Privacy Policy — Daftari
Last updated: 2026-10-10
What we collect
When you create an account we store your phone number, your shop name and a hashed password. Your ledger is stored on our servers, linked to your account: your customers (name, phone number, rating and notes), your transactions (type, amount, currency, date and description) and your shop settings (see below). With the team accounts feature we also store the name, phone number and hashed password of each employee the owner adds.
We also record the date you accepted the terms of use, the terms version, the platform and the app build at the time — that record IS the consent log.
Your ledger on our servers
Your ledger (customers, transactions, cheques and promises, and shop settings) is stored on our servers record by record and sent encrypted in transit (HTTPS). It is held for one purpose: showing it to you in the app — on any device you sign in from — and computing what the app shows you from it, such as balances, the collection round and reports, and keeping the devices of a team in sync. We do not read it for any other purpose, analyse it beyond what the app shows you, or share it with any third party. Attachment photos (e.g. invoices) are uploaded and linked to your account so your team can review them and so they can be attached to WhatsApp receipts when needed; they are encrypted in transit and never shared with any third party. The ledger and the attachments are permanently deleted when you delete your account.
The number of transactions you record is counted on our servers for billing (balance and quota).
How much is deducted per transaction and per WhatsApp message is a commercial term we set and may change at any time at our discretion — see the Terms of Use. That does not change what we keep about you.
Your business logo
If you add a logo for your business (Settings → Business card → Image), a copy is kept on your device and a copy is uploaded to our servers linked to your account. The uploaded copy exists for one purpose only: showing the logo on your team's devices and when your account is restored on a new device. It appears at the top of the PDF statements you generate and send to your customers; it is not attached to WhatsApp messages. We do not use it for anything else and do not share it with any third party. You can remove it at any time from the same screen, and it is permanently deleted with your account.
Team accounts
Ledger records (customers and entries) are stored on our servers record by record for every account; with team accounts, each entry also records who added or edited it (owner or employee) so the ledger can show it. Employees see the shop ledger according to the permissions the owner sets; the owner sees everything. Each employee has a role: "admin", with full control over entries, customers and managing moderators; or "moderator", who records and adds customers and edits or deletes only their own entries — editing or deleting another member's transactions requires the owner's or an admin's approval, and those decisions are kept as an audit log inside the ledger. This data is encrypted in transit, we do not read, analyze or share it with any third party, and it is permanently deleted when the shop account is deleted. Removing an employee ends their access immediately, while what they recorded remains in the shop ledger under their name.
WhatsApp messages
Linking WhatsApp is optional. If you link it, session credentials are stored on our servers so receipts can be sent from your number. We keep technical metadata for sent messages (recipient number, type, status) but not the content of your financial transactions.
WhatsApp Business account: the shop owner links one WhatsApp account for the shop number, and we strongly recommend a "WhatsApp Business" account — it is the right fit for messaging customers and reduces the risk of the number being restricted. Team members (admins and moderators) do not link WhatsApp from their own devices; all their messages are sent from the shop's own WhatsApp number. Automatic sending through WhatsApp is subject to WhatsApp's own terms and you are responsible for complying with them; we are not liable for any restriction or ban WhatsApp imposes on your number.
Payments
In-app payments are processed by the platform store (App Store on iOS, Google Play Billing on Android), and no in-app payment goes through external payment links. Website purchases are processed by Stripe. In every case we never see or store card numbers on our servers — we receive only the store's purchase confirmation, which activates your plan.
Ads
The app shows rewarded ads (an optional watch in exchange for free transactions) through Google AdMob. To serve them, the network reaches the advertising identifier on your device along with general technical data such as device type, operating system and approximate country — it does not receive your ledger, your customers' names or their amounts, and we do not send it your phone number or shop name.
Before the first ad the app asks for your consent to personalised advertising through Google's own consent dialog (UMP). If you decline, ads are served non-personalised — the advertising identifier is not used to build interests. You can change your mind later in your device settings (Tracking on iOS, or resetting the advertising ID on Android).
On iOS we use Apple's SKAdNetwork to measure ad performance without individual tracking. We do not sell your data and we never share your ledger with an advertiser.
Notifications
If you allow notifications we store the device token for them (APNs on iOS, FCM on Android) against your account, so we can send things like a support reply, a purchase confirmation or a balance warning. The token is a technical device identifier holding none of your ledger, and it is deleted when you delete your account or revoke the permission.
Voice entry
If you dictate a transaction, the recording is sent to a speech-to-text provider to be turned into text and then dropped: we keep no audio archive on our servers. We use a paid tier whose terms forbid using what is sent to it for training models.
What reaches the provider is the words in that one sentence — which may include a customer name and an amount, because those are what you said — and never your ledger or your other customers. Matching the name against your customers and working out the transaction type happen on your device; your customer list is never sent to the speech provider. The feature is entirely optional and does not work without microphone permission.
Support chat
Support messages you send (text, image or voice note) are stored on our servers against your account so the support team can follow them up. The app may answer common questions automatically; where a canned answer is not enough, the text of your question may be sent to an AI provider to compose a reply — with digits stripped out first — and without your phone number, your shop name or anything from your ledger.
Verifying your number
When you ask to verify your number, that phone number is sent to whichever channel you choose to deliver the code: our own Business WhatsApp, an SMS provider, or Google (Firebase) — depending on what is available at the time. Nothing from your ledger goes with it. If you ask support instead of a code, a ready-made WhatsApp message opens from your own number containing only your shop id and your phone number, and you are the one who presses send.
We keep a technical log of every code we attempt to send (the number, the channel, whether it succeeded, and when) for support and to prevent abuse.
Device and usage information
Requests from the app carry simple technical information: device type and operating system, app build number, display language, and the time of last activity. We use it for support (knowing which build you hit a problem on) and to send our notifications in your language. We do not use it for advertising tracking.
If the app crashes, a crash report is sent containing the error message, the code path, the build number and a device identifier — with nothing from your ledger — so the fault can be fixed.
What we do not do
We do not sell your data, and we never share your ledger — your customers, transactions and their amounts — with any third party for marketing. Rewarded ads are served by Google's network as described above, and nothing from your ledger reaches it. On iOS the system asks for tracking permission (ATT) before the first ad: if you decline, the advertising identifier is not used and ads stay non-personalised. We ourselves never track you across other apps either way.
Reports you send us
When you send a report from inside the app — from the required-update screen, the maintenance screen or the account-closed screen — we store what you wrote, the number you left for us to reach you on, your phone’s platform and the app’s build number. Those screens come before sign-in, so a report needs no account and is linked to one only if you were actually signed in. We use it to answer you and to learn what is blocking people, and not for marketing.
Aggregate platform figures
From the ledgers we hold we compute aggregate figures about the service as a whole — total debts and payments per currency, and counts of shops and entries — to follow how large the service is. These are totals for our own administration; they do not show us your customers’ names, and we do not sell or share your data.
How long we keep your data
Your ledger is kept for as long as your account exists. A record you delete disappears from your ledger at once; a marker of the deletion is kept for 90 days so that your other devices learn of it, then purged.
We keep operational backup copies of our database so the service can be restored after a failure. They are kept for a limited period (normally up to 30 days) and then expire; data you delete, or an account you delete, drops out of them as they expire.
Deleting your account
You can permanently delete your account and its data from our servers at any time from inside the app: Settings → Delete account permanently.
We may also close an account ourselves where the terms of use are broken — including entering unrealistic amounts. If we do, the reason is shown to you inside the app along with a way to tell us, and the same retention periods above apply. See “Suspension and closure” in the terms of use.