This Privacy Policy explains how TBSI – The Billing Software (“TBSI”, “the Service”, “we”, “our” or “us”) handles information when a business user creates an account, prepares bills or quotations, manages products and stock, links business partners, uses password-recovery questions, or uses other features available through the Service.
This policy applies to information submitted through the TBSI billing website and to information generated through normal use of the billing application. It is intended for account holders, administrators and persons whose business/contact details may be entered into bills, quotations, partner records or stock workflows.
A person creating an account is required to review and accept this Privacy Policy before the account is created. By selecting the acceptance checkbox on the signup page and submitting the signup form, the user confirms that they have had an opportunity to read this policy and understand the categories of data and processing described here.
During signup and account management, the Service may collect information such as company name, GST number when available, business address, mobile number, owner/contact name, email address, password-derived authentication data, plan status, subscription dates, company logo, billing preferences, bank/payment display details and other settings configured by the account holder.
Signup asks for three password-recovery answers associated with:
These answers are used to verify a password-reset request. The application stores password-derived hashes of the answers rather than displaying the original answers back to the user. Because these answers may be memorable personal facts, users should avoid sharing them and should choose answers that are not easily guessed by unauthorized persons.
When bills and quotations are created, the Service may process document numbers, dates, customer/business-partner information, GST details, addresses, contact information, product descriptions, HSN/SAC information, quantities, rates, GST percentages, tax calculations, totals, notes, terms, payment details, stamps, logos and other information intentionally entered by the user.
The Service may process product names, rates, units, GST rates, stock quantities, linked business partners, accepted or pending stock requests, business sales and purchase values required to provide stock and business-management functions.
We use information to create and authenticate accounts; provide billing, quotation, PDF, product, partner, stock, purchase and sales functions; calculate document totals and taxes based on information supplied by users; maintain account settings; and present data back to the authorized account holder.
Email and the three security-answer hashes are used to evaluate a password-reset request. The Service does not need to reveal the original answers to perform this verification. Passwords are stored using one-way password hashing supported by PHP.
Information entered into a bill or quotation may be rendered into an A4 PDF. A user may download that PDF or use a secure sharing link where such a feature is available. The content of a shared document is determined by the account holder, and the account holder should confirm that the intended recipient is authorized to receive it.
When a GST number corresponds to another participating business account, the Service may associate that business with a partner record so that stock-request workflows can operate. This may permit a receiving business to accept an incoming stock request and have accepted quantities reflected in its stock records.
When an authenticated TBSI user imports a purchase bill containing a valid GSTIN and reviews the extracted supplier information before import, TBSI may add or refresh that supplier’s business information in a shared GST Business Directory. Directory information may include business name, GSTIN, business address, business mobile number and business email address.
The directory is intended to reduce repeated business-data entry between TBSI users. It is not exposed as a browseable public list. An authenticated TBSI user must enter the exact GSTIN to retrieve a matching business record in the Add Business Partner workflow. Search by business name, mobile number or email address is not provided by this directory feature.
Purchase-bill information should be reviewed before import because OCR or document extraction can be inaccurate. A later reviewed purchase import may refresh non-empty directory details for the same GSTIN. Empty detected fields do not erase existing directory data.
Authorized administrators may process account information to administer plans, review Premium requests, maintain service settings, investigate reported problems and operate the Service. Administrative access should be limited to persons who need it for those functions.
Depending on the context and applicable law, processing may be necessary to provide the Service requested by an account holder, perform requested billing or account functions, protect the Service, comply with applicable legal obligations, or act on a valid consent or other lawful basis recognized under applicable law.
Business users may enter information relating to customers, suppliers, business partners or other persons into bills, quotations and partner records. The account holder is responsible for ensuring that they have an appropriate reason and authority to enter and use that information and for limiting the information to what is reasonably necessary for the business purpose.
TBSI provides software tools for recording and calculating information entered by users. Account holders are responsible for checking company information, GST numbers where applicable, HSN/SAC codes, tax percentages, product prices, quantities, document dates and other business records before issuing or sharing a document.
TBSI may provide automatic extraction or optical character recognition (“OCR”) features to help read information from purchase bills, invoices, PDFs or bill images. OCR is an assistance tool. It does not approve an accounting entry, verify the legal validity of an invoice, certify a GST treatment, or replace review by the account holder.
TBSI is responsible for operating the software features it provides, but automatic extraction cannot guarantee that every value in every source document will be read correctly. Users should correct detected information before import when the source bill and the extracted result differ.
The Service is intended to be operated in accordance with privacy and data-protection obligations that apply to its processing. Where applicable in India, this may include requirements under the Digital Personal Data Protection Act, 2023 and rules or other legal requirements in force from time to time. This policy does not represent a certification of legal compliance and should be read together with obligations that apply to the particular business using the Service.
The Service may provide tools that allow an account holder to download, print or share bills and quotations. When the user shares a document or secure document link, the recipient may be able to see the information contained in that document. Users should verify recipients before sharing business or contact information.
When two business accounts are linked through a partner relationship for stock purposes, information necessary to identify the sender, receiving business, related bill and requested stock transaction may be made available within that workflow. Accepted requests may be reflected as business purchases for the receiving account.
The Service may rely on hosting, database, software-library, network and infrastructure providers to make the application available. Such providers may process technical or stored information as necessary to provide their contracted infrastructure or support functions, subject to their own terms and applicable obligations.
Information may be disclosed where required by applicable law, lawful process or a valid government request, or where reasonably necessary to investigate abuse, protect the security or integrity of the Service, protect users or enforce applicable rights.
Payments made for a TBSI Premium subscription, Premium renewal or other paid plan activation are treated as final once the payment request has been approved and the Premium plan has been activated.
Except where a refund is required by applicable law, Premium plan fees are non-refundable and non-transferable. This includes, for example, situations where the account holder changes their mind, stops using the Service, does not use all Premium features, closes the business, changes devices, experiences a change in business requirements, or chooses not to continue using TBSI during the remaining subscription period.
The account holder should review the Premium features, subscription period and payment amount before submitting payment details for approval. Activation of Premium makes the paid features available for the approved subscription period; it does not guarantee that every feature will suit every business workflow.
TBSI does not use this Privacy Policy to grant permission to sell personal information. If the Service's data-use practices materially change, the Privacy Policy should be updated and users should be informed as required by applicable law.
The application uses password hashing for account passwords and password-recovery answer verification. Users are responsible for keeping login credentials confidential and for using passwords and recovery answers that are not easily guessed.
The Service may use controls such as authenticated sessions, role-based access restrictions, prepared database statements, CSRF protection and controlled document-sharing tokens. Security measures reduce risk but cannot guarantee that unauthorized access, data loss or misuse will never occur.
If a suspected security incident affects Service information, the operator should investigate the incident, take reasonable containment and remediation measures, and provide notifications where required by applicable law.
Internet transmission and online storage involve inherent risk. Users should maintain appropriate copies of important business records and should not treat the Service as the sole repository for records that must be retained under tax, accounting or other law.
Account and business records may be retained for as long as necessary to operate the account, provide billing and stock functions, maintain transaction history, resolve disputes, protect the Service, satisfy legitimate business requirements or comply with applicable legal or accounting obligations.
Bills, quotations and related accounting information may be subject to legal retention requirements applicable to the account holder. Users should determine the retention period required for their own GST, tax, accounting and business records before requesting deletion.
The Service may allow account holders to edit company settings, products, partners, bills and quotations. Editing a historical document can affect business records, stock or linked workflows, so users should make such changes carefully and maintain any external records required by their accounting processes.
Where deletion tools are provided, deletion may remove or alter information needed for application functions. Certain deletion actions may be restricted where a record is referenced by another business record or where retention is reasonably required for security, legal, audit or accounting purposes.
Deleted information may remain temporarily in routine infrastructure backups until those backups are overwritten according to the hosting or backup schedule. Backup copies should not be restored for the purpose of reactivating data that has been intentionally deleted unless necessary for disaster recovery or another legitimate reason.
Subject to applicable law and reasonable verification, an account holder may request information about personal data associated with their account and may request correction of inaccurate account information. Many business-account details can be corrected directly through the available account settings.
Where applicable law provides such rights, a user may request deletion of personal data or withdraw a consent on which processing relies. A request may be limited where information must be retained for legal obligations, fraud prevention, security, establishment or defense of legal claims, or other lawful purposes.
Before acting on a privacy or account request, the Service may need to verify that the requester is authorized to act for the relevant account. Verification may involve account authentication or other reasonable steps appropriate to the request.
Users may raise a privacy concern with the operator or administrator responsible for the Service. Where applicable law gives a person the right to approach a regulator or other authority, this policy does not limit that right.
A customer, supplier or business contact whose information appears in a document should generally contact the business account holder that created the document, because that business selected and entered the information into TBSI.
TBSI is designed as business billing software and is not designed as a consumer service directed to children. A business account should be created and managed by a person authorized to act for the business.
The application may use session cookies or similar browser mechanisms that are necessary to keep a user signed in, maintain security state and support normal application functions. Disabling essential session functionality may prevent login or other features from working correctly.
Hosting or server infrastructure may generate technical logs such as timestamps, requested URLs, IP addresses, user-agent details and error information. Such logs may be used for security, diagnostics, service availability and troubleshooting, subject to applicable retention and access controls.
If a user chooses to share a document through a third-party service, opens a third-party website, or otherwise leaves the TBSI environment, the privacy practices of the external service apply to information processed there. TBSI cannot control the independent privacy practices of third-party services.
Data may be processed on infrastructure used by the Service's hosting and technical providers. If information is transferred across jurisdictions, the operator should use measures required by applicable data-protection law for the relevant transfer.
This Privacy Policy may be updated when the Service changes, data practices change, legal requirements change or additional privacy clarification is needed. The effective date and version shown on Page 1 should be updated when material revisions are published.
Where required by applicable law, users should be given appropriate notice of material privacy changes and, where necessary, asked to provide a new consent before processing based on that consent takes place.
Privacy, account or data-related questions should be directed to the administrator or operator responsible for the TBSI installation through the official support/contact channel provided with the Service or on the official tbsi.online website.
TBSI is a software tool. Each business using it remains responsible for its own obligations relating to invoices, GST, tax records, customer or supplier information, lawful communications and retention of business documents.
If a part of this policy is found to be invalid or unenforceable, the remaining sections should continue to apply to the extent permitted by law. Headings are provided for readability and do not limit the meaning of the provisions.
Before creating an account, the signup page requires the user to confirm that they have read and accept this Privacy Policy. The signup page also explains that the answers to Favorite place, Birthplace and Favorite Person name are used to reset the account password.