Privacy Policy
IBMP (Integrated Business Management Platform) is a service for Indian businesses and their accountants to keep their books, GST, payroll and compliance. It is run by APBIZ CONSULTING INDIA LLP ("we", "us") at ibmp.apbiz.in. This policy explains what personal data we handle, why, who else sees it, and the choices you have.
1. Two kinds of data
Your account data: information about you as a user of IBMP. Your business data: everything you or your team enter into IBMP, such as customers, vendors, items, invoices, bills, ledger entries, GST returns, employees and payslips. For your business data, you decide what to enter and we process it only on your behalf to run the service. Where you enter other people's personal data (for example your employees' or customers' details), you are responsible for having the right to do so.
2. What we collect
| Data | Why we need it |
|---|---|
| Name, email address and a password (stored only as a one-way hash, never in readable form) | To create and secure your account and to contact you about it |
| If you sign in with Google or LinkedIn: your name, your email address, whether the provider has verified it, and the provider's identifier for you | To sign you in and link the provider to your IBMP account. We do not receive your password, contacts, posts, files or any other data from them |
| Company details you enter: company name, GSTIN, PAN, address, bank and UPI details, logo | To print invoices and prepare GST and other returns |
| Business records you enter or import (see section 1) | To provide the books, reports, reminders and payroll features you use |
| Technical and security logs: IP address, browser type, request time, errors | To keep the service secure, limit abuse and fix faults |
| Records of emails IBMP sends for you (recipient, time, whether it was sent) | To show you what was sent and to prevent misuse |
| Subscription and payment status. Card or bank details are handled by the payment provider and are not stored by IBMP | To manage your plan |
3. How we use it
We use data only to provide, secure and support IBMP; to send service messages you ask for (such as compliance reminders and the invoices you choose to email); to manage subscriptions; and to meet legal obligations. We do not sell personal data and we do not show advertising.
4. Information we receive from Google and LinkedIn
IBMP's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use the basic profile information (name, email address, verified status and account identifier) only to authenticate you and to link that sign-in to your IBMP account. We do not use it for advertising, do not sell it, do not transfer it to others except as needed to run the service or as required by law, and do not use it to train any model. LinkedIn sign-in works the same way and is limited to the OpenID Connect profile and email information.
5. Who else handles your data
We use service providers who process data on our behalf, only as needed for their function:
- Hosting and infrastructure: the cloud server and database that run IBMP.
- Email delivery: Brevo, to send emails such as invoices and reminders.
- Sign-in: Google and LinkedIn, only if you choose to sign in with them.
- Payments, SMS and WhatsApp reminders, and GST portal connections: the relevant providers, only if and when these features are switched on for your account.
We may disclose data where the law requires it, for example to a court or authority. If our business is transferred, data may move with it under the same protections.
6. Where it is stored and for how long
Data is stored on servers we control. Encrypted-in-transit connections (HTTPS) are used for all access. We keep your account and business data while your account is active. Database backups are kept for about 14 days and then deleted. You can ask us to delete your account and data at any time (section 9); we will do so unless the law requires us to keep certain records, and we will tell you if so. Accounting and tax records you create may have their own legal retention periods that apply to you as a business.
7. Security
We protect data with HTTPS, hashed passwords, access control between companies, limits on repeated sign-in attempts, regular database backups and restricted server access. No system is perfectly secure, and you should use a strong, unique password and keep it private. Tell us immediately at the address below if you suspect unauthorised access.
8. Cookies and similar storage
IBMP does not use advertising or tracking cookies. It keeps your sign-in token in your browser's local storage so you stay signed in, and uses one short-lived cookie during Google or LinkedIn sign-in to protect that process from forgery. Clearing your browser data signs you out.
9. Your rights
Under the Digital Personal Data Protection Act, 2023 and other applicable law you may ask to access your personal data, correct it, have it erased, withdraw consent, and raise a grievance. To do so, write to the contact below; we will respond within a reasonable time and in any case within the period the law requires. If you are not satisfied you may complain to the Data Protection Board of India once it is constituted and accepting complaints.
10. Children
IBMP is for businesses and professionals. It is not intended for anyone under 18 and we do not knowingly collect data from children.
11. Changes
We may update this policy. The date at the top shows the latest version. If a change is significant we will notify account holders by email or in the application.
12. Contact and grievance officer
APBIZ CONSULTING INDIA LLP
Email: sivaravella@o2labs.com