Privacy Policy

This policy explains exactly what Pinnacle GST360 stores when you connect a client's GST portal account, and what we never keep.

Last updated 2 October 2026

Who we are

Pinnacle GST360 is operated by Pinnacle Consultancy Group, 3-3-110/VF/301, Veejay Flora, Hyderabad – 500048, India. For any privacy question, write to enquiry@pinnacleconsultancygroup.in.

How GST portal access works

Return data is retrieved through Alankit, a GST Suvidha Provider licensed by GSTN, under Alankit's licence. We do not connect to the GST portal by any other route, and we do not scrape the portal website.

Connecting a GSTIN uses the portal's own username and one-time password. We do not store the GST portal password. What we store is the encrypted API session the portal issues, and it is retained only for the life of that session — when it expires the record is unusable and a fresh OTP is required.

What we store

  • Your account details: name, email, phone and firm name.
  • Client GSTINs, legal names and the contact details you enter for report delivery.
  • Return data retrieved for the periods you request (GSTR-1, GSTR-2A, GSTR-2B, GSTR-3B summaries and credit ledger balances), and the reports generated from it.
  • Encrypted GST portal API sessions, for the validity of the session only.
  • Filing authorisations, reconciliation decisions, portal validation responses, filed figures, ARN evidence and the identities of the people who prepared, approved and filed.
  • Enquiry form submissions: name, email, phone, firm and your message.

EVC one-time passwords are used for the instructed filing step and are never stored. We do not sell data, and we do not use client return data to train any model.

Where it is stored and for how long

Data is held in a managed PostgreSQL database and object storage hosted in an India region, encrypted at rest, and reached only over TLS.

Retrieved return data and generated reports are retained while your subscription is active and for 30 days after it ends, so you can export what you need. You can ask for earlier deletion at any time and we will action it. Encrypted portal sessions are removed when they expire. Invoices, payment records and other statutory records are retained for the period Indian law requires.

Who can see client data

Access is scoped to your organisation. Members of your own practice see only your organisation's clients, and roles control who can add clients or send reports. Inside Pinnacle Consultancy Group, access to production data is limited to the named administrators who operate the service, is used only to investigate a fault you have reported, and is not used to view client returns otherwise.

How a client revokes access

A client can withdraw access at any time. Remove the GSTIN from the Clients page, which deletes its stored session and stops all scheduled delivery, or ask us and we will remove it and confirm. Because access depends on a portal session that expires, withholding the next OTP also ends retrieval on its own.

Processors we rely on

Alankit (GST Suvidha Provider, portal access), our cloud database and hosting provider, Razorpay (payments), and our transactional email provider for report delivery and account emails. Each receives only what its function requires.

Your rights

You can ask for a copy of your data, correction of anything inaccurate, or deletion of your account and its data. Write to enquiry@pinnacleconsultancygroup.in and we will respond within 30 days.