Security & data protection
Your mandi data. Your control.
An arhtiya's khata is the business. Here is exactly how MandiGrow keeps it private from staff, safe from loss, and always exportable — in plain words, no marketing.
Your staff see only what you allow
Role-based access: the operator can bill but cannot see profit; the accountant can reconcile but cannot delete a patti; only the owner sees everything. Permissions are set per user, per module.
Every change is on record
Who created, edited or cancelled which patti, invoice or payment — with the time and the old value. Corrections are made by cancel-and-reissue, never by silent overwrite, so your books stay auditable.
One login, one device at a time
Each user can be signed in on only one device. A new login signs the old one out, and an idle session is closed automatically after 10 minutes — shared phones in the yard do not become open doors.
Backed up every day
Your database is backed up automatically every day on managed cloud infrastructure, with retained copies, so a lost phone or a broken laptop never means a lost khata.
Export everything, any time
Ledgers, pattis, invoices, daybook and reports export to Excel/CSV and PDF whenever you want — for your CA, for Tally, or simply to keep your own copy. Your data is yours, also after you leave.
Encrypted in transit, protected at rest
All traffic is HTTPS with HSTS; session cookies are HttpOnly and cannot be read by scripts; a strict content-security policy limits what can run on the page. Databases are isolated per customer organisation.
We never see your card
Subscription payments go through Razorpay/Paytm hosted checkout. MandiGrow does not store card numbers, UPI PINs or bank passwords.
Compliant records for your CA
GST-compliant invoices with HSN/SAC, e-invoice where applicable, GSTR-1/3B exports, commission and market-fee registers — kept in the format your auditor expects.
For owners
Give each staff member their own login. Never share the owner password. Review the audit log weekly — it takes two minutes.
For CAs & accountants
Ask for the accountant role: full ledgers, GSTR exports and registers, without the ability to alter submitted pattis.
Found a security issue?
Write to support@mandigrow.com with the subject "Security". We acknowledge within one business day.
Security questions traders ask
Is my mandi data safe in cloud software?
Yes. Data is stored on managed cloud infrastructure with daily automated backups, encrypted connections, per-customer isolation and access controlled by user roles. A cloud khata is safer than a register or a single laptop that can be lost, stolen or damaged.
Can my munshi or operator see my profit and bank balance?
Only if you give that role. MandiGrow uses role-based access, so billing staff see billing, accountants see accounts, and only the owner sees profit, bank and settings.
What happens to my data if I stop using MandiGrow?
You can export all ledgers, invoices, pattis and reports to Excel/CSV and PDF at any time, including during the trial and after cancellation. There is no lock-in.
Can someone log in from another phone with my password?
Only one active session per user is allowed. A login from a new device signs the previous one out, and idle sessions close automatically after 10 minutes. Change your password immediately if you suspect it is shared.
Does MandiGrow share my data with the mandi board or anyone else?
No. Your data is used only to run your account. Reports for the APMC/mandi board are generated by you, from your account, when you choose to submit them. See our Privacy Policy for details.
Do you store my card or UPI details?
No. Payments are handled by Razorpay/Paytm hosted checkout. MandiGrow never receives or stores card numbers or UPI PINs.
See also: Privacy Policy · Terms · Refund Policy