Privacy

Privacy Policy

Last updated: 21 July 2026

1. Our commitment

The short version: We hold the truth about your money. That is a responsibility, not a footnote. We never sell your data, we take API keys not passwords, and the AI never touches the math.

This Privacy Policy explains what data RakamHQ collects, why, how we protect it, and the choices you have. It applies to our websites, apps, and services (the "Service").

A breach of financial data would end this company, so trust is built into how RakamHQ works - by construction, not by promise. If anything here is unclear, email us and we will explain it plainly.

2. What we collect

We collect only what we need to reconcile and report on your money, and to run your account:

  • Account details - your name, phone number and/or email, and organisation information.
  • Money-trail data - the files and records you provide: provider reports (eSewa, Khalti, Fonepay), bank statements, order exports and cash totals.
  • Connected-source data - transactions we pull using API keys you connect.
  • Concierge submissions - the contact details, business information and documents you send for a free reconciliation.
  • Usage & device data - basic logs needed to operate, secure and improve the Service.

3. Provider credentials

The short version: We accept API secret keys only - never dashboard logins or passwords - and you can revoke any credential in one click.

Where you connect a payment provider, we accept API secret keys only. We never ask for, store, or accept dashboard passwords. Credentials are encrypted at rest with per-organisation keys, exist in plaintext only in memory during a connector call, and are never logged or shown in full (last-4 only). You can revoke a credential at any time and we stop using it immediately.

4. Document uploads

Files you upload - on the concierge page or inside the product - are stored securely in Cloudflare R2, our file-storage provider. They are used only to reconcile and report on your money, and to communicate with you about it. You can request deletion of uploaded files at any time.

5. How we use your data

We use your data to:

  • Provide the Service - reconcile your money, produce your daily close, and answer your questions.
  • Communicate with you about your account, security, and the reconciliation.
  • Secure, maintain and improve the Service.

We do not use your financial data for advertising. Aggregate, anonymised benchmarks are produced only with your explicit opt-in.

6. What we never do

The short version: No selling. No sharing for advertising. No AI computing your numbers. These are commitments, written into the product and this policy.
  • We never sell your data, and never share it for advertising.
  • The AI never computes a number - the ledger computes; the model only explains, so your figures never pass through it.
  • We never hold or move your funds. RakamHQ is read-only on your world, except for gated, capped refunds you confirm.

7. How we protect it

  • Encryption - credentials and sensitive data are encrypted at rest; traffic is encrypted in transit.
  • Isolation - every query is scoped to your organisation; no path exists to another organisation's data.
  • Audit trail - every credential use, refund action and export is logged in an append-only audit spine you can read yourself.
  • Minimisation - we store masked payer hints where masking is lossless, and full values only where matching genuinely requires them.

8. Sub-processors

We use a small set of trusted providers to run the Service, each bound to protect your data: a managed Postgres database (Neon), file storage (Cloudflare R2), email delivery (Resend), and SMS delivery (Twilio). We share only what each needs to perform its function, and never for their own purposes.

9. Retention & deletion

The short version: Delete your account and we cryptographically shred your data keys and purge stored files - with a certificate of deletion on request.

We retain your records for the life of your account and a reasonable period afterward to meet Nepali record-keeping norms. On deletion, we crypto-shred your data keys and run a purge of stored files, and can provide a certificate of deletion on request. Backups are retained on a rolling basis and then expire.

10. Your rights

You may access, correct, export, or delete your data, and withdraw any credential or consent, at any time. Email us and we will act promptly. If you believe we have mishandled your data, tell us first - we would rather fix it directly than have you find out any other way.

11. Cookies & analytics

We use essential cookies to keep you signed in and to operate the Service. We keep any analytics privacy-respecting and to a minimum, and we do not use your financial data for tracking or advertising.

12. Changes & contact

We may update this policy as the Service evolves; material changes are communicated to account holders and reflected in the "last updated" date.

Privacy questions, or a request about your data? Email hello@rakamhq.com.