Legal
Privacy policy
Last updated 23 August 2026
This policy explains what MyCA collects, why, and what you can ask us to do about it.
What we collect
- Account details — name, email, mobile number, and a hashed password. Passwords are never stored in readable form.
- Business details — entity type, GSTIN, PAN and address, where you choose to provide them.
- Documents — files you upload for a consultation or, for CAs, for verification.
- Booking and payment records — what you booked, when, and what it cost. Card details are handled by the payment provider and never reach MyCA.
- Activity records — an audit trail of significant actions, including who accessed a document and when.
Why we collect it
To operate the service you asked for: matching you with a Chartered Accountant, holding a slot, taking payment, issuing an invoice, and giving the CA the context they need to advise you. Verification data is collected so that the badge on a profile means something.
Who can see your documents
Documents are private by default. They are not served from public addresses. Access requires an authenticated session and a short-lived, single-recipient link, and each access is recorded.
Your choices
You can ask for a copy of your data, ask us to correct it, or ask us to delete your account. Some records — invoices, audit entries, and transaction history — are retained because we are required to keep them.