The short version.
TrackMonez has two parts. Your personal expense tracking data never leaves your phone — we cannot see it, and we cannot recover it if you lose your device. Bill splitting works differently: because it is shared with other people, that data is stored on our servers in Mumbai, India, and is visible to the other members of your group.
We collect your mobile number and a display name. Your email address is optional. We do not show ads, we do not sell your data, we do not read your SMS or email, and we never touch your money.
This Privacy Policy explains how Prasad Simpi, a sole proprietor trading as TrackMonez ("we", "us", "our"), collects, uses, stores, shares and protects your personal data when you use the TrackMonez mobile application (the "App").
We are the Data Fiduciary in respect of the personal data described in this Policy, as that term is defined under India's Digital Personal Data Protection Act, 2023 ("DPDP Act").
The App is offered only in India and only to individuals aged 18 years or above.
| Data Fiduciary | Prasad Simpi (sole proprietor), trading as TrackMonez |
|---|---|
| Address | Block No. 5, Room No. 831, Opposite Malwani Police Station, Malad West, Mumbai – 400095, Maharashtra, India |
| simpiprasad50@gmail.com |
Please read this Policy together with our Terms of Service.
This is the most important section of this Policy. TrackMonez stores two kinds of data in two completely different places.
The transactions, categories, budgets, balances and savings goals you enter for your own use are stored only in local storage on your phone. This data is never transmitted to our servers. We cannot see it, access it, read it or retrieve it.
Because this data never leaves your device:
Keeping your own backups is your responsibility.
Bill splitting necessarily involves sharing information with other people. Data you enter into a shared group — group name, expense amounts, dates, who paid, how it is split, and settlement records — is stored on Google Firebase (Cloud Firestore) infrastructure located in the Mumbai, India region, and is visible to every other member of that group.
Anything you enter into a shared group can be seen by every other member of that group. Please keep this in mind when naming groups.
We collect only what is listed below. We collect nothing else.
| Data | Required? | Why we collect it |
|---|---|---|
| Mobile number | Mandatory | To create your account, verify you by one-time password (OTP), secure your account, and identify you to other members of a bill splitting group |
| Display name or nickname | Mandatory | So other members of a group can recognise who you are. This may be a nickname — it does not have to be your real name |
| OTP verification records and timestamps | Automatic | Account security, preventing fraudulent sign-ins, and confirming account ownership in a dispute |
| Firebase User ID | Automatic | An internal identifier that links your account to your bill splitting records |
| Email address | Optional | Only if you choose to provide it: to help you recover access to your account, to respond to support and grievance requests, and to send you a summary of your spending statistics if you specifically ask us for one |
| Push notification token (FCM) | Automatic | To send you notifications about your groups, such as when someone adds an expense or records a settlement |
We do not collect a profile photo.
| Data | Where it is stored |
|---|---|
| Transaction amount, date, payee and category | Your device only. Never transmitted to us. |
| Budgets, balances and savings goals |
The App does not support free-text notes or descriptions on personal transactions, and does not support attaching photos or receipt images.
| Data | Why we collect it |
|---|---|
| Group name | To identify the group to its members |
| Member list | To show who is in the group and calculate each person's share |
| Expense amounts, dates, who paid, and how the amount is split | To calculate and display who owes what |
| Settlement records | To track whether an amount has been marked as settled |
| Edit history | So members can see what changed in a shared group and when, and to resolve disagreements about entries |
| Invite link tokens and their status | To let you invite people to a group and to expire or revoke invitations |
Bill splitting does not include group chat, comments, or image or receipt attachments.
You add people to a group by sharing an invite link. You choose how to share it — WhatsApp, SMS, email, or any other way. We do not ask you for anyone else's phone number, and we do not read your contacts.
We only receive another person's details when they choose to open the link and join the group, at which point they provide their own mobile number and display name directly to us, and this Policy applies to them.
An invite link acts as a key to the group. Anyone who has the link can join and see that group's expenses. Please share invite links only with people you intend to include.
| Data | Why we collect it | Collected by |
|---|---|---|
| Device model, operating system version, App version | To diagnose crashes and support the App across different devices | Google Firebase Crashlytics / Google Analytics for Firebase |
| Crash reports, error logs and stack traces | To find and fix defects in the App | Google Firebase Crashlytics |
| App opens, screen views and feature usage events | To understand which features are used, so we can improve the App | Google Analytics for Firebase |
| Firebase Installation ID | An identifier the Firebase SDK uses to deliver notifications and attribute crash reports | Google Firebase |
| IP address | Processed transiently to route your request and protect against abuse. We do not store it as part of your profile | Google Firebase |
For the avoidance of doubt, TrackMonez does not:
We process your personal data only for these specific purposes:
We will not use your personal data for any new purpose without telling you and, where required, asking for your fresh consent.
We process your personal data on the basis of the consent you give us, as provided under Section 6 of the DPDP Act. Where the law permits, we may also process data for certain legitimate uses under Section 7 of the DPDP Act, such as complying with a legal obligation or an order of a court or authority.
You give consent separately for:
You can use personal expense tracking without ever using bill splitting. If you never use bill splitting, we hold nothing about you except your account data.
You can withdraw your consent at any time, and it is exactly as easy to withdraw as it was to give. Go to Settings → Privacy → Manage consent in the App, or write to us at simpiprasad50@gmail.com.
If you withdraw consent for bill splitting, we will stop processing that data and delete it as described in Section 8, except where the law requires us to keep it. Withdrawing consent does not affect anything we lawfully did before you withdrew it. Withdrawing consent for a feature will mean that feature stops working. Your expense tracking data on your device is not affected.
We do not sell your personal data, and we do not share it for anyone's marketing.
Data you enter into a shared group is visible to every other member of that group — including your display name, the group name, expense amounts and dates, how expenses are split, settlement records and edit history. This sharing is the entire purpose of the feature and happens at your instruction.
All of our infrastructure is provided by Google. These providers process data on our behalf, under contract, and only on our instructions.
| Service | What it does | What it processes | Where |
|---|---|---|---|
| Firebase Authentication (Phone) | Account creation and OTP sign-in, including delivery of the OTP SMS | Mobile number | Google infrastructure |
| Cloud Firestore | Database for bill splitting and account data | Account data, bill splitting data | Mumbai, India (asia-south1) |
| Cloud Functions for Firebase | Server-side logic supporting the App | Account data, bill splitting data | Google infrastructure |
| Firebase Cloud Messaging | Delivering push notifications | Push token, notification content | Google infrastructure |
| Firebase Crashlytics | Crash and error reporting | Device and diagnostic data | Google infrastructure |
| Google Analytics for Firebase | Anonymous usage analytics | App usage events, device data, installation ID | Google infrastructure |
These services are provided by Google LLC and its affiliates. Their handling of data is also governed by the Firebase Privacy and Security policy and the Google Privacy Policy.
We do not use any third-party support desk, advertising network, or analytics provider other than those listed above.
We may disclose personal data where we are required to by law, or where we believe in good faith that it is necessary to comply with a legal obligation, respond to a lawful request from a court, law enforcement or regulator, enforce our Terms of Service, or protect the rights, safety or property of our users or the public.
If TrackMonez or its assets are acquired by another person or company, your personal data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy, and your rights under the DPDP Act will continue to apply.
Personal expense tracking data is stored only on your device.
Account data and bill splitting data are stored in Cloud Firestore in Google's Mumbai, India region (asia-south1).
Certain supporting Google services — push notification delivery, crash reporting and analytics — may process limited technical data on Google infrastructure outside India. The DPDP Act permits transfers of personal data outside India except to countries the Central Government restricts by notification. Where any data is processed outside India, your rights of access, correction and erasure continue to apply, and any deletion request is applied to all copies of your data.
| Data | How long we keep it |
|---|---|
| Personal expense tracking data | Kept on your device until you delete it or uninstall the App. We never hold it. |
| Account data (mobile number, display name, email if given) | While your account is active, then deleted within 30 days of your deletion request |
| Bill splitting data | While the group exists. On account deletion, see Section 8.1 |
| OTP and authentication logs | 12 months, for security and fraud prevention |
| Crash and diagnostic logs | 90 days |
| Invite link tokens | Until expiry or revocation, plus 30 days |
| Emails you send us | 24 months from the date the matter is closed |
| Records we are required by law to keep | For the period the applicable law requires |
Inactive accounts: if you do not use your account for 24 months, we will attempt to contact you at your registered mobile number and, if you do not respond, delete your account and its data.
Bill splitting records belong jointly to everyone in a group. If we deleted your entries outright, everyone else's balances would become wrong.
So when you delete your account, we remove your personal details — your mobile number, email and display name — and your past entries remain in the group shown as "Deleted user", so that the other members' records and balances stay accurate.
This means the other members of your groups will still be able to see the historical expenses you shared with them, without any information identifying you. This is the same approach used by other bill splitting apps, and it is necessary for the feature to work at all.
Under the DPDP Act you have the following rights. These apply to the data we hold on our servers — the data on your device is already entirely within your control.
| Right | What it means and how to use it |
|---|---|
| Access | To get a summary of the personal data we process about you and what we do with it. Most of it is visible in the App. For a full summary, email us and we will respond within the time in Section 11 |
| Correction | To correct data that is wrong or incomplete. You can edit your account details and your individual entries directly in the App at any time |
| Erasure | To have your data deleted. Use Settings → Account → Delete account in the App, or our account deletion page. Subject to Section 8.1 and to anything the law requires us to keep |
| Grievance redressal | To raise a complaint with us. See Section 11 |
| Nomination | To nominate another person who may exercise your rights on your behalf if you die or become incapacitated. Email us to register a nominee |
| Withdraw consent | At any time — see Section 5.2 |
| Complain to the Board | If you are not satisfied with our response, you may complain to the Data Protection Board of India |
If you want to step away without losing your data, you can deactivate your account instead. Deactivating hides your account and stops notifications, but keeps your data so you can come back. You can reactivate by signing in again, or by emailing us.
If you take no action on a deactivated account for 24 months, we will delete it as described in Section 8.
The App does not currently have a one-tap export feature. If you want a copy of the data we hold about you on our servers, email us and we will send it to you in a machine-readable format within the time in Section 11.
Before we act on a request, we may need to confirm you are who you say you are — usually by sending an OTP to your registered mobile number. This is to make sure we never hand your data to someone else.
We take reasonable security safeguards to protect the personal data in our control, including:
No method of transmission or storage is completely secure and we cannot guarantee absolute security. You are responsible for keeping your device secure, for not sharing your OTP with anyone, and for being careful about who you send invite links to. We will never ask you for your OTP.
If you have any question, concern or complaint about how we handle your data, contact our Grievance Officer:
| Grievance Officer | Prasad Simpi |
|---|---|
| simpiprasad50@gmail.com | |
| Address | Block No. 5, Room No. 831, Opposite Malwani Police Station, Malad West, Mumbai – 400095, Maharashtra, India |
| Response time | We aim to respond within 72 to 120 hours. In every case we will resolve your grievance within the period required by law, and no later than 90 days |
If you are not satisfied with our response, you may complain to the Data Protection Board of India under the DPDP Act.
If a personal data breach affects your data, we will tell you without delay, in plain language — what happened, what data was affected, what we have done about it, and what you can do to protect yourself. We will also report the breach to the Data Protection Board of India and to CERT-In within the timelines required by law.
TrackMonez is not intended for anyone under the age of 18 and we do not knowingly collect the personal data of children. You must be at least 18 to create an account.
If we learn that we have collected data from someone under 18, we will delete it promptly. If you believe a child has provided us with data, please email us at simpiprasad50@gmail.com.
We may update this Policy from time to time. If we make a material change — in particular if we start collecting a new category of data or using it for a new purpose — we will tell you in the App and, where required, ask for your fresh consent before the change takes effect.
The "Last updated" date at the top shows when this Policy was last revised.
This Policy is published in English. TrackMonez is offered only in India. If you would like this Policy in another language listed in the Eighth Schedule to the Constitution of India, email us and we will provide one.
Prasad Simpi, trading as TrackMonez
Block No. 5, Room No. 831, Opposite Malwani Police Station, Malad West, Mumbai – 400095, Maharashtra, India
simpiprasad50@gmail.com