Terms of Service
Last Updated: April 10, 2026
1. Service Description
Riyazee provides FBR Digital Invoice compliance, business management, inventory, POS, and tax engine features for registered Pakistani businesses.
2. User Responsibilities
- Provide accurate business registration information (NTN, STRN)
- Ensure invoice data accuracy before FBR submission
- Maintain confidentiality of login credentials
- Comply with all applicable Pakistani tax laws and FBR regulations
- Not attempt to reverse-engineer, modify, or exploit the application
3. Subscriptions & Payments
Subscriptions are managed through Stripe. We accept all major credit and debit cards (Visa, Mastercard, American Express, UnionPay), bank transfers, and digital wallets. No payment information is stored by Riyazee. All prices are in PKR plus applicable taxes.
4. Free Plan
Riyazee offers a free plan with 30 invoices per month, both Sandbox and Production access, and core features. No credit card required. The free plan is available indefinitely with no time restrictions.
5. Invoice Limits & Grace Period
FBR compliance is never blocked by billing. You will receive notifications at 80%, 90%, and 100% of your plan limit. If you exceed your limit, a very limited number of invoices will be issued during the grace period to keep your business running while you upgrade.
6. Data Retention
All plans include 7 years of data retention as required by the Sales Tax Act, 1990 (Section 24) and Income Tax Ordinance 2001 (Section 174). Your invoice and financial data is securely stored for the full retention period.
7. Limitation of Liability
Riyazee is provided on an "as-is" basis. The developer is not liable for FBR penalties from user data errors, service interruptions, or data loss beyond commercially reasonable measures. Total liability shall not exceed subscription fees paid in the preceding 12 months.
8. Governing Law
These terms are governed by the laws of Pakistan. Disputes shall be resolved in the courts of Karachi.
Security Policy
TLS 1.2+ Encryption
All data encrypted in transit between your device and our servers
Encrypted Storage
Data encrypted at rest on AWS servers and on your device
JWT Authentication
Secure signed tokens with session timeout
Biometric Auth
Face ID and Fingerprint authentication supported
8-Level Role System
SUPER_ADMIN to VIEWER hierarchy with granular permissions
Rate Limiting
Authentication endpoints limited to prevent brute force attacks
CORS Protection
Only authorized origins can access the API
Input Sanitization
All HTML/script tags stripped from inputs (XSS prevention)
SQL Injection Prevention
Prisma ORM with parameterized queries
Cross-Business Isolation
Each business's data is completely isolated at the API level
Audit Logging
All sensitive operations logged with user, timestamp, and action
Device Tamper Detection
Root/jailbreak and debugger detection on mobile
For inquiries:
support@riyazee.com