Skip to content

Legal

Privacy Policy

What LalKitaab collects, what never leaves your computer, and how to get your data removed.

Last updated 16 August 2026

This policy explains what Dacitos Technologies Pvt Ltd ("we") collects when you use the LalKitaab website and desktop application, and what we do not.

What stays on your computer

The desktop application keeps everything it does in a SQLite database in your Windows app-data folder. On the Offline plan nothing in that database is ever transmitted to us, and the application works with no connection at all.

  • Products, categories, brands and stock ledger
  • Customers, suppliers and their contact details
  • Invoices, purchases, payments, expenses and every report drawn from them
  • Your company profile, logo and printing preferences

Local backups are encrypted with AES-256-GCM using a passphrase held in Windows DPAPI storage on your machine. If you switch on Google Drive backup, the encrypted file goes to your own Google account — not to us — under Google's terms, not this policy.

What we collect

DataWhyWhen
Name, shop name, phone, email, GSTINTo raise your order, issue a licence and provide supportYou type it at checkout, or tell support
Order and payment recordsLegal and accounting obligation; proof of purchaseWhen you buy or renew
Licence key, plan, seats, expiryTo let your copy of the application runOn purchase, activation and renewal
Computer IDTo bind a licence to a machine and enforce seat countsOn activation, and each time the app re-checks
Activation attempts: time, IP address, app version, outcomeFraud prevention, seat transfers and support diagnosisEach activation or re-check
Support tickets and notesTo answer you and keep a record of what was doneWhen you contact us

A Computer ID is a one-way SHA-256 hash of two Windows installation identifiers. It cannot be reversed into your name, and it is not a serial number of your hardware, but it does identify a particular Windows installation — so we treat it as personal data.

Card details

We never see or store your card, UPI or netbanking credentials. Payments are handled by our payment gateway, which collects those directly. We receive only the outcome, an amount, a payment reference and the method used.

The website

This site sets no cookies of its own, runs no analytics, and does not track you across pages or sites. Our hosting provider records ordinary server logs, which include IP addresses, for security and diagnostics.

One exception: when you open the payment window at checkout, a script is loaded from our payment gateway. That script is theirs, and it may set cookies and collect data under their privacy policy. It does not load unless you begin a purchase.

The desktop application asks this site once a day whether a newer version has been released. That request sends no personal data — but like any web request, your IP address is visible to the server that answers it.

Online plan: backups and the trade network

The Online plan adds two things that involve our servers. Both are optional and neither is switched on by itself.

  • Online backup: your database is encrypted on your computer, with a key we never receive, and only then uploaded. We store the encrypted file and can tell you its size and date. We cannot read what is inside it, and we cannot recover it for you if you lose your passphrase.
  • Trade network: when you send a requirement to a wholesaler, or they send you an invoice, that document passes through our server and is stored until it is delivered and answered. We carry it; we do not interpret or analyse it. The other shop sees your shop name and what you chose to send them.

Who else sees your data

  • Our payment gateway, for taking payment and issuing refunds.
  • Our hosting and database providers, who store the records described above on our behalf.
  • A trading partner you deliberately send a document to, and only what you sent.
  • Anyone we are legally required to disclose to, such as a tax authority or a court order.

We do not sell your data, and we do not use it for advertising.

How long we keep it

  • Order, payment and invoice records: retained as required by Indian tax and companies law, commonly six to eight years, even if you ask us to close your account.
  • Licence and activation records: for as long as the licence exists, and then as part of the sales record above.
  • Support tickets: three years after the ticket is closed.
  • Trade network documents: until delivered and answered, and then twelve months as an audit trail for both shops.
  • Encrypted online backups: while your plan is active, and thirty days after it lapses, after which they are deleted.

Your rights

Under the Digital Personal Data Protection Act, 2023 you may ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to erase it, and nominate someone to exercise these rights if you cannot.

Write to privacy@dacitos.com and we will respond within thirty days. See the Data Deletion page for exactly what is removed and what we are obliged to keep.

Grievances

If you are unhappy with how we have handled your data, contact our Grievance Officer, Grievance Officer, at grievance@dacitos.com. If you remain unsatisfied you may complain to the Data Protection Board of India.

Changes

If this policy changes in a way that affects you, we will say so on this page and update the date at the top. Continuing to use LalKitaab after that means you accept the revised policy.