Legal

Privacy Policy

Version 2026-10-08 · Effective October 8, 2026

This Privacy Policy explains how Selah Studio (“TUKO”, “we”, “us”, “our”) collects, uses, discloses, and protects personal data when you use the TUKO application, websites, and related services (the “Service”).

It applies globally. Where a section applies only to specific jurisdictions (for example the EEA/UK, California, or the Philippines), it says so. By creating an account you acknowledge this Policy; a few processing activities additionally rely on your explicit opt-in consent.

1. Roles: controller and processor

For your account data, billing data, and usage data, TUKO is the data controller (or “personal information controller” under Philippine law; “business” under California law).

For personal data inside your workspace — records about your customers, employees, and suppliers that you create or import — you (the workspace owner) are the controller and TUKO acts solely as your processor/service provider, processing that data on your documented instructions to provide the Service. This Policy describes our practices as controller; our role as processor is further governed by Section 3 of the Terms of Service and any data processing agreement you execute with us.

2. Personal data we collect

Account data: name, email address, password (stored only as a secure hash by our authentication provider), and your choices such as legal-document consents (with version and timestamp) and marketing preferences.

Workspace data you provide: business name, type, country, currency, timezone, member names/emails/roles, and the operational records you enter or import — customers, products, orders, payments, expenses, suppliers, employees, tasks, and attachments. This may include personal data about your own customers and staff; you are responsible for your lawful basis to share it with us.

Usage and device data: app interactions, feature usage, approximate device and platform information, IP address (processed transiently for security and anti-abuse), diagnostics and crash data, and local preferences (theme, active workspace) stored on your device.

Support data: correspondence when you contact us.

We do not intentionally collect payment-card numbers (billing, where offered, is handled by our payment provider) or special categories of personal data, and you should not upload them.

3. Purposes and lawful bases

We process personal data to:

Where we rely on legitimate interests, we balance them against your rights; you may object as described in Section 9.

4. Consent records

When you accept our Terms or Privacy Policy, or opt in to marketing, we record the document, version, your choice, and the timestamp. We keep these records to demonstrate compliance and apply them to your account. You may withdraw optional consents at any time without affecting the lawfulness of prior processing.

5. Automated analysis

The Service produces opportunity suggestions, scores, and estimated values from workspace data using deterministic business rules. We do not make decisions with legal or similarly significant effect about you solely by automated means. Estimates are labelled and are not guarantees.

6. How we share personal data

We do not sell personal data and do not share it for cross-context behavioural advertising.

We share data only with: (a) sub-processors and service providers who process it on our instructions under contract — Supabase (authentication, database hosting), Netlify (web hosting), Resend (transactional email), Expo/EAS (application build and delivery), and app-store providers (Apple, Google) for distribution; (b) professional advisers and authorities where required by law, to enforce our Terms, or to protect rights, safety, and security; (c) parties to a merger, acquisition, or asset sale, subject to this Policy; and (d) other members of your own workspace, per your role settings.

An up-to-date list of sub-processors is available on request at [email protected].

7. International transfers

Your data may be processed in countries other than your own, including the United States and the Philippines, where our providers operate. Where required, we rely on appropriate safeguards for cross-border transfers — including adequacy decisions, EU Standard Contractual Clauses (and the UK addendum), or the provider’s certification under applicable frameworks. You may request a copy of the safeguards applicable to your data.

8. Retention

We keep account and workspace data while your account is active. If you delete your account or request erasure, we delete or anonymize personal data within a reasonable period (target: 30 days in primary systems, up to 90 days in encrypted backups), except records we must keep to meet legal, tax, audit, or dispute-resolution obligations — such as consent records and audit logs — which are retained only as long as the obligation requires.

Demo data loaded into a workspace can be cleared by an admin at any time.

9. Your rights

Depending on your jurisdiction, you may have the right to: access your personal data and receive a copy; correct inaccurate data; delete your data; restrict or object to processing; data portability; withdraw consent (without affecting prior processing); not be subject to solely automated decisions with significant effect; and lodge a complaint with a supervisory authority.

EEA/UK/Switzerland (GDPR/UK GDPR): the rights above apply in full. Our representative obligations are met through [email protected]; you may complain to your local supervisory authority.

California and other US states (CCPA/CPRA and similar): you have rights to know, access, correct, delete, portability, non-discrimination, and to opt out of sale or sharing — we do not sell or share personal data as those laws define it. Authorized agents may submit requests with proof of authorization.

Philippines (Data Privacy Act of 2012, RA 10173): you have the rights to be informed, to object, to access, to rectification, to erasure or blocking, to damages, and to data portability, and you may complain to the National Privacy Commission (NPC).

Canada (PIPEDA), Brazil (LGPD), Australia (Privacy Act 1988), and other jurisdictions: we honour materially equivalent rights to access, correction, deletion, and complaint, and we will identify any local-representative or DPO requirements that apply to our processing for you.

To exercise any right, use the in-app privacy controls (Settings → Legal) or email [email protected]. We verify requests against your account and respond within the period your law requires (generally 30 days; 45 days for US state laws). Requests about workspace data you control (for example a request from one of your customers) are your responsibility as controller — we will reasonably assist.

10. Security

We use encryption in transit (TLS), hashed credentials via our auth provider, per-tenant row-level security enforced by the database, least-privilege service access, and audit logging. No method of transmission or storage is 100% secure; please keep your credentials confidential.

If a personal-data breach creates a risk to your rights and freedoms, we will notify you and any required authority without undue delay and within statutory deadlines.

11. Cookies and local storage

The web app uses strictly necessary storage only: authentication session tokens and your UI preferences. We do not use advertising, analytics, or third-party tracking cookies, and we honour Global Privacy Control / do-not-track style signals by simply not tracking. The landing site loads Google Fonts; no tracking cookie is set.

12. Children

The Service is a business tool not directed at children. You must be at least 18 (or the age of digital consent in your jurisdiction, whichever applies to contract with us) to create an account. We do not knowingly collect personal data from children; contact us if you believe a child has provided data and we will delete it.

13. Do Not Sell / Global privacy choices

We do not sell personal information, do not share it for cross-context behavioural advertising, and do not use or disclose sensitive personal information for purposes requiring an opt-out right. If our practices change we will update this Policy and provide the required opt-out mechanisms before they take effect.

14. Changes to this Policy

We may update this Policy; material changes will be announced in the Service or by email before the new effective date, and the version you accepted is recorded in your consent records. Continued use after the effective date means you acknowledge the updated Policy.

15. Contact and complaints

Privacy questions and requests: [email protected]. Legal notices: [email protected].

You may also complain to your local supervisory authority — for example, an EU/EEA data protection authority, the UK ICO, the Philippine National Privacy Commission, the Office of the Privacy Commissioner of Canada, the Brazilian ANPD, or the Australian OAIC.