Privacy policy

Effective date: 14 September 2026 Last updated: 14 September 2026

This Privacy Policy explains how Elite Ensemble, trading as Fintabb ("Fintabb", "we", "us", "our"), collects, uses, discloses and protects personal information.

It covers all of our services:

  • the fintabb.com website and online store; and
  • the Fintabb mobile and desktop applications listed in Section 2.

If you only visit our website or buy from our online store, Sections 3, 5 and 6 are the ones that apply to you. If you use one of our business applications at work, please read Section 4 first — it explains an important point about who controls your information.


1. Who we are, and how to contact us

Entity Elite Ensemble (trading as Fintabb)
Registered address Office No. 1918, 19th Floor, Tower A, Spectrum Mall Phase 1, Sector 75, Noida, 201301, Uttar Pradesh, India
GSTIN 09AALFE2562J1Z5
Email support@fintabb.com
Phone +91 96675 69002

Grievance Officer. Questions, complaints or requests about personal data may be sent to support@fintabb.com marked "Attention: Grievance Officer", or by post to the registered address above.

We acknowledge every complaint within 24 hours and dispose of it within 15 days, in line with Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. Where a complaint depends on your own organisation's administrator or on a third party and cannot be closed in that time, we will tell you within the 15 days where it stands and what happens next.

For the purpose of the UK GDPR and EU GDPR, Fintabb is the data controller for the categories of information described in Section 4 as account and service data, and a processor acting on our business customers' instructions for the categories described as business records.


2. The products this policy covers

Product Identifier Availability
Fintabb ERP com.fintabb.erp Public — Google Play and the Apple App Store
Fintabb POS com.fintabb.pos Public — Google Play and the Apple App Store
Fintabb Management com.fintabb.management Private distribution to authorised organisations only
Fintabb Network Suite com.fintabb.networksuite Private distribution to authorised members only
fintabb.com — Public website and online store

Each application also has a staging build (identifiers ending .staging) used by our own team and by customers taking part in pre-release testing. Staging builds connect to a separate test environment and are covered by this policy in the same way.

We may add products over time. Where a new product processes personal information differently, we will update this policy before it is released.


3. The fintabb.com website and online store

Our website and store are hosted by Shopify, which enables us to provide them to you.

What we collect: your name, billing and shipping address, email address, phone number; payment confirmation and transaction details; what you view, add to a cart and purchase; the content of any message you send us; and technical information such as your IP address, device, browser and how you navigate the site.

Why: to take and fulfil your order, take payment, provide support, keep the store secure and detect fraud, comply with tax and accounting law, and — where you have not opted out — to send you marketing about our products.

Payment card details are not collected or stored by us. They are handled by our payment processors.

Shopify. Information you submit to the store is transmitted to and processed by Shopify, which may process it in countries other than your own. Shopify's own handling of that information is described in the Shopify Consumer Privacy Policy, and you may exercise rights directly with Shopify through the Shopify Privacy Portal.

Cookies. The store uses cookies and similar technologies to keep your cart, remember your preferences, measure traffic and, where permitted, support marketing. You can control cookies through your browser settings; blocking them may stop parts of the store working.


3A. Two deployment arrangements — and which you have changes who holds your data

Fintabb is supplied in two arrangements. Your Order states which applies to you.

Hybrid — the applications run on your own devices (installed on Windows and macOS desktops and on Android and iOS phones and tablets, and reachable in a web browser), while your database and your files are hosted by us. Everything in this policy about data we hold applies to you.

On-Premises — both the application and the database run on your own servers, inside your own network. We do not hold your data, cannot see it, and have no copy of it. Most of this policy then describes processing that happens entirely on your own infrastructure, under your control: we supply the software, updates and support, and you are the custodian. Where a section below applies only to data we host, it says so.


4. The Fintabb applications — the important point first

Our applications are business software licensed to organisations, not consumer apps. You will normally be using one because your employer, or an organisation you belong to, has given you an account.

That produces two different kinds of information, and we treat them differently:

4.1 Business records — your organisation decides, not us

Most of what moves through a Fintabb application is your organisation's own business data: customers, suppliers, invoices, stock, bills, payments, ledgers, tax records, employees and attendance. Where that data relates to an identifiable person — a customer's phone number, an employee's attendance record — your organisation is the controller and we are the processor. We process it on their documented instructions in order to provide the service, and we do not use it for our own purposes, do not sell it, and do not use it to train any artificial-intelligence model.

If you want that data corrected or deleted, the fastest route is your own organisation's administrator or HR contact, who can act on it directly inside the product. See Section 11.

4.2 Account and service data — we are the controller

Separately, we collect information needed to run the software itself: your login identity, the device the app is running on, diagnostic information when something fails, and usage analytics. For this, Fintabb is the controller. Section 5 describes it.


5. What the applications collect

The tables below are exhaustive for the current release of each application. Where an item applies to only one product, it says so.

5.1 Collected by every application

Category What specifically Why
Account identity Your login name (an email address in ERP), your user ID, your display name, your role, your organisation's licence number and the company or site you have selected To sign you in, to show you the right data, and to keep your session
Authentication token A session token (JWT) Kept in the device's secure store — Android Keystore or iOS Keychain — and erased when you sign out
Device and connection data Device model and operating system, app version, network status, IP address To deliver the service, to diagnose faults, and for security
Push notification identifier A Firebase Cloud Messaging registration token So the app can receive notifications. In Fintabb POS this token stays on the device and is never sent to a Fintabb server
Diagnostics and crash information Error message and type, stack trace, the screen and method where it happened, app version, device host name, your numeric user ID and licence number To find and fix defects. Sent only from release builds. Fintabb Network Suite sends no crash reports at all

All traffic is encrypted in transit. Every connection our applications make uses HTTPS. There is no plaintext HTTP endpoint in any shipped build, and certificate validation is never relaxed in a release build.

Audit trail. Fintabb records an audit trail of every transaction — every create, edit and deletion, with the user who made it and when. It cannot be disabled, by your staff, by your administrator, or by us. It exists to protect the integrity of your records, and because Indian law requires accounting software used by companies to keep one. Note what this means in practice: when an entry is deleted in the application, the business content goes but the record that it was deleted, by whom and when, remains.

5.2 Usage analytics

Fintabb ERP, Fintabb POS and Fintabb Network Suite use Google Firebase Analytics. Fintabb Management does not — it contains no analytics SDK at all.

What is sent: screen views, sign-in and sign-out events, and one event per API call carrying the method, the request path, the response status, how long it took and whether it failed. Your user ID, and properties identifying your organisation, licence, site and role, are attached so that we can tell one tenant's usage from another's.

What is not sent: query strings are removed entirely, and numeric and GUID path segments are replaced with a placeholder, before any path reaches Analytics. No customer record, employee name, bill content, login credential or business document is ever sent to Analytics.

Google also collects, inherent to the Analytics SDK, an app-instance identifier, the advertising identifier, device model and operating system, approximate geography derived from IP address, and install-referrer information.

5.3 Fintabb ERP — additional collection

Face attendance (biometric information). Where your organisation has enabled it, ERP can record attendance using your face.

  • The camera is used to enrol your face once, and thereafter to take a photograph when you clock in or out. Audio is never captured — the camera is opened with sound disabled.
  • The enrolment and punch images are sent to Fintabb's servers and passed on to Amazon Rekognition, a face-comparison service operated by Amazon Web Services, which returns a match result. Fintabb does not operate its own face-recognition model.
  • If the device is offline, a punch photograph is stored as a file in the application's private storage and deleted as soon as the server accepts it.
  • This is sensitive personal data. It is processed because your organisation has instructed us to, for the single purpose of recording attendance. It is never used for surveillance, for identifying you anywhere else, for advertising, or for training any model. The feature is optional — the application installs and runs without a camera.

Invoice scanning. If you photograph or upload an invoice, the image or PDF itself is sent to Google Gemini (through Firebase AI) so that its contents can be read into a draft entry. That document may contain supplier and buyer names, addresses, phone numbers, email addresses, GSTIN and PAN identifiers, bank account numbers, IFSC codes and invoice amounts. Use the feature only for documents your organisation is willing to have processed this way.

Location. ERP reads your device's location in exactly one place: when an administrator registers a device and sets the attendance geo-fence. Location is not recorded when you clock in or out, and is not read anywhere else in the application.

Files. Documents you attach to expense vouchers or send as catalogues are uploaded to Fintabb's servers.

5.4 Fintabb POS — additional collection

Payments. POS supports three payment routes, and they differ:

  1. Physical card terminal. The customer presents their card to a separate payment terminal. Fintabb never receives the full card number, and never receives or stores a PIN. Nothing about a card is typed into our software — there is no field for it. After the transaction succeeds or fails, the terminal returns a result which the app forwards to Fintabb's servers for reconciliation only: the last four digits, the card brand, the cardholder name as the gateway reports it, the masked card number as the terminal formats it, and the acquirer's authorisation and settlement references. A field is stored only if the terminal actually supplied it. This is the same information a printed charge slip carries, and it exists so that a disputed line on a statement can be matched back to a bill.
  2. Razorpay checkout. The app opens Razorpay's own payment sheet, prefilled with the customer's name, phone number and email address. The customer enters card or UPI details into Razorpay's interface, not ours, and those details never pass through Fintabb.
  3. Razorpay payment links. The customer's name, phone number and email address, together with the amount and description, are sent to Razorpay to generate a link.

Card terminal and payment-gateway credentials belong to the merchant operating the till.

Customer details at the till. Names, phone numbers and email addresses entered to raise a bill are business records of the merchant (Section 4.1).

5.5 Fintabb Management

Fintabb Management contains no analytics SDK and no advertising component of any kind. It collects the common items in Section 5.1 and administers POS configuration. Its only third-party data-collecting components are Firebase Cloud Messaging (push) and the remote-support component described in Section 6, which is unavailable on phones and tablets.

5.6 Fintabb Network Suite — additional collection

Sign in with Apple. If you choose it, Apple provides your name and email address to us on the first authorisation only. You may ask Apple to hide your real email address, in which case we receive a relay address and never see your own.

Passkeys. Network Suite supports passkeys for sign-in. A passkey works by having your device produce a cryptographic signature. Your fingerprint, face or device passcode is used by your own device to unlock the key and is never transmitted to us; we receive no biometric data and no private key material from this feature.

Member directory. Network Suite shows member profile information provided by the organisation. This is business data under Section 4.1.

Network Suite sends no crash reports.


6. Remote support sessions

Fintabb ERP, Fintabb POS and Fintabb Management include a remote-support capability that lets a Fintabb support agent view your screen while helping you. Fintabb Network Suite has no such feature.

  • It is not available on phones or tablets at all. The capability is limited to the desktop (macOS and Windows) and web builds of those three products. On the Android and iOS builds it cannot be started by anyone, including us.
  • A session can only be started deliberately, and never silently. It is initiated by an operator and requires action at your end.
  • During a session, the agent sees your screen, and an identity payload is transmitted containing your user ID, your name, your organisation's licence number and name, your site, your device name, and the application version and platform.
  • Screen sharing is delivered by a specialist third-party provider under contract to us.
  • Nothing is captured outside a session.

7. Who we share information with

We do not sell personal information. We share it only as set out here.

Recipient What they receive Which product
Google — Firebase Cloud Messaging Push registration token, notification payloads All
Google — Firebase Analytics Usage events, user and organisation identifiers, device identifiers ERP, POS, Network Suite
Google — Gemini (via Firebase AI) The invoice image or PDF you scan, and its contents ERP
Amazon Web Services — Rekognition Face enrolment and attendance images, via our servers ERP
Razorpay Customer name, phone, email, amount; and the payment instrument the customer enters into Razorpay's own sheet POS
Card-terminal gateway Merchant credentials, amount, bill reference, terminal ID, customer name and mobile number POS
Apple Sign in with Apple authentication Network Suite
Our remote-support provider Screen contents and the identity payload, during a session only ERP, POS, Management — desktop and web only, never on phones or tablets
Shopify Website and store activity fintabb.com
Our hosting, infrastructure and communications providers As needed to run the service All

We may also disclose information where we are required to by law or valid legal process; to establish, exercise or defend legal claims; to protect the rights and safety of our users, our staff or the public; and in connection with a merger, acquisition or sale of assets, in which case we will give notice before your information becomes subject to a different policy.


7A. When a government or law-enforcement agency asks for data

We publish how we handle this, because how a provider behaves under pressure is worth knowing before you need it.

What we do:

  • We require a written, valid legal order that cites the provision it is made under and names the business, the period and the categories of data sought. We do not act on a phone call, a verbal request or a message — ever.
  • We verify it is genuine before responding.
  • We disclose only what the order covers. The named business, the stated period, the stated categories. Never a whole-database export, never another customer's data.
  • We tell the affected customer, unless the order legally prohibits it — some do.
  • We direct the agency to the customer where the request should properly be served on them. The business records are theirs; we hold them on their behalf.
  • We log every request and keep a copy of exactly what was produced.
  • We do not delete or alter anything once a request is known.

What we will not do: give anyone access to your systems or your credentials, or hand over more than the order compels. Indian law makes over-disclosure an offence in its own right — Section 72A of the Information Technology Act, 2000 — so limiting what we give is not only our policy, it is our legal obligation.

What we cannot do: refuse a lawful order. No provider can, and one that promises you otherwise is either uninformed or misleading you. What we can do — and what actually protects you — is insist on proper process, disclose the minimum the law compels, and make sure you know about it so you can exercise your own rights.

On-Premises customers: your data sits on your own servers, so an order for it comes to you directly. We would have nothing to give.


8. Advertising, and the advertising identifier

We do not display advertising in any Fintabb application. There are no advertising SDKs, no ad networks, no third-party banners and no sponsored content in any of our products. Grepping our dependency locks for the major ad and attribution SDKs returns nothing, and that is deliberate.

Separately from that, we do advertise our own products — Fintabb ERP, Fintabb POS and Fintabb Network Suite — on external platforms, and we use the device advertising identifier to measure those campaigns and to reach people who have shown interest in them. This is why those three applications declare use of an advertising ID in their store listings. Fintabb Management does not use an advertising identifier at all.

You can reset or limit the advertising identifier at any time in your device settings: on Android under Settings → Privacy → Ads, and on iOS under Settings → Privacy & Security → Tracking. Doing so does not affect any application feature.


9. Where information is stored, and international transfers

Fintabb's servers are operated in India. Our service providers may process information in other countries, including the United States and the European Union — in particular Google (Firebase and Gemini), Amazon Web Services, Apple, Razorpay, Shopify and our remote-support provider.

Where we transfer personal information out of the European Economic Area or the United Kingdom, we rely on a recognised transfer mechanism, such as the European Commission's Standard Contractual Clauses or the UK equivalent, unless the destination has an adequacy decision.


10. How long we keep information

Information Retention
Business records inside the applications For as long as your organisation's contract with us runs, and afterwards as agreed with that organisation
Account and session data For the life of your account; session tokens are erased on sign-out
Face enrolment data Until your organisation removes the enrolment or the feature is disabled for them
Offline attendance photographs on a device Until the server accepts the punch, then deleted
Diagnostics and crash reports No longer than needed to investigate and fix the fault, and to confirm the fix
Analytics For the period configured in our Google Firebase Analytics retention setting
Website and store orders As required by Indian tax and accounting law

11. Your rights, and how to use them

Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal information; to object to or restrict processing; to withdraw consent; and to complain to a supervisory authority. Under India's Digital Personal Data Protection Act, 2023 you also have the right to nominate another person to exercise your rights in the event of death or incapacity.

How to exercise them depends on what the information is:

  • Information held inside a Fintabb application on behalf of your employer or organisation — contact your organisation's administrator or HR contact. They can view, correct and delete member, employee and attendance records, including face enrolments, directly in the product. This is deliberate: your employer controls that data, and we act on their instructions. If you do not know who to contact, write to us and we will point you to the right person.
  • Everything else, including website and store data — email support@fintabb.com.

We will not treat you differently for exercising a right. We may need to verify your identity first. You may use an authorised agent, in which case we will ask for proof of authorisation.

If we cannot resolve your complaint, you may complain to the Data Protection Board of India, or — in the EEA or UK — to your local supervisory authority.


12. Security

We protect information with encryption in transit on every connection, platform-backed secure storage for credentials on the device (Android Keystore and iOS Keychain), authentication and role-based access control, tenant isolation so that one organisation cannot reach another's data, and restricted internal access on a need-to-know basis.

No system is perfectly secure, and we do not claim otherwise. Please keep your credentials to yourself: do not share your username, password or passkey with anyone, including anyone claiming to be from Fintabb. Our support staff will never ask you for your password.


13. Children

Our products are business software and are not directed at children. We do not knowingly collect personal information from anyone under the age of 18. If you believe a child has provided us with personal information, contact us and we will delete it. We do not sell or share the personal information of anyone under 16.


14. Changes to this policy

We may update this policy to reflect changes in our practices or for operational, legal or regulatory reasons. We will post the revised policy at https://fintabb.com/policies/privacy-policy, update the "Last updated" date, and where the change is material give notice as required by law. Continuing to use our products after a change takes effect means you accept the revised policy.


15. Contact

Questions about this policy, or about how we handle personal information:

Email: support@fintabb.com Phone: +91 96675 69002 Post: Elite Ensemble, Office No. 1918, 19th Floor, Tower A, Spectrum Mall Phase 1, Sector 75, Noida, 201301, Uttar Pradesh, India