Legal
Privacy
MergeWise is a record of your money. It reads and remembers; it never moves a rupee. This page is the notice India's data protection law requires us to give you, written so you can actually read it.
Last updated 8 August 2026 · Version 1.0 · Applies to MergeWise at x.pankajfabricators.com and the app at /app
On this page
- The short version
- Who we are, and who you are
- This page is the notice
- What we collect, and why
- What never leaves your device
- Why we are allowed to hold it
- Consent Managers
- Who else can see it
- Where it is stored, and border crossings
- How long we keep it
- What erasure means here
- Your rights, and how to use each
- Nomination
- What the Act asks of you
- Children
- How we protect it
- If there is a breach
- Grievance Officer
- Changes to this notice
- Contact
1. The short version
You can read the whole page, and we would rather you did. If you only read one part, read this one. Nothing below contradicts it.
- MergeWise stores the money records you type, scan or speak: amounts, categories, notes, accounts, pots, trips and the exchange rates frozen on the day you spent.
- It never asks for a bank account number, a netbanking login, a UPI PIN, a card number or a CVV, and it has no way to move money.
- Your data is stored in India, in Mumbai.
- The Keys vault, your receipt photos, your statement files and your voice stay on your device. There is no server table for them and no endpoint that can return them.
- We do not sell your data, we do not show you advertising, we run no analytics or tracking scripts, and we do not train models on your records.
- You can ask for a copy of everything, ask us to correct it, or ask us to erase your account. The route is one email, and it is answered by a person.
2. Who we are, and who you are
MergeWise is made and operated by Pankaj Fabricators, [legal form: proprietorship / LLP / private limited], registered at [registered office address, with PIN code], India.
Corporate identity number: [CIN / LLPIN, or delete this line if not applicable]. GSTIN: [GSTIN, or delete this line].
Under the Digital Personal Data Protection Act, 2023 (we call it the Act below), we are the Data Fiduciary. That is the legal word for the person who decides why and how your personal data is processed. Where we use another company to do the actual storing or sending, that company is a Data Processor and works only on our instructions.
You are the Data Principal. That is the legal word for the person the data is about. The Act gives you a set of rights over your data and gives us a set of duties. Section 12 of this page tells you how to use every one of those rights.
We hold your records. You own them. The law calls us the Data Fiduciary and you the Data Principal, and it puts the burden on us, not on you.
3. This page is the notice
Section 5 of the Act says that before or when we ask for your consent, we have to give you a notice that says what personal data we want, what we want it for, how you can exercise your rights, and how you can complain to the Data Protection Board of India. This page is that notice. It is linked from the sign-up screen and from the footer of every page, and you can read all of it before you type anything.
Here is where each required part lives, so you do not have to hunt:
| What the notice must say | Where it is on this page |
|---|---|
| The personal data we want | Section 4, itemised line by line |
| The purpose of each item | Section 4, in the column next to it |
| How to withdraw consent | Section 6 |
| How to exercise your rights | Section 12 |
| How to complain to the Board | Section 18 |
| Who else the data goes to | Section 8 |
4. What we collect, and why
This is the whole list. If something is not on it, we do not collect it. Every item is here because a feature you can point at needs it; nothing is collected on the theory that it might be useful one day.
To make you an account
| What | Why it is needed | Where it sits |
|---|---|---|
| Email address | To create the account, sign you in, send the confirmation link, and send a reset link if you forget your password. It is also how we reach you about the service. | Supabase Auth, Mumbai |
| Password | To sign you in. We store a one-way hash of it, never the password itself. Nobody at MergeWise can read your password, including us. | Supabase Auth, Mumbai |
| Your name | So the app can address you by name, and so that a person you share a pot with knows who logged what. | Supabase Auth and the profiles table |
| Phone number, optional | Only if you type it. Today it is a note on your account. If sign-in by SMS is switched on later, it is where the code would go. Leave it blank and nothing breaks. | Supabase Auth |
| Home currency and time zone | So amounts and days are shown the way you actually live them, and so an entry lands on the day it happened rather than the day it synced. | The profiles table |
| Account created date, sign-in timestamps | Security. It is how we can tell you when the account was made and how we spot a sign-in that is not you. | Supabase Auth |
The records you keep (your ledger)
| What | Why it is needed | Where it sits |
|---|---|---|
| Entries | The product. Each one holds the amount, the currency, a category, a note, which account it came from, who paid, when it happened, and how it was logged (typed, scanned, spoken or imported from a statement). | The entries table |
| Frozen exchange rates | A foreign entry keeps the rate used on the day, so your history never moves under you when the rate changes. | On the entry itself |
| Corrections and removals | Every correction carries the reason you typed. That reason is what makes a corrected figure trustworthy rather than suspicious, and it is why the app can always show you why a number changed. | The amendments table |
| Accounts you set up | The bank's name, the kind of account, the last four digits if you choose to type them, the balance you record and the date it was true. We never ask for and never store a full account number, a customer id, a netbanking or UPI credential, a card number or a CVV. | The accounts table |
| Pots | Name, whether it is shared or private, the initials of the people in it, the budget, the goal and the log of what was allocated when. | The pots table |
| Trips | Name, dates, budget, who is coming, and the plan items and papers you type, including a booking reference and what it cost, if you type those. | The trips, trip_plan_items and trip_papers tables |
| Transfers, budgets, currency lots, repeats and category rules | Moves between your own accounts, the ceilings you set, the foreign currency you actually bought and at what rate, the subscriptions the app noticed, and the rules it learned about where a merchant files. | Their own tables |
| Attachment names | The name, kind and a size label of a paper you attached, so another one of your devices knows the paper exists. The file itself never leaves your phone. | The attachments_meta table |
| A copy of the app's own object for each record | So that when your records come back to a new phone they come back exactly as you left them, with nothing quietly reshaped in transit. | A raw column beside each record |
Technical data
| What | Why it is needed | Where it sits |
|---|---|---|
| IP address and browser user agent | Written into the service logs of the companies that host us, so that the service can be kept up and abuse can be spotted. We do not build profiles from these and we do not link them to your records. | Supabase and Netlify service logs, kept short term |
| Your sign-in token and your own records | Kept in your browser's local storage so the app opens signed in and works offline. Clearing your browser data clears it. | Your device |
MergeWise runs no analytics, no advertising SDK and no third-party tracking scripts. There is no measurement cookie, no pixel, no session recorder, no heatmap. We do not sell, rent or share your records with anyone for money, and we do not use them to train machine learning models. If any of that ever changes, it will be a new consent screen you have to say yes to, not a quiet edit to this page.
5. What never leaves your device
Some of what MergeWise handles is deliberately never sent to us at all. This is a design contract, not a setting, and it is enforced by the fact that the server has nowhere to put these things.
- The Keys vault. Passwords, documents and the spare key you keep in it are stored on your device only. There is no vault table in our database and no endpoint that can return a secret. That is the whole contract: even if someone had our database, there would be no vault in it.
- Receipt photos and bank statement files. The camera reads the bill on the device. The statement is parsed on the device. Only the lines you decide to keep become entries, and the image or the PDF stays where it was.
- Your voice. When you speak an entry, the speech is turned into text by your own device or browser and used to fill the form. We do not record it and we do not keep it.
- Small preferences. Which currencies you show, your recent categories, the rates you paid. These live on the device unless they are part of a record you chose to sync.
Because the vault never reaches us, we cannot recover it. If you lose the device or clear the browser's storage, what was in the vault is gone, and there is no support ticket that can bring it back. That is the price of the promise, and we would rather say it here than surprise you later.
6. Why we are allowed to hold it
Consent
Almost everything we process runs on your consent. The Act says consent has to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the personal data actually needed for the stated purpose. In practice, that means:
- You read this notice, then create an account. Creating the account is the clear affirmative action.
- Consent covers the purposes listed in section 4 and nothing else. We will not quietly reuse your ledger for a new purpose.
- Any new purpose gets its own request. Bank feeds are the obvious example: they are designed but not built, and when they arrive they will be a separate screen with a separate yes.
Withdrawing consent
You can withdraw your consent at any time, and it must be as easy to withdraw as it was to give. Email us at [grievance email] with the subject "Withdraw consent" and we will stop processing and erase your account, unless a law requires us to keep something (see section 10).
The consequence of withdrawing is plain: MergeWise cannot show you your records without holding them, so withdrawing consent ends the account. We will tell you that before we act, and we will offer you an export first.
Certain legitimate uses
The Act also allows processing for a short list of legitimate uses without separate consent. Two of them can apply to us:
- Data you hand us yourself for a purpose you clearly intended. If you email support with a screenshot to get a bug fixed, we process what is in that email to fix the bug. We do not need a separate consent form for the thing you deliberately sent us.
- Compliance with law. If a court, a tribunal or a lawful order under Indian law requires us to disclose or retain something, we comply. We will tell you when we are allowed to tell you.
7. Consent Managers
The Act creates a role called a Consent Manager: a company registered with the Data Protection Board of India that gives you one place to give, review, manage and withdraw consent across every service you use, through an accessible and interoperable platform. A Consent Manager is accountable to you, not to us.
As of the date at the top of this page, MergeWise is not registered with any Consent Manager, and consent to us is given and withdrawn directly, in the app and by email as described in section 6. If we ever connect to a Consent Manager, we will name it here, tell you before the change takes effect, and honour a withdrawal that arrives through it exactly as we honour one that arrives by email.
9. Where it is stored, and border crossings
Your records are stored in India, in Amazon's Mumbai region (ap-south-1), on infrastructure operated by Supabase. Backups sit in the same region.
Two honest qualifications, because "stored in India" is often said and rarely explained:
- Supabase is a company based outside India. Its engineers can, under contract and for support and reliability work, access the systems that hold the data. That is an access from outside India even though the data itself does not move.
- Netlify serves the site from a global content delivery network. A person opening the site from Berlin is served the page by a machine near Berlin, and that machine logs the request. Those logs contain an IP address and a user agent, not your ledger.
Section 16 of the Act permits transferring personal data outside India, except to a country the Central Government restricts by notification. As of the date at the top of this page no such restriction affects our processors. If one is notified that does affect them, we will move or stop the transfer and say so here.
MergeWise is not a bank, a payment system operator or any other entity regulated by the Reserve Bank of India, so the RBI's payment data localisation direction does not apply to us. We keep the data in India anyway, because that is where you are.
10. How long we keep it
The rule is simple: we keep your records while your account exists, and we erase them when you ask. The account is the container; the records are only useful because you can come back and read them.
- While you are using MergeWise, we keep everything in section 4. A ledger with holes in it is not a ledger.
- When you ask us to erase your account, we erase, on the terms in section 11.
- If you go quiet, we will not sit on your data forever. If you have not signed in for three years, we will write to your email address, wait 30 days, and then erase the account.
- Service logs at Supabase and Netlify roll off on their own short schedules and are not kept by us separately.
- Anything a law requires us to keep is kept for exactly as long as that law says, and no longer. Today we are aware of no such requirement for this product. If one appears, we will name the law here.
11. What erasure means here
MergeWise has an unusual property and you deserve the specifics rather than a comfortable sentence. The ledger is append-only. Nothing inside it is ever overwritten or deleted. That is a deliberate design and it is enforced in the database itself, not by a rule someone might forget.
Deleting inside the app is not erasure
- When you correct an entry, MergeWise does not overwrite it. It writes a new row that records what changed and the reason you gave, and the original stays underneath where you can see it.
- When you remove an entry, MergeWise writes a void. The entry stops counting towards every total immediately, and it does not vanish from your history.
- This is why a figure you looked at last March still means what it meant last March, and why the app can always answer the question "why did this number change".
Erasing your account is a real deletion
Append-only is a promise to you about your own history. It is not a licence for us to keep your history after you have gone. When you ask us to erase your account:
- We delete the authentication record and every row that belongs to you: entries, amendments, voids, accounts, pots, trips, plans, papers, transfers, budgets, currency lots, repeats, rules and attachment names. Not archived, not anonymised, deleted.
- We offer you a copy of everything first, so that leaving does not mean losing.
- We do it within 30 days of confirming the request is really from you, and we email you when it is done.
- We do not keep a shadow copy on the grounds that the ledger is append-only. If we ever had to keep something, we would tell you what and why, in writing, before erasing the rest.
The two caveats, said plainly
- Encrypted backups. The database is backed up on a rolling schedule and those backups expire by themselves. Your rows can sit inside an unexpired backup for up to seven days after the live deletion. We never restore an erased account from a backup, and when the backup expires the copy goes with it.
- Shared pots. Today, a pot is a record kept in your own account; invitations to a second person are designed but not switched on, so there is no other person's copy of your entries to worry about, and erasing your account erases the pot. Before that changes, this page will spell out exactly what a shared pot means for erasure, and you will be told what you are agreeing to before you join one.
12. Your rights, and how to use each
The Act gives you four rights. Here is each one, what it actually gets you, and the exact way to ask.
The right to access
You can ask for a summary of the personal data we hold about you, a summary of what we do with it, and the identity of every other Data Fiduciary and Data Processor we have shared it with, along with a description of what was shared.
How: most of it is already on your screen, because the app is a reader of your own records. For a machine readable copy of everything we hold, and for the formal summary described above, email [grievance email] with the subject "Access request". We answer within 30 days. A download button inside the app is on the list and is not built yet; until it is, the email route is the real one and a person answers it.
The right to correction, completion, updating and erasure
You can ask us to correct data that is wrong, complete data that is partial, update data that has gone stale, and erase data we no longer need for the purpose you gave it for.
How: in the app, you can correct any entry yourself, and the correction is recorded with your reason rather than overwriting the original. For your name, email address or anything else on the account, or to erase the account, email [grievance email] with the subject "Correction request" or "Erasure request". Section 11 says exactly what erasure does.
The right to grievance redressal
If you are unhappy with anything we do with your data, or with how we answered a request, you can complain to us first, and we have to have a route ready for you. Section 18 names the person and the address.
The right to nominate
See section 13.
Only enough to be sure the request is from you: that it comes from the email address on the account, and, if the request is erasure, one confirmation reply. We will not ask you to send us an identity document to prove you are the owner of your own email address.
13. Nomination
Section 14 of the Act lets you nominate another person to exercise your rights on your behalf if you die or become unable to act for yourself. This matters more for a money record than for most apps: your ledger may be the clearest account of what you owed and what you were owed.
To nominate someone, email [grievance email] with the subject "Nomination", the nominee's full name, their email address, their relationship to you and a phone number. We record it against your account and confirm to you in writing. You can change or cancel a nomination the same way, at any time.
A nominee can ask us for access to your records and can ask us to erase the account. They cannot sign in as you and they cannot change your records, because a ledger with a second author would not be your ledger. There is no in-app screen for nomination yet; email is the route, and it is a real one.
14. What the Act asks of you
The Act puts a few duties on Data Principals too, and it is fairer to tell you than to leave them in the statute. In short: give us real information rather than someone else's, do not impersonate another person when creating an account or making a request, do not suppress something material when you are legally required to disclose it, and do not raise a grievance you know to be false or frivolous. Breaching these duties can attract a penalty of up to ten thousand rupees under the Act. We say this once, here, and we will not use it as a threat.
15. Children
Under the Act, a child is anyone under eighteen years of age. We may not process a child's personal data without verifiable consent from a parent or lawful guardian, and we may never track a child, run behavioural monitoring on a child, or show a child targeted advertising. The last three are absolute prohibitions and we do none of them for anyone.
Our position, stated plainly: MergeWise accounts are for people aged eighteen and over. We do not offer accounts to under-18s and we have not built a verifiable parental consent flow. By creating an account you confirm you are eighteen or older.
If you believe a child has created an account, write to [grievance email] and we will verify and delete it, along with everything in it. We would rather do that than pretend a checkbox is a birth certificate.
16. How we protect it
The Act requires reasonable security safeguards. These are ours, described concretely enough that you could check them.
- Row level security on every table. The database itself refuses to return another person's row, whatever the app asks. Access by anonymous callers is revoked entirely; every read needs a valid session.
- Append-only where it counts. The privileges to update or delete a ledger row do not exist. An attempt fails loudly rather than quietly succeeding.
- No secrets endpoint. There is no API route that can return a vault item, because there is nothing to return. This is checked as part of our own release checks.
- Encryption in transit and at rest. Every connection is TLS. The database and its backups are encrypted at rest.
- Passwords are hashed, never stored. A one-way hash means nobody can read your password out of our database, including us.
- Least privilege for people. Access to production is limited to those who need it, and administrative access is protected by multi-factor authentication.
- No third parties in the page. Fewer scripts is fewer ways in. The app loads its own code and nothing that watches you.
No system is perfect and we will not claim otherwise. What we can promise is that we do not trade a security property for a convenience, and that when we find something we say so.
17. If there is a breach
A personal data breach means any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access, that compromises your data's confidentiality, integrity or availability.
If one happens:
- We tell you. Every affected person is notified directly, without delay, in plain words. The notice will say what happened, what data was involved, what we have done about it, what we suggest you do, and who to write to with questions. We will not bury it in a status page.
- We tell the Board. We intimate the Data Protection Board of India without delay, and follow it with the detailed report the rules require, within seventy-two hours of becoming aware, or such longer period as the Board allows.
- We write it down. What happened, what we changed, and how we will know if it happens again.
None of this is conditional on the breach being embarrassing.
18. Grievance Officer
The Act requires us to publish the contact details of a person who answers your questions about your data. That is not a form; it is a named human.
- Grievance Officer[full name], Grievance Officer, Pankaj Fabricators
- Email[grievance email]
- Post[registered office address, with PIN code], India
- Phone[phone number, optional]
- We acknowledgewithin 3 working days
- We answerwithin 30 days of the request
MergeWise is not, today, a Significant Data Fiduciary, so we are not required to appoint a Data Protection Officer. If the Central Government ever notifies us as one, we will appoint one, name them here, and say so before the change takes effect.
If we do not fix it
You have to come to us first. If we do not answer, or you are not satisfied with the answer, you can complain to the Data Protection Board of India, which is the authority set up under the Act to hear exactly these complaints. Its procedure and contact details are published by the Government of India at meity.gov.in. Complaining to the Board costs you nothing and we will not hold it against you.
19. Changes to this notice
We will change this page when the product changes, and the date at the top is the honest record of when. If a change is material, meaning it affects what we collect, why, who sees it, or how long we keep it, we will email you before it takes effect and say in one sentence what changed. We will not rely on you noticing a new date.
A change that widens what we do with your data needs your consent, not your silence.
20. Contact
- About your data[grievance email]
- Everything else[support email]
- PostPankaj Fabricators, [registered office address, with PIN code], India
MergeWise is in beta and free. The terms of use say what that means, and the refunds page says what happens if paid plans ever arrive.