The short version. Tuloy keeps only what you need to run your booth: your account and what you enter in the app. We never sell your data, show ads, or track you around the web. Your shop data is yours, and you can ask for a copy or ask us to delete it at any time.
Who we are
Tuloy is a point-of-sale app for bazaar, pop-up and convention vendors in the Philippines. An independent developer based in the Philippines builds and runs it ("Tuloy", "we", "us"). Under the Data Privacy Act of 2012 (Republic Act No. 10173), Tuloy is the personal information controller for the data described here.
Send questions, requests or concerns to our Data Protection Officer at aaronjohn.tamayo29@gmail.com.
What we collect
When you create an account
- Your name and email address.
- Your password, stored only as a one-way hash. We never see or keep the password itself.
- The one-time 6-digit codes we email you to confirm your address or reset your password. We store each code only as a hash, and it stops working after 10 minutes.
- Your plan (Libre or Pro), which decides which features your account has. We store no payment details: Tuloy doesn't take payments yet.
- If you sign in with Google: the name, email address and profile photo that Google shares with us. We never see your Google password.
When you use the POS
- Your shop details, products, variants, prices and stock.
- The product photos and the booth logo you add. Tuloy shrinks each one on your phone before uploading it to our own storage server, and only your account can load them.
- Your events: name, venue, dates, opening cash, and a closing cash count if you gave one.
- Your sales: items, amounts, discounts, the payment method you tag (Cash, GCash, Maya or QR Ph), and voids.
- The e-wallet QR images you upload so buyers can pay you.
- If you use Padala boxes (consignment): the box's name, the cashier's cut, the pieces packed and their prices, which booths redeemed it, and the remit slips (what buyers paid for those pieces each day, who marked a slip sent and when it was received).
- If you turn on notifications: the address your browser gives us to reach it (a push subscription). You can turn them off on Profile at any time.
Automatically, to keep your account secure
- The IP address and browser details (user agent) of each signed-in session.
- Essential cookies that keep you signed in. See the Cookie Policy.
- Server logs. Every request to our server writes one line: the date and time, which screen or endpoint was asked for, whether it worked, how long it took, your IP address, and your user id if you were signed in. If something failed, the line also keeps your browser details. It never holds your password, an email code, or anything you typed into the app. We read these only to fix faults and to spot abuse such as password guessing.
What we don't collect
- Your buyers' personal data. Tuloy records what sold and how it was paid, not who bought it.
- Card numbers, bank details or e-wallet logins. Tuloy never handles money: buyers pay you directly, and you tag the method.
- Your location, contacts, photo library, or anything else on your device that you don't choose to upload.
- Analytics, advertising IDs or tracking pixels.
How we use it, and why we're allowed to
| What we do | Why | Legal basis (RA 10173, Sec. 12) |
|---|---|---|
| Create and run your account, and sign you in | So you can use Tuloy | Contract with you |
| Email you a code to confirm your address or reset your password | So only you can get into your account | Contract with you |
| Store and sync your shop data, events and sales | This is the service | Contract with you |
| Show reports and end-of-event tallies | This is the service | Contract with you |
| Keep sessions secure, stop abuse, fix bugs | To protect you and the service | Legitimate interest |
| See totals across Tuloy and each shop's sales totals | To run, fix and improve the service | Legitimate interest |
| Back up the database every night | So a server failure never loses your sales | Legitimate interest |
| Email you about your account or changes to our policies | You need to know | Contract with you |
| Answer lawful requests from authorities | The law requires it | Legal obligation |
We don't use your data for advertising, we don't sell it, and we don't build profiles about you. We make no automated decisions about you that have legal or similar effects.
Where your data lives
- On your device. Tuloy is offline-first. Your shop data and sales are saved in your browser's storage on your phone, tablet or laptop, so selling works with no signal.
- On our server. When you're online, your data syncs to our database. A cloud provider hosts it in the United States or the European Union, so your data is transferred outside the Philippines. We stay responsible for it wherever it's stored, and we only use providers that are bound to protect it at a level comparable to the Data Privacy Act.
- In our backups. Every night we save a copy of the database to private, encrypted storage at Amazon Web Services (AWS), away from our server, so a server failure can't lose your sales. This is also a transfer outside the Philippines.
Who we share it with
We don't sell or rent your personal data. We share it only with:
- Our hosting provider, which runs the server and database that store your synced data and backups. It processes data only on our instructions.
- Amazon Web Services (AWS), which stores our nightly database backups. It keeps them only on our instructions and can't use them for anything else. AWS is based in the United States, so this is a transfer outside the Philippines.
- Resend, our email provider, which delivers the codes for confirming your email and resetting your password. It receives your email address and the code, and uses them only to send that email. Resend is based in the United States, so this is a transfer outside the Philippines.
- Better Auth, which runs the dashboard we use to manage accounts and watch sign-in activity. It receives your name, email, user id, and the IP address, rough location and browser details of sign-ins and other account events, and uses them only to show them to us. Better Auth is based in the United States, so this is a transfer outside the Philippines.
- Booths you link with through a Padala box, only what the box needs. A booth that redeems your claim tag sees your booth name, the pieces you packed (names, photos, prices) and how many are left. As the owner you see each cashier by the name on their Tuloy account (or, if it has none, the part of their email before the @), how many pieces each sold, and the remit slips; every booth on the box sees the combined slip, including each cashier's name and what they sold that day. No one sees anything else of the other's shop.
- Your browser's push service (for example Google's for Chrome on Android, or Apple's), only if you turn on notifications. It delivers each notification to your device. The message is encrypted so the push service can't read it, and we keep amounts out of it.
- Google, only if you choose to sign in with Google. Google's privacy policy covers what happens on its side.
- Authorities, only when the law requires it, and only what the request lawfully covers.
If Tuloy is ever sold or merged, your data would move to the new owner under this same policy, and we'd tell you first.
Your buyers' data
Tuloy isn't designed to hold data about your buyers. If you type a buyer's personal details into a note or a product name, you're the controller of that data, and we process it only to store and sync it for you.
How long we keep it
- Account and shop data: for as long as you have an account.
- After you delete your account: we remove your data from the live database within 30 days. Copies in backups age out within 30 days after that.
- Nightly backups: 14 days, then deleted automatically.
- Session records (IP address and browser details): until the session ends or expires.
- Server logs: they sit on the server until they're rotated away by newer ones or the app is updated, which is days, not months. They're never copied into a backup or sent anywhere else.
- Email codes: until you use them, and no longer than 10 minutes.
- On your device: until you clear Tuloy's site data or uninstall it. Clearing it also deletes any sales that haven't synced yet, so sync first.
We keep something longer only if the law requires it, and only for as long as it requires.
How we protect it
- All traffic is encrypted with HTTPS.
- Passwords are hashed. Session cookies are HTTP-only and sent only over secure connections.
- Every shop's data is kept separate on the server. One account can never read or change another's.
- Only the person who runs Tuloy can access the server, and only their account can open the admin overview. It shows each shop's name, owner email and sales totals, never the items sold.
No system is perfectly secure. If a breach puts your personal data at risk, we'll notify you and the National Privacy Commission within 72 hours of learning about it, as NPC rules require.
Your rights
Under the Data Privacy Act, you have the right to:
- Be informed about how your data is collected and used. This page is that notice.
- Access your data and get a copy of it.
- Correct data that is wrong or out of date.
- Object to processing, or withdraw consent where we relied on it.
- Erasure or blocking: ask us to delete your data or stop using it.
- Data portability: get your data in a common electronic format. You can also export your sales as a CSV file from Reports in the app, any time.
- Damages, if you're harmed by inaccurate, incomplete, outdated, false or unlawfully obtained data.
- Complain to the National Privacy Commission.
To use any of these rights, email aaronjohn.tamayo29@gmail.com from the address on your account. We may ask you to confirm it's you. We'll reply as soon as we can, and within 30 days at the latest.
Children
Tuloy is made for running a business and isn't directed at children. If you believe a child gave us personal data without a parent or guardian knowing, email us and we'll delete it.
Changes to this policy
When this policy changes, we'll update the date at the top. If a change affects how we use your data in a meaningful way, we'll tell you by email or in the app before it takes effect.
Contact
Data Protection Officer: aaronjohn.tamayo29@gmail.com.
If you're not satisfied with our answer, you can contact the National Privacy Commission.