Legal

Privacy Policy

Last updated: January 1, 2025

Summary: ClearTax collects only the information necessary to provide our tax filing services. We never sell your data. You can request deletion of your data at any time. We use bank-grade encryption to protect your information.

1. Information We Collect

We collect the following types of information to provide our tax filing services:

<strong>Personal Information:</strong> Name, email address, mobile number, PAN card number, Aadhaar number (last 4 digits only), date of birth.

<strong>Financial Information:</strong> Income details, Form 16 data, bank account information, investment details, capital gains information — all provided by you for the purpose of ITR filing.

<strong>Usage Data:</strong> Device information, IP address, browser type, pages visited, and time spent on our platform to improve user experience.

<strong>Documents:</strong> Tax documents you voluntarily upload to our platform for filing purposes.

2. How We Use It

We use your information exclusively to:

• Provide ITR filing and tax advisory services
• Process payments securely
• Send you OTP for authentication
• Communicate about your filing status, queries, and account
• Send filing deadline reminders
• Comply with legal and regulatory requirements
• Improve our platform and services

We do <strong>not</strong> use your financial data for any purpose other than providing the services you requested.

3. Data Sharing

We do not sell, rent, or trade your personal information.

We share data only with:

<strong>Service Providers:</strong> Payment gateways (Razorpay, PhonePe), SMS providers (MSG91), cloud storage, and email service providers — only for the purpose of providing our services.

<strong>Legal Authorities:</strong> When required by law, court order, or government directive.

<strong>Income Tax Department:</strong> Your ITR data is submitted to the Income Tax Department of India as part of our filing service — which is the primary purpose of our platform.

All third-party service providers are contractually bound to maintain confidentiality.

4. Data Security

We implement industry-standard security measures:

• 256-bit SSL/TLS encryption for all data in transit
• AES-256 encryption for sensitive data at rest
• ISO 27001 certified infrastructure
• Regular security audits and penetration testing
• Multi-factor authentication for admin access
• Automated threat detection and monitoring
• Document password protection (optional, user-controlled)

In the unlikely event of a data breach, we will notify affected users within 72 hours as required by applicable law.

5. Your Rights

You have the following rights regarding your personal data:

<strong>Access:</strong> Request a copy of all personal data we hold about you.

<strong>Correction:</strong> Request correction of inaccurate personal data.

<strong>Deletion:</strong> Request deletion of your account and all associated data (subject to legal retention requirements — typically 7 years for tax records).

<strong>Portability:</strong> Request your data in a machine-readable format.

<strong>Withdrawal of Consent:</strong> Withdraw consent for data processing at any time (this may affect our ability to provide services).

To exercise any of these rights, email privacy@cleartax.in or write to us at our registered office.

6. Cookies

We use the following types of cookies:

<strong>Essential Cookies:</strong> Required for the platform to function (login sessions, security). Cannot be disabled.

<strong>Analytics Cookies:</strong> Help us understand how users interact with our platform (Google Analytics). Can be disabled.

<strong>Preference Cookies:</strong> Remember your settings and preferences. Can be disabled.

You can manage cookie preferences in your browser settings. Disabling non-essential cookies will not affect core functionality.

7. Children's Privacy

ClearTax is not intended for children under the age of 18. We do not knowingly collect personal information from minors.

If you believe a minor has provided us with personal information, please contact us at privacy@cleartax.in and we will delete such information promptly.

Minors who are dependents can be included in a parent's/guardian's ITR filing, but the account must be held by an adult.

8. Changes to Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or for other reasons.

We will notify you of material changes by:
• Email notification to your registered email
• Prominent notice on our website
• In-app notification

Your continued use of ClearTax after such notice constitutes acceptance of the updated policy. If you do not agree, please discontinue use and contact us to delete your account.

9. Contact Us

For privacy-related queries, concerns, or requests:

<strong>Privacy Officer:</strong> privacy@cleartax.in

<strong>Postal Address:</strong>
Defmacro Software Private Limited
6th Floor, Tower D, IBC Knowledge Park
Bannerghatta Road, Bengaluru – 560029
Karnataka, India

<strong>Grievance Officer:</strong> grievance@cleartax.in
(As required under IT Act 2000 and IT Rules 2011)

Response time: Within 30 days of receiving your request.