Skip to main content
Legal

Privacy Policy

Effective 21 April 2026 Last updated 21 April 2026 Terms of Service

This Privacy Policy explains how MyVyay Technologies Pvt. Ltd. ("MyVyay", "we", "us", or "our") collects, uses, shares, and protects personal information when you use the MyVyay mobile application (the "App"), available on the Google Play Store and Apple App Store (Android package com.myvyay and the equivalent iOS bundle).

Please read this policy carefully. By installing or using MyVyay, you confirm that you have read and understood this policy.

1. About MyVyay

MyVyay is a business-to-business (B2B) expense management, travel, and petty-cash management platform. The App is distributed to employees, managers, approvers, and administrators of organisations ("Customers") that have subscribed to the MyVyay service. Your employer (the "Customer") is the controller of most personal data processed through the App; MyVyay acts as a processor on your employer's behalf for that data, and as an independent controller for certain operational data described below.

2. Information We Collect

We collect the following categories of information:

2.1 Information you provide directly

  • Account information — full name, work email address, employee ID, role, department, reporting manager, grade, and any profile photo you upload.
  • Contact information — mobile phone number.
  • Financial information — bank account number, bank name, IFSC code, prepaid card number and card type (where applicable) used for reimbursements and disbursements.
  • Expense data — merchant/vendor name, amount, currency, date, category, GL code, cost centre, justification, tax details (GSTIN, tax amount, tax rate, invoice number), and payment method.
  • Receipts and attachments — photographs, scans, and other files you upload as proof of expense.
  • Travel data — origin and destination, travel dates, purpose of travel, booking preferences, and related itinerary information.
  • Petty-cash data — fund requests, settlements, reconciliation entries, advance requests, and voucher information.
  • Approval and comment data — approvals, rejections, and comments you submit as an approver or requester.
  • Authentication data — login credentials, one-time passwords (OTPs), app passcode, and SSO tokens (e.g., Google SSO).

2.2 Information we collect automatically

  • Device information — device model, operating system and version, unique device identifiers, language settings, time zone, and network type.
  • Usage information — screens viewed, actions taken within the App, feature usage, crash reports, and performance diagnostics.
  • Log data — IP address, access timestamps, API request details, and error logs.
  • Push notification tokens — FCM (Android) or APNs (iOS) tokens used to deliver notifications about approvals, comments, and other events.

2.3 Information from third parties

  • Employer-provided data — your employer may upload or synchronise employee records, approval hierarchies, grades, department codes, and policies.
  • Authentication providers — if you sign in via Google SSO, Google shares your name, email, and profile picture with us.

2.4 Information we do not collect

We do not collect precise location data. We do not access your contacts, calendar, SMS, or call logs. We do not use advertising identifiers and do not serve third-party advertising inside the App.

3. Permissions We Request

MyVyay requests only the permissions required to provide its core features:

Permission Purpose When requested
Camera Capture receipt photographs for expense submission and AI-assisted extraction. When you tap "Camera" or "Scan Receipt" on the expense screen.
Photo Library / Storage Select existing receipt images from your gallery. When you tap "Gallery" on the expense screen.
Internet / Network access Communicate with MyVyay servers to sync data. Always (required for the App to function).
Notifications Deliver in-app alerts for approvals, comments, and policy events. On first launch (iOS) or first notification trigger.

You may revoke these permissions at any time via your device's system settings. Revoking required permissions may prevent you from using the related feature.

4. How We Use Your Information

We use your information to:

  • Provide the core expense, travel, petty-cash, and approval features of the App to you and your employer.
  • Authenticate you, keep your session secure, and prevent unauthorised access.
  • Extract structured data from receipt images using AI-assisted optical character recognition ("OCR") — see Section 6.
  • Enforce your employer's policies (e.g., spend limits, category restrictions, approval workflows).
  • Send you transactional notifications (approvals required, approvals granted, policy violations, payment status, etc.).
  • Monitor, debug, and improve the App's performance, reliability, and security.
  • Detect and prevent fraud, abuse, and policy violations.
  • Comply with our legal, tax, audit, and regulatory obligations.
  • Communicate with you about important service changes or security incidents.

We rely on the following lawful bases under the India DPDP Act 2023, GDPR, and analogous laws: (a) performance of a contract with your employer that benefits you, (b) your consent where required, (c) our legitimate interests in securing and improving the service, and (d) compliance with legal obligations.

5. How We Share Your Information

We share personal information only as follows:

  • With your employer (the Customer) — including authorised administrators, approvers, finance, and audit personnel who have a legitimate need to view your expenses, trips, advances, and profile data within the scope of their role.
  • With sub-processors and service providers — cloud hosting (Amazon Web Services, Mumbai region), email/notification providers, AI/OCR providers (see Section 6), crash-reporting and analytics providers, and support tools. Each is bound by contract to process data only on our instructions and to implement adequate security measures.
  • For legal reasons — to comply with a valid legal request, court order, or law-enforcement demand; to protect the rights, property, or safety of MyVyay, our Customers, or any person; or to investigate fraud or security incidents.
  • In a corporate transaction — in connection with a merger, acquisition, reorganisation, or sale of assets, subject to standard confidentiality protections.

We do not sell your personal information. We do not share your personal information with advertisers or data brokers.

6. AI and Automated Processing

MyVyay uses AI-assisted features, including:

  • Receipt OCR — when you scan or upload a receipt, the image is transmitted to our servers and processed by a large-language-model-based OCR service (currently Google Gemini) to extract merchant, amount, date, category, tax, and invoice fields. The image and extraction results are stored on our servers and associated with your expense record.
  • Spend analytics and insights — aggregated spend patterns may be analysed to surface budget insights and policy anomalies to you and your employer.
  • Speech-to-text (if enabled) — voice input may be transcribed via a third-party speech-to-text service.

These features are automated but do not produce legal or similarly significant decisions about you without human review (e.g., a human approver still reviews every expense before reimbursement). Where required by law, you have the right to request human intervention or to contest automated outputs.

7. Data Retention

We retain personal data for as long as:

  • your account is active with your employer; and
  • required to provide the service, comply with our contractual obligations to your employer, or meet applicable legal, tax, and audit retention requirements (typically 7 years for financial records under Indian law).

When your employment with the Customer ends, or when the Customer terminates its subscription, we will delete or anonymise your personal data in accordance with the Customer's instructions and our data-retention policy, subject to applicable legal hold requirements.

Receipt images associated with closed expense reports are retained for the same duration as the expense record.

8. Data Security

We implement administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including:

  • Encryption in transit (TLS 1.2+).
  • Encrypted storage for sensitive fields (bank details, authentication tokens).
  • Role-based access controls and tenant isolation within the multi-tenant architecture.
  • JWT-based session authentication with short-lived access tokens and rotating refresh tokens.
  • Security logging, monitoring, and periodic vulnerability assessments.

No method of transmission or storage is 100% secure. If we become aware of a security incident that affects your personal data, we will notify you and the appropriate regulator as required by law.

9. International Data Transfers

Your data is primarily stored and processed in India (Amazon Web Services, Mumbai region). Some sub-processors (e.g., AI/OCR providers) may process data in other jurisdictions, including the United States and the European Union. Where required, we use standard contractual clauses or other lawful transfer mechanisms.

10. Your Rights

Subject to applicable law (including the India DPDP Act 2023, GDPR for EU/UK residents, and CCPA/CPRA for California residents), you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data (you can directly edit your profile in the App).
  • Delete your personal data, subject to legal retention requirements.
  • Object to or restrict certain processing.
  • Withdraw consent at any time, where processing is based on consent.
  • Data portability — receive your data in a structured, machine-readable format.
  • Lodge a complaint with a supervisory authority, such as the Data Protection Board of India.

Because your employer controls most of the data in the App, please first contact your employer's administrator to exercise these rights. If your employer cannot assist, contact us at the address in Section 14, and we will work with your employer to respond within the timelines set by applicable law.

11. Children's Privacy

MyVyay is a workplace application and is not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us and we will delete it.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by in-app notice, email, or by updating the "Last Updated" date at the top of this policy. Your continued use of the App after the effective date of the change constitutes acceptance of the updated policy.

14. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, contact:

MyVyay Technologies Pvt. Ltd.
Attention
Data Protection Officer
Registered address
715 Global Business Hub, Kharadi, Pune, Maharashtra 411014

For Customers (employers): if you are an administrator with questions about your tenant's data processing agreement, please contact your account manager at MyVyay.

15. Grievance Officer (India — DPDP Act 2023)

In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000:

Designation
Grievance Officer
Response time
within 30 days of receipt of a complaint

Questions about this document? Contact our team — we respond within two business days.