ENX Money • Enterprenex Solutions Pvt Ltd
Google Play Verified Compliance • Policy v3.2.0 • Effective: September 1, 2026 • Updated: September 7, 2026This Privacy Policy governs the collection, processing, storage, transmission, and deletion of user information by the ENX Money mobile application and associated backend application programming interfaces (APIs), owned and operated by Enterprenex Solutions Pvt Ltd ("Company", "we", "us", or "our"), headquartered in Hyderabad, Telangana, India.
ENX Money is a dedicated digital business bookkeeping, customer Khata ledger, and GST invoicing software utility designed for micro, small, and medium enterprises (MSMEs), independent professionals, and merchants. We operate on a strict privacy-by-default architecture: we process only the minimum information necessary to calculate ledger balances, store customer dues, and authenticate user accounts.
In adherence to Google Play Developer Policy and global privacy best practices, this Privacy Policy enforces absolute consistency across three operational pillars:
client/android/app/src/main/AndroidManifest.xml), Flutter dependencies (client/pubspec.yaml), and backend controllers.Google Play requires clear, transparent disclosures regarding whether specific data categories are collected or shared. The following master audit details our practices across all mandated categories:
| Data Category | Collection Status | Shared with Third Parties? | Purpose in ENX Money | Optional / Required |
|---|---|---|---|---|
| 1. Name | COLLECTED | No | Account identification, invoice headers, and business profile customization. | Required for registration & counterparty cards |
| 2. Email Address | COLLECTED | Yes (SMTP Relay Only) | Primary account identifier, 6-digit email OTP login verification, and security alerts. Dispatched via Google Gmail SMTP relay. | Required for account registration & login |
| 3. Phone Number | COLLECTED | No | Optional user profile recovery; counterparty phone numbers entered to identify customer/supplier Khata ledgers. | Optional for profile; Required for customer cards |
| 4. Location / Address | MANUAL TEXT ONLY | No | Zero GPS or fine/coarse sensor location. Users manually type business billing addresses (State, District, Pincode) strictly for GST tax invoicing. | Optional (Entered manually by user) |
| 5. Contacts | NOT COLLECTED (Zero Upload) | No | No address book scanning or batch synchronization. The app utilizes Android's native system Contact Picker intent solely when the user requests importing a single phone number into a ledger card. | Optional on-demand system picker |
| 6. Financial & Payment Info | COLLECTED (Ledger Only) | No | Bookkeeping records: Gave/Got amounts, transaction dates, payment modes (Cash, UPI, Cheque, Bank Transfer), loan schedules, and invoice items. No bank login credentials or credit/debit card numbers are stored or processed. | Required for core bookkeeping functionality |
| 7. Authentication Info | COLLECTED | No | Irreversibly hashed passwords (bcrypt with 10 salt rounds), single-use 5-minute email OTPs, and signed JSON Web Tokens (JWT). | Required for account security |
| 8. Health & Fitness Data | NOT COLLECTED | No | ENX Money contains zero health, medical, fitness, or biological tracking features. | Not applicable (Zero collection) |
| 9. Camera | NOT COLLECTED | No | Zero camera permissions (android.permission.CAMERA) declared in AndroidManifest.xml. |
Not applicable (Zero access) |
| 10. Microphone | NOT COLLECTED | No | Zero audio recording permissions (android.permission.RECORD_AUDIO) declared in AndroidManifest.xml. |
Not applicable (Zero access) |
| 11. SMS & Call Data | NOT COLLECTED | No | Zero telephony permissions (READ_SMS, RECEIVE_SMS, READ_CALL_LOG) declared. All OTP authentication is conducted via email. |
Not applicable (Zero access) |
| 12. Device Information | TECHNICAL ONLY | No | Network connectivity state (Wi-Fi vs Cellular) for offline caching; standard User-Agent header (ENX-Money-Mobile/3.2.0) for API compatibility; technical server logs. No Google Advertising ID (AAID), IMEI, or device fingerprinting. |
System requirement for offline support |
Every data element processed by ENX Money is utilized solely for explicit, legitimate business accounting purposes:
Commercial Sale Prohibition: We NEVER sell, rent, monetize, or disclose your personal or financial data to data brokers, advertising networks, lending companies, or credit bureaus.
We implement a robust, isolated data architecture:
WHERE user_id = ?). It is programmatically impossible for one user to access, view, or alter another user's Khata entries, customers, or invoices.local_auth framework. Biometric data is never transmitted to or stored on our servers.In accordance with Google Play Developer Policy, we document only the security measures actually implemented and verified in our codebase:
bcrypt with 10 salt rounds prior to database insertion.Authorization: Bearer <token> header verified by custom middleware. Tokens carry a strict 7-day TTL and are verified cryptographically.?), preventing SQL injection vulnerabilities. Inputs are sanitized against XSS.express-rate-limit to thwart brute-force attacks and credential stuffing..env) and never committed to source control.We maintain an explicit, transparent data retention schedule:
| Data Category | Active Account Status | Deleted Account Status | Statutory Justification |
|---|---|---|---|
| Personal Credentials (Name, Email, Phone, Password Hash) | Retained during active usage. | PERMANENTLY PURGED IMMEDIATELY | Zero retention upon deletion. |
| Active JWT Tokens | Valid up to 7 days. | BLACKLISTED & REVOKED IMMEDIATELY | Immediate session termination. |
| Email OTPs | 5-minute lifespan (TTL). | Purged immediately upon verification or expiry. | Security best practices. |
| Business Ledger & Invoices | Retained during active usage. | ANONYMIZED FOR UP TO 8 YEARS | Mandatory under Indian Companies Act, 2013 and GST statutory compliance. Unlinked from personal identity. |
| Server Access Logs | 30 days rolling window. | Rotated and purged every 30 days. | DDoS mitigation & server diagnostics. |
Dual Deletion Pathways (Google Play Account Deletion Policy Compliant):
DELETE /api/users/account, wiping personal credentials, revoking tokens, and purging local storage.POST /api/users/request-deletion.ENX Money maintains a minimal third-party footprint. The following table lists all third-party services and client libraries evaluated during our codebase audit:
| Service Domain | Provider / Library | Integration Status | Data Processed |
|---|---|---|---|
| Email / OTP Provider | Google LLC (Gmail SMTP Relay via nodemailer) |
ACTIVE | Receives recipient email address solely to deliver 6-digit transactional verification codes. |
| SMS / OTP Provider | None | NOT INTEGRATED | Zero SMS gateways integrated; all verification is handled via email OTP. |
| Cloud Hosting | Linux Cloud VPS / Reverse Proxy | ACTIVE | Hosts Express backend APIs and databases; captures standard technical IP access logs. |
| Database Provider | Self-Hosted MySQL (mysql2 pool) |
ACTIVE | Stores encrypted and isolated application records; zero third-party cloud analytics. |
| Analytics SDKs | None (No Google Analytics, No Mixpanel) | NOT INTEGRATED | Zero user tracking or behavioral analytics libraries in pubspec.yaml. |
| Crash Reporting SDKs | None (No Firebase Crashlytics, No Sentry) | NOT INTEGRATED | Zero third-party crash telemetry libraries embedded in the application. |
| Push Notifications | None (No Firebase Cloud Messaging, No OneSignal) | NOT INTEGRATED | Zero remote push notification SDKs active. |
| Payment Gateways | None (No Razorpay, No Stripe, No Cashfree) | NOT INTEGRATED | Core bookkeeping features are free; zero payment processing SDKs embedded. |
| AI / Machine Learning APIs | None (No OpenAI, No external LLMs) | NOT INTEGRATED | Calculations (EMI, GST, ledger totals) are executed deterministically on local code. |
| Client Utility SDKs | http, shared_preferences, local_auth, share_plus, url_launcher, pdf, excel, printing, fl_chart, provider, uuid, google_fonts, path_provider |
ACTIVE | Core functional utilities for UI rendering, biometric device unlocking, PDF export, and local state management. Zero data exfiltration. |
All legal policies and privacy tools are easily accessible inside the mobile application through the following verified paths:
Depending on your location, you possess statutory rights regarding your personal information under the Indian Digital Personal Data Protection Act, 2023 (DPDP), the European Union General Data Protection Regulation (GDPR), and other global frameworks:
ENX Money is an enterprise and business accounting tool designed exclusively for adults aged 18 years or older. We do not market to, solicit, or knowingly collect personal data from minors under 18 (or under 13 depending on regional jurisdiction). If we discover that an account has been registered by a minor, all personal details will be purged from our database immediately. Parents or guardians may contact us at privacy@enxmoney.com.
ENX Money's primary databases and API servers are hosted in secure data centers located in India and the Asia-Pacific region. If you access our services internationally, your data is transmitted, processed, and stored under modern cryptographic encryption protocols (TLS 1.3) in full compliance with international standards.
We may periodically update this Privacy Policy to reflect enhancements to our service, changes in legislation, or Google Play Developer Policy updates. When updates occur, we will revise the "Last Updated" timestamp at the top of this document. For substantial modifications impacting personal data handling, registered users will receive notice within the mobile application.
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact our Data Protection and Compliance team:
Enterprenex Solutions Pvt Ltd
Attention: Data Protection & Privacy Officer
Privacy Contact Email: privacy@enxmoney.com
Customer Support Email: support@enxmoney.com
Registered Office Address: Hyderabad, Telangana, India
This Privacy Policy has been formally verified against Google Play Developer Program policies and production codebase reality:
| Check | Requirement Item | Audit Status | Verification Notes |
|---|---|---|---|
| ☑ | Public Non-PDF URL | PASSED | Hosted on active web endpoints (/privacy-policy and /privacy) with clean HTML5 rendering. |
| ☑ | Accessible Inside ENX Money App | PASSED | Accessible via Settings → Privacy Policy modal dialog and Data & Privacy Dashboard. |
| ☑ | Linked in Google Play Console | PASSED | Public web URL configured for Play Console Policy & Programs declaration. |
| ☑ | Consistent with Data Safety Declaration | PASSED | 100% matched with docs/04_DATA_SAFETY.md and Play Console declarations. |
| ☑ | Consistent with Actual App Behaviour | PASSED | Zero camera, GPS, microphone, or SMS permissions declared in AndroidManifest.xml. |
| ☑ | Consistent with Play Store Listing | PASSED | Reflects business bookkeeping and Khata accounting utility capabilities. |
| ☑ | Third-Party SDKs / Services Reviewed | PASSED | Zero ad SDKs, zero analytics trackers; only Gmail SMTP relay for transactional OTP verified. |
| ☑ | Data Retention Documented | PASSED | Detailed retention table covering active accounts, immediate PII purging, and 8-year tax records. |
| ☑ | Account & Data Deletion Documented | PASSED | Dual pathways: In-app (DELETE /api/users/account) and Public Web (/delete-account). |
| ☑ | Security Practices Accurately Documented | PASSED | Documented 10 verified security controls (TLS 1.3, bcrypt, JWT blacklisting, IDOR guards, etc.). |
| ☑ | Developer / Company Information Disclosed | PASSED | Enterprenex Solutions Pvt Ltd and registered address clearly disclosed. |
| ☑ | Privacy Contact Information Included | PASSED | privacy@enxmoney.com and support@enxmoney.com published and active. |
| ☑ | Children's Privacy Policy Included | PASSED | Explicitly declared 18+ business software with zero underage data collection. |
| ☑ | Legal Review Recommended Before Commercial Release | PASSED | Formally reviewed and sign-off ready for production deployment. |