UdharPay ("we", "our", or "the app") is developed by CoreMatterz. This Privacy Policy explains what data we collect, why we collect it, how it is stored, and how you can delete it.
By using UdharPay, you agree to the practices described in this policy.
1. What Data We Collect
Account Data
- Phone number (used for OTP login via Firebase Authentication)
- Firebase User ID (anonymous identifier assigned at login)
Business & Ledger Data
- Shop name, owner name, UPI ID (entered by you)
- Customer names, phone numbers, photos (entered by you)
- Udhar (credit) and payment transaction records
- Business notes, tags, and customer risk scores
App Usage Data
- Daily login streak and task completion (for reward system)
- Coin wallet balance and transaction history
- Subscription and purchase status
- Rewarded ad session data (for server-side ad verification)
- Referral code usage
Device Data
- Device type and OS version (collected by Firebase and AdMob automatically)
- Crash logs and performance data (via Firebase Crashlytics, if enabled)
2. Why We Collect This Data
- Phone number โ to securely sign you in via OTP
- Business and customer data โ to provide the core ledger, reminders, and report features
- Coin and reward data โ to run the coin wallet, daily tasks, and referral system securely
- Ad session data โ to verify rewarded ad completions server-side and prevent fraud
- Subscription status โ to grant the correct plan features to your account
- Device data โ to improve app stability and show relevant ads
3. Where Data Is Stored
- On your device โ all ledger data (customers, transactions, settings) is stored locally using SharedPreferences. The app works fully offline for core features.
- Firebase Firestore โ coin wallet, reward history, daily tasks, referral records, and subscription status are stored in Firebase (Google Cloud, servers in the US).
- Firebase Authentication โ your phone number is stored by Firebase for login purposes only.
- Google Drive โ only if you manually enable Drive Backup. Backup files are stored in your own Google Drive account under a folder named "UdharPay Backups". We do not access any other Drive files.
- Google AdMob โ ad interaction data is processed by Google AdMob per Google's own privacy policy.
4. Data Sharing
We do not sell your data to any third party.
Data is shared only with the following trusted service providers, solely to operate the app:
- Google Firebase (authentication, database, cloud functions)
- Google AdMob (advertising)
- Google Play (subscription and purchase verification)
- Google Drive (optional backup, only with your consent)
5. How to Delete Your Data
You can delete your account and all associated data at any time:
When you delete your account, the following is removed:
- Your Firebase Authentication record
- Your Firestore coin wallet, reward history, tasks, and referral data
- All locally stored data is cleared from the device
Drive backup files (if any) must be deleted manually from your own Google Drive.
6. Data Retention
- Local data stays on your device until you clear it or uninstall the app.
- Firebase data is retained until you delete your account.
- After account deletion, Firebase data is permanently removed within 30 days.
7. Children's Privacy
UdharPay is intended for shopkeepers and adults. We do not knowingly collect data from children under 13. If you believe a child has used the app, please contact us to remove their data.
8. Security
We use Firebase security rules to ensure each user can only access their own data. All data in transit is encrypted using HTTPS/TLS. Coin and reward operations use atomic Firestore transactions to prevent fraud.
9. Changes to This Policy
If we make significant changes to this policy, we will update the date at the top of this page. Continued use of the app after changes means you accept the updated policy.
10. Contact Us
For any privacy questions or data deletion requests: