Legal

Privacy Policy

Electricity bills are personal records. This policy sets out exactly what we hold, why, for how long, and what you can ask us to do about it.

Last updated 20 July 2026

01

Who this covers

This policy explains how LiteBill handles information belonging to two groups: our clients (organisations using the platform) and the account holders whose electricity connections our clients are authorized to submit.

Our role
For bill data we act as a processor: we process connections on our client’s documented instructions, under the authorization the account holder gave. For our client’s own account and billing details, we act as a controller.
02

What we collect

Client account data:

  • Organisation code and name, contact name, username, email address and mobile number.
  • Authentication data — password hashes, session tokens, login timestamps and IP addresses.
  • Support tickets, messages and any attachments you send us.
  • Billing and plan details.

Connection and bill data, for authorized connections only:

  • Connection identifiers — consumer/account number, site identifier, DISCOM, region and connection type.
  • Portal credentials where the portal requires a login, supplied under the account holder's authorization.
  • The bill document itself, and the fields extracted from it — amounts, units, meter readings, dates, sanctioned load, address and similar billing fields.
  • Processing metadata — retrieval timestamps, pipeline stage, validation outcomes and error logs.
03

Why we hold it

  • To retrieve, read, validate and deliver bills for connections that have a valid authorization.
  • To show, if asked, the basis on which any given bill was accessed.
  • To operate accounts, authenticate users and provide support.
  • To secure the platform — detecting misuse, abuse and unauthorized access attempts.
  • To meet legal, tax and accounting obligations.
04

How credentials are protected

  • Portal credentials are encrypted at rest and are not displayed back in the client portal once submitted.
  • They are used only to fetch bills for the connection they belong to — never for payments, profile edits or other portal actions.
  • They are never shared between clients and are never sold or disclosed to third parties.
  • When an authorization is withdrawn, the credentials are removed from active processing.
  • Passwords for LiteBill accounts are stored only as salted hashes; we cannot read them.
05

Who we share with

We do not sell data
We never sell bills, extracted bill data, consumer information or credentials. We do not use them to build marketing lists or to profile individuals.

We disclose data only to:

  • The client that submitted the connection, and the destination systems that client nominates.
  • Infrastructure providers who host and run the platform under contract, bound to confidentiality and processing only on our instructions.
  • Professional advisers, where necessary and under a duty of confidence.
  • Authorities, where we are legally compelled — and we tell the affected client unless we are prohibited from doing so.
06

How long we keep it

  • Bill documents and extracted data: for the term of the client's agreement, and up to 30 days after termination to allow export.
  • Portal credentials: until the authorization is withdrawn or the connection is removed.
  • Authorization audit records: retained after a connection ends, because we must be able to evidence the basis for past access.
  • Account, billing and tax records: for the period required by applicable law.
  • Operational logs: on a rolling short-term window, then deleted or aggregated.
07

Your rights

Account holders and client users can ask us to confirm what we hold, correct it, stop processing it, or delete it. Where a request concerns a connection submitted by a client, we coordinate with that client — but an account holder can always come to us directly.

  • Ask whether a connection is registered and who registered it.
  • Ask us to stop retrieval for a connection.
  • Ask for a copy of the data we hold about a connection.
  • Report a connection registered without permission — we treat these as urgent and suspend processing while we investigate.
How to ask
Write to privacy@litebill.in. We acknowledge requests promptly and aim to resolve them within 30 days.
08

Security and changes

We use encryption in transit and at rest, least-privilege access, isolated per-client data scoping and audit logging. More detail is on our security page. No system is perfectly secure, but we design so that a single failure does not expose bulk data.

We update this policy as the Service evolves and will give reasonable notice of material changes. Questions go to privacy@litebill.in.

Questions about this page?

Our team answers policy and compliance questions directly.

Contact us