Legal

Privacy Policy

Last updated 1 August 2026  ·  Applies to Prime Practice at primepractice.in and every firm workspace hosted on it.

Prime Practice is built so that the data you are most responsible for — your clients’ records — never sits on our servers. This policy explains what that means in practice, what limited information we do hold, and what you can ask us to do with it.

Who this policy is from

Prime Practice is operated by [LEGAL ENTITY NAME] (“Prime Practice”, “we”, “us”), with its registered office at [REGISTERED ADDRESS], India. You can reach us any time at cashantanusaxena@gmail.com.

This policy covers primepractice.in, every firm workspace hosted under it, the client portal, and the setup wizard.

The part that matters most: where your data lives

Most practice-management software stores every firm’s client list on the vendor’s own servers. Prime Practice does not work that way.

When your firm sets up a workspace, you create a database in your own Google account (a Firebase project, which is Google’s hosted database service). Your clients’ names, PANs, GSTINs, documents, invoices, ledgers, tasks and chat messages are written into that database. It belongs to your firm. We hold no login to it and cannot read it.

In plain terms

Your client data is not ours to lose, sell, mine or hand over. If you stop using Prime Practice, the database stays with you — we do not have a copy to delete, because we never had one.

The practical consequence: for the personal data of your clients, your firm is the Data Fiduciary under the Digital Personal Data Protection Act, 2023. Prime Practice supplies the software that runs against your database; it is not a destination for that data.

What we do collect

We hold a deliberately small amount of information, and only about the firm — not about the firm’s clients.

WhatWhy we need it
Firm name, workspace address, administrator emailTo route primepractice.in/your-firm to the right workspace at login.
Subscription status and expiry dateTo keep your workspace active and to show trial or renewal reminders.
Name, firm, email and phone submitted through the contact formTo reply to your enquiry and set your workspace up.
GSTIN and return period, when you use the GST filing-status checkerPassed to a government-data provider to fetch the filing status, then returned to your screen. We do not store the result.
Basic technical logs (IP address, browser, timestamps)Security, abuse prevention and diagnosing faults.

We do not run advertising trackers, we do not sell data to anyone, and we do not profile you.

Cookies and browser storage

Prime Practice uses browser storage rather than tracking cookies. Specifically:

None of this is shared with third parties or used to follow you across other websites.

Service providers we rely on

Running the product means a small number of vendors process data on our behalf or on yours:

ProviderRole
Google (Firebase, Cloud Functions, Hosting)Hosts the application, the authentication system and — inside your own Google account — your firm’s database.
Transactional email providerDelivers workspace invitations, client-portal invitations and welcome emails.
Government-data provider for GST lookupsReturns public GST filing status for a GSTIN you ask about.
Payment gatewayProcesses subscription payments. Card details go to the gateway, never to us — we see only whether a payment succeeded.

We disclose information to anyone else only where the law compels it, and we will tell you unless we are legally barred from doing so.

How we protect what we hold

Traffic runs over HTTPS. Access to a workspace requires an email and password issued by your firm, and staff accounts are limited by the permissions the firm’s administrator grants them. Every significant action inside a workspace is written to an audit log that the administrator can read.

Passwords are handled by Google Firebase Authentication and are never visible to us. Credentials stored in the in-app password vault are encrypted behind a master PIN that only your firm sets — if that PIN is lost, we cannot recover the vault for you.

No system is perfect. If a breach ever affects data we hold, we will notify affected firms and the Data Protection Board as required under the DPDP Act, 2023.

Your rights

Under the Digital Personal Data Protection Act, 2023 you may ask us to:

Write to cashantanusaxena@gmail.com and we will respond within thirty days. For data held inside your firm’s own database, the request should go to the firm — we have no access to act on it.

How long we keep it

Directory and subscription records are kept for as long as your workspace exists and for one year afterwards, so a returning firm can be reconnected. Contact-form enquiries are kept for two years. Technical logs are kept for ninety days. Anything we are required to retain for tax or statutory reasons is kept for the period the law prescribes.

Children

Prime Practice is a tool for professional firms and is not directed at children. We do not knowingly process the personal data of anyone under 18. If you believe a child’s data has reached us, write to us and we will delete it.

Grievance officer

In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000, complaints may be addressed to:

Grievance officer

[OFFICER NAME]
[LEGAL ENTITY NAME]
[REGISTERED ADDRESS]
Email: cashantanusaxena@gmail.com

We acknowledge every complaint within forty-eight hours and aim to resolve it within thirty days.

Changes to this policy

If we change how we handle data in a way that affects you, we will update the date at the top of this page and, for anything material, tell you inside the app or by email before it takes effect.