Privacy Policy
Last updated: 2 July 2026 Effective: 2 July 2026
Draft notice. This document is a v1 draft generated from the facts in
docs/compliance.md. A lawyer review (Indian privacy counsel with EU experience) will harden specific clauses before paid launch. Markers like [TBD: …] flag the facts that must be resolved before this draft is published athttps://naame.in/privacy.
This policy explains what data Naame collects, why we collect it, how we use it, and the rights you have over it. It applies to the service at naame.in and any related subdomains.
1. Who we are
Naame (the "Service") is a personal khata (ledger) and personal-finance tracker operated by Bhaumik Dhameliya, a sole proprietor based at 360, Raj Imperia, Vraj Chowk, Sarthana Jakatnaka, Surat, Gujarat, India ("we", "us", "our").
- Privacy contact:
privacy@naame.in - General support:
support@naame.in
Naame is not currently a Significant Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDPA"). If that changes, this policy will be updated and a designated Grievance Officer / Data Protection Officer will be named here.
EU and UK residents. Naame is not offered to residents of the European Union or the United Kingdom. At signup we ask for your country of residence; selecting an EU or UK country will prevent account creation. Because we do not offer the Service to data subjects in those jurisdictions, the General Data Protection Regulation (Regulation (EU) 2016/679) and the UK-GDPR do not apply to our processing (GDPR Art. 3(2)(a); UK-GDPR Art. 3). No EU representative (GDPR Art. 27) or UK representative (UK-GDPR Art. 27) is appointed. If you are a resident of the EU or UK and have managed to create an account (for example, by selecting a non-EU country at signup), please contact privacy@naame.in and we will close your account and delete your data.
2. Scope
This policy covers:
- Visitors — people who use Naame in their browser without creating an account.
- Account Holders — people who sign up and use the cloud-backed service.
- Contacts — people whose names and details an Account Holder enters into their own ledger. We treat data about Contacts as data belonging to the Account Holder; we do not separately profile Contacts.
It does not cover third-party websites or services that Naame links to.
3. Data we collect
3.1 If you are a Visitor
We collect no personal data on our servers. The app stores your data in your browser's local storage (IndexedDB) on your device. We never see it, never receive it, and cannot recover it for you.
3.2 If you are an Account Holder
When you sign up and use the service, we collect:
| What | When | Why | |---|---|---| | Email address | Signup, every sign-in | Identifying your account; sending magic-link sign-in emails and account notifications | | Name and profile picture | If you sign in with Google | Personalising your account display | | Your Contacts (names, optional phone numbers, optional notes) | When you create them | Core product function — your ledger needs Contacts | | Your Ledger Entries (amount, direction, date, due date, note, payment method) | When you create them | Core product function | | Your Personal Entries (amount, direction, date, category, note) | When you create them | Core product function | | Your chosen Currency | At signup | Storing and displaying your amounts |
3.3 Analytics and error monitoring (everyone, V1)
Naame is currently a browser-only app (no accounts yet — see Section 1 note below). To understand traffic and catch bugs before accounts exist, we use:
- Cloudflare Web Analytics (beacon mode) — anonymous, cookieless pageview analytics. Cloudflare receives pageview events but we do not proxy your traffic through Cloudflare.
- Sentry — client-side error reports if the app crashes in your browser (e.g. stack trace, browser/OS info). Used only to fix bugs.
None of these tools use cookies, track you across other websites, or build a profile tied to your identity.
3.4 Standard server logs (everyone)
We log basic technical information when you make a request to our servers:
- IP address
- User-Agent (browser/device identifier string)
- Request path and timestamp
- HTTP response status
These are used for security, abuse detection, debugging, and rate-limiting. They are kept for 30 days and then deleted.
4. How we use your data
We use your data only to:
- Provide the Service (display your ledger, sync between your devices, send the emails you ask for).
- Authenticate you and keep your account secure.
- Send transactional and account emails (sign-in links, due-date reminders if you enable them, account notices).
- Debug problems, prevent abuse, and respond to security incidents.
- Comply with legal obligations.
We do not:
- Sell your data.
- Share your data for advertising.
- Use your data to train AI models.
- Track you across other websites.
- Build behavioural or marketing profiles of you.
5. Legal grounds for processing
Under India's DPDPA, we process your personal data on the following grounds:
- Consent for the core service — by creating an account, you consent to our processing of your data to provide the Service.
- Consent for optional features — if you opt in to anything outside the core service (e.g., due-date reminder emails), we rely on your consent for that processing. You can withdraw consent at any time by disabling the setting in-app or emailing us.
- Legitimate uses under DPDPA Section 7 — limited processing of logs and metadata for security, fraud prevention, debugging, and to respond to law-enforcement requests or other legal obligations.
Because Naame is not offered to EU or UK residents (see Section 1), GDPR / UK-GDPR legal bases under Article 6 are not applicable.
6. Third parties we share with
We use a small number of service providers ("data processors"). Each is listed below with what they receive and why.
| Provider | Purpose | What they receive |
|---|---|---|
| Google | Google Sign-In, only if you choose it | email, name, picture from your Google profile |
| Resend (Resend, Inc.) | Sending sign-in links and notification emails | Your email address; email content |
| Hostinger (Mumbai, India) | Hosting the Service on a Virtual Private Server (VPS). Our hosting provider may change over time; this table reflects who hosts us as of the "Last updated" date above | Whatever is sent to or from our servers — incidental access only |
| Sentry | Client-side error monitoring | Error/crash reports (stack trace, browser/OS info) — no account data, since accounts don't exist yet |
| Cloudflare | Email routing for our @naame.in addresses; anonymous Web Analytics (beacon mode) | Inbound email metadata, forwarded to our inbox; anonymous pageview events |
We do not share your data with anyone else except:
- When you ask us to (e.g., exporting your data so you can send it elsewhere yourself).
- When required by law (a valid legal order from a competent authority).
- In a business transfer: if we ever sell or transfer the Service, we will notify Account Holders before the transfer and explain what changes; you will have the chance to delete your account first.
7. Data we do not collect
We deliberately avoid:
- Browser or device fingerprinting.
- Advertising-oriented analytics (no Google Analytics, no Mixpanel). We use only privacy-respecting, cookieless analytics — see Section 3.3.
- Advertising trackers, pixels, or remarketing tags.
- Software development kits (SDKs) that exfiltrate user data.
- Any data about your Contacts beyond what you, the Account Holder, explicitly enter.
We will not add a tracking cookie or third-party advertising tracker.
8. Retention
| Data | How long we keep it | |---|---| | Account and ledger data while your account is active | Indefinitely, until you delete your account | | Account data after you click "Delete Account" | Soft-deleted for 30 days so you can recover by mistake, then permanently purged | | Server access logs | 30 days rolling | | Backups | 30 days rolling; backups of deleted data expire on this schedule too | | Visitor data (IndexedDB) | Lives on your device. We have no copy and no way to recover it. |
9. Your rights
You have the following rights over your personal data. We do not charge for exercising them.
| Right | How to use it |
|---|---|
| Access a copy of your data | In-app: Settings → Privacy → Export My Data. We generate a zip with data.json, contacts.csv, ledger_entries.csv, and personal_entries.csv. Self-serve, instant. |
| Correct anything that is wrong | Edit any field in the app at any time. Everything is mutable. |
| Delete your account and data | In-app: Settings → Privacy → Delete Account. Soft-deleted for 30 days (so you can recover), then permanently purged. |
| Take your data elsewhere (portability) | Same export as Access — JSON + CSV satisfies the GDPR / DPDPA standard for "structured, commonly used, machine-readable" formats. |
| Object to or restrict specific processing | Email privacy@naame.in. |
| Withdraw consent (where we rely on consent) | Disable the relevant setting in-app, or email us. Withdrawing consent does not affect processing already carried out. |
| Complain (grievance) | Email privacy@naame.in. We respond within 30 days. |
Indian users may approach the Data Protection Board of India under DPDPA. Users in other jurisdictions may approach their local data protection authority where one exists.
10. Children
The Service is intended for users 18 years of age or older. At signup we ask you to confirm that you are 18 or older. We do not knowingly collect personal data from anyone under 18. If you believe a child has signed up, email privacy@naame.in and we will delete the account.
11. Cookies and similar technology
Naame sets a single session cookie for authentication (issued by our auth layer, Auth.js). It is essential to keep you signed in and expires when your session ends.
We do not use:
- Tracking cookies.
- Third-party cookies.
- Advertising or analytics cookies.
Because we only use strictly necessary cookies, no cookie consent banner is shown. If we ever add non-essential cookies (we are committed to avoiding this), we will publish the change here and add a consent banner for EU and UK users before doing so.
12. Cross-border data transfer
Our servers run on a Virtual Private Server (VPS) hosted by Hostinger, located in Mumbai, India, as of the "Last updated" date above — our hosting provider may change over time. Email is sent via Resend (Resend, Inc., United States), whose infrastructure may process your email content outside your country of residence in the course of delivery.
This means the personal data you provide to Naame is stored in India. Regardless of jurisdiction, we apply technical and organisational safeguards: TLS in transit, encryption at rest, data minimisation, and no collection of special-category data.
- For users in India, your data is stored in India. No cross-border transfer occurs for our hosting. Transactional email via Resend involves the United States, which complies with the cross-border rules in the DPDPA — transfers are permitted unless the Government notifies a restriction, and the United States is not currently restricted.
- Naame is not offered to residents of the European Union or the United Kingdom (see Section 1), so GDPR and UK-GDPR do not apply to our processing regardless of where our servers are located.
- For users in other jurisdictions (e.g., Canada, Australia, the UAE, Singapore, GCC countries), your data is stored in India; please review your local data-protection law for any specific requirements that may apply.
13. Security
We protect your data with:
- TLS (HTTPS) on all connections.
- Server-side hashing of credentials.
- Minimal internal access (only systems and operators that need the data to run the Service).
- Logging and alerting on unusual access patterns.
No service can promise zero risk. If we ever experience a breach affecting your personal data, we will notify you and the relevant data protection authority within the timeframes required by law — 72 hours under GDPR; without undue delay under DPDPA.
14. Changes to this policy
We will update this policy when our practices, vendors, or the law change. The "Last updated" date at the top reflects the most recent revision. For material changes, we will notify Account Holders by email or an in-app banner before the change takes effect.
A change history of this document is kept in our public source repository.
15. Contact
- Privacy questions, requests, complaints:
privacy@naame.in - General support:
support@naame.in - Operator postal address: Bhaumik Dhameliya, 360, Raj Imperia, Vraj Chowk, Sarthana Jakatnaka, Surat, Gujarat, India
We respond to verifiable privacy requests within 30 days of receipt, or sooner where required by law.