This document is the Privacy Policy for the tutucash application, suitable for App Store / TestFlight / Enterprise distribution submission.
tutucash (the "App") is developed and operated by Guangzhou Tianxingke Network Technology Co., Ltd (referred to as "we" or "the Company"). It is a multi-role internal bookkeeping tool for use exclusively by authorized employees of the Company.
We take your privacy very seriously. This Privacy Policy is drafted in accordance with three jurisdictions:
By using this App, you acknowledge and agree to this Privacy Policy.
This Privacy Policy applies to all employees of tutucash worldwide, regardless of their location:
As employees are distributed across multiple countries, this policy is designed to simultaneously comply with the following data protection laws (see Section 15 for details):
| Data | Purpose | Retention |
|---|---|---|
| Employee account info (name, employee ID, role) | Identity verification and login | Account deleted 30 days after departure |
| Role (employee / leader / admin) | Permission control | Deleted on departure |
| Bookkeeping records (amount, category, time, notes) | Core business | Long-term retention (Company archives) |
| Photo receipts (invoices, bills, screenshots) | Business attachment archive | Long-term retention (bound to records) |
| Company org structure (departments, reporting lines) | Leader review and statistics | Long-term retention |
| Data | Purpose | Retention |
|---|---|---|
| Device model / OS version | Troubleshooting | 3 months |
| Crash logs (anonymized) | Bug localization | 3 months |
| Access logs (who, when, viewed what) | Internal audit | Long-term retention |
| Purpose | Description |
|---|---|
| Business functionality | Daily bookkeeping, leader review and approval |
| Internal management | Role permissions, account lifecycle |
| Audit compliance | Financial reconciliation, regulatory inspection |
| Troubleshooting | Crash analysis, performance optimization |
| Security protection | Abnormal login detection |
NEVER used for: marketing / user profiling / personalized recommendations / resale / AI training.
| Role | Permission Scope |
|---|---|
| Employee | Only their own bookkeeping data |
| Leader | All employees' bookkeeping data / approval / export |
| Admin | User management / system configuration / delete operations |
Leader access to all employee data is a necessary design, with hierarchical authorization within the Company.
We DO NOT share your information with third parties, EXCEPT in the following circumstances:
Data is stored on servers in Japan and is subject to Japan's Personal Information Protection Act (APPI). In the event of a conflict between Chinese and Japanese law, Chinese law prevails.
Since employees may be distributed across multiple countries (specific distribution known by Company HR), this policy uniformly applies to cross-border transfers in the following scenarios:
| Origin | Destination | Applicable Laws | Compliance Measures |
|---|---|---|---|
| Mainland China → Japan | Data storage | PIPL + APPI | PIPL Art. 38 SCC |
| Japan → Mainland China | Leader review | APPI → PIPL | Equivalent protection |
| Korea → Japan | Data storage | PIPA → APPI | Written consent + encryption |
| Singapore → Japan | Data storage | PDPA § 26 (Transfer Limitation) | Equivalent protection determination |
| Thailand → Japan | Data storage | PDPA § 24-25 (Cross-border Transfer) | Written consent + security measures |
| Vietnam → Japan | Data storage | Decree 13/2023 Art. 22-23 | Written consent + cross-border impact assessment |
| Malaysia → Japan | Data storage | PDPA 2010 § 129 | PDP Commissioner approval |
| Southeast Asia → Japan | Data storage | Respective PDPA | Written consent + encryption |
| Country | Cross-Border Requirements |
|---|---|
| 🇨🇳 China | PIPL Articles 38-40 / CAC Assessment / SCC |
| 🇯🇵 Japan | APPI Article 28 / Employee Written Consent |
| 🇰🇷 Korea | PIPA / Cross-Border Impact Assessment |
| 🇸🇬 Singapore | PDPA § 26 (Transfer Limitation) / Equivalent Protection Determination |
| 🇹🇭 Thailand | PDPA B.E. 2562 § 24-25 / Written Consent |
| 🇻🇳 Vietnam | Decree 13/2023 Art. 22-23 / Cross-Border Impact Assessment |
| 🇲🇾 Malaysia | PDPA 2010 § 129 / PDP Commissioner Approval |
You can actively upload photos as bookkeeping receipts (invoices, receipts, bill screenshots). Photos are bound to corresponding records for storage.
Starting from iOS 14, tutucash will show a system authorization dialog (PhotoKit framework) when you need to upload photos.
Our commitments:
Our commitments:
NO third-party SDKs (except Apple official services).
We do not integrate: advertising SDKs / marketing SDKs / user profiling SDKs / third-party analytics / any other third-party services.
Since employees may be distributed across multiple Southeast Asian countries, this section provides a unified explanation of each region's data protection law requirements for tutucash.
Key Obligations:
Our Commitments:
Key Obligations:
Our Commitments:
Key Obligations:
Our Commitments:
Key Obligations:
Our Commitments:
| Common Requirement | Description |
|---|---|
| Written Consent | All employees sign at onboarding |
| Explicit Purpose | Only for internal bookkeeping and review |
| Data Security | AES-256 + TLS 1.3 + RBAC |
| Cross-Border Transfer | Written consent + encryption + equivalent protection |
| Data Subject Rights | See Section 10 |
| Complaint Channels | See Section 16.5 |
You may exercise the following rights at any time:
| Right | Description | Response Time |
|---|---|---|
| Right of Access | Obtain a copy of all your data | 15 business days |
| Right of Rectification | Modify incorrect data | Immediately |
| Right of Erasure (Right to be Forgotten) | Special Note: After employee departure, bookkeeping records are retained for leader review (per internal financial policy) | 30 business days (account itself) |
| Right of Data Portability | Export in standard format (CSV / JSON) | 15 business days |
| Right of Restriction | Temporarily freeze data processing | Immediately |
| Right to Withdraw Consent | Withdraw cross-border transfer consent | Immediately |
| Right to Lodge a Complaint | Complain to regulatory authorities | Permanent |
Contact the Data Protection Officer (DPO): txk18122252653@163.com to exercise your rights.
tutucash is NOT intended for children under 18. If we discover a child has used the App, we will immediately delete their account.
tutucash DOES NOT engage in any automated decision-making or user profiling. All data is reviewed manually, with no algorithmic scoring.
In the event of a data breach, we will notify within 72 hours:
When this policy changes:
| Country/Region | Law | Effective | Key Clauses |
|---|---|---|---|
| 🇨🇳 Mainland China | PIPL Personal Information Protection Law | 2021-11-01 | Cross-border transfer requires CAC assessment / SCC |
| 🇭🇰 Hong Kong | PDPO Personal Data (Privacy) Ordinance | 1996 (revised 2013) | No cross-border transfer restrictions |
| 🇲🇴 Macau | Personal Data Protection Law | 2023-01-01 | GDPR-equivalent level |
| 🇹🇼 Taiwan | Personal Data Protection Act | 2012-10-01 | Cross-border transfer requires data subject consent |
| 🇯🇵 Japan | APPI Personal Information Protection Act | 2005 (revised 2022) | Cross-border transfer requires data subject consent |
| 🇰🇷 Korea | PIPA Personal Information Protection Act | 2011 (revised 2023) | Cross-border impact assessment |
| 🇸🇬 Singapore | PDPA Personal Data Protection Act | 2014-07-02 | § 26 Transfer Limitation |
| 🇲🇾 Malaysia | PDPA 2010 | 2013-11-15 | § 129 Cross-border requires PDP Commissioner approval |
| 🇹🇭 Thailand | PDPA B.E. 2562 (2019) | 2022-06-01 (partial) | § 24-25 Cross-border requires explicit consent |
| 🇻🇳 Vietnam | Decree 13/2023/ND-CP | 2023-07-01 | Art. 22-23 Cross-border impact assessment |
| 🇵🇭 Philippines | Data Privacy Act 2012 | 2012-09-08 | NPC supervision, cross-border requires notification |
| 🇮🇩 Indonesia | UU PDP Personal Data Protection Law | 2022-10-17 (pending implementation) | Pending |
| 🇮🇳 India | DPDP Act 2023 | 2023-08-11 (pending implementation) | Cross-border transfer restrictions |
To comply with GDPR Articles 37-39:
| Region | Regulatory Authority | Website |
|---|---|---|
| 🇨🇳 Mainland China | Cyberspace Administration of China (CAC) | www.cac.gov.cn |
| 🇭🇰 Hong Kong | Office of the Privacy Commissioner for Personal Data (PCPD) | www.pcpd.org.hk |
| 🇲🇴 Macau | Office for Personal Data Protection | www.gpdp.gov.mo |
| 🇹🇼 Taiwan | Personal Data Protection Committee | www.pdpc.gov.tw |
| 🇯🇵 Japan | Personal Information Protection Commission (PPC) | www.ppc.go.jp |
| 🇰🇷 Korea | Personal Information Protection Commission (PIPC) | www.pipc.go.kr |
| 🇸🇬 Singapore | Personal Data Protection Commission (PDPC) | www.pdpc.gov.sg |
| 🇲🇾 Malaysia | Jabatan Perlindungan Data Peribadi (JPDP) | www.jpdp.gov.my |
| 🇹🇭 Thailand | Personal Data Protection Committee (PDPC Thailand) | www.pdpc.or.th |
| 🇻🇳 Vietnam | Ministry of Information and Communications / Ministry of Public Security | mic.gov.vn |
| 🇵🇭 Philippines | National Privacy Commission (NPC) | privacy.gov.ph |
| 🇪🇺 EU (general) | European Data Protection Board (EDPB) | edpb.europa.eu |