Privacy Policy - MunimChaCha
← Back to Home

Privacy Policy

Last updated: 4 April 2026

1. Introduction

This Privacy Policy ("Policy") is published in compliance with the Information Technology Act, 2000 ("IT Act"), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), the Digital Personal Data Protection Act, 2023 ("DPDP Act"), and all applicable rules and regulations thereunder.

Elitale Softwares Private Limited (CIN: U62013RJ2023PTC089483), a company incorporated under the Companies Act, 2013, having its registered office at D2 121 A, Near Ballabh Garden, Bikaner, Rajasthan, India ("Company", "we", "us", or "our") operates the website https://munimchacha.com ("Website") and the MunimChaCha mobile application available on iOS and Android ("App"). The Website and App are collectively referred to as the "Platform".

This Policy describes our practices regarding the collection, use, storage, disclosure, and protection of your personal data when you access or use the Platform and our AI-powered tax preparation and ITR e-filing services ("Services"). By accessing or using the Platform, you consent to the practices described in this Policy.

2. Definitions

  • "Personal Data" means any data about an individual who is identifiable by or in relation to such data, as defined under the DPDP Act, 2023.
  • "Sensitive Personal Data or Information" ("SPDI") means personal information as defined under Rule 3 of the SPDI Rules, including passwords, financial information (bank account, PAN, tax-related data), and biometric data.
  • "Data Principal" means the individual whose personal data is collected and processed — i.e., you, the user.
  • "Data Fiduciary" means Elitale Softwares Private Limited, which determines the purpose and means of processing personal data.
  • "Processing" includes collection, storage, use, disclosure, sharing, erasure, or destruction of personal data.

3. Data We Collect

3.1 Information You Provide Directly

Category Data Points Purpose
Identity Data Full name, date of birth, phone number Account creation, OTP-based authentication, ITR preparation
Government Identifiers PAN (Permanent Account Number), Aadhaar number ITR filing with the Income Tax Department of India, identity verification as required by law
Financial Data Bank account details (account number, IFSC), salary information, Form 16, Form 26AS, Annual Information Statement (AIS), salary slips Computation of taxable income, identification of deductions under Sections 80C, 80D, HRA, and other applicable provisions; ITR preparation and e-filing
Tax Documents Uploaded documents (Form 16, investment proofs, rent receipts, insurance policies, medical bills) Automated extraction of relevant data for accurate ITR computation

3.2 Information Collected Automatically

Category Data Points Purpose
Device & Technical Data Device model, operating system version, unique device identifiers, IP address, browser type, screen resolution Service optimization, crash reporting, security monitoring
Usage Data Pages viewed, features used, session duration, clicks, navigation paths Product improvement, analytics, personalization
Crash & Performance Data Error logs, stack traces, app performance metrics Debugging, reliability improvements (via Firebase Crashlytics and Performance Monitoring)

3.3 Device Permissions (Mobile App)

The MunimChaCha mobile app may request the following device permissions. Each permission is requested only when needed and can be denied or revoked at any time through your device settings:

  • Camera: To scan and photograph tax documents for upload.
  • Document Picker / File Access: To select and upload tax documents (Form 16, salary slips, etc.) from your device storage.
  • Contacts: To enable referral features. Contact data is not uploaded or stored on our servers without your explicit action.
  • Media Library / Photos: To save generated tax computation results or receipts to your device.
  • Push Notifications: To send filing status updates, deadline reminders, and important service announcements.

4. Legal Basis for Processing

We process your personal data on the following legal grounds as permitted under the DPDP Act, 2023 and the IT Act, 2000:

  • Consent: You provide explicit consent when you create an account, upload tax documents, and authorize us to prepare or file your ITR. You may withdraw consent at any time (see Section 11).
  • Performance of Contract: Processing is necessary to provide the Services you have requested, including tax computation and ITR filing.
  • Legal Obligation: We may process and retain your data to comply with applicable tax laws, the IT Act, and regulatory requirements of the Income Tax Department of India.
  • Legitimate Interest: For fraud prevention, security monitoring, service improvement, and analytics, where such interests are not overridden by your rights.

5. How We Use Your Data

  • Tax Preparation & Filing: To compute your taxable income, identify applicable deductions, prepare your ITR, and (where authorized by you) e-file it with the Income Tax Department of India.
  • Account Management: To create and manage your account, authenticate you via phone OTP, and maintain your filing history.
  • Payment Processing: To process service fees through our payment partner (Razorpay). We do not store your credit/debit card numbers or UPI credentials on our servers.
  • Communication: To send filing status updates, tax deadline reminders, service notifications, and respond to your support queries.
  • Product Improvement: To analyze aggregate usage patterns, diagnose technical issues, and improve the accuracy and usability of our AI-powered services.
  • Legal Compliance: To comply with applicable laws, respond to lawful requests from government authorities, and enforce our Terms of Service.

6. Third-Party Services and Data Sharing

We do not sell, rent, or trade your personal data to any third party. We share your data only in the following limited circumstances:

6.1 Government Authorities

When you authorize us to e-file your ITR, we transmit the necessary filing information to the Income Tax Department of India through official channels. This is essential for the performance of the Services and is required by law.

6.2 Service Providers

We engage the following categories of service providers who process data on our behalf under strict contractual obligations:

Provider Purpose Data Shared
Amazon Web Services (AWS) Cloud infrastructure and data storage All Platform data (stored in AWS Mumbai region, ap-south-1)
Razorpay Software Pvt Ltd Payment processing Transaction amount, order ID; Razorpay's own privacy policy governs card/bank data
Google (Firebase) Crash reporting (Crashlytics), performance monitoring, app security (App Check), remote configuration Device identifiers, crash logs, performance metrics
PostHog Inc. Product analytics Anonymized usage events, device type, session data
Google LLC (Google Analytics) Website analytics Anonymized browsing data, page views, device information
Meta Platforms Inc. Advertising measurement (Meta Pixel) Page views, conversion events (no personal financial data is shared)
Zoho Corporation Pvt Ltd Customer support chat Chat messages, name (if provided during chat)
Sentry (Functional Software Inc.) Website error monitoring Error logs, stack traces, browser information

6.3 Legal Disclosure

We may disclose your personal data if required to do so by law, or in the good-faith belief that such action is necessary to: (a) comply with a legal obligation or lawful request by public authorities; (b) protect and defend our rights or property; (c) prevent fraud or illegal activity; or (d) protect the personal safety of users or the public.

7. Data Storage and Security

7.1 Storage Location

All personal data is stored on servers located in India (AWS Mumbai region, ap-south-1), in compliance with data localization requirements applicable to financial data under Indian law.

7.2 Security Measures

We implement reasonable security practices and procedures as required under the SPDI Rules, including:

  • Encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256).
  • Authentication tokens stored securely on-device using platform-native secure storage (Expo SecureStore).
  • Role-based access controls limiting internal access to personal data on a need-to-know basis.
  • Regular security assessments and vulnerability monitoring.
  • Firebase App Check to prevent unauthorized API access from non-genuine app instances.

While we implement industry-standard safeguards, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data.

8. Data Retention

Data Category Retention Period Reason
Tax filing records (ITR data, Form 16, 26AS, AIS, computation sheets) 7 years from the end of the relevant assessment year Section 149 of the Income Tax Act, 1961 permits reassessment proceedings for up to 6 years (10 years in specific cases); 7-year retention ensures compliance
Account and identity data (name, phone number, PAN) Duration of your account + 7 years Legal compliance and dispute resolution
Payment transaction records 7 years from the date of transaction Compliance with applicable financial regulations and the Companies Act, 2013
Usage and analytics data Deleted upon your request, or anonymized after 24 months of account inactivity Product improvement; no legal retention requirement
Crash logs and error reports 90 days Debugging and service stability

When data reaches the end of its retention period, it is securely deleted or irreversibly anonymized.

9. Cookies and Tracking Technologies

Our Website uses the following cookies and tracking technologies:

  • Essential Cookies: Required for the Website to function (e.g., session management). Cannot be disabled.
  • Analytics Cookies: Google Analytics and PostHog use cookies to collect anonymized usage data. You can opt out by using your browser's cookie settings or by installing the Google Analytics Opt-out Browser Add-on.
  • Advertising Cookies: Meta Pixel places cookies for advertising measurement. You can manage your ad preferences through Meta's Ad Preferences.

The MunimChaCha mobile app does not use cookies. Mobile analytics are collected via Firebase and PostHog SDKs using device identifiers.

10. Cross-Border Data Transfers

Your primary personal data (including all financial and tax-related data) is stored within India in the AWS Mumbai region.

Certain third-party service providers (PostHog, Google Analytics, Meta, Sentry) may process limited, non-financial data (such as device information, anonymized usage events, and crash logs) on servers located outside India, including in the United States. Such transfers are made in accordance with the provisions of the DPDP Act, 2023, and only to jurisdictions or entities that maintain adequate data protection standards.

No financial data, government identifiers (PAN, Aadhaar), or tax filing documents are transferred outside India.

11. Your Rights as a Data Principal

Under the DPDP Act, 2023 and the IT Act, 2000, you have the following rights:

  • Right to Access: You may request confirmation of whether we process your personal data and obtain a summary of the data we hold.
  • Right to Correction: You may request correction of inaccurate or incomplete personal data.
  • Right to Erasure: You may request deletion of your personal data, subject to our legal retention obligations (see Section 8). Tax filing records required under the Income Tax Act cannot be deleted before the statutory retention period expires.
  • Right to Withdraw Consent: You may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing conducted prior to withdrawal. Note that withdrawing consent may result in our inability to provide the Services.
  • Right to Grievance Redressal: You have the right to file a complaint with our Grievance Officer or with the Data Protection Board of India.
  • Right to Nominate: Under the DPDP Act, you may nominate another individual to exercise your rights on your behalf in the event of your death or incapacity.

To exercise any of these rights, contact us at soni+privacy@munimchacha.com. We will respond to your request within 30 days.

12. Children's Privacy

MunimChaCha is a tax filing service and is designed for use by individuals who are required to file income tax returns in India. While we do not impose a minimum age restriction, the nature of the Services (requiring PAN, Aadhaar, and financial data) means the Platform is intended for use by taxpayers or their authorized representatives.

If a minor (individual below 18 years of age) uses the Platform, we require that they do so with the consent and supervision of a parent or legal guardian. In accordance with the DPDP Act, 2023, any processing of a child's personal data shall only be done with verifiable consent of the parent or lawful guardian.

If we become aware that we have collected personal data from a child without verifiable parental consent, we will take steps to delete such data promptly. Please contact us at soni+privacy@munimchacha.com if you believe a child has provided us with personal data without appropriate consent.

13. Grievance Officer

In accordance with Section 5(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the DPDP Act, 2023, the details of the Grievance Officer are as follows:

Name: Dharmendra Soni

Designation: Grievance Officer

Company: Elitale Softwares Private Limited

Address: D2 121 A, Near Ballabh Garden, Bikaner, Rajasthan, India

Email: soni+privacy@munimchacha.com

The Grievance Officer shall acknowledge your complaint within 24 hours and resolve it within 15 days from the date of receipt of the complaint, in compliance with applicable laws.

If you are unsatisfied with the resolution, you may escalate your grievance to the Data Protection Board of India as established under the DPDP Act, 2023.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or regulatory guidance. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page.
  • Notify you via push notification (mobile app) or email where a material change affects your rights.
  • Where required by law, obtain fresh consent before processing your data under the updated terms.

Your continued use of the Platform after the effective date of any changes constitutes your acceptance of the updated Policy, to the extent permitted by law.

15. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us:

Elitale Softwares Private Limited

D2 121 A, Near Ballabh Garden, Bikaner, Rajasthan, India

CIN: U62013RJ2023PTC089483

Email: soni+privacy@munimchacha.com

← Back to MunimChaCha.com