Trust & Security

Last updated: 16 September 2026

Your books, your bills, your stock, your staff records. You are trusting us with the working memory of your business, and you are entitled to know exactly how we look after it.

This page is deliberately specific. Every statement here is something we are prepared to be held to.


1. The three promises

Your data is yours. You can take it out whenever you want, in a format you can actually use.

We will never hold your data hostage — not over an unpaid invoice, not over a dispute, not over a cancellation. Data and money are separate conversations.

Every change is recorded. Who did it, what changed, and when. It cannot be switched off — not by your staff, not by your administrator, not by us.


2. How Fintabb is deployed

Fintabb runs in two arrangements. Which one you have is stated in your Order, and it changes who holds what.

Hybrid — our standard

The name describes how it is built. The applications run on your own devices — installed on Windows and macOS desktops and on Android and iOS phones and tablets, and reachable in a web browser, where there is nothing to install. Your database and your files are hosted by us.

You get the responsiveness of software running on the machine in front of you, while your data sits in one place — current on every device, every branch and every platform at once, with no copies to reconcile and nothing to sync by hand.

In this arrangement we hold your data, and the commitments in Sections 3 to 6 are ours to keep.

On-Premises

Both the application and the database run on your own servers, inside your own network. Your data never leaves your premises. You have complete control and complete sovereignty over it.

In this arrangement your data is in your hands, not ours. We supply the software, the updates and the support. We do not hold a copy, we cannot see your data, and — this is the part that matters — we cannot restore it for you if it is lost. Backups, server security, and disaster recovery are yours.

Some businesses want exactly that, and for them it is the right answer. But choose it with your eyes open: the responsibility that comes with sovereignty is real, and it is daily.


3. Where your data lives

Hybrid Your database and files are hosted on infrastructure in India
On-Premises On your own servers, wherever you put them
In transit Every connection, on every platform, is encrypted with HTTPS/TLS. There is no unencrypted endpoint in any Fintabb build, and certificate validation is never relaxed in a release build
On your device Credentials are held in the platform's secure store — Android Keystore, iOS Keychain, or the operating system's equivalent — never in plain text

If you are a company keeping your books of account electronically, Indian law requires the backup of those books to be kept on servers physically located in India, on a daily basis. Ask us in writing where your data is and we will tell you in writing — your auditor and your Registrar filing may need it.


4. Backups — how they work, and what they cost

We back up your hosted data, and we carry that risk. That is included; you do not pay extra for us to protect the platform.

But backups consume storage, and storage costs money. So beyond the baseline, backups are something you choose and configure — how often, how many copies, how far back — and the price follows the space you use. We would rather be straightforward about that than bundle a vague promise into the licence fee and quietly ration it.

What you can choose

Backup type What it does Space it needs
Overwriting One copy, replaced each time it runs. You always have the most recent snapshot Lowest
One-time A snapshot taken at a moment you choose and kept — before a migration, at year end, before a big change Fixed, one copy
Incremental A full copy, then only what changed after it. Lets you go back to a point in time, not just to last night Grows over time — most space
Combinations Most businesses run a frequent overwriting or incremental schedule, plus one-time snapshots at year end Depends

What you choose

  • Frequency — daily, more often, or on a schedule that suits your business
  • Retention — how many copies, and how far back you can go
  • Type — as above, or a combination

How pricing works: you pay for the storage your chosen configuration actually consumes. Back up more often, keep more history, keep it longer — more space, and the charge reflects that. A modest overwriting schedule costs very little. Twelve months of incrementals for a busy multi-branch operation costs considerably more, because it genuinely uses considerably more.

Tell us what matters to you and we will size it with you. The question worth asking yourself is not "how much backup can I afford" but "if I lost everything this morning, how far back could I bear to go?" Answer that honestly and the configuration follows.

What we commit to

  • Backups of hosted data are encrypted.
  • Backups of hosted data are held in India.
  • We test restores. A backup that has never been restored is a hope, not a backup — and we would rather find a problem in a test than on the day you need it.
  • If you are on On-Premises, none of this applies to you and you must arrange your own. Please do not discover this on the day of a disk failure. We will help you design a backup regime if you ask.

5. Getting your data out — while you are with us, and when you leave

While you are a customer

Any time you want, without asking us. Export from inside the product — your ledgers, bills, stock, customers, reports — in open formats you can open in Excel or import elsewhere. It is your data and you should not need our permission or our mood to get at it.

If you need something the standard exports do not cover, ask. We will not charge you for reasonable requests to get at your own records.

When you leave

You get everything. A complete export of your data, in open formats, on request.

  • Available throughout your licence Term and for 30 days after it ends.
  • Provided whether or not you are leaving on good terms.
  • We do not withhold data over a commercial dispute. If you owe us money, we will pursue that as a debt, like any other business. We will not use your own records as leverage. Nothing about that is negotiable.

Please do not leave it to the last day. After the 30-day window we may permanently delete your data from our live systems, and once it is gone we may not be able to get it back.


6. The audit trail

Fintabb records an audit trail of every transaction. Every create, every edit, every deletion — with the user who did it, what changed, and when.

It cannot be disabled. Not by your staff, not by your administrator, not by us. That is the whole point of it: a log that can be switched off proves nothing.

This matters in three ways:

  1. For your own control. When a figure is wrong, you can see who changed it and when, instead of guessing.
  2. For your statutory audit. Since 1 April 2023, Indian law requires companies keeping books of account electronically to use accounting software that records an audit trail, logs every change with its date, and cannot have that trail disabled — and your auditor is separately required to report on whether it existed and operated throughout the year. Fintabb is built to meet that. Ask us for the audit-trail report your auditor needs and we will provide it.
  3. For your protection and ours. A complete, tamper-evident record is the best evidence that your books are what they say they are.

What we will never build: a way to delete a record without trace, a way to backdate silently, a way to keep a second set of books, or a way to hide transactions from reports. If you need one of those, Fintabb is the wrong software, and we would rather tell you so now.


7. Who can see your data

Your data is yours. We do not sell it. We do not share it with other customers. We do not use it to train artificial-intelligence models.

Our own staff can reach customer data only where they need to for support or operations, under access controls, and only to the extent necessary. We do not browse customer data.

We do not edit your data for you. If something needs correcting, you correct it in the product, where the audit trail records it. That protects you, and it keeps the record honest.

Remote support lets a support agent see your screen while helping you. It only happens in a session you take part in, it cannot be started silently, and nothing is captured outside a session. It is not available on phones or tablets at all.

Service providers that help us run Fintabb — cloud hosting, notifications, payment processing, and the AI service that reads scanned invoices — are listed in our Privacy Policy, with what each one receives.


8. Payment and card data

If you use Fintabb POS with a card terminal or with Razorpay:

  • We never receive the full card number. Ever.
  • We never receive or store a PIN. Ever.
  • Nothing about a card is typed into Fintabb. Your customer enters their details on the payment terminal, or in Razorpay's own secure sheet. Our software has no field for it and never sees it.
  • What we keep is what the payment gateway returns to us after the transaction succeeds or fails — the last four digits, the card brand, the cardholder name as the gateway reports it, and the authorisation and settlement references.
  • Why we keep it: reconciliation, and nothing else. It is how a disputed line on a statement is matched back to a bill — exactly what a charge slip prints.

9. If something goes wrong

Security incidents. If there is a breach affecting your data, we will tell you — promptly, honestly, with what we know and what we are doing — and we will notify the authorities as the law requires. We will not sit on bad news hoping it resolves itself.

Please report problems. If you believe you have found a security vulnerability in Fintabb, email support@fintabb.com with the subject line "Security". We will take it seriously, respond, and we will not pursue anyone who reports a genuine issue responsibly and in good faith.


10. When a government agency asks for your data

We publish how we handle this, because how a provider behaves under pressure is worth knowing before you need it.

What we do:

  • We require a written, valid legal order. We do not act on a phone call, a verbal request, or a message. Ever.
  • We verify it — that the officer and the reference are genuine — before responding.
  • We give only what the order covers. The named business, the stated period, the stated categories. Never a whole-database dump, never another customer's data.
  • We tell you, unless the order legally prohibits us from doing so.
  • We point the agency to you where the request should properly be served on you. Your books are yours; we hold them on your behalf.
  • We log every request and keep a copy of exactly what was produced.

What we will not do:

  • Give anyone access to your systems or credentials.
  • Hand over more than the order covers. Indian law makes over-disclosure an offence in its own right — we are legally bound to limit what we give, and we do.
  • Delete or alter anything once a request is known. That would be destruction of evidence, and we do not do it whoever asks.

What we cannot do: refuse a lawful order. Nobody can, and a provider who promises you they will is either uninformed or lying to you. What we can do — and what actually protects you — is insist on proper process, limit disclosure to the minimum the law compels, and make sure you know about it so you can exercise your own rights.

On-Premises customers: your data is on your own servers, so an order for it will come to you directly. We would have nothing to give.


11. Your responsibilities — said plainly

Security is shared, and some of it only you can do:

  • Give every person their own login. Shared logins destroy the audit trail, which is the thing protecting you.
  • Remove people who leave, the day they leave.
  • Keep your devices and your network secure, and your operating systems updated.
  • Never share your password or passkey. We will never ask for it — treat any such request, however official it sounds, as fraud.
  • Export and retain what the law requires you to keep. GST records run to 72 months and income tax to six years; company books and the audit trail longer still. Those obligations are yours, and our 30-day post-termination window is not a substitute for meeting them.
  • On-Premises: take your backups, and test them.

12. Ask us

If your auditor, your lawyer or your board has questions we have not answered here — where the data sits, what the backup regime is, who our sub-processors are, whether we will sign a data processing agreement — ask. We would far rather answer a hard question before you buy than have you find out afterwards.

Email: support@fintabb.com Phone: +91 96675 69002 Post: Elite Ensemble, Office No. 1918, 19th Floor, Tower A, Spectrum Mall Phase 1, Sector 75, Noida, 201301, Uttar Pradesh, India