On this page

1. Who we are and scope

Ratify.ai is a product and brand operated by Pritasha Solutions Private Limited (“Company”, “Ratify.ai”, “we”, “us” or “our”), a company incorporated under the Companies Act, 2013, with its registered office at N.H. 11, Dohar Kalan, Narnaul, Haryana — 123001, India.

This Privacy Policy explains how we handle personal data across:

  • The ratifyai.in website and its subdomains
  • The Ratify.ai apps on web and mobile — Ratify Billing, Inventory, Payments, GST, AI Assistant and AI Agents
  • Sign-ups, demo bookings, sales conversations and support
  • Service messages and marketing communications

This policy is written to meet the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Information Technology Act, 2000 and the rules made under them.

Under the DPDP Act, we are the Data Fiduciary for personal data we collect directly: website visitors, people who contact us, and Ratify account holders and their team members. For personal data about your own customers, suppliers and staff that you record in Ratify, you are the Data Fiduciary and we act as your Data Processor (see Section 3).

2. Information we collect

2.1 Information you give us

When you create an account, fill in a form, book a demo or write to us:

  • Identity and contact: name, mobile number and email address
  • Business details: business name, business type, team size, GSTIN and billing address
  • Account credentials: the login details you use to sign in, stored securely
  • Plan and payments: the plan you choose and payment confirmations — we do not store full card or UPI details
  • Preferences: the products you are interested in, and your preferred demo date, time and language
  • Communications: messages you send through our contact, demo and sign-up forms, emails, support requests and call notes

2.2 Information we collect automatically

When you visit the website or use Ratify, our systems record technical data so the service works and stays secure:

  • Device and browser: device type, operating system, browser type and language
  • Network: IP address and approximate location (city level)
  • Usage: pages and features used, referring pages, time spent and error logs
  • Cookies: the identifiers described in Section 7

2.3 Information from third parties

  • Payment partners: whether a payment succeeded or failed, and a transaction reference
  • Messaging and email providers: delivery status of invoices, reminders and service messages sent through Ratify
  • Referrals and partners: basic contact details when an accountant, CA partner or someone else introduces you to us

3. Business data in your Ratify account

This section matters most if you run your business on Ratify. The short version: your business records are yours, we process them on your instructions, and we do not use them for anything you did not sign up for.

3.1 What counts as business data

  • Invoices, quotations, delivery challans, credit notes and bills of supply
  • Customer and supplier records — names, phone numbers, addresses, GSTINs and balances
  • Items, stock, purchases, expenses and godown details
  • Payments, receivables, payment links and reminders
  • GST data such as HSN and SAC codes, tax summaries and reconciliation results
  • Questions you ask Ratify AI, and the drafts and suggestions it prepares
  • Activity and audit logs for your account

3.2 How we process it

For personal data inside your business data, we act as your Data Processor. That means:

  • We process it only to provide Ratify and the features you choose to use
  • You decide what is recorded and who on your team can see it
  • Our staff access it only when needed to operate or support the service, or when you ask us for help
  • Access to it is controlled and logged

You are responsible for having a lawful basis to record your customers’, suppliers’ and staff members’ personal data in Ratify, and for answering their requests about it. We will help you do so.

3.3 Where it is stored

Business data is hosted with cloud infrastructure providers and backed up in the cloud. Section 10 explains how we handle storage and transfers outside India.

4. How we use your information

We use personal data for the following purposes:

  • Providing Ratify: running billing, inventory, payments, GST and AI features, and sending the invoices and reminders you ask us to send
  • Account management: signing you in, processing plan payments, issuing GST invoices for your plan and sending service messages
  • Support: answering questions, arranging demos, fixing problems and following up on your requests
  • Security: detecting fraud, abuse and unauthorised access, and protecting our systems
  • Product improvement: aggregated, de-identified analytics on how features are used — never the contents of your business records
  • Communications: product updates and offers where permitted, with an unsubscribe option in every marketing message
  • Legal and compliance: meeting tax, accounting and regulatory obligations and responding to lawful requests

We do not sell personal data. We do not rent or share contact lists for anyone else’s marketing.

Under the DPDP Act, we process personal data on one of these grounds:

  • Consent: when you sign up, submit a form, or opt in to marketing or optional features. When we ask for consent, we tell you what data we collect and why.
  • Legitimate uses: where the DPDP Act allows processing without separate consent — for example, data you voluntarily give us for a specific purpose, such as a demo request, or processing needed to comply with the law, a court order or a lawful request from an authority.

Where consent is the basis, you can withdraw it at any time, as easily as you gave it — by using the unsubscribe link, changing your account settings or writing to info@ratifyai.in. Withdrawing consent does not affect processing already carried out, and some features may stop working without the data they need.

6. How we share information

We share personal data only when there is a real reason to, and only with parties bound by appropriate obligations.

6.1 Service providers

We work with vendors that help us run Ratify. Each one is bound by a written agreement covering confidentiality, security and data protection. The current categories are:

  • Cloud hosting and storage
  • Messaging and email: services that deliver WhatsApp messages, SMS and emails
  • Payments: payment gateways and banking partners that process plan payments and payment links
  • AI model providers: for Ratify AI features, as described in Section 3
  • Support and analytics: customer support tools and website analytics such as Google Analytics

A current list of service providers is available on request.

6.2 Legal and regulatory disclosures

We disclose personal data when the law requires it — for example, in response to a court order, a tax notice or a lawful request from a government authority. Where the law allows, we will tell you before we disclose.

6.3 Business transfers

If Pritasha Solutions Private Limited is involved in a merger, acquisition or sale of assets, personal data may transfer with the business. We will publish a notice and, where required, ask for fresh consent before the new entity changes how the data is used.

6.4 When you direct us

When you share an invoice on WhatsApp or by email, send a payment link, export data for your accountant or connect another service, we send the relevant data to that recipient or service on your instruction. How they handle it is governed by their own terms and privacy policies.

7. Cookies and similar technologies

The Ratify.ai website and apps use a small set of cookies and similar technologies.

7.1 What we use

  • Strictly necessary: cookies and tokens that keep you signed in and keep your session secure. Ratify does not work without these.
  • Analytics: Google Analytics, to understand aggregate website traffic — which pages help people and which do not. We do not use it to track you across other websites.
  • Third-party content: the website loads fonts from Google Fonts, which receives your IP address to deliver them.

We do not use advertising or remarketing cookies. If that changes, we will update this policy and ask for your consent first.

7.2 Your choices

You can block or delete cookies in your browser settings, and opt out of Google Analytics with Google’s opt-out browser add-on. Blocking strictly necessary cookies will stop parts of Ratify from working.

Inside the Ratify apps, we use cookies and tokens only to keep you signed in and to secure your session. There is no advertising tracking in the product.

8. Data security

We protect personal data with reasonable security practices and procedures, as required under the IT Act, 2000 and the DPDP Act. Our controls include:

  • Encrypted connections: data travelling between your device and Ratify is encrypted in transit
  • Access control: role-based access for your team, and need-to-know access for our staff
  • Secure authentication: sign-in is checked before anyone reaches your data
  • Audit logs: a record of who created, changed or approved a record
  • Backup and recovery: cloud backups so records can be restored
  • People controls: confidentiality obligations for every employee and contractor
  • Incident response: a documented process to investigate and contain security incidents

If a personal data breach occurs, we will inform affected users and the Data Protection Board of India, as the DPDP Act requires.

No system is completely secure. What we commit to is serious safeguards and honest communication if something goes wrong. Read more on our Security page.

9. Data retention

We do not keep personal data longer than we need it. Retention depends on the category:

  • Website enquiries and demo requests: up to 24 months after our last meaningful interaction, then deleted or anonymised
  • Account data: while your account is active, plus 90 days after it is closed
  • Business data in your account: while your account is active; after closure, you have 90 days to export it before we delete it
  • Audit and security logs: 12 months by default, longer where the law requires
  • Plan invoices, payment and tax records: 8 years, as required under Indian tax and company law
  • Support correspondence: 24 months after the request is closed

Deleted data is removed from backups as they roll over, within 35 days. Where the law requires us to keep certain records longer, we keep only what is required.

You remain responsible for keeping your own copies of invoices and books of account for as long as GST and tax law requires. You can export them from Ratify at any time.

10. Data storage and transfers outside India

Ratify.ai is operated from India for businesses in India. Our service providers may store or process data in data centres in India or in other countries.

When personal data is processed outside India, we:

  • Transfer it only to countries that are not restricted by the Government of India under Section 16 of the DPDP Act
  • Require providers, by contract, to protect it to the standard of this policy and Indian law
  • Apply the same security controls wherever the data is processed

11. Your rights and choices

Under the DPDP Act, you have the following rights over your personal data, whichever plan you use:

To exercise any of these rights, email info@ratifyai.in from the email address linked to your account, or tell us how we can verify your identity. We respond within 30 days, and sooner where practical.

If you are a customer or supplier of a business that uses Ratify, contact that business about the data it records; we will help it respond.

12. Children’s privacy

Ratify.ai is a business product for use by adults. We do not knowingly collect personal data from anyone under 18, and we do not track, monitor or target advertising at children.

If you believe a child has given us personal data, email info@ratifyai.in and we will delete it.

13. Changes to this policy

We update this policy when the law changes, our practices change, or we launch features that use personal data in a new way. The current version always lives at ratifyai.in/privacy, with the “Last updated” date at the top of the page.

Material changes — such as new categories of data, new purposes or new types of service providers — are notified to active users by email or in-app notice at least 30 days before they take effect. Where a change needs fresh consent, we will ask for it.

14. Contact and grievance information

For privacy questions, requests about your rights, or complaints: