Terms of Service

Last Updated: April 10, 2026

1. Service Description

Riyazee provides FBR Digital Invoice compliance, business management, inventory, POS, and tax engine features for registered Pakistani businesses.

2. User Responsibilities

  • Provide accurate business registration information (NTN, STRN)
  • Ensure invoice data accuracy before FBR submission
  • Maintain confidentiality of login credentials
  • Comply with all applicable Pakistani tax laws and FBR regulations
  • Not attempt to reverse-engineer, modify, or exploit the application

3. Subscriptions & Payments

Subscriptions are managed through Stripe. We accept all major credit and debit cards (Visa, Mastercard, American Express, UnionPay), bank transfers, and digital wallets. No payment information is stored by Riyazee. All prices are in PKR plus applicable taxes.

4. Free Plan

Riyazee offers a free plan with 30 invoices per month, both Sandbox and Production access, and core features. No credit card required. The free plan is available indefinitely with no time restrictions.

5. Invoice Limits & Grace Period

FBR compliance is never blocked by billing. You will receive notifications at 80%, 90%, and 100% of your plan limit. If you exceed your limit, a very limited number of invoices will be issued during the grace period to keep your business running while you upgrade.

6. Data Retention

All plans include 7 years of data retention as required by the Sales Tax Act, 1990 (Section 24) and Income Tax Ordinance 2001 (Section 174). Your invoice and financial data is securely stored for the full retention period.

7. Limitation of Liability

Riyazee is provided on an "as-is" basis. The developer is not liable for FBR penalties from user data errors, service interruptions, or data loss beyond commercially reasonable measures. Total liability shall not exceed subscription fees paid in the preceding 12 months.

8. Governing Law

These terms are governed by the laws of Pakistan. Disputes shall be resolved in the courts of Karachi.

Security Policy

TLS 1.2+ Encryption

All data encrypted in transit between your device and our servers

Encrypted Storage

Data encrypted at rest on AWS servers and on your device

JWT Authentication

Secure signed tokens with session timeout

Biometric Auth

Face ID and Fingerprint authentication supported

8-Level Role System

SUPER_ADMIN to VIEWER hierarchy with granular permissions

Rate Limiting

Authentication endpoints limited to prevent brute force attacks

CORS Protection

Only authorized origins can access the API

Input Sanitization

All HTML/script tags stripped from inputs (XSS prevention)

SQL Injection Prevention

Prisma ORM with parameterized queries

Cross-Business Isolation

Each business's data is completely isolated at the API level

Audit Logging

All sensitive operations logged with user, timestamp, and action

Device Tamper Detection

Root/jailbreak and debugger detection on mobile

For inquiries:

support@riyazee.com