Credit Khata Shared Ledger

Privacy Policy

How Credit Khata handles the information you and your shop put into it.

Last updated 9 September 2026

Credit Khata is a credit-ledger (udhar khata) app for small shops. It is published by Abdohoo, which is the controller of the data described here. Write to support@abdohoo.app with any question about this policy or to exercise any of the rights below.

There are three kinds of user, and what we hold differs for each: a shopkeeper who runs a shop, a customer who keeps a khata with that shop, and a branch login that a shopkeeper issues to whoever runs a branch.

What we collect

Account information

Shop content you upload

Ledger information

Information a shopkeeper records about their customers

This is worth stating plainly. A shopkeeper enters their customers' details — name, and optionally phone, WhatsApp, address, city and notes — along with what each customer owes. Much of that is entered by the shopkeeper, not by the customer. The shopkeeper is responsible for having a proper basis to record it; we process it on their behalf so their shop works. A customer who has been given a sign-in can see their own khata in the app.

Device and technical information

We do not collect your location, your contacts, your photos beyond the shop images you choose to upload, your calendar, your microphone, or any advertising identifier. There are no advertising SDKs anywhere, and the Android app carries no analytics SDK at all. Our web pages count visits with a cookieless beacon, described under Website analytics below. We do not sell your information, and we do not use it to build advertising profiles.

Camera

The app asks for camera access for one purpose: scanning a QR code to sign a customer in. Frames are read on your device to decode the code. No image is stored and none is uploaded. You can decline, and sign in with a typed code or an email and password instead.

Website analytics

Our web pages — the site at duk.abdohoo.app, the counter app and the customer app — count visits using Cloudflare Web Analytics. It is measurement, not tracking: it sets no cookies, stores nothing on your device, uses no fingerprinting, and cannot follow you to anyone else's website. What reaches Cloudflare is the address of the page you are on, the address you arrived from, your browser and device type, your country, and how long the page took to load. Cloudflare states that it does not use your IP address, your user-agent string or anything else to fingerprint or identify you as an individual; these signals are counted, not attached to a person.

Two limits are built in. Pages whose address carries a one-time link — a password reset, an account-deletion confirmation — are never measured, because the beacon would report that address. And the Android app is not measured at all: the beacon is browser code and the app has no place to run it.

Analytics can be switched off for the whole platform, or for any one of those surfaces, from the site owner's settings; when it is off, nothing is loaded and no request is made to Cloudflare. If your browser sends a “Do Not Track” or Global Privacy Control signal and the operator has chosen to honour it, you are not counted either.

Who we share it with

We share only what a specific function requires:

ServiceWhat reaches themWhy
Google Firebase Cloud Messaging A device push token and the alert text To deliver notifications about your khata
Cloudflare Web Analytics The address of the page you are viewing, the page you came from, your browser and device type, and your country To count visits to our web pages, without cookies
Cloudflare Turnstile Signals from your browser or device during a sign-in challenge To tell people from automated abuse
An AI provider, where the shop has the writing assistant enabled The item text being typed, plus the shop's country, city and business type To suggest an item description

The writing assistant is off unless it has been configured, and no customer name or ledger balance is sent to it. We also disclose information where the law requires it.

How it is protected

All traffic between the apps and our servers uses HTTPS. Passwords are hashed. Sign-in tokens are stored per device and can be revoked individually. The app does not include its local data in Android backups or in a phone-to-phone transfer, so a copy of your ledger does not travel to a new device without a fresh sign-in.

How long we keep it

Deleting your account

You can delete your account from inside the app, or without the app at https://duk.abdohoo.app/legal/delete-account. What happens depends on which kind of account it is.

If you are a shopkeeper

Your account stops working immediately and a 30-day countdown begins, so that an accidental deletion is recoverable. When it expires we permanently erase your account, your shops, the customers recorded under them, every ledger entry, and the logo and banner images you uploaded. Customers who hold their own sign-in for your shop are told, and their accounts and khatas are erased at the same time — a khata has no meaning once the shop is gone. To stop the deletion, sign in again during the countdown and cancel it.

If you are a customer

Your sign-in is deleted straight away: your email address, password, push registrations and any outstanding login codes are removed, and you can no longer open your khata in the app.

The shop keeps its own record of what you owe or have paid. That record is the shopkeeper's business account of trade with you, in the same way a paper ledger would be, and deleting your app account does not settle or erase a debt. If you want the shop to remove its record of you, ask the shop directly.

If you hold a branch login

The credential your shopkeeper issued is deleted. The branch, its customers and its trade belong to the shop and are unaffected.

Your rights

You can ask us to give you a copy of your information, correct it, or delete it. Shopkeepers can edit most of their own and their customers' details directly in the app, and export their customer list. For anything else, write to support@abdohoo.app and we will respond within 30 days. Depending on where you live you may also have the right to complain to a data protection authority.

Children

The app is for people running or trading with a business and is not directed at children. We do not knowingly create accounts for under-18s. If you believe a child has an account, write to us and we will remove it.

Where your information is held

Our servers and the services listed above may process your information in countries other than your own, including where Google and Cloudflare operate. We use these services under their standard terms for the purposes described here.

Changes

If this policy changes materially we will update the date at the top and, where the change affects how your information is used, tell you in the app.