Legal

Privacy Policy

We take your data and your customers' data seriously. This policy explains what we collect, how we use it, and what rights you have.

Last updated: July 2026

Introduction

This Privacy Policy describes how VoyceBook, operated by CoolCodes Technologies Private Limited ("Company", "we", "us", or "our"), collects, uses, and shares information about you when you use our business document management platform at voycebook.in and related services (collectively, the "Service").

By accessing or using our Service, you agree to this Privacy Policy. If you do not agree with our practices, please do not use the Service. This policy applies to all users of VoyceBook, including account holders, team members, and visitors to our marketing website.

We process personal data in compliance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and in preparation for compliance with the Digital Personal Data Protection Act, 2023 (DPDPA).


Information We Collect

We collect information you provide directly, information generated as you use the Service, and limited information from third-party sources. Here is a breakdown of each category:

Account Information

  • Name, email address, and password when you register
  • Business name, GSTIN, PAN, and registered address for invoicing compliance
  • Phone number for verification and support
  • Profile photo (optional)
  • Team member details added by account owners

Business & Document Data

  • Customer records, contact information, and transaction history you enter
  • Proposals, contracts, invoices, purchase orders, and other documents you create
  • Notes, comments, and activity logs attached to documents
  • File attachments and uploads (PDFs, images)

Billing Information

  • Subscription plan and billing cycle
  • Payment method type (card, UPI, net banking) — we do not store full card numbers
  • Transaction IDs and payment history, processed via Razorpay

Usage Data

  • IP address and approximate location (city/state level)
  • Browser type, device type, and operating system
  • Pages visited, features used, and time spent in the application
  • Error logs and crash reports to diagnose issues

Cookies & Similar Technologies

We use cookies and local storage for authentication sessions, preferences, and analytics. See the Cookies & Tracking section for details.


How We Use Your Information

We use the information we collect for the following purposes:

Service Delivery

  • Creating and managing your account and workspace
  • Generating, storing, and delivering your business documents
  • Enabling team collaboration, approvals, and role-based access
  • Powering timeline memory, version history, and AI-assisted features

Billing & Compliance

  • Processing subscription payments and issuing receipts
  • Calculating and applying GST on your subscription where applicable
  • Maintaining financial records as required under Indian law

Communications

  • Sending transactional emails (account verification, password resets, invoices)
  • Notifying you of important updates to the Service or this policy
  • Sending product newsletters and feature announcements (you may opt out at any time)
  • Responding to support requests

Product Improvement

  • Analysing aggregated usage patterns to improve features
  • Diagnosing bugs and performance issues
  • Conducting internal research and development

Legal & Safety

  • Enforcing our Terms of Service
  • Detecting and preventing fraud, abuse, and security incidents
  • Complying with applicable laws and court orders

Data Storage & Security

We are committed to protecting your data with industry-standard security practices.

Infrastructure & Hosting

VoyceBook is hosted on Amazon Web Services (AWS) in the Asia Pacific (Mumbai) region (ap-south-1). All customer data — including documents, business records, and personal information — is stored within India. We do not transfer data outside India except as described in the Sharing & Disclosure section below.

Encryption

  • All data is transmitted over TLS 1.2 or higher (HTTPS enforced site-wide)
  • Data at rest is encrypted using AES-256 managed by AWS KMS
  • Passwords are stored as bcrypt hashes and are never stored in plain text
  • Database backups are encrypted using the same standards

Access Controls

  • Access to production systems is restricted to authorised engineering staff only
  • Multi-factor authentication is required for all internal system access
  • Access logs are maintained and reviewed regularly
  • Role-based access control within your VoyceBook workspace limits data access to team members you designate

Security Practices

We conduct periodic security reviews and vulnerability assessments. If you discover a security issue, please report it responsibly to security@voycebook.com. We investigate all reports and respond within 72 hours.

While we take reasonable precautions, no system is perfectly secure. In the event of a data breach that affects your personal information, we will notify you and the relevant authorities as required by law within 72 hours of discovering the breach.


Sharing & Disclosure

We do not sell your personal data or your customers' data to any third party. We share data only in the circumstances described below.

Service Providers (Data Processors)

We engage carefully selected third-party service providers to help us operate the Service. These processors act only on our instructions and are bound by data protection agreements:

  • Razorpay — payment processing and subscription billing (India-based, RBI compliant)
  • Amazon Web Services (AWS) — cloud infrastructure and data storage (Mumbai region)
  • SendGrid (Twilio) — transactional email delivery
  • PostHog — product analytics (self-hosted on AWS Mumbai, no data leaves India)

Legal Requirements

We may disclose your information if required by law, regulation, legal process, or governmental request — for example, in response to a court order, summons, or other legal process. We will notify you of such requests where permitted by law.

Business Transfers

In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email and a prominent notice in the Service at least 30 days before your data becomes subject to a different privacy policy.

Protection of Rights

We may disclose information where we believe it is necessary to investigate, prevent, or take action against illegal activities, suspected fraud, violations of our Terms of Service, or to protect the rights, property, or safety of VoyceBook, our users, or others.


Your Rights

Under the Digital Personal Data Protection Act, 2023 (DPDPA) and applicable Indian privacy law, you have the following rights regarding your personal data:

Right to Access

You may request a copy of the personal data we hold about you. We will provide this within 30 days of a verified request.

Right to Correction

You may request correction of any inaccurate or incomplete personal data. Many corrections can be made directly from your account settings page without contacting us.

Right to Deletion (Erasure)

You may request deletion of your personal data. Deleting your account will remove your profile and associated data in accordance with our Data Retention policy. Note that we may retain certain data where required by law or for legitimate business purposes such as financial record-keeping.

Right to Data Portability

You may request an export of your data in a machine-readable format (JSON or CSV). Use the "Export your data" option in Account Settings, or contact us directly.

Right to Withdraw Consent

Where processing is based on your consent (for example, marketing emails), you may withdraw consent at any time. Withdrawing consent does not affect the lawfulness of processing prior to withdrawal.

Right to Nominate

Under the DPDPA, you have the right to nominate another individual to exercise your data rights on your behalf in the event of your death or incapacity.

To exercise any of these rights, email us at privacy@voycebook.com from the email address registered to your account. We will verify your identity before processing the request.


Cookies & Tracking

We use cookies and similar technologies (such as local storage) to operate and improve the Service.

Essential Cookies

These are necessary for the Service to function. They include authentication session tokens, CSRF protection tokens, and user preference settings. You cannot opt out of essential cookies without stopping use of the Service.

Analytics Cookies

We use PostHog (self-hosted in India) to understand how users interact with VoyceBook. This helps us identify popular features, diagnose drop-off points, and prioritise improvements. Analytics data is aggregated and does not identify you personally. You can opt out of analytics tracking from your account settings under Privacy & Data.

Third-Party Cookies

Our payment processor Razorpay may set cookies during the checkout flow to prevent fraud and comply with RBI guidelines. These are governed by Razorpay's own privacy policy.

You can control cookie behaviour through your browser settings. Note that disabling all cookies may impact the functionality of certain features.


Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. Here is how our retention works in practice:

  • Active account data is retained indefinitely while your subscription is active
  • If you downgrade to a free tier, document history beyond the free-tier limit is archived but not deleted for 90 days
  • On account deletion or subscription cancellation, your personal data is deleted within 30 days from our live systems
  • Anonymised analytics data and aggregated usage statistics may be retained indefinitely
  • Financial records (invoices, payment receipts, audit logs) are retained for 8 years from the date of transaction as required under the Companies Act, 2013 and GST regulations
  • Backup copies of deleted data are purged within 90 days from the backup rotation schedule

If you would like your data deleted sooner, contact us at privacy@voycebook.com. We will accommodate requests where not prevented by legal obligations.


Children's Privacy

VoyceBook is a business software platform and is not directed at, or intended for use by, individuals under the age of 18. We do not knowingly collect personal data from anyone under 18.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@voycebook.com. We will delete such information promptly upon verification.


Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

When we make material changes to this policy, we will:

  • Update the "Last updated" date at the top of this page
  • Send an email notification to the primary email address on your account at least 14 days before the changes take effect
  • Display a prominent notice within the VoyceBook application for 30 days after the change

For non-material changes (such as clarifications, typo corrections, or reorganisation of content), we will update the policy with a new date but may not provide advance notice. We encourage you to review this policy periodically.

Your continued use of the Service after a change takes effect constitutes acceptance of the updated policy.


Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out to us:

CoolCodes Technologies Private Limited

Data Protection Officer

Email: privacy@voycebook.com

General: hello@voycebook.com

Website: voycebook.in

We aim to respond to all privacy-related queries within 5 business days.

If you believe we have not addressed your concern adequately, you have the right to lodge a complaint with the Data Protection Board of India once it becomes operational under the Digital Personal Data Protection Act, 2023.