The short version
We collect what we need to run Ratify, keep it secure and support you. Your business records stay yours, and you can export them at any time. We do not sell personal data. We do not use your business data to train shared AI models without your explicit consent. Ratify AI never sends, changes or files anything without your approval.
On this page
1. Who we are and scope
Ratify.ai is a product and brand operated by Pritasha Solutions Private Limited (“Company”, “Ratify.ai”, “we”, “us” or “our”), a company incorporated under the Companies Act, 2013, with its registered office at N.H. 11, Dohar Kalan, Narnaul, Haryana — 123001, India.
This Privacy Policy explains how we handle personal data across:
- The ratifyai.in website and its subdomains
- The Ratify.ai apps on web and mobile — Ratify Billing, Inventory, Payments, GST, AI Assistant and AI Agents
- Sign-ups, demo bookings, sales conversations and support
- Service messages and marketing communications
This policy is written to meet the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Information Technology Act, 2000 and the rules made under them.
Under the DPDP Act, we are the Data Fiduciary for personal data we collect directly: website visitors, people who contact us, and Ratify account holders and their team members. For personal data about your own customers, suppliers and staff that you record in Ratify, you are the Data Fiduciary and we act as your Data Processor (see Section 3).
2. Information we collect
2.1 Information you give us
When you create an account, fill in a form, book a demo or write to us:
- Identity and contact: name, mobile number and email address
- Business details: business name, business type, team size, GSTIN and billing address
- Account credentials: the login details you use to sign in, stored securely
- Plan and payments: the plan you choose and payment confirmations — we do not store full card or UPI details
- Preferences: the products you are interested in, and your preferred demo date, time and language
- Communications: messages you send through our contact, demo and sign-up forms, emails, support requests and call notes
2.2 Information we collect automatically
When you visit the website or use Ratify, our systems record technical data so the service works and stays secure:
- Device and browser: device type, operating system, browser type and language
- Network: IP address and approximate location (city level)
- Usage: pages and features used, referring pages, time spent and error logs
- Cookies: the identifiers described in Section 7
2.3 Information from third parties
- Payment partners: whether a payment succeeded or failed, and a transaction reference
- Messaging and email providers: delivery status of invoices, reminders and service messages sent through Ratify
- Referrals and partners: basic contact details when an accountant, CA partner or someone else introduces you to us
3. Business data in your Ratify account
This section matters most if you run your business on Ratify. The short version: your business records are yours, we process them on your instructions, and we do not use them for anything you did not sign up for.
3.1 What counts as business data
- Invoices, quotations, delivery challans, credit notes and bills of supply
- Customer and supplier records — names, phone numbers, addresses, GSTINs and balances
- Items, stock, purchases, expenses and godown details
- Payments, receivables, payment links and reminders
- GST data such as HSN and SAC codes, tax summaries and reconciliation results
- Questions you ask Ratify AI, and the drafts and suggestions it prepares
- Activity and audit logs for your account
3.2 How we process it
For personal data inside your business data, we act as your Data Processor. That means:
- We process it only to provide Ratify and the features you choose to use
- You decide what is recorded and who on your team can see it
- Our staff access it only when needed to operate or support the service, or when you ask us for help
- Access to it is controlled and logged
You are responsible for having a lawful basis to record your customers’, suppliers’ and staff members’ personal data in Ratify, and for answering their requests about it. We will help you do so.
Ratify AI and your data. Ratify AI reads the business data in your account to answer your questions, prepare drafts and suggest next steps. It never sends, changes or files anything without your approval, and every approval is logged. We do not use your business data to train, fine-tune or improve shared AI models unless you give us your explicit consent, which you can withdraw at any time. Where a request is processed by a third-party AI model provider, that provider acts as our sub-processor under a written agreement and may not use your data to train its own models.
3.3 Where it is stored
Business data is hosted with cloud infrastructure providers and backed up in the cloud. Section 10 explains how we handle storage and transfers outside India.
4. How we use your information
We use personal data for the following purposes:
- Providing Ratify: running billing, inventory, payments, GST and AI features, and sending the invoices and reminders you ask us to send
- Account management: signing you in, processing plan payments, issuing GST invoices for your plan and sending service messages
- Support: answering questions, arranging demos, fixing problems and following up on your requests
- Security: detecting fraud, abuse and unauthorised access, and protecting our systems
- Product improvement: aggregated, de-identified analytics on how features are used — never the contents of your business records
- Communications: product updates and offers where permitted, with an unsubscribe option in every marketing message
- Legal and compliance: meeting tax, accounting and regulatory obligations and responding to lawful requests
We do not sell personal data. We do not rent or share contact lists for anyone else’s marketing.
5. Legal basis for processing
Under the DPDP Act, we process personal data on one of these grounds:
- Consent: when you sign up, submit a form, or opt in to marketing or optional features. When we ask for consent, we tell you what data we collect and why.
- Legitimate uses: where the DPDP Act allows processing without separate consent — for example, data you voluntarily give us for a specific purpose, such as a demo request, or processing needed to comply with the law, a court order or a lawful request from an authority.
Where consent is the basis, you can withdraw it at any time, as easily as you gave it — by using the unsubscribe link, changing your account settings or writing to info@ratifyai.in. Withdrawing consent does not affect processing already carried out, and some features may stop working without the data they need.
6. How we share information
We share personal data only when there is a real reason to, and only with parties bound by appropriate obligations.
6.1 Service providers
We work with vendors that help us run Ratify. Each one is bound by a written agreement covering confidentiality, security and data protection. The current categories are:
- Cloud hosting and storage
- Messaging and email: services that deliver WhatsApp messages, SMS and emails
- Payments: payment gateways and banking partners that process plan payments and payment links
- AI model providers: for Ratify AI features, as described in Section 3
- Support and analytics: customer support tools and website analytics such as Google Analytics
A current list of service providers is available on request.
6.2 Legal and regulatory disclosures
We disclose personal data when the law requires it — for example, in response to a court order, a tax notice or a lawful request from a government authority. Where the law allows, we will tell you before we disclose.
6.3 Business transfers
If Pritasha Solutions Private Limited is involved in a merger, acquisition or sale of assets, personal data may transfer with the business. We will publish a notice and, where required, ask for fresh consent before the new entity changes how the data is used.
6.4 When you direct us
When you share an invoice on WhatsApp or by email, send a payment link, export data for your accountant or connect another service, we send the relevant data to that recipient or service on your instruction. How they handle it is governed by their own terms and privacy policies.
7. Cookies and similar technologies
The Ratify.ai website and apps use a small set of cookies and similar technologies.
7.1 What we use
- Strictly necessary: cookies and tokens that keep you signed in and keep your session secure. Ratify does not work without these.
- Analytics: Google Analytics, to understand aggregate website traffic — which pages help people and which do not. We do not use it to track you across other websites.
- Third-party content: the website loads fonts from Google Fonts, which receives your IP address to deliver them.
We do not use advertising or remarketing cookies. If that changes, we will update this policy and ask for your consent first.
7.2 Your choices
You can block or delete cookies in your browser settings, and opt out of Google Analytics with Google’s opt-out browser add-on. Blocking strictly necessary cookies will stop parts of Ratify from working.
Inside the Ratify apps, we use cookies and tokens only to keep you signed in and to secure your session. There is no advertising tracking in the product.
8. Data security
We protect personal data with reasonable security practices and procedures, as required under the IT Act, 2000 and the DPDP Act. Our controls include:
- Encrypted connections: data travelling between your device and Ratify is encrypted in transit
- Access control: role-based access for your team, and need-to-know access for our staff
- Secure authentication: sign-in is checked before anyone reaches your data
- Audit logs: a record of who created, changed or approved a record
- Backup and recovery: cloud backups so records can be restored
- People controls: confidentiality obligations for every employee and contractor
- Incident response: a documented process to investigate and contain security incidents
If a personal data breach occurs, we will inform affected users and the Data Protection Board of India, as the DPDP Act requires.
No system is completely secure. What we commit to is serious safeguards and honest communication if something goes wrong. Read more on our Security page.
9. Data retention
We do not keep personal data longer than we need it. Retention depends on the category:
- Website enquiries and demo requests: up to 24 months after our last meaningful interaction, then deleted or anonymised
- Account data: while your account is active, plus 90 days after it is closed
- Business data in your account: while your account is active; after closure, you have 90 days to export it before we delete it
- Audit and security logs: 12 months by default, longer where the law requires
- Plan invoices, payment and tax records: 8 years, as required under Indian tax and company law
- Support correspondence: 24 months after the request is closed
Deleted data is removed from backups as they roll over, within 35 days. Where the law requires us to keep certain records longer, we keep only what is required.
You remain responsible for keeping your own copies of invoices and books of account for as long as GST and tax law requires. You can export them from Ratify at any time.
10. Data storage and transfers outside India
Ratify.ai is operated from India for businesses in India. Our service providers may store or process data in data centres in India or in other countries.
When personal data is processed outside India, we:
- Transfer it only to countries that are not restricted by the Government of India under Section 16 of the DPDP Act
- Require providers, by contract, to protect it to the standard of this policy and Indian law
- Apply the same security controls wherever the data is processed
11. Your rights and choices
Under the DPDP Act, you have the following rights over your personal data, whichever plan you use:
- Right to information
- Ask what personal data we hold about you, how we use it and who we have shared it with.
- Right to correction
- Ask us to correct inaccurate or misleading data, complete incomplete data, or update it.
- Right to erasure
- Ask us to delete personal data that is no longer needed for its purpose, unless the law requires us to keep it.
- Right to withdraw consent
- Withdraw consent you gave earlier — for example, for marketing or optional features — as easily as you gave it.
- Right to grievance redressal
- Raise a complaint with our Grievance Officer and get a response within the timelines in Section 14.
- Right to nominate
- Nominate another person to exercise your rights if you die or become unable to do so.
- Right to complain to the Board
- If you are not satisfied with how we resolve your grievance, complain to the Data Protection Board of India.
- Data export
- Export your business records from Ratify whenever you want.
- Human approval for AI actions
- Ratify AI does not send, change or file anything on its own — every such action needs a person’s approval.
To exercise any of these rights, email info@ratifyai.in from the email address linked to your account, or tell us how we can verify your identity. We respond within 30 days, and sooner where practical.
If you are a customer or supplier of a business that uses Ratify, contact that business about the data it records; we will help it respond.
12. Children’s privacy
Ratify.ai is a business product for use by adults. We do not knowingly collect personal data from anyone under 18, and we do not track, monitor or target advertising at children.
If you believe a child has given us personal data, email info@ratifyai.in and we will delete it.
13. Changes to this policy
We update this policy when the law changes, our practices change, or we launch features that use personal data in a new way. The current version always lives at ratifyai.in/privacy, with the “Last updated” date at the top of the page.
Material changes — such as new categories of data, new purposes or new types of service providers — are notified to active users by email or in-app notice at least 30 days before they take effect. Where a change needs fresh consent, we will ask for it.
14. Contact and grievance information
For privacy questions, requests about your rights, or complaints:
Company details
- Legal entity
- Pritasha Solutions Private Limited
- Brand / product
- Ratify.ai
- info@ratifyai.in
- Website
- https://ratifyai.in
- Registered address
- N.H. 11, Dohar Kalan, Narnaul, Haryana — 123001, India
Data Protection Officer
- Designation
- Data Protection Officer
- info@ratifyai.in
- Subject line
- Privacy Request — [your topic]
- Response time
- Within 30 days; sooner where practical
Grievance Redressal Officer (India)
- Designation
- Grievance Officer
- info@ratifyai.in
- Statutory response
- Acknowledgement within 48 hours; resolution within 15 days, per the IT Rules, 2021
About the company. Ratify.ai is built by Pritasha Solutions Private Limited, which is recognised by the Department for Promotion of Industry and Internal Trade (DPIIT) under the Startup India initiative.