Privacy Policy

MyTaxLocker — A Product of MaxLeaf

← Back to Home

Version 2.0 • Last updated April 2026 • Effective immediately

In plain language: MaxLeaf is the company that runs MyTaxLocker. We collect your tax data only to help you file ITR. Your data is encrypted, stored in India, and never sold. You can delete everything anytime.

1. Who We Are

MaxLeaf ("Company", "we", "us") operates the MyTaxLocker application and website at mytaxlocker.maxleaf.in.

Under the Digital Personal Data Protection Act (DPDPA) 2023, MaxLeaf is the Data Fiduciary responsible for securing all personal data collected through the MyTaxLocker app, including PAN, Aadhaar, Form 16, and bank account information.

2. What We Collect

CategoryData PointsPurpose
IdentityPAN, Aadhaar, name, DOB, mobile, emailITR form fields
FinancialSalary (Form 16), deductions, investments, bank account, IFSCTax computation
DocumentsForm 16 PDF, rent receipts, investment proofsFiling evidence
DeviceDevice type, OS versionCrash reporting only

We do NOT collect: passwords, biometric templates, payment card details, location data, contacts, or call logs.

3. How We Use It

We will NEVER sell, rent, or share your personal data with third parties for marketing.

4. How We Protect It

LayerTechnology
Encryption at restAES-256 field-level encryption for PAN, Aadhaar, bank accounts
Encryption in transitTLS 1.2+ with certificate pinning
Access controlPer-user data isolation via AWS IAM + Cognito
AuthenticationEmail + password with biometric (Face ID / fingerprint) option
Key managementPer-user encryption key stored in device secure enclave
Audit trailPII access logged with timestamps for DPDPA compliance
Data residencyAWS Mumbai (ap-south-1), fully within India

5. Data Sharing

With Chartered Accountants (CAs)

If you opt for CA-assisted filing, your filing data is shared with an assigned CA. This requires your explicit consent, is limited to one assessment year, and can be revoked by cancelling the request. The CA acts as a Data Processor under DPDPA.

With Service Providers

ProviderPurposeData Shared
Amazon Web Services (AWS)Hosting, storage, authenticationAll data (encrypted)
SentryCrash reportingError messages, stack traces (no PII)
ExpoApp build & updatesApp binary only (no user data)

We do NOT share data with advertisers, data brokers, or social media platforms.

6. Data Retention

7. Your Rights

Under DPDPA 2023, you have the right to:

RightHow to Exercise
AccessView all your data in-app (Tax Profile, Vault, Filing History)
CorrectionEdit any field in your Tax Profile at any time
Erasure"Delete Account" in app → purges DynamoDB, S3, and Cognito
Portability"Export Data" in app → JSON download of all your data
Withdraw ConsentDelete account (app cannot function without processing tax data)

8. Aadhaar Handling

Aadhaar is collected solely for ITR JSON generation (mandated by the Income Tax Department). It is encrypted at rest, masked in the UI (last 4 digits only), never shared with third parties, and deleted when you delete your account. We do not authenticate using Aadhaar or access UIDAI services.

9. Children's Privacy

MyTaxLocker is not intended for users under 18 years of age. We do not knowingly collect data from minors. If we learn that we have collected data from a child, we will delete it promptly.

10. Cookies & Tracking

The MyTaxLocker mobile app does not use cookies. The website (mytaxlocker.maxleaf.in) uses no third-party trackers, analytics scripts, or advertising pixels. We collect zero browsing data from the website.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via in-app notification and updated on this page. Continued use of the App after changes constitutes acceptance.

12. Contact & Grievance Officer

Company: MaxLeaf
Email: support@maxleaf.in
Website: maxleaf.in
Response time: Within 72 hours

Social: @MaxLeafIndia on Instagram, X, Facebook
GitHub: github.com/MaxLeafIndia

You may also contact the Data Protection Board of India if your grievance is not resolved satisfactorily.