-correct accounting vouchers in your chosen ERP.
- To validate configuration before posting (e.g. blocking a push when a GST rate or ledger mapping is missing) rather than guessing.
- To show you sync status, retry failed pushes, and alert you to configuration gaps (e.g. an expiring LUT).
- To provide support when you contact us, and to secure the service against abuse.
- To meet our own legal, tax, and accounting obligations as a business.
We do not sell personal information, and we do not use order or customer data for advertising.
Who we share information with
Information is shared only with the service providers needed to run Ledgeree, and only to the extent each one needs:
- Shopify Inc. -- the platform Ledgeree is installed on; all order/fulfillment data originates from Shopify’s own APIs.
- Supabase (database, authentication, and edge functions) -- hosts the application database and the serverless functions that process webhooks and run daily aggregation.
- Cloudflare -- hosts the embedded app and the marketing website, and provides the network edge in front of both.
- Zoho Corporation -- only if you connect Zoho Books; order data is sent to your own Zoho Books organization via Zoho’s API under your own OAuth authorization.
- Web3Forms -- only processes messages submitted through the ledgeree.com contact form (name, email, message); it never receives order or accounting data.
We disclose information beyond this list only where required by law, regulation, or a valid legal process, or to protect the rights, property, or safety of Ledgeree, our users, or the public.
Your Tally Prime data never leaves your own network for Tally-specific processing: the relay agent runs on your machine and talks to Tally over your local network. Only the resulting sync status and any data you explicitly configure for cloud-side aggregation (the voucher figures themselves) reach our servers.
International data transfer
Our infrastructure providers (Supabase, Cloudflare) may process and store data outside India as part of their global infrastructure. Where this occurs, we rely on those providers’ own contractual and technical safeguards for cross-border transfer.
Data retention and deletion
- If you uninstall the app, sync halts immediately and your session credentials are deleted.
- When Shopify sends a
customers/redactorshop/redactrequest (per Shopify’s mandatory privacy webhooks), we clear customer-identifying fields and stored credentials tied to that request. - Customer and shop data subject to a valid Shopify deletion request is erased or irreversibly de-identified. Accounting figures may be retained only where Bytefacts Software Solutions has an independent legal obligation or the merchant has expressly instructed a lawful archival service; unnecessary customer identifiers are removed.
- Customer data-access exports are compiled when Shopify sends a valid
customers/data_requestwebhook and are retained only long enough to fulfil and document the request.
Operational diagnostics are ordinarily retained for 90 days, security logs for up to 12 months, support correspondence for 2 years, and privacy/grievance records for 3 years. Bytefacts Software Solutions’ own GST records are retained for 72 months from the applicable annual-return due date, and corporate books for up to eight financial years only where that rule applies. Encrypted backup copies expire through the backup lifecycle within 90 days.
Security measures
Access tokens for connected accounts (e.g. Zoho Books) are encrypted at rest using AES-256-GCM before storage. All traffic runs over TLS. The Tally Prime relay agent means your Tally instance is never exposed on a public port -- the agent polls out to our servers rather than accepting inbound connections. Access to production infrastructure is limited to the people operating the service.
Cookies and tracking
The ledgeree.com marketing site does not use analytics or advertising cookies. The embedded Shopify app uses only the session mechanism Shopify itself requires for embedded apps to function.
Your rights
You may request access to, correction of, or deletion of your personal information, or object to a particular use of it, by emailing [email protected]. We may need to verify your identity and authority (e.g. store ownership) before acting on a request. Deleting data required for your own statutory accounting records may not be possible while you remain subject to those requirements.
Children’s privacy
Ledgeree is a B2B accounting tool for merchants and is not directed at, or knowingly used by, children.
Grievance officer
Grievances and questions about personal-data processing may be addressed to the Grievance and Privacy Contact, Bytefacts Software Solutions, Tamil Nadu, India, at [email protected]. We aim to acknowledge a grievance within 72 hours and provide a substantive response within 30 days.
Governing law
This policy is governed by the laws of India. Subject to any mandatory statutory forum, disputes are subject to the jurisdiction of the competent courts in Tamil Nadu.
Changes to this policy
We’ll update the “last updated” date above when this policy changes, and post material changes on this page before they take effect.
Contact
Questions about this policy: [email protected].