Loby Technologies Private Limited ("we," "our," or "us") operates the Let's Split mobile application and website at letsplit.app (collectively, the "Service"). This Privacy Policy explains how we collect, use, share, and protect information about you when you use our Service.
By using Let's Split, you agree to the collection and use of information in accordance with this policy.
1. Who We Are
Let's Split is a bill-splitting and shared expense management application. We are incorporated as Loby Technologies Private Limited and operate the Service to help groups track and settle shared expenses fairly.
Contact: support@letsplit.app
2. Information We Collect
2.1 Information You Provide Directly
Account Information
- Phone number – Your phone number is your primary identifier. We collect it to authenticate you via a one-time password (OTP).
- Name – Your first and last name, provided during profile setup.
- Email address – Optional. You may provide an email address for account recovery or communication purposes.
- UPI ID – Optional. You may provide your UPI (Unified Payments Interface) ID so group members can send you payments to settle balances. We store this but do not use it to initiate or process any payments.
Expense and Group Data
- Details of expenses you record: amount, description, date, category, and how the expense is split among members.
- Groups you create or join: group name, type (e.g., trip, home, office), and member list.
- Settlement records: amounts you mark as settled between group members.
2.2 Information Collected Automatically
Device Contacts (with your permission)
When you grant access to your device's contacts, we read contact names and phone numbers locally on your device to help you find friends who also use Let's Split. Phone numbers from your contacts are hashed (SHA-256) on your device before any data is sent to our servers. We never transmit raw contact phone numbers. The hashed values are used solely to identify which of your contacts are registered Let's Split users.
Usage and Analytics Data
We use Firebase Analytics (Google) to collect anonymised information about how you use the Service, including:
- Screens visited and features used
- Session duration and frequency of use
- Onboarding and authentication events (e.g., OTP requested, verified)
- Device type, operating system version, and app version
Crash and Performance Data
We use Firebase Crashlytics and Firebase Performance Monitoring (Google) to automatically collect error reports and performance metrics. These reports may include your Firebase user ID, device model, OS version, and a stack trace of the error.
Website Analytics
When you visit letsplit.app, Firebase Analytics collects standard web analytics data such as pages visited, session duration, approximate geographic location derived from your IP address, browser type, and referring URL.
2.3 Information We Do Not Collect
- We do not collect or access your device camera, microphone, photos, location, or calendar.
- We do not process or facilitate any payments. Expense amounts and UPI IDs are recorded for informational purposes only; actual money transfers happen outside our Service.
- We do not sell your personal information.
3. How We Use Your Information
| Purpose | Data Used |
|---|---|
| Create and authenticate your account | Phone number, Firebase authentication token |
| Display your profile to group members | Name, phone number |
| Record and display shared expenses | Expense details, group membership, splits |
| Find friends on the app | Hashed phone numbers from your contacts |
| Allow group members to settle up | UPI ID (displayed to group members only) |
| Send OTP for login and re-authentication | Phone number (via Firebase) |
| Improve app stability and fix bugs | Crash reports, error logs |
| Understand feature usage and improve the product | Analytics events |
| Respond to support requests | Email address (if provided), account details |
| Prevent fraud and enforce our Terms of Service | Account and activity data |
4. How We Share Your Information
We do not sell your personal information. We share information in the following limited circumstances:
4.1 With Other Users
To make the Service work, certain information is visible to other users:
- Your name is visible to members of any group you belong to and to users you are connected with as friends.
- Your UPI ID (if provided) is visible to members of your groups to facilitate settlements.
- Your balance (how much you owe or are owed) is visible to the relevant group members and friends.
4.2 With Service Providers
We share data with the following third-party service providers who process data on our behalf:
| Provider | Purpose | Data Shared |
|---|---|---|
| Google Firebase (Authentication) | Phone OTP authentication, account management | Phone number, Firebase UID |
| Google Firebase (Analytics) | Usage analytics | Anonymised usage events, device info |
| Google Firebase (Crashlytics) | Crash and error reporting | Firebase UID, device info, error stack traces |
| Google Firebase (Performance) | App performance monitoring | Anonymised performance metrics |
| MongoDB | Cloud database hosting | All user and transaction data stored in our database |
4.3 For Legal Reasons
We may disclose your information if we believe in good faith that disclosure is necessary to comply with applicable law, a court order, or a legal process; to protect our rights or property; or to protect the safety of our users or the public.
4.4 Business Transfers
If Loby Technologies Private Limited is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information is transferred and becomes subject to a different privacy policy.
5. Data Storage and Retention
Local Storage: The app stores certain data (your profile, group and transaction data, contact lookup cache) locally on your device using encrypted storage (MMKV). This data remains on your device until you log out or uninstall the app.
Cloud Storage: Your account data, groups, and transaction history are stored in our cloud database. We retain this data for as long as your account is active.
Account Deletion: You can permanently delete your account from within the app (Account Settings → Delete Account). Upon deletion, your personal profile and account data will be removed from our active systems. Transaction records in shared groups may be retained in anonymised form to preserve the integrity of other members' expense history.
Retention Period: We retain your data for as long as your account is active. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required to retain it for legal, tax, or audit obligations.
6. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request that we correct inaccurate or incomplete data. You can update most information directly in the app (Profile Settings).
- Deletion: Request deletion of your account and associated data. You can initiate this in the app or by emailing support@letsplit.app.
- Portability: Request a copy of your data in a structured, machine-readable format.
- Objection: Object to or restrict how we process your data in certain circumstances.
- Withdraw Consent: Where processing is based on consent (e.g., Contacts access), you can withdraw consent at any time by revoking the permission in your device settings (Settings → Privacy → Contacts → Let's Split).
To exercise any of these rights, contact us at support@letsplit.app. We will respond within 30 days.
7. Contacts Permission
When you grant the Contacts permission, we access your device's contact list to identify which of your contacts use Let's Split. This helps you quickly add friends to groups.
- Contact data is processed entirely on your device.
- Only SHA-256 hashes of phone numbers are sent to our servers—never raw names, phone numbers, or other contact details.
- Contact lookup results are cached locally on your device and are not stored on our servers beyond the lookup request.
- You can revoke this permission at any time in your device Settings. Revoking contacts access does not affect existing groups or friends already added.
8. Notifications
The app may send you push notifications for activity in your groups (e.g., a new expense was added). You can manage notification preferences in your device Settings (Settings → Notifications → Let's Split).
9. Security
We implement technical and organisational measures to protect your information, including:
- All data in transit is encrypted using HTTPS/TLS.
- Authentication is handled by Firebase, using industry-standard JWT tokens.
- Local data on your device is stored in encrypted MMKV storage.
- Access to our systems is restricted to authorised personnel.
- All database records include audit trails (created/updated/deleted timestamps and user IDs).
- Phone numbers for contact lookup are one-way hashed (SHA-256) and cannot be reversed to recover the original number.
No method of electronic transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
10. Children's Privacy
Let's Split is not directed to children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us at support@letsplit.app and we will promptly delete it.
11. International Data Transfers
We are based in India and our services are primarily intended for users in India. However, some of our third-party service providers (including Google Firebase) process data in data centres around the world. By using the Service, you consent to the transfer of your data to countries that may have different data protection laws than your country of residence. We rely on service providers that offer adequate data protection measures (such as Google's standard contractual clauses) for such transfers.
12. Third-Party Links
The Service may contain links to third-party websites or services (for example, payment apps you use to settle balances). We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any third-party services you access.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and notify you through the app or by email (if provided). Your continued use of the Service after changes become effective constitutes your acceptance of the revised policy.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Loby Technologies Private Limited
Email: support@letsplit.app
Website: https://letsplit.app
We aim to respond to all enquiries within 30 days.