Privacy
Privacy Policy
Effective 1 Aswin 2083 BS (2026-09-17 AD)
1. Who runs XoraPro
XoraPro is built and run by M/s N.P. Xora Private Limited, a company registered in Nepal.
- Company Registration Number: 387740/82/83
- PAN: 623570591
- Registered address: Ward No. 3, Samakhusi, Kathmandu Metropolitan City, Nepal
- Email: support@xorapro.com
- Phone: +977 9766007553
This policy covers the XoraPro mobile app, the website at xorapro.com, and every screen you reach after signing in.
2. Two kinds of data, two different duties
This is the most important section. Read it first.
XoraPro holds two different kinds of information, and our duty is different for each.
The first is information about you and your business, because you are our customer. You gave it to us when you opened your account and while you paid for the service. We decide how that information is used, so the responsibility for it is ours.
The second is everything your business types into XoraPro about other people. Your customers, your staff, your suppliers. Their names, their phone numbers, what they owe you, what you pay them. That information belongs to your business, not to us. You decide what goes in, who in your team can see it, and when it comes out. We hold it and process it only on your instruction.
Your customer is not our user. We do not contact the people in your khata for our own purposes. We do not sell their details. We do not use one business's records to serve another business.
In legal language, we are the controller of the first kind and the processor of the second kind. In plain language: your books are your books.
If you are a customer, a staff member or a supplier of a business that uses XoraPro, section 13 is written for you.
3. What we hold about you as an account holder
When you open and run a XoraPro account, we hold:
- Your name, mobile number and email address.
- Your business name, PAN or VAT number, address and business type.
- The passkey, sign-in code or password you use to get in, plus which devices you marked as trusted and for how long.
- Your role in the business and which screens your role can open.
- Sign-in records: date, time, device and IP address. We keep these so you can see who opened your books and when.
- What you pay us, when the subscription renews, and which plan you are on.
- Messages you send us for support.
4. What your business puts in about other people
This is your data. We list it here so you can see what sits on our servers under your account. Which of these apply depends on the features your business turns on.
- Accounting and invoicing. IRD-format invoices, VAT figures, TDS deductions, journal entries, credit and debit notes.
- Parties. Names, phone numbers, addresses and PAN numbers of the customers and suppliers you trade with.
- Khata. What each party owes you, what you owe them, and every entry that made up the balance.
- Payroll. Staff names, salary figures, allowances, tax deductions, advances (peshki) and repayments.
- Staff records. Contact details, role, joining date, attendance and leave.
- Worksite clock-in. The GPS position of a staff phone at the moment they scan the QR to clock in or out, how far that was from the worksite, and the time. At a shared kiosk device, a selfie photo taken at the punch and whether the PIN matched.
- Inventory and POS. Products, batches, stock counts, sales, discounts and refunds.
- Deliveries. Runs, stops, what was handed over, and photos of the handover.
- Calendar and bookings. Appointments, customer bookings and reminders.
- Messaging. Chats between your business and your customers, including voice messages, attachments and calls placed inside the app.
- XoraPro Find. If you list your business as a service provider, your trade, service area and the job requests you receive.
- Schools. If you run a school: student names, dates of birth, guardian contacts, daily attendance, exam marks, fee schedules and payment status.
- Pharmacies. If you run a pharmacy: patient name, the prescriber's name and registration number, the drug, batch and quantity dispensed, and a photograph of the paper prescription. The dispensing register is kept as an unbroken chain by law and cannot be deleted.
- Hotels. If you run a hotel: guest name, phone, nationality, identity document type and number, address, stay dates, rate and deposit.
- Photos and files. Receipt photos, batch photos, product images, your logo and anything else uploaded into a record.
5. What the app asks for on your phone
XoraPro asks for these only when a feature needs them. You can refuse any of them and the rest of the app keeps working.
- Location. Asked only when a staff member scans the QR to clock in or out at a worksite. We take the position at that moment, work out the distance from the worksite, and store both. We do not track anyone in the background, and we do not follow a phone between punches. If a staff member refuses location, the punch is still recorded with no position attached.
- Camera. For scanning QR codes, photographing receipts, batches, products and delivery handovers, taking the kiosk clock-in selfie, and video calls.
- Microphone. For voice messages in chat and for voice and video calls.
- Screen sharing. Only during a call, and only when someone starts it.
- Notifications. To send reminders, payment alerts and chat messages.
We do not read your contacts, your SMS inbox, your call log, or the other files on your phone.
6. What we never do
- We do not sell your data, or your customers' data, to anyone.
- We do not share it with advertisers, and there is no advertising or ad-tracking code in the app.
- We do not build profiles of your customers for our own use.
- We do not look at one business's books to help another business.
- We do not read your records except when you ask us for support and we need to see the screen you are stuck on, or when the law requires it.
7. Who else touches the data
We keep this list short on purpose. These are the only outside companies involved in running XoraPro, and each one gets only what it needs to do its job.
- Ncell Axiata Limited. Runs our server in its data centre in Pokhara, Nepal. All of your data sits here.
- Cloudflare. Stores our backups. They are encrypted on our server in Nepal before they leave it, so Cloudflare cannot read your records.
- Fly.io, in Singapore. Ran our servers and database until 17 September 2026. A frozen copy of the data as it stood that day stays there until we delete it at the end of September 2026.
- Resend. Sends sign-in links, codes and system emails. Gets the email address and the message.
- Apple Push Notification service and Google Firebase Cloud Messaging. Deliver push notifications to your phone. They get the notification and a device token, not your records.
- Anthropic. Only when someone uses the Xora AI assistant. See section 15.
- eSewa and Khalti. Only when your business connects one of them to collect payment on an invoice. See section 14.
- Sparrow SMS. Only when your business sends a receipt, a reminder or a guest message by SMS. It gets the mobile number and the text of that message.
- The call relay servers. Only when a voice or video call is placed inside the app. They receive IP addresses, call timing and duration, and pass through encrypted audio and video that they cannot themselves read.
- The Inland Revenue Department's CBMS. Only if your business switches on electronic billing itself. When it is on, the buyer's name and PAN go to the Department with each invoice. Nothing is sent until you turn it on.
If we ever add another company to this list, we will update this policy and tell account holders before it starts.
8. Where the data is kept
From 17 September 2026, XoraPro's servers and database run in Nepal, in Ncell's data centre in Pokhara. Your records are stored there. Our backups are encrypted on that server and kept with Cloudflare, outside Nepal, and cannot be read without keys that only we hold.
We tell you this plainly because it matters. Nepal's Electronic Billing Procedure 2082 requires billing software's server and database to be inside Nepal, which is why we moved. Until we delete it at the end of September 2026, a frozen copy of the data as it stood on 17 September 2026 remains with Fly.io in Singapore.
Your data does not stop being yours because of where the machine sits. The duties in this policy apply wherever it is stored.
9. How we protect it
- Everything travels over an encrypted connection. Nothing about your business moves in plain text.
- Every business record carries the business id, and every request checks the signed-in person's membership of that business before reading or writing it.
- You can sign in with a passkey or a one-time code instead of a password. Two-step sign-in is available and we recommend it for the owner account.
- Payment gateway secrets are stored encrypted, not in readable form.
- Each person is invited with a role. Only an owner, the payroll role, your accountant liaison, or your accounting firm's owner or admin can run payroll, set pay, or change payment settings.
- Actions that touch money leave an audit trail showing who did it and when.
- Access to production systems is limited to the people who run XoraPro, and every such access is logged.
No system is perfectly safe. If a breach happens that puts your data at risk, we will tell affected account holders and explain what was involved and what we did about it.
10. How long we keep it
Nepali tax law fixes most of this for us, not the other way round.
- VAT records. A registered person must safely retain the records kept under the VAT Rules for six years. That is Rule 23(7) of the Value Added Tax Rules 2053, under section 16(4) of the Value Added Tax Act 2052.
- Income tax documents. Documents supporting a tax return must be retained for five years from the end of the income year concerned. That is section 81(2) of the Income Tax Act 2058.
- Everything else. Data that is not part of your books, such as sign-in logs and support messages, is kept while your account is open and removed within twelve months after you close it.
So if you close your XoraPro account, we still hold your invoices, VAT records and supporting documents for as long as the two laws above require. We hold them only to meet that obligation and to answer a lawful demand. We do not keep using them for anything else.
11. Why records cannot simply be deleted
You will notice that XoraPro will not let you delete a posted invoice, a stock movement or a khata entry. It lets you reverse it instead, and both the original and the correction stay on the screen.
This is deliberate. The Procedure Related to Computerized Invoicing 2072 requires that data once entered into the database cannot be deleted, that corrections are recorded rather than erased, and that every entry carries the user, date and time. Software that allows hard deletes cannot be certified by the Inland Revenue Department.
It also protects you. If a figure is questioned two years from now, the trail shows what happened and who changed it.
Drafts and things that never touched your books can be deleted normally.
12. Closing your account and taking your data out
Your books are yours and you can take them with you.
- Export. You can export your invoices, ledgers, party balances, payroll and inventory from inside the app at any time, in a form your accountant can open.
- Correct. You can correct anything about you or your business from your settings. Posted entries are corrected by reversal, as explained in section 11.
- Close. How to close the account, and exactly what happens afterwards, is set out in full on the account deletion page.
- After closing. We remove sign-in logs, support messages and everything not covered by section 10 within twelve months. Accounting records stay for the statutory period in section 10 and nothing else is done with them.
Export your data before you close the account. It is easier than asking for it afterwards.
13. If you are a customer, a staff member or a supplier of a business that uses XoraPro
This section is for you, not for the shop owner.
Your name, your phone number, what you owe, your salary, your clock-in location: the business you deal with put those into XoraPro. That business decides what is held about you and for how long. We only keep it for them, on their instruction. We cannot change or remove it on our own.
So if you want to see what is held about you, get it corrected, or ask why something is recorded, go to the business first. They can do it straight away from their own screen.
If you have gone to the business and got nowhere, write to us at support@xorapro.com. We will pass it to them and tell you that we have. If what you are describing looks like misuse of the system, we will look into it.
Your rights under the Individual Privacy Act 2075 are against whoever holds your information. In most cases here, that is the business, not us.
14. Payments
Two different things happen here, and it is worth separating them.
Money your customers pay you. If your business connects eSewa or Khalti, the customer pays on that provider's own page and the money settles into your account with that provider. XoraPro never holds the funds. We store your merchant code and an encrypted secret so we can match the payment to the right invoice, plus the reference number the provider returns. We never see or store a card number, a wallet PIN or a bank password.
When you record a payment as Fonepay QR, bank transfer or cash, that is a note you are making in your own book. XoraPro is not connected to those rails and no data goes to them.
Money you pay us. For your XoraPro subscription we keep what you paid, when, and the reference for it. Payment is handled by the provider, not by us.
15. Xora AI
Xora AI is the assistant inside XoraPro that answers questions about your own numbers.
When you ask it something, we send your question and the business figures needed to answer it, such as balances, deadlines or a report total, to Anthropic, which runs the model. Anthropic processes the request and returns the answer. Your conversations are stored in your account so you can look back at them.
Only your own business data is sent, and only for the question you asked. The assistant cannot reach another business's records. It is not trained on your books.
If you would rather not use it, do not open it. Nothing is sent to Anthropic unless you ask the assistant something.
16. When we must hand data to the authorities
We give data to a government body only when the law requires it. In practice that means:
- A written demand from an authorised official in the course of investigating or prosecuting an offence, or an order of a court. The Individual Privacy Act 2075 allows disclosure in those circumstances at sections 10(4), 12(5) and 26(1).
- A demand from the Inland Revenue Department in relation to your tax records. Note that section 16(1a) of the Value Added Tax Act 2052 gives the Department continuous access to the computer database of taxpayers. That is a duty that sits on you as a taxpayer, and it is one reason your records cannot be deleted at will.
We will tell you if your data is demanded, unless the law forbids us from telling you.
We do not hand over anything on an informal request. If someone asks without lawful authority, the answer is no.
17. Children
XoraPro is a tool for running a business. It is not meant for children and we do not knowingly open accounts for anyone under 18.
Schools using XoraPro do hold student records, including names and guardian contact details. That data belongs to the school. The school decides what is held and is answerable for it. Under section 33 of the Individual Privacy Act 2075, consent for a person under 18 is given by the guardian.
18. Your rights under Nepal law
The Individual Privacy Act 2075 is the main law here. The parts that bear on what we do:
- Sections 12(2) and 12(3). Personal and family data may be collected only with consent, and data collected by a body corporate with consent may be used only for the purpose it was collected for. That is why we do not repurpose your books.
- Section 12(4). Details of health, property and income, employment, family matters, biometrics, signature, political affiliation and business or transactions may not be given to anyone else or published without consent. Most of what XoraPro holds falls under this.
- Section 10(3). A body corporate holding details of a person's property must not disclose or publish them without that person's consent.
- Section 26(1). Personal information under the control of a public body or body corporate may not be used or given out without consent, apart from the listed exceptions.
- Section 29(2). An offence under the Act carries imprisonment up to three years, a fine up to thirty thousand rupees, or both.
- Section 30(2). A complaint goes to the concerned District Court, and it must be filed within three months of the act complained of.
- Section 31. The District Court may order compensation for damage or loss.
The Individual Privacy Rules 2077 sit under the Act. The Electronic Transactions Act 2063 also applies: unauthorised access to a computer system is an offence under section 45, and disclosing material obtained in confidence in the course of duty is an offence under section 48.
Nepal has no data protection authority and no regulator to complain to. Complaints go to the District Court. Come to us first and we will try to fix it without that.
19. Changes to this policy
When we change this policy we will change the date at the top. If the change affects what we do with your data, we will tell account holders by email and inside the app before it takes effect.
Old versions are available on request from support@xorapro.com.
20. Contact us
Ask us anything about this policy, or about what we hold.
- M/s N.P. Xora Private Limited
- Ward No. 3, Samakhusi, Kathmandu Metropolitan City, Nepal
- support@xorapro.com
- +977 9766007553
Write in Nepali or English. We reply in whichever you used.