Privacy Policy

Your Privacy is Our Priority

At LaabamOne, we are committed to protecting your personal information and your right to privacy.

Last Updated: September 28, 2026

Introduction

LaabamOne Business Solutions Pvt Ltd ("we", "us", or "our") operates the LaabamOne ERP platform, including our website (laabam.one), web application (laabam.app), and mobile applications available on the Google Play Store and Apple App Store. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services across all platforms.

Google User Data

This section explains how Laabam.One handles information we receive from Google: when you choose "Sign in with Google" in our mobile app, and when you connect a Google account to the web application (laabam.app) to sync your Google Calendar or connect your Gmail inbox. Using Google with Laabam.One is optional, and we receive nothing from your Google account until you choose to and approve Google's consent screen. Where anything elsewhere in this policy differs from this section, this section is what applies to Google user data.

Laabam.One's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

What we access, and why

  • Your Google account email address and name: to sign you in when you choose "Sign in with Google" in our mobile app, to show you which Google account is connected, and to keep each connected account separate.
  • Google Calendar — your primary calendar only: we read the start and end times of your upcoming events that are not marked "Free", so that nobody can book you at a time you are already busy. Depending on the privacy level you choose when connecting, we also store each event's title and location (and, at the fullest level, its description) — or nothing except that the time is busy. We also create, update and remove events on that calendar for the bookings, lessons, meetings and interviews you schedule in Laabam.One, so they appear in your Google Calendar.
  • Gmail — only if you connect Gmail: to show your recent email (the last 7 days, then new mail as it arrives) in the Laabam.One Email Hub; to find bills and receipts sent to you so you can record them as expenses; and to send the emails you choose to send from Laabam.One from your own address. Depending on the privacy level you choose, we read each message's sender, recipients, subject, date and body. To find receipts we search for messages with attachments that look like bills or receipts — up to two years back when you first connect, then new ones as they arrive — and save those attachments to your company's private storage.

How we use it

We use Google user data only to provide and improve the features described above, which you can see and control in the app. We do not use it for any other purpose.

What we never do with Google user data

  • Sell, rent or trade it — to anyone, for any purpose.
  • Use it for advertising, including personalised, retargeted or interest-based ads, or pass it to advertising platforms or data brokers.
  • Use it for marketing or promotional messages, analytics, profiling or research.
  • Use it to determine creditworthiness or for lending purposes.
  • Use it to develop, improve or train generalised artificial intelligence or machine-learning models — ours or anyone else's.

Google user data and AI

Google user data reaches an AI service in one case only: a receipt that arrived by Gmail, when you open it and ask Laabam.One to read it (AI receipt scan, section 3.1). That attachment alone is sent to OpenAI, solely to extract the vendor, date, amounts and tax details and return them to you; under the OpenAI API terms it is not used to train models. Your calendar events and email messages are never sent to an AI service. AI assistant connections (section 3.2) cannot read your email, attachments or calendar events — when an assistant checks booking availability, it receives only free time slots, never the events behind them.

Who we share it with

We do not share Google user data with anyone, except:

  • Service providers that store and process it on our behalf, only to run the features above: our cloud hosting provider (servers and private file storage), and OpenAI for receipts you ask us to read. They may use it only for that purpose and must protect it.
  • The recipients of an email you choose to send through Gmail from Laabam.One.
  • Where required by law, or where necessary to protect against fraud, abuse or security threats.
  • As part of a merger, acquisition or sale of assets — and then only with your explicit prior consent.

Email and calendar data you sync becomes part of your company's Laabam.One workspace: people in your company who have access to the Email Hub, receipts or calendars can see it, according to the roles and permissions your company sets. A record you save from it — such as an expense you create from a receipt — becomes part of your business records and is handled like the rest of them.

Who can read it

Our staff do not read your Google user data unless you ask us to (for example, by sharing a specific message or event with our support team), it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or it has been aggregated and anonymised for internal operations.

How we protect it

The access tokens Google issues to us are encrypted before they are stored. Google user data travels over encrypted connections and is stored in your company's own workspace on our servers, protected by the measures in section 5; receipt attachments are kept in private storage that is not publicly accessible.

How long we keep it, and how to delete it

  • Calendar events you delete or move in Google Calendar are removed or updated in Laabam.One at the next sync.
  • You can disconnect a Google account at any time from the Email Configuration settings or the Calendar Sync page in Laabam.One. We stop reading from and writing to it immediately. What was already synced stays in your company's workspace until you ask us to delete it.
  • You can also remove Laabam.One's access from your Google Account at any time at myaccount.google.com/permissions.
  • To have the Google user data we hold deleted — including stored tokens, synced calendar events, email and saved receipt attachments — email privacy@laabam.one. We delete it within 30 days. Records you saved into your books from it follow section 6.
  • Deleting your Laabam.One account deletes all Google user data we hold (section 10).

1. Information We Collect

1.1 Personal Information

When you register for LaabamOne, we collect:

  • Full name and email address
  • Phone number
  • Company name and business details
  • Billing and payment information
  • Tax identification numbers (GST, PAN)

1.2 Business Data

During your use of our platform, we store:

  • Customer and vendor information
  • Financial records and transactions
  • Employee and payroll data
  • Inventory and product information
  • Invoices, receipts, and documents

1.3 Usage Data

We automatically collect:

  • IP address and device information
  • Browser type and version
  • Pages visited and features used
  • Time spent on the platform
  • Log data and error reports

2. How We Use Your Information

✓

Service Delivery

To provide, maintain, and improve our ERP platform and features

✓

Account Management

To create and manage your account, process payments, and handle subscriptions

✓

Customer Support

To respond to inquiries, provide technical assistance, and resolve issues

✓

Communications

To send service updates, security alerts, and promotional materials (with your consent). Google user data is never used for promotional or marketing messages.

✓

Compliance

To comply with legal obligations, tax regulations, and GST filing requirements

✓

Analytics

To analyze usage patterns and improve our services. Google user data is never used for analytics.

3. How We Share Your Information

Important Note

We DO NOT sell, rent, or trade your personal information to third parties for marketing purposes. Google user data is never sold, rented or traded for any purpose, and is shared only as described under Google User Data above.

We may share data with:

  • Service Providers: Payment processors, cloud hosting providers, and email services that help us operate
  • Government Authorities: When required by law, for GST filing, tax compliance, or legal proceedings
  • Business Transfers: In case of merger, acquisition, or sale of assets (with prior notice; Google user data only with your explicit prior consent)
  • With Your Consent: When you explicitly authorize us to share information

3.1 Artificial Intelligence (AI) Features

These features are off until you allow them. Nothing is sent to an AI service unless you tap "Allow" on the notice that names exactly what will be sent.

Some optional features use AI to read a document or message you choose and fill in a form for you. When you use one, the file or text you picked is uploaded to our server and passed to OpenAI, L.L.C. (United States) — our AI processing provider — which reads it and returns the extracted values to the app.

Which features use AI, and what each one sends:

  • AI Scan on a sales invoice or quote: the image/PDF you pick, including the customer name, address, GSTIN, item lines and amounts printed on it.
  • AI Scan on a purchase bill: the image/PDF you pick, including the vendor name, GSTIN, bill number, item lines and amounts.
  • AI receipt scan on an expense: the receipt image/PDF you pick, including vendor, date, amount, tax and GSTIN.
  • AI bank-statement analysis: the statement file you pick, including every transaction line and the account number, bank, branch and IFSC printed on it.
  • AI replies in Live Chat: the messages you type and any file you attach, plus your company name and the screen you asked from.

We ask permission separately for each of these features, before anything is sent, and the request names the data that feature will send. You can withdraw permission at any time in Settings → AI features & data; the feature then stops sending anything and asks again the next time you use it. If you never use these features, no data is sent to any AI service, and every one of them has a manual alternative.

We do not keep the file or message you picked after the values have been extracted from it. It is held only for as long as that single request takes and is not saved to our servers afterwards; only the extracted values are returned to the app, and they are stored only if you choose to save the form.

OpenAI processes this data as our service provider in order to return the extracted values. Under the OpenAI API terms that govern this use, OpenAI may process the data only to return that result, is required to protect it, and does not use data submitted through the API to train its models. We do not use it for advertising and we do not share it with any other AI service.

3.2 AI Assistant Connections (ChatGPT, Claude and other MCP clients)

Nothing is connected until you authorise it. You sign in, choose exactly one company, and approve — on a screen that names the application asking and the exact address your approval will be sent to.

Separately from the features above, you can connect an outside AI assistant — such as ChatGPT or Claude — so that it can answer questions about one of your companies. This works the opposite way round from 3.1: instead of us sending a document to an AI service, the assistant you chose asks us for figures and we answer. It reaches us over a standard connector interface (the Model Context Protocol) at mcp.laabam.one.

What a connection can and cannot do:

  • Read-only: every operation an assistant can call only reads. None of them creates, edits, deletes, sends a message, or moves money.
  • One connection, one company: the company is fixed at the moment you approve, and cannot be changed afterwards — not by you, not by the assistant, and not by anything written into a conversation with it. To reach a second company you approve a second, separate connection.
  • What it can read: for that one company only — invoices, customers, products, vendors, bank balances, expenses, profit and loss, and receivables. It cannot list or reach your other companies, and it is never given the name of the database your records are held in.
  • Checked on every request: your permission to open that company is re-verified each time the assistant asks, not once when you connected. If you lose access to a company, the connection loses it at the same moment.

The assistant you connect is not our service provider, and this is the part worth reading closely. Whatever it reads is then handled by whoever operates it — OpenAI for ChatGPT, Anthropic for Claude — under their privacy policy and their terms, not ours. Once figures leave us in answer to a question you asked, they can appear in that conversation and be retained by that provider under its own rules, which may differ from ours. Connect only assistants you are content to give that visibility to.

On our side we store the credential the connection uses, which single company it is fixed to, which of your logins approved it, and when. We do not store your conversations with the assistant, the questions it asks us, or the answers we return.

That credential lasts until you revoke it or it expires, whichever comes first. Nothing about the connection survives revocation except the record that it once existed.

You can see every AI assistant you have authorised, across all of your companies, in Settings → Security → AI Connections, and revoke any of them from there. Revoking takes effect immediately rather than waiting for expiry, and the assistant must ask for your approval again before it can read anything further. Removing a person from a company also ends the connections that person authorised for it.

4. Your Privacy Rights

Access

Request a copy of all personal data we hold about you

Correction

Update or correct inaccurate information

Deletion

Request deletion of your personal data (subject to legal requirements)

Restriction

Limit how we use your data in certain situations

To exercise your rights, please contact us at privacy@laabam.one or call +91 73056 41462

5. Data Security

We implement industry-standard security measures to protect your information:

🔒

SSL Encryption

256-bit SSL encryption for data in transit

🛡️

Database Encryption

AES-256 encryption at rest

🔐

Access Control

Role-based access with 2FA

💾

Daily Backups

Automated backups with 30-day retention

🚨

Intrusion Detection

24/7 monitoring and alerts

✅

ISO/IEC 27001:2022 (ISMS/24M04105)

Certified security management

6. Data Retention

We retain your personal and business data for as long as your account is active or as needed to provide services. After account deletion:

  • Personal data is deleted within 30 days
  • Financial records are retained for 7 years (as per GST laws)
  • Backup copies are purged within 90 days
  • Anonymous analytics data may be retained indefinitely (this never includes Google user data)

7. Cookies & Tracking

We use cookies and similar technologies to:

  • Keep you signed in
  • Remember your preferences
  • Analyze site traffic and usage
  • Provide personalized features

You can control cookies through your browser settings. Note that disabling cookies may limit platform functionality.

8. Children's Privacy

LaabamOne is designed for business use and is not intended for children under 18. We do not knowingly collect information from minors. If you believe we have inadvertently collected such data, please contact us immediately.

9. Mobile Application Data

Our mobile applications (available on Google Play Store for Android and Apple App Store for iOS) collect additional data specific to mobile usage. This section details the data we collect, the permissions we request, and the third-party services integrated into our apps.

9.1 Mobile-Specific Data Collection

In addition to the data described above, our mobile apps may collect:

  • Device identifiers (Android Advertising ID, iOS Identifier for Vendors)
  • Device model, operating system version, and app version
  • Push notification tokens for sending alerts and updates
  • App crash reports and diagnostic data for improving stability
  • Local storage data for offline functionality
  • Network connection type and status
  • Approximate or precise location, where you allow it — for field-work features and to record where each sign-in to your account happened. Never collected while the app is closed.
  • Call duration, where you allow call log access (Android, Laabam Connect only) — the length in seconds of a work call you place to a lead from inside the app. Nothing else from your call log is kept.

9.2 App Permissions

Our mobile apps request the following permissions, each for a specific purpose:

📷

Camera

To scan documents, capture receipts, and upload profile photos

📁

Storage / Files

To download invoices, reports, and attachments for offline access

🔔

Push Notifications

To send payment reminders, invoice alerts, and approval notifications

🌐

Internet Access

Required for syncing data with our cloud servers and real-time updates

📍

Location

Optional. Used for field-work features such as recording visits and filling in addresses, and to record where each sign-in happened so an unrecognised sign-in can be spotted. Read only while the app is open — never in the background — and you can refuse without losing access to the app.

📞

Call Log (Android, Laabam Connect only)

Optional. Used only to measure how long a work call lasted. When you place a call to a lead from inside the app, we read the single call log entry for that one call — the number, its duration and when it started — and keep only its length in seconds against that call record. We do not read the rest of your call history, we do not keep the number or start time on your device or our servers, and we never share or sell any of it. You can refuse: calls are then timed by the app itself, which includes ringing time, and you can correct the figure by hand.

9.3 Third-Party SDKs & Services

Our mobile apps integrate the following third-party services, each with their own privacy policies:

  • Firebase (Google) — Push notifications, crash reporting, and analytics
  • Sentry — Error tracking and performance monitoring
  • DigitalOcean Spaces — Secure file storage for documents and attachments
  • Razorpay / Stripe — Payment processing (payment data is handled directly by these providers and never stored on our servers)

9.4 Advertising & Tracking

We do NOT use advertising identifiers to track you across other apps or websites. We do NOT serve targeted advertisements. We do NOT sell your data to advertisers. Our apps do NOT participate in cross-app tracking. On iOS, we comply with Apple's App Tracking Transparency (ATT) framework. We will request your permission before any tracking, which you can decline without affecting core app functionality.

10. Account & Data Deletion

You have the right to delete your account and all associated data at any time. We provide clear and accessible methods for account deletion as required by Google Play Store and Apple App Store policies.

How to Request Account Deletion

  • 1
    Send an email to privacy@laabam.one with the subject "Account Deletion Request"
  • 2
    Include your registered email address and company name for verification
  • 3
    Our team will verify your identity and process the request within 30 days
  • 4
    You will receive a confirmation email once all data has been permanently deleted

Data That Will Be Deleted

  • Your profile information (name, email, phone number, profile photo)
  • Authentication tokens, session data, and push notification tokens
  • Business data including invoices, customers, vendors, and transactions
  • All files and documents uploaded to our platform
  • App preferences and settings

Legal Retention Notice

Certain financial records may be retained for up to 7 years as required by GST laws and regulations (Income Tax Act, GST Act). Anonymized and aggregated analytics data that cannot identify you may be retained. All other personal data will be permanently deleted within 30 days of your request.

11. International Data Transfers

Your data is primarily stored in secure data centers located in India. If we transfer data internationally, we ensure adequate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs)
  • Data Processing Agreements (DPAs)
  • Compliance with GDPR and applicable data protection laws

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or through the platform. Continued use of our services after changes indicates acceptance of the updated policy.

Contact Us

If you have questions or concerns about this Privacy Policy or our data practices:

📍

Address

LaabamOne Business Solutions Pvt Ltd Madurai, Tamil Nadu, India