Munib ji

Privacy Policy

Last updated: 1 August 2026

Munib ji ("we", "our", "us") is business-management software owned and operated by Ritamvara Technologies, a sole proprietorship registered under GSTIN 07IALPS4664D1Z8, trading as "Munib ji", with its principal place of business at RZ-48-49, Sai Apartment, Uttam Nagar, West Delhi, 110059. Munib ji is used by small and medium Indian businesses ("organizations") and their staff, clients, and accountants. This policy explains what data we collect through the Munib ji web app and native mobile apps, why, and what rights you have over it under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and its associated Rules.

Who this covers

If you use Munib ji as an employee, manager, or owner of a business that has signed up for Munib ji, your organization's admin is the data fiduciary for your work-related information — Ritamvara Technologies processes it on their behalf, as a data processor. If you're a client uploading bills or booking services through Munib ji, or a CA, CS, or CMA using the professional portal, the same applies to the organization you're interacting with. For account-level data we collect directly (e.g. sign-up details, payment records, support requests), Ritamvara Technologies is itself the data fiduciary.

What we collect

  • Account & profile: name, phone number, role, address, bank/UPI details (for payroll or payouts), emergency contact details.
  • Location: if you're a field employee, Munib ji records GPS location for attendance geofencing and route tracking while Field Mode is on — including in the background on the native app, so a manager can see live progress. This can be turned off; check-in falls back to manual verification instead.
  • Camera & photos: photos you take for expense receipts, bill uploads, or barcode/QR scanning. These are stored to fulfil the purpose you took them for (e.g. an expense claim) and are not used for any other purpose.
  • Device push token: if you enable notifications on the native app, we store a device identifier (not tied to any personal profile beyond your account) used only to deliver notifications like approvals, payroll updates, or safety alerts.
  • Business & financial records: sales, invoices, inventory, GST filings, and payroll data your organization enters or generates through Munib ji.
  • On-device biometric unlock: the native app offers an optional Face ID/Touch ID/fingerprint app-lock. This is handled entirely by your phone's own operating system — Munib ji never receives, stores, or transmits any biometric data for this feature. It only ever knows whether your phone confirmed "yes, this is the device owner."
  • Selfie/face-match attendance verification: Munib ji's attendance system has support for optional photo-based check-in verification. As of this writing, no screen in the app actually captures this photo — it is not an active feature. If and when it is turned on, it will require your explicit consent first, and this policy will be updated with the specific retention period and purpose before that happens.

Who we share data with

To operate Munib ji, we share limited data with:

  • Supabase (database hosting, Mumbai region) and Cloudflare R2 (file storage)
  • Razorpay, for payment processing — we never see or store full card details
  • WhatsApp Business API and MSG91, to deliver WhatsApp/SMS notifications
  • Firebase Cloud Messaging, to deliver push notifications on the native app
  • Anthropic and Google, whose AI models power the in-app business advisors
  • Setu, for GSTIN verification when you or your organization looks up a business's GST registration details

We do not sell your data, and we don't share it with anyone for advertising.

Cross-border transfers: our database and file storage are hosted in India (Mumbai region). Some of the service providers above (including Anthropic and Google, for AI processing) may process data on servers located outside India. We only share what's needed for that specific service to function, and we don't transfer data to any country the Government of India restricts under the DPDP Act. If this changes, we'll update this section.

How long we keep it

Business records are kept for as long as your organization's account is active, plus any period required by Indian tax/labour law. Location history is retained only as long as needed for attendance/route records. If face-match verification is ever turned on, that photo data is deleted automatically after 90 days, and immediately if you leave the organization.

Your rights

Under the DPDP Act, you have the right to:

  • Access a summary of the personal data we (or your organization) hold about you, and how it's been processed.
  • Correct or update inaccurate or incomplete personal data.
  • Erase personal data that's no longer needed for the purpose it was collected for.
  • Withdraw consent at any time for anything you've opted into (like location tracking or photo-based attendance verification, if enabled) — withdrawing is as easy as giving consent was, and won't affect processing that already happened lawfully before you withdrew.
  • Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
  • Register a grievance — see the Grievance Officer section below — and, if unresolved, escalate to the Data Protection Board of India.

If you're an employee, client, or CA interacting with an organization on Munib ji, start with your organization's admin — they are the data fiduciary for your work-related data and are best placed to act on these requests directly. If you can't resolve something with your organization, or your request concerns data Ritamvara Technologies holds directly (e.g. sign-up or payment records), contact our Grievance Officer below.

Grievance Officer

As required under the DPDP Act, Ritamvara Technologies has appointed a Grievance Officer to address complaints and requests regarding your personal data:

[GRIEVANCE OFFICER NAME]
Ritamvara Technologies
Email: munibjiofficial@gmail.com

We aim to acknowledge grievances within a reasonable time and resolve them promptly. If you're not satisfied with our response, you may approach the Data Protection Board of India.

Security

We use encryption in transit and at rest, role-based access controls, and audit logging on sensitive data access. No system is perfectly secure, but we treat this seriously — including that sensitive profile fields (like medical information used for SOS alerts) are encrypted at the field level, not just the database level.

If something goes wrong

In the event of a personal data breach, we will notify the Data Protection Board of India and affected data principals as required under the DPDP Act, including what happened, what data was involved, and what we're doing about it.

Children

Munib ji is a workplace business tool and is not directed at or intended for children under 18. If we become aware that a child's personal data has been collected without verifiable parental/guardian consent, we will delete it.

Changes to this policy

If we make a material change to what we collect or why, we'll update this page and the "Last updated" date above, and where required, provide a fresh consent notice for the specific change.

Contact us

Ritamvara Technologies
RZ-48-49, Sai Apartment, Uttam Nagar, West Delhi, 110059
Questions about this policy or your data: munibjiofficial@gmail.com