1.Who we are
- 1.1QuickCA is a product of AI Methods, operating from Rajasthan, India ("QuickCA", "we" and "us").
- 1.2QuickCA sells income-tax filing and related tax services. A Chartered Accountant or firm, engaged by us as a partner, performs the work on our behalf.
- 1.3For the personal data described here, we are the Data Fiduciary under the Digital Personal Data Protection Act, 2023.
- 1.4Write to us at support@aimethods.in.
2.What this policy covers
- 2.1The QuickCA WhatsApp service, through which a client gives us their details, sends documents and buys a filing.
- 2.2quickca.aimethods.co, including the partner dashboard a CA or firm signs in to.
- 2.3It does not cover the Income Tax Department's portals, the GST portal, WhatsApp itself, or a partner's own systems and records.
- 2.4The QuickCA browser extension has its own notice at https://quickca.aimethods.co/privacy-policy.html, which supplements this one.
3.The two people this policy is about
- 3.1A client - a taxpayer who buys a filing through WhatsApp.
- 3.2A partner - a CA or firm who signs in to the dashboard to bid on cases and file them.
- 3.3Sections 4 and 5 differ accordingly. Everything after them applies to both.
4.What we hold about a client
- 4.1Your WhatsApp number, the name you gave, and the language you chose to be spoken to in.
- 4.2Your PAN, and the tax profile you gave the bot: income type, income bracket, the regime you file under and whether you are GST-registered.
- 4.3The documents you upload - such as Form 16, PAN, Aadhaar, bank statements, AIS and investment proofs - and the fields our checks read out of them.
- 4.4Your income-tax portal user ID and password, only where you chose to give them. Section 8.
- 4.5Your payment status for a case, and the acknowledgement number of a return filed for you.
- 4.6Your conversation with the bot, and which reminders it has already sent you.
5.What we hold about a partner
- 5.1Your name, email address and phone number.
- 5.2Your ICAI membership number, or your firm's GSTIN, and the result of checking it against that registry.
- 5.3Your years of experience, the languages you work in, your specialisations and the fees you bid.
- 5.4The bank account or UPI handle you nominate to be paid into.
- 5.5A record that you accepted the Partner Agreement: which version, when, and the IP address and browser it came from.
- 5.6A conduct record of decisions we take about your account.
6.Why we hold it
- 6.1To deliver what you bought or agreed to perform: matching a case to a partner, collecting the documents a return needs, filing it, and paying the partner afterwards.
- 6.2To keep the two sides apart until a client has chosen. Section 9.
- 6.3To meet obligations the law places on us, including tax and record-keeping.
- 6.4To answer a support request, and to investigate a complaint about a case.
- 6.5We do not use it to advertise to you, and we do not profile you.
7.WhatsApp, and Meta
- 7.1The service runs on the WhatsApp Business Platform. Messages between you and the bot pass through Meta's systems and are subject to Meta's own terms as well as this policy.
- 7.2Meta knows which number messaged which business and when. We do not send Meta your documents or your tax profile.
- 7.3Where we message you outside an open conversation, we use a message template Meta approved in advance. Tell support at any time to stop them.
- 7.4We will never ask you on WhatsApp for a card number, a bank password or a UPI PIN. Nobody from QuickCA will.
8.Your income-tax portal login
- 8.1We ask for it only where a filing needs it, and only through a link that expires.
- 8.2The password is encrypted with AES-256-GCM before it is stored, and is never sent to a browser in a form that could be read.
- 8.3It is decrypted only when the partner assigned to your case asks for it. Every decryption is counted, timestamped, and recorded against the person who made it.
- 8.4We do not store your portal OTP. When one is needed, the bot asks you for it and relays that single code.
- 8.5You may decline to give the login. Some services cannot be completed without it.
9.Who else sees it
- 9.1Before you choose a CA, nobody sees who you are. A partner considering your case sees the service, the period, your income bracket, how many documents are in, a complexity score and your preferred language - not your name, PAN, phone number or documents.
- 9.2After you choose, the partner you chose and the staff of their firm they assign see the case and its documents, because they cannot file without them.
- 9.3Under clause 7 of the Partner Agreement, a partner may use your data only for your case, must keep it confidential, and must delete their own copies when the case closes.
- 9.4Our own staff reach it only to run the service or to resolve a complaint.
- 9.5We do not sell, rent or trade personal data, and we do not share it for anyone's advertising.
10.Who processes it for us
- 10.1Google, through Firebase - hosting, database, file storage and sign-in. Data is held on Google Cloud infrastructure.
- 10.2Meta, for the WhatsApp Business Platform, as in section 7.
- 10.3Razorpay, for payments. Card and UPI details are entered on Razorpay's own page; we receive the outcome of a payment and its reference, never the instrument.
- 10.4Each acts on our instructions, and none is permitted to use the data for its own purposes.
11.How long we keep it
- 11.1While your account is open and your case is live.
- 11.2Afterwards, for as long as we need the record - a filing can be questioned after it is made, and the objection window on a case is 4 days but a tax record is not.
- 11.3Where the law requires us to retain something, we retain it for the period that law prescribes and for no other purpose.
- 11.4You can ask us to delete the rest at any time. What we delete, and what we cannot, is set out at https://quickca.aimethods.co/legal/data-deletion.
12.Security
- 12.1Portal passwords are encrypted at rest, as described in section 8.
- 12.2What each account can read is enforced by the database itself rather than by the screen, so hiding something is not the same as protecting it here.
- 12.3Documents are served through short-lived links rather than public addresses.
- 12.4No system is immune. Where a breach affects your personal data, we will notify you and the Data Protection Board of India as the law requires.
13.What we do not do
- 13.1We carry no analytics, no advertising code and no third-party trackers on any QuickCA page.
- 13.2We do not sell, rent or trade personal data, and we do not buy it.
- 13.3We do not message you about anything other than your case and the service.
- 13.4We do not read your documents for any purpose other than preparing and filing the return they belong to.
14.Your rights
- 14.1To ask what personal data we hold about you and what we have done with it.
- 14.2To have it corrected, completed or updated where it is wrong.
- 14.3To have it erased, subject to section 11 and the deletion page.
- 14.4To nominate another person to exercise these rights for you in the event of death or incapacity.
- 14.5To raise a grievance. Section 15.
- 14.6To exercise any of these, write to support@aimethods.in from the email address or phone number registered on your account. We will respond within the period the applicable rules prescribe.
15.Grievance redressal
- 15.1If you are dissatisfied with how your personal data has been handled, write to The Grievance Officer, AI Methods, at support@aimethods.in.
- 15.2We acknowledge within 72 hours and resolve within 30 days.
- 15.3If it is not resolved to your satisfaction, you may escalate to the Data Protection Board of India under the Digital Personal Data Protection Act, 2023 and the rules made under it.
16.Children
- 16.1QuickCA is not directed at children and we do not knowingly collect personal data from one.
- 16.2Where a return necessarily includes details of a family member, those details are given to us by the taxpayer filing it.
- 16.3We do not track, behaviourally monitor or advertise to children.
17.Changes to this policy
- 17.1We may update this policy. The effective date at the end changes with it.
- 17.2Where a change materially affects how we handle your data, we will tell you through the service before it takes effect.
- 17.3Continuing to use QuickCA after a change takes effect means you accept it.
18.Contact and governing law
- 18.1Questions about this policy, or about data we hold: support@aimethods.in. For anything else: hello@aimethods.co.
- 18.2This policy is governed by the laws of India.
- 18.3The courts at Rajasthan, India have exclusive jurisdiction over any dispute arising from it.
Effective 21 September 2026.