Privacy Policy
Last updated: 28 September 2026
This Privacy Policy explains what personal information হিসাব খাতা (the "Service") collects, why, who can see it, and the choices you have. The Service is operated by হিসাব খাতা (Hishab Khata) ("we", "us"). It should be read together with our Terms of Service.
1. Two roles: your employer and us
হিসাব খাতা is used by businesses ("organizations"). For the information an organization enters about its own staff, finances and operations, the organization decides what is collected and why, and we process it on the organization’s behalf to provide the Service. For account, security and billing information about the people and organizations who use the Service, we decide how it is used.
If you are an employee and have a question about what your employer holds about you, please ask your employer first — they control that data.
2. Information we collect
Account and organization information
- name, e-mail address, phone number (optional) and role;
- a securely hashed password (we never store your password in readable form);
- organization name, type, contact details, address, working hours, time zone and settings;
- sign-in times and verification / password-reset status.
Employee and business records entered by organizations
- employee profile details: name, contact details, designation, department, joining date, national ID number, address, emergency contact, and bank name and account details;
- salary, allowances, bonuses, deductions, overtime and payslips;
- attendance (check-in/out times, method — QR, self-service or manual — late and overtime minutes, notes) and leave requests and decisions;
- income and expense transactions, categories, sources and references;
- notices, messages employees send to their administrators, and in-app notifications.
Activity and technical information
- an activity log recording who did what and when inside an organization (for example sign-ins, employee changes, payroll runs and settings changes);
- IP address and request details, used for security, abuse prevention and rate limiting, and kept in server logs;
- basic device/browser information sent with normal web requests.
Payment information
- when an organization pays for a plan we receive from our payment gateway (SSLCommerz) the transaction ID, amount, plan, status and related confirmation details. We do not receive or store full card numbers or mobile-wallet PINs.
3. How we use information
- to provide, operate and secure the Service, including attendance, leave, payroll, finance, reports and the employee portal;
- to create accounts, authenticate users and send service e-mails such as verification, password reset, invitations and leave decisions;
- to process subscription payments and apply the correct plan;
- to prevent fraud and abuse, enforce our Terms, and keep an audit trail;
- to provide support, diagnose problems and improve reliability;
- to meet legal obligations.
We do not sell personal information and we do not use it for third-party advertising.
4. Who can see what
- Employees see only their own attendance, leave, payslips, profile and the organization’s notices.
- Managers and Organization Admins of an organization can see that organization’s employee, attendance, leave, payroll, finance and report data, according to their role. Only Organization Admins can see the organization’s activity log, settings, team and billing controls.
- The platform administrator (operated by us) can see organization-level information needed to run the platform — organization profiles, team member lists, subscription and payment history, platform statistics and activity logs — and can suspend or reactivate an organization. Our systems and authorised staff may also access stored data where necessary for maintenance, security and support.
5. Cookies and local storage
We use only what is needed to make the Service work:
- a secure, HTTP-only sign-in cookie that lets you stay signed in and is not readable by scripts on the page;
- a language preference cookie and, in your browser storage, your theme choice and a copy of basic profile details (name, role, organization) so the app can load quickly.
Your short-lived access token is kept in memory only. We do not use advertising or cross-site tracking cookies.
6. Who we share information with
We share information only with service providers that help us run the Service, under appropriate obligations, and only as needed:
- hosting and database providers that store the data;
- an e-mail delivery provider for service e-mails;
- our payment gateway (SSLCommerz) to process plan payments.
We may also disclose information if required by law or a valid legal request, or to protect the rights, safety and security of users, the public or the Service. If our business is restructured or sold, information may transfer to the successor under the same protections.
7. International processing
Our hosting and other providers may store or process data in countries other than where you live. Where that happens we take reasonable steps so that the data remains protected in line with this policy.
8. How long we keep information
We keep organization data while the organization’s account is active. Employee records are kept until the organization deletes or deactivates them; deactivated employees’ history is retained so past payroll and attendance stay accurate. After an account is closed we delete or anonymise data after a reasonable period, except where we must keep it by law or for legitimate accounting, fraud-prevention and security records. Backups are overwritten on a rolling schedule.
9. Security
We use measures such as encrypted connections (HTTPS), hashed passwords, short-lived access tokens with revocable sign-in sessions, role-based access controls, per-organization data separation, request rate limiting and an audit trail. No system is completely secure, so we cannot guarantee absolute security — please use a strong, unique password and tell us straight away about any suspected unauthorised access.
10. Your rights and choices
Subject to applicable law you may ask to access, correct, export or delete personal information we hold about you, and to object to or restrict certain uses. You can update your own name, phone and password in the app at any time.
For employee records, please contact your employer first. For account, billing or other requests to us, e-mail support@example.com. We may need to verify your identity before acting on a request.
11. Children
The Service is intended for business use and is not directed at children. Organizations must only add staff who are legally permitted to work and be recorded under applicable law.
12. Changes to this policy
We may update this policy from time to time. If a change is material we will notify you in the app or by e-mail before it takes effect. The date at the top shows when it was last updated.
13. Contact
হিসাব খাতা (Hishab Khata), Dhaka, Bangladesh. E-mail: support@example.com.