Privacy Policy — UdharDiary
Effective Date: July 18, 2026
Last Updated: July 18, 2026
Service Provider / Legal Entity: UdharDiary (“UdharDiary”, “we”, “us”, or “our”)
Registered / Business Address: Available on request at support@udhardiary.com
Website: https://udhardiary.com
Contact / Privacy Email: support@udhardiary.com
Support Email: support@udhardiary.com
This Privacy Policy explains how UdharDiary collects, uses, stores, shares, and protects information when you use:
- the UdharDiary Android application (and future iOS application);
- related Flutter admin / manager panel access (where provided);
- our landing website hosted on Vercel; and
- related backend services powered by Firebase (including Firebase Hosting where used).
UdharDiary is a shop credit (“udhar”) management application that helps shopkeepers manage customers, credit transactions, payments, reminders, staff, managers, and reports.
By creating an account, using the app, or using our website, you acknowledge this Privacy Policy. If you do not agree, please do not use UdharDiary.
Table of Contents
- Introduction
- Scope and Roles
- Information We Collect
- Information We Do Not Collect
- How We Use Information
- Legal Bases for Processing
- Firebase Usage
- Authentication
- Cloud Storage and Synchronization
- Offline Storage (Isar)
- Subscription Data
- Advertisements and AdMob
- Analytics
- Notifications
- Data Sharing
- Data Security and Encryption
- Data Retention
- Account Deletion
- Your Rights
- Children’s Privacy
- Third-Party Services
- International Transfers
- Policy Updates
- Contact Information
1. Introduction
UdharDiary (“the App”, “the Service”) is designed for shopkeepers and their authorized staff/managers to digitize credit (udhar) records. We process business and personal data only as needed to provide authentication, offline-first operation, cloud backup/sync, reminders, subscriptions, advertisements (on the Free plan), and website analytics.
This Policy is written for compliance alignment with:
- Google Play Developer Program Policies;
- Apple App Store Review Guidelines (for future iOS distribution);
- India’s Digital Personal Data Protection Act, 2023 (DPDP Act), as applicable;
- the EU General Data Protection Regulation (GDPR), where it applies to you; and
- applicable platform and advertising partner requirements (including Google AdMob).
This Policy is not legal advice. Placeholders in square brackets must be completed by UdharDiary before public publication.
2. Scope and Roles
2.1 What this Policy covers
This Policy covers personal data and business data processed through UdharDiary’s mobile apps, admin/manager access surfaces, website, Firebase backend, Cloud Functions, and related Google services used by UdharDiary.
2.2 Shopkeeper as business data controller for customer records
When you enter customer names, customer phone numbers, credit transactions, payments, and reminder information, you act as the business that decides why that customer data is stored. UdharDiary processes that data on your behalf to provide the Service (cloud sync, offline storage, reminders, reports, staff/manager access).
You are responsible for:
- collecting customer information lawfully;
- telling your customers (where required) that you store their details in your shop records; and
- using UdharDiary only for legitimate shop credit management.
2.3 UdharDiary as service provider
For account data (such as your phone number, owner name, shop name, language preference, subscription status, and device/app diagnostics needed to run the Service), UdharDiary / UdharDiary determines the purposes and means of processing as described in this Policy.
3. Information We Collect
We collect the following categories of information. Exact fields may vary by feature version, but we do not expand collection beyond what is needed for the App’s stated features.
3.1 Account and shop profile information
- Phone number (used for Firebase Authentication via OTP)
- Owner name
- Shop name
- Language preference
- Subscription status (Free / Premium) and related entitlement state
3.2 Business and operational data you enter
- Customer names
- Customer phone numbers
- Credit (udhar) transactions
- Payment history
- Reminder information (for example, due dates and reminder-related settings needed to send notifications)
- Staff information (for staff accounts you create or invite)
- Manager information (for manager access you configure)
3.3 Authentication and security data
- OTP verification status via Firebase Authentication
- App lock / MPIN-related security settings stored to protect access on the device (we do not ask for your banking PINs or payment card secrets)
3.4 Device and technical information
- Device information reasonably required to operate the App, deliver notifications, show ads (Free plan), maintain sync integrity, and diagnose issues (for example, device model, OS version, app version, and similar technical identifiers used by Firebase / Google SDKs)
3.5 Notifications-related data
- Push notification tokens / identifiers used by Firebase Cloud Messaging (FCM) to deliver reminder and service notifications, subject to your device permission choices
3.6 Subscription and billing metadata
- Subscription product status and purchase/entitlement metadata provided by Google Play Billing (and, in the future, Apple In-App Purchase)
- We do not receive or store your full payment card number, UPI PIN, or bank login credentials through UdharDiary
3.7 Advertising data (Free plan)
- Advertising identifiers and interaction data processed by Google Mobile Ads (AdMob) to show ads in the Free version, subject to Google’s advertising technologies and your device/ad settings
3.8 Website analytics (landing website)
- On
https://udhardiary.com, we may use Google Analytics 4 (GA4) and, if configured, Google Tag Manager to understand page views, button clicks (for example, download, pricing, contact, FAQ), external link clicks, and scroll depth - Contact form submissions on the website (for example, email and message description) may be stored in Cloud Firestore when that feature is enabled
3.9 Crash logs (future)
- If Firebase Crashlytics is enabled in a future release, crash logs and related diagnostic data may be collected to improve stability. Until enabled, this category may not apply.
3.10 Firebase Storage (future)
- If Firebase Storage is enabled in a future release for user content (for example, backups or files), uploaded objects and associated metadata would be processed under this Policy as updated. Until enabled, file object storage via Firebase Storage may not apply.
4. Information We Do Not Collect
UdharDiary is not a banking app and does not collect or request:
- Bank account numbers (as a required app feature)
- UPI PIN
- Debit card numbers
- Credit card numbers
- SMS content
- Call history
- Photos / gallery access as a core permission
- Device contacts
- Precise or approximate location
- Microphone access
- Camera access
We do not require location, camera, microphone, contacts, SMS, or call-log permissions for UdharDiary’s core features described in this Policy.
5. How We Use Information
We use information to:
- Create and secure accounts using Firebase Authentication (OTP) and optional MPIN protection on the device.
- Provide core shop features, including customer management, credit entries, payments, reports, staff accounts, and manager access.
- Enable offline-first usage via local Isar storage and synchronize data with Cloud Firestore when online.
- Provide cloud backup / sync so your shop data can be restored or accessed across authorized sessions.
- Send reminder notifications and other service notifications via Firebase Cloud Messaging (with your permission where required).
- Manage Free and Premium plans, including ads on Free and ad-free Premium entitlements.
- Process subscriptions through Google Play Billing (and future Apple In-App Purchase).
- Operate the landing website, including analytics and contact inquiries.
- Improve reliability and security, prevent abuse, and comply with law.
- Respond to support and privacy requests.
We do not sell your personal data.
6. Legal Bases for Processing
Depending on your location and applicable law:
6.1 India (DPDP Act)
We process personal data for lawful purposes such as providing the Service you request, fulfilling contracts (including subscriptions), improving security, complying with legal obligations, and other legitimate uses permitted under applicable Indian law. Where consent is required (for example, certain notifications or advertising technologies), we will rely on that consent.
6.2 GDPR (where applicable)
Where GDPR applies, we may rely on:
- Contract — to provide the App features you request;
- Legitimate interests — to secure, maintain, and improve the Service in a balanced way;
- Consent — where required for optional analytics/advertising technologies; and
- Legal obligation — where we must retain or disclose data under law.
You may withdraw consent where processing is consent-based, without affecting the lawfulness of prior processing.
7. Firebase Usage
UdharDiary uses Google Firebase services, which may include:
| Service | Purpose in UdharDiary |
|---|---|
| Firebase Authentication | Phone OTP login and session security |
| Cloud Firestore | Cloud database for synced shop and account data |
| Firebase Cloud Functions | Server-side logic supporting the Service |
| Firebase Cloud Messaging | Reminder and service push notifications |
| Firebase Hosting | Hosting of certain web/admin surfaces (where used) |
| Firebase Storage | Future file/object storage (if/when enabled) |
| Firebase Crashlytics | Future crash reporting (if/when enabled) |
Firebase processes data according to Google’s terms and privacy documentation. Data may be stored on Google infrastructure in regions configured for the Firebase project.
8. Authentication
8.1 Firebase Authentication (OTP)
Account access is based on phone number OTP authentication through Firebase Authentication. Your phone number is a primary account identifier.
8.2 MPIN protection
UdharDiary may allow an MPIN (or similar app lock) to reduce unauthorized local access on a device. Protect your MPIN. We will never ask for your MPIN, UPI PIN, or banking passwords by email or message.
8.3 Staff and manager access
If you create staff or manager access, those users may access shop data according to the permissions you grant. You are responsible for authorizing only trusted persons and revoking access when employment or roles end.
9. Cloud Storage and Synchronization
9.1 Cloud Firestore
Shop and account data needed for sync, backup, multi-device/staff access, and reports may be stored in Cloud Firestore.
9.2 Automatic sync
When a network connection is available, the App is designed to synchronize local changes with the cloud and pull updates so authorized users see current records.
9.3 Cloud Functions
Firebase Cloud Functions may process data server-side (for example, to support secure workflows, notifications-related logic, or subscription entitlement checks).
9.4 Firebase Storage (future)
If enabled later, Firebase Storage may store user-uploaded or generated files. This Policy will be updated if that materially changes data practices.
10. Offline Storage (Isar)
UdharDiary is offline-first. Business data may be stored locally on the device using Isar (or successor local database technology used by the App) so you can continue work without internet.
Local device storage is protected by the security of your device, OS user lock, and any MPIN/app-lock you enable. Uninstalling the App, clearing app data, or device loss can affect local-only unsynced data. Keep sync enabled when you need cloud backup.
11. Subscription Data
11.1 Google Play Billing
Premium subscriptions on Android are processed by Google Play Billing. Google handles payment method collection and charging. We receive subscription status / entitlement information needed to unlock Premium features (for example, unlimited customers, advanced reports, cloud backup features as offered, staff management, and no ads).
11.2 Apple In-App Purchase (future)
When the iOS app is available, Premium purchases may use Apple In-App Purchase. Apple will process payments under Apple’s terms; we will receive entitlement/status information needed to provide Premium.
11.3 What we do not store
We do not store your full card numbers, UPI PIN, or bank passwords in UdharDiary.
12. Advertisements and AdMob
12.1 Ads on the Free plan
The Free plan may display advertisements served by Google Mobile Ads (AdMob).
12.2 Premium and ads
Premium plans are intended to provide an ad-free app experience for entitled accounts, subject to active subscription status.
12.3 AdMob technologies and cookies / identifiers
AdMob and Google advertising services may use advertising IDs, cookies (on web surfaces), SDKs, and similar technologies to serve, measure, and personalize ads according to Google’s policies and your device settings (for example, Android advertising ID reset/opt-out controls).
For more information, review:
- Google Privacy Policy: https://policies.google.com/privacy
- Google Advertising / AdMob policies and user controls available in Google account and device settings
We do not control all AdMob personalization choices made by Google; use Google’s and your device’s ad controls where available.
13. Analytics
13.1 Landing website (GA4)
Our landing website may use Google Analytics 4 to measure usage (page views and selected interaction events). GA4 is configured through environment settings and may fail closed if not configured.
13.2 Optional Google Tag Manager
If configured, Google Tag Manager may load tags that help manage website measurement.
13.3 App analytics
Firebase / Google Analytics measurement may be used in connection with Firebase products where enabled for product improvement. We do not use analytics to sell your shop’s customer lists.
14. Notifications
UdharDiary may request notification permission on your device to deliver:
- payment / due reminder notifications; and
- other service-related notices important to App operation.
You can disable notifications in device settings; some reminder features will not work fully without notification permission. We do not use notification permission as a substitute for SMS, call-log, or contacts access.
15. Data Sharing
We share data only as needed to operate UdharDiary:
15.1 Service providers / processors
- Google / Firebase (Authentication, Firestore, Cloud Functions, FCM, Hosting, and future Storage/Crashlytics)
- Google AdMob (advertising on Free plan)
- Google Play / Apple (subscription billing platforms)
- Vercel (landing website hosting)
- Support / infrastructure vendors strictly as needed
15.2 Staff and managers you authorize
Shop data may be visible to staff and managers according to roles you configure.
15.3 Legal requirements
We may disclose information if required by law, regulation, legal process, or governmental request, or to protect rights, safety, and security.
15.4 Business transfers
If UdharDiary is involved in a merger, acquisition, reorganization, or asset sale, data may transfer as part of that transaction subject to confidentiality and applicable law.
15.5 No sale of personal data
We do not sell personal data to data brokers.
16. Data Security and Encryption
We implement reasonable technical and organizational measures appropriate to the nature of the Service, including:
- authentication via Firebase Authentication (OTP);
- transport security (HTTPS/TLS) for network communication with our services and Google/Firebase endpoints;
- access controls and Firebase security rules / server-side controls as configured for the project;
- optional on-device MPIN / app lock;
- least-privilege access practices for operational systems; and
- monitoring and abuse-prevention measures where practical.
No method of transmission or storage is 100% secure. You are responsible for device security, account OTP access, MPIN confidentiality, and promptly revoking staff/manager access when needed.
17. Data Retention
We retain data for as long as needed to:
- provide the Service to your account;
- maintain backups/sync integrity;
- comply with legal, tax, accounting, or dispute requirements; and
- enforce our Terms.
Typical practices:
- Active accounts: retained while the account remains open and as needed for sync/backup.
- Deleted accounts: deleted or anonymized within a reasonable period after a verified deletion request, except where retention is required by law or for legitimate security/dispute needs.
- Website contact messages: retained as needed to respond and for abuse prevention.
- Ads / analytics logs: retained according to Google product retention practices and our configuration.
Local Isar data remains on the device until cleared, uninstalled, or overwritten by sync/user action.
18. Account Deletion
You may request deletion of your UdharDiary account and associated cloud account data.
18.1 How to request deletion
- Use any in-app account deletion flow if available in your App version; and/or
- Email
support@udhardiary.comfrom the phone number / account associated with your UdharDiary account with the subject line “Account Deletion Request – UdharDiary”.
18.2 What deletion covers
Upon verification, we will delete or irreversibly anonymize personal account data and cloud shop data associated with that account from systems under our control, subject to legal retention needs.
18.3 What deletion may not undo
- Data already exported or copied by you or your staff outside UdharDiary;
- Local device copies until you uninstall/clear app data;
- Billing records retained by Google Play or Apple under their policies;
- Aggregated analytics that no longer identifies you; and
- Records we must keep under applicable law.
Deleting your account may make Free/Premium access and cloud-synced records permanently unavailable.
19. Your Rights
Subject to applicable law (including DPDP and, where applicable, GDPR), you may have rights to:
- access personal data we hold about you;
- correct inaccurate personal data;
- delete personal data / account (see Section 18);
- withdraw consent where processing is consent-based;
- nominate another person to exercise rights on your behalf (where DPDP provides);
- object to or restrict certain processing (where applicable); and
- data portability (where applicable).
To exercise rights, contact support@udhardiary.com. We may need to verify your identity (for example, via the registered phone number) before acting on a request.
If you are a customer of a shopkeeper using UdharDiary, please contact that shopkeeper first for corrections to shop credit records they control. We can assist where appropriate as a service provider.
20. Children’s Privacy
UdharDiary is intended for shopkeepers and adult business users, not for children. The Service is not directed to children under 18 (or the minimum digital-consent age in your jurisdiction).
We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact support@udhardiary.com and we will take appropriate steps to delete it.
21. Third-Party Services
UdharDiary relies on third-party services. Their processing is governed by their own terms and privacy policies, including:
21.1 Google services
- Google Privacy Policy: https://policies.google.com/privacy
- Google Terms of Service: https://policies.google.com/terms
21.2 Firebase
- Firebase / Google Cloud privacy and security documentation published by Google
21.3 AdMob / Google Mobile Ads
- Google advertising and AdMob policies and disclosures
21.4 Google Play Billing
- Google Play Terms of Service and payment/subscription terms
21.5 Apple In-App Purchase (future)
- Apple Media Services Terms and App Store policies when iOS billing is offered
21.6 Vercel (landing website)
- Vercel’s published privacy/security terms for website hosting
We are not responsible for third-party sites or SDKs beyond our instructions to them as service providers, except as required by law.
22. International Transfers
Google Firebase and related Google services may process and store data in data centers outside your country (including outside India). Where required, we rely on appropriate safeguards and Google’s applicable transfer mechanisms and contractual terms.
By using UdharDiary, you understand that your information may be transferred to and processed in other countries that may have different data-protection rules than your home country.
23. Policy Updates
We may update this Privacy Policy to reflect product, legal, or operational changes. The Effective Date at the top will be revised when changes are published.
Material changes will be communicated by one or more of: in-app notice, website notice, or email/SMS where appropriate. Continued use after the updated Effective Date constitutes acceptance of the updated Policy, except where applicable law requires additional consent.
24. Contact Information
For privacy questions, data requests, or account deletion:
| Item | Details |
|---|---|
| Legal entity | UdharDiary |
| Address | Available on request at support@udhardiary.com |
| Privacy / contact email | support@udhardiary.com |
| Support email | support@udhardiary.com |
| Website | https://udhardiary.com |
If you have an unresolved concern under applicable law, you may also have the right to contact the relevant data protection / regulatory authority in your jurisdiction.
End of Privacy Policy