Privacy Policy
Last updated: July 2026
HisabConnect (“HisabConnect”, “we”, “us”, or “our”) provides a workforce attendance and payroll management platform for Indian businesses. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices and rights you have — whether you are a Business Owner using HisabConnect to run your business, a staff member invited to help manage it, or an employee whose attendance and salary records are tracked in it.
1. Who We Are
HisabConnect is operated by Hisabconnect Technologies Private Limited, having its registered office at 218, Sainath Society, Kankapur, Sachin, Surat – 394230, Gujarat, India. For the purposes of India's Digital Personal Data Protection Act, 2023 (“DPDP Act”), HisabConnect acts as a Data Fiduciary for the account and business data described below, and processes employee data on behalf of, and under the instructions of, the Business Owner who entered it (see Section 7).
2. Scope of This Policy
This Policy applies to:
- Business Owners who sign up to create and manage a business on HisabConnect;
- Staff members a Business Owner invites to help manage their business, with permissions the owner controls;
- Employees whose attendance, salary, and advance records a Business Owner or staff member enters into the platform, including employees who use the optional self-service portal to view their own records.
If you are an employee and have questions about how your specific employer uses HisabConnect, please contact your employer directly in the first instance — they control what information about you is entered into the system. Section 7 explains this relationship in more detail.
3. Information We Collect
3.1 Account Information
- Phone number — used as your login identifier and to send one-time passcodes (OTPs). We use passwordless, phone-based authentication; we never ask for or store a password.
- Name — provided during signup or business setup.
- Email address (optional) — collected only from Business Owners, if provided, for account notifications and verification. Employees and invited staff are not required to provide an email.
3.2 Business Information
- Business name, logo, and configuration settings (working days, overtime rules, attendance policy thresholds).
- Holiday calendars and designation/role labels you create.
- Subscription plan and billing-related notes associated with your account phone number.
3.3 Employee & Payroll Information
Entered by a Business Owner or authorized staff member to operate the platform:
- Employee name, phone number, job role/designation, salary type and rate, and joining date;
- Daily attendance records (present/absent/half-day, hours worked, overtime);
- Salary calculations, processed salary records, advances, payments, and deductions;
- Running balance and monthly ledger history.
3.4 Technical & Usage Information
- IP address, recorded against account actions for audit-trail and security/rate-limiting purposes;
- Timestamps of logins and key actions (e.g. attendance marked, salary processed) stored in an audit log visible to the relevant Business Owner;
- Standard web request metadata (browser type, device type) processed transiently to serve the application and is not sold or used for advertising.
We do not use third-party advertising trackers, and we do not sell personal information to any third party, ever.
4. How We Use Your Information
- To create and authenticate your account (phone-based OTP login);
- To provide the core service: recording attendance, calculating salaries, tracking advances and balances, and generating reports for the Business Owner;
- To enforce access control, so that staff members only see what they've been permitted to, and employees using self-service can only see their own records;
- To send OTP codes (via SMS), account notifications, and subscription-related emails (e.g. a welcome email, or a subscription-expiry notice);
- To maintain an audit trail of actions taken within a business, for the Business Owner's own record-keeping and dispute resolution;
- To detect and prevent fraud, abuse, and unauthorized access (e.g. rate-limiting login attempts, bot-detection on signup);
- To comply with applicable law and respond to lawful requests from authorities.
5. Legal Basis for Processing
Under the DPDP Act, we process personal data on the basis of your consent (given when you sign up and agree to this Policy and our Terms of Service), and, for employee data entered by a Business Owner, on the basis of a legitimate employment relationship between the Business Owner and the employee, for purposes reasonably necessary for employment administration (attendance tracking and wage payment) — consistent with the DPDP Act's provisions for processing without separate consent where necessary for employment-related purposes.
6. Sharing & Third-Party Service Providers
We do not sell your data. We share information only with the service providers necessary to run HisabConnect, each acting as our data processor under contract, and only to the extent needed to provide their specific function:
| Provider | Purpose | Data Shared |
|---|---|---|
| 2Factor.in | SMS delivery for OTP login codes | Phone number, one-time OTP code |
| Resend | Transactional email (welcome, verification, subscription notices) | Email address, name |
| Cloudflare (Turnstile) | Bot and abuse protection on sign-up/login | Browser/device signals; no personal profile is built |
| Supabase | Database hosting for all application data | All data described in Section 3, encrypted at rest and in transit |
We may also disclose information if required by law, court order, or governmental request, or to protect the rights, property, or safety of HisabConnect, our users, or the public.
If HisabConnect is ever involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction; we will notify you of any such change and any choices you may have.
7. A Special Note on Employee Data
If you are an employee whose attendance or salary is tracked on HisabConnect, your data was entered by your employer (the Business Owner), not by you directly (unless you use the optional self-service portal). Your employer is responsible for the accuracy of that data and for having any consents or notices in place required under their own obligations to you as an employer. HisabConnect processes this data solely to provide the platform to your employer and does not use it for any independent purpose of our own, such as marketing.
If your employer has enabled self-service access for you, you can log in with your own phone number to view (read-only) your attendance history, running balance, and salary slips. You cannot edit this data yourself — corrections must go through your employer.
8. Data Security
We apply industry-standard technical safeguards, including:
- Passwordless authentication (OTP-based), removing the risk of password reuse or theft;
- HTTPS/TLS encryption in transit, and HTTP security headers (including HSTS) on every request;
- Role-based access control, independently enforced on our servers (not just hidden in the interface), so staff can only access what they've been explicitly permitted to;
- Strict tenant isolation, so one business's data is never visible to another business;
- Rate limiting on authentication and sensitive endpoints to deter brute-force and abuse;
- An internal audit log of significant actions, so unusual activity can be investigated.
No system can be guaranteed 100% secure. If we become aware of a data breach affecting your personal data, we will notify affected users and the relevant authorities as required under the DPDP Act.
9. Data Retention
We retain account and business data for as long as your account remains active. If a Business Owner deletes an employee, that employee's historical attendance and salary records are retained (marked inactive) so the business's payroll history and audit trail stay intact — this is standard practice for financial and employment records, which businesses may themselves be required to retain for a period under applicable labour and tax law. If a business account itself is permanently deleted, all associated data is permanently and irreversibly removed from our active systems, other than what we are legally required to retain.
10. Your Rights
As a Data Principal under the DPDP Act, you have the right to:
- Access a summary of the personal data we hold about you;
- Correct or update inaccurate or incomplete data (Business Owners and staff can self-serve this for account details; employees should route corrections through their employer, or contact us directly if their employer is unresponsive);
- Erasure of your personal data, subject to our legitimate need to retain financial/employment records as described in Section 9;
- Withdraw consent at any time, which may result in us no longer being able to provide you the service;
- Nominate another individual to exercise these rights on your behalf in the event of death or incapacity, as provided under the DPDP Act;
- Grievance redressal — see Section 14 for how to raise a concern.
To exercise any of these rights, contact us using the details in Section 14.
11. Cookies & Local Storage
HisabConnect does not use third-party advertising or analytics tracking cookies. We use your browser's local storage to keep you signed in (storing your session token) and to remember interface preferences such as light/dark mode and language. Our bot-protection provider, Cloudflare Turnstile, may set a short-lived cookie strictly to distinguish human visitors from automated traffic during sign-up and login — this is necessary for the security of the service and is not used to track you across other websites.
12. Children's Privacy
HisabConnect is a business tool intended for use by adults managing or working within a business, and is not directed at or knowingly used by children. We do not knowingly collect personal data from anyone under the age of 18. If you believe a minor has provided us data, please contact us and we will remove it.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal reasons. We will update the “Last updated” date at the top of this page and, for material changes, provide additional notice (such as an in-app banner or email) before the change takes effect. Continued use of HisabConnect after a change takes effect constitutes acceptance of the revised Policy.
14. Grievance Officer & Contact
In accordance with the DPDP Act, we have designated a Grievance Officer to address any concerns regarding this Policy or our handling of your personal data:
- Name: Ketan Vardekar
- Email: support@hisabconnect.in
- Address: 218, Sainath Society, Kankapur, Sachin, Surat – 394230, Gujarat, India
For any other question about this Privacy Policy, reach us at support@hisabconnect.in.