语言 / Language: 中文 | English

tutucash Privacy Policy

Last Updated: 2026-07-28
Effective Date: 2026-07-28
Version: v1.0

This document is the Privacy Policy for the tutucash application, suitable for App Store / TestFlight / Enterprise distribution submission.

Table of Contents


1. Introduction

tutucash (the "App") is developed and operated by Guangzhou Tianxingke Network Technology Co., Ltd (referred to as "we" or "the Company"). It is a multi-role internal bookkeeping tool for use exclusively by authorized employees of the Company.

We take your privacy very seriously. This Privacy Policy is drafted in accordance with three jurisdictions:

By using this App, you acknowledge and agree to this Privacy Policy.


1.5 Scope Extension

This Privacy Policy applies to all employees of tutucash worldwide, regardless of their location:

As employees are distributed across multiple countries, this policy is designed to simultaneously comply with the following data protection laws (see Section 15 for details):


2. Information We Collect

2.1 Actively Provided (entered by the Company backend)

DataPurposeRetention
Employee account info (name, employee ID, role)Identity verification and loginAccount deleted 30 days after departure
Role (employee / leader / admin)Permission controlDeleted on departure
Bookkeeping records (amount, category, time, notes)Core businessLong-term retention (Company archives)
Photo receipts (invoices, bills, screenshots)Business attachment archiveLong-term retention (bound to records)
Company org structure (departments, reporting lines)Leader review and statisticsLong-term retention

2.2 Automatically Collected

DataPurposeRetention
Device model / OS versionTroubleshooting3 months
Crash logs (anonymized)Bug localization3 months
Access logs (who, when, viewed what)Internal auditLong-term retention

2.3 We Do NOT Collect


3. Purpose of Use

PurposeDescription
Business functionalityDaily bookkeeping, leader review and approval
Internal managementRole permissions, account lifecycle
Audit complianceFinancial reconciliation, regulatory inspection
TroubleshootingCrash analysis, performance optimization
Security protectionAbnormal login detection

NEVER used for: marketing / user profiling / personalized recommendations / resale / AI training.


4. Multi-Role Permissions

RolePermission Scope
EmployeeOnly their own bookkeeping data
LeaderAll employees' bookkeeping data / approval / export
AdminUser management / system configuration / delete operations

Leader access to all employee data is a necessary design, with hierarchical authorization within the Company.


5. Information Sharing

We DO NOT share your information with third parties, EXCEPT in the following circumstances:


6. Data Storage & Security


7. Cross-Border Data Transfer ⚠️ Critical Section

7.1 Transfer Scenarios

7.2 Legal Basis

7.3 Our Commitments

7.4 Risk Disclosure

Data is stored on servers in Japan and is subject to Japan's Personal Information Protection Act (APPI). In the event of a conflict between Chinese and Japanese law, Chinese law prevails.


7.5 Cross-Border Transfer (Multi-Country Version)

⚠️ Important: This section is an extension of Section 7, covering the multi-country employee + Southeast Asia scenarios.

7.5.1 Applicable Employee Distribution

Since employees may be distributed across multiple countries (specific distribution known by Company HR), this policy uniformly applies to cross-border transfers in the following scenarios:

OriginDestinationApplicable LawsCompliance Measures
Mainland China → JapanData storagePIPL + APPIPIPL Art. 38 SCC
Japan → Mainland ChinaLeader reviewAPPI → PIPLEquivalent protection
Korea → JapanData storagePIPA → APPIWritten consent + encryption
Singapore → JapanData storagePDPA § 26 (Transfer Limitation)Equivalent protection determination
Thailand → JapanData storagePDPA § 24-25 (Cross-border Transfer)Written consent + security measures
Vietnam → JapanData storageDecree 13/2023 Art. 22-23Written consent + cross-border impact assessment
Malaysia → JapanData storagePDPA 2010 § 129PDP Commissioner approval
Southeast Asia → JapanData storageRespective PDPAWritten consent + encryption

7.5.2 Cross-Border Transfer Specific Measures

7.5.3 Country-Specific Requirements

CountryCross-Border Requirements
🇨🇳 ChinaPIPL Articles 38-40 / CAC Assessment / SCC
🇯🇵 JapanAPPI Article 28 / Employee Written Consent
🇰🇷 KoreaPIPA / Cross-Border Impact Assessment
🇸🇬 SingaporePDPA § 26 (Transfer Limitation) / Equivalent Protection Determination
🇹🇭 ThailandPDPA B.E. 2562 § 24-25 / Written Consent
🇻🇳 VietnamDecree 13/2023 Art. 22-23 / Cross-Border Impact Assessment
🇲🇾 MalaysiaPDPA 2010 § 129 / PDP Commissioner Approval

8. Photo Receipts & Photo Library Access

8.1 What We Collect

You can actively upload photos as bookkeeping receipts (invoices, receipts, bill screenshots). Photos are bound to corresponding records for storage.

8.2 iOS Photo Library Permission Request

Starting from iOS 14, tutucash will show a system authorization dialog (PhotoKit framework) when you need to upload photos.

Our commitments:

8.3 Metadata Contained in Photos

Our commitments:

8.4 Photo Storage and Deletion


9. Third-Party Services

NO third-party SDKs (except Apple official services).

We do not integrate: advertising SDKs / marketing SDKs / user profiling SDKs / third-party analytics / any other third-party services.


9.5 Southeast Asia PDPA Summary (Multi-Country Adaptation)

Since employees may be distributed across multiple Southeast Asian countries, this section provides a unified explanation of each region's data protection law requirements for tutucash.

9.5.1 Singapore PDPA (Personal Data Protection Act 2012)

Key Obligations:

Our Commitments:

9.5.2 Thailand PDPA (Personal Data Protection Act B.E. 2562 / 2019)

Key Obligations:

Our Commitments:

9.5.3 Vietnam Personal Data Protection (Decree No. 13/2023/ND-CP, effective July 2023)

Key Obligations:

Our Commitments:

9.5.4 Malaysia PDPA 2010 (Personal Data Protection Act 2010)

Key Obligations:

Our Commitments:

9.5.5 Common Compliance Requirements

Common RequirementDescription
Written ConsentAll employees sign at onboarding
Explicit PurposeOnly for internal bookkeeping and review
Data SecurityAES-256 + TLS 1.3 + RBAC
Cross-Border TransferWritten consent + encryption + equivalent protection
Data Subject RightsSee Section 10
Complaint ChannelsSee Section 16.5

10. Your Rights

You may exercise the following rights at any time:

RightDescriptionResponse Time
Right of AccessObtain a copy of all your data15 business days
Right of RectificationModify incorrect dataImmediately
Right of Erasure (Right to be Forgotten)Special Note: After employee departure, bookkeeping records are retained for leader review (per internal financial policy)30 business days (account itself)
Right of Data PortabilityExport in standard format (CSV / JSON)15 business days
Right of RestrictionTemporarily freeze data processingImmediately
Right to Withdraw ConsentWithdraw cross-border transfer consentImmediately
Right to Lodge a ComplaintComplain to regulatory authoritiesPermanent

Contact the Data Protection Officer (DPO): txk18122252653@163.com to exercise your rights.

10.1 Special Note on "Right to be Forgotten"

⚠️ Employee account deletion ≠ Data deletion. Per internal financial policies and legal requirements, employee bookkeeping records are retained for leader review (minimum 1 years). This is a lawful exception under GDPR Article 17(3)(b) "for compliance with a legal obligation."

11. Children's Privacy

tutucash is NOT intended for children under 18. If we discover a child has used the App, we will immediately delete their account.


12. Automated Decision-Making & Profiling

tutucash DOES NOT engage in any automated decision-making or user profiling. All data is reviewed manually, with no algorithmic scoring.


13. Data Security Incidents

In the event of a data breach, we will notify within 72 hours:


14. Changes to This Policy

When this policy changes:


15. Governing Law & Disputes


15.5 Southeast Asia Specific Laws

Country/RegionLawEffectiveKey Clauses
🇨🇳 Mainland ChinaPIPL Personal Information Protection Law2021-11-01Cross-border transfer requires CAC assessment / SCC
🇭🇰 Hong KongPDPO Personal Data (Privacy) Ordinance1996 (revised 2013)No cross-border transfer restrictions
🇲🇴 MacauPersonal Data Protection Law2023-01-01GDPR-equivalent level
🇹🇼 TaiwanPersonal Data Protection Act2012-10-01Cross-border transfer requires data subject consent
🇯🇵 JapanAPPI Personal Information Protection Act2005 (revised 2022)Cross-border transfer requires data subject consent
🇰🇷 KoreaPIPA Personal Information Protection Act2011 (revised 2023)Cross-border impact assessment
🇸🇬 SingaporePDPA Personal Data Protection Act2014-07-02§ 26 Transfer Limitation
🇲🇾 MalaysiaPDPA 20102013-11-15§ 129 Cross-border requires PDP Commissioner approval
🇹🇭 ThailandPDPA B.E. 2562 (2019)2022-06-01 (partial)§ 24-25 Cross-border requires explicit consent
🇻🇳 VietnamDecree 13/2023/ND-CP2023-07-01Art. 22-23 Cross-border impact assessment
🇵🇭 PhilippinesData Privacy Act 20122012-09-08NPC supervision, cross-border requires notification
🇮🇩 IndonesiaUU PDP Personal Data Protection Law2022-10-17 (pending implementation)Pending
🇮🇳 IndiaDPDP Act 20232023-08-11 (pending implementation)Cross-border transfer restrictions

16. Data Protection Officer (DPO)

To comply with GDPR Articles 37-39:


16.5 Regulatory Authorities

RegionRegulatory AuthorityWebsite
🇨🇳 Mainland ChinaCyberspace Administration of China (CAC)www.cac.gov.cn
🇭🇰 Hong KongOffice of the Privacy Commissioner for Personal Data (PCPD)www.pcpd.org.hk
🇲🇴 MacauOffice for Personal Data Protectionwww.gpdp.gov.mo
🇹🇼 TaiwanPersonal Data Protection Committeewww.pdpc.gov.tw
🇯🇵 JapanPersonal Information Protection Commission (PPC)www.ppc.go.jp
🇰🇷 KoreaPersonal Information Protection Commission (PIPC)www.pipc.go.kr
🇸🇬 SingaporePersonal Data Protection Commission (PDPC)www.pdpc.gov.sg
🇲🇾 MalaysiaJabatan Perlindungan Data Peribadi (JPDP)www.jpdp.gov.my
🇹🇭 ThailandPersonal Data Protection Committee (PDPC Thailand)www.pdpc.or.th
🇻🇳 VietnamMinistry of Information and Communications / Ministry of Public Securitymic.gov.vn
🇵🇭 PhilippinesNational Privacy Commission (NPC)privacy.gov.ph
🇪🇺 EU (general)European Data Protection Board (EDPB)edpb.europa.eu

17. Contact Information