← Claify
PrivacyEULA

Privacy Policy

Effective date: 9 July 2026 · Last updated: 9 July 2026

This Privacy Policy explains how Homeauto Solution Pte Ltd("Claify", "we", "us", "our") collects, uses, discloses, and protects personal data when you use the Claify accounting platform at claify.homeauto.sgand related services (the "Service"). We are committed to complying with the Singapore Personal Data Protection Act 2012 ("PDPA") and, where applicable, the EU General Data Protection Regulation ("GDPR").

1. Data we collect

Account data

  • Name and email address (including via Google sign-in, if you choose it)
  • Password (stored only as a cryptographic hash — we never see or store your plain password)
  • Business name, GST registration status, and organisation settings

Business and financial data you enter

  • Contacts (your customers and vendors): names, emails, addresses
  • Quotations, invoices, payments, receipts, and journal entries
  • Bank transaction data you import (e.g. CSV exports from DBS, OCBC, UOB)
  • Documents you upload (e.g. receipts and supporting files)

Data from connected accounting platforms

If you connect a third-party accounting platform such as Xero or QuickBooks Online, we access the accounting data you authorise (e.g. chart of accounts, invoices, contacts, transactions) strictly to provide the Service. Connection tokens are encrypted at rest with AES-256-GCM. You can disconnect a platform at any time, which revokes our access.

Payment data

Card and payment processing is handled by Stripe. We do not receive or store your full card details — we receive only confirmation of payment and limited metadata (e.g. amount, status, reference).

Technical data

  • Log data: IP address, browser type, pages visited, timestamps
  • Cookies strictly necessary to keep you signed in and secure the Service

2. How we use your data

  • To provide, operate, and maintain the Service (invoicing, accounting records, GST computation, reports)
  • To send transactional emails you initiate or configure (e.g. invoices, receipts, overdue payment reminders) via our email provider
  • To authenticate you and secure your account (including optional two-factor authentication)
  • To process payments and subscriptions
  • To respond to support requests
  • To comply with legal obligations, including Singapore tax and accounting record-keeping requirements

We do not sell your personal data. We do not use your accounting data for advertising.

3. Who we share data with

We share data only with service providers needed to run the Service:

ProviderPurposeLocation
SupabaseDatabase, authentication, and file storageSingapore (ap-southeast-1)
VercelApplication hostingGlobal edge network
StripePayment processingGlobal
ResendTransactional email deliveryGlobal
GoogleOptional sign-in (OAuth)Global
Xero / Intuit (QuickBooks)Optional accounting platform connections you authoriseGlobal

We may also disclose personal data where required by law, regulation, or a valid request from a public authority.

4. Where your data is stored

Your account and accounting data are stored in Supabase's Singapore region (ap-southeast-1). Where a provider processes data outside Singapore, we ensure a comparable standard of protection as required by the PDPA's transfer limitation obligation.

5. How we protect your data

  • Encryption in transit (TLS) for all connections
  • Encryption at rest for stored data; third-party platform tokens encrypted with AES-256-GCM
  • Row-level security so each organisation can only access its own records
  • Passwords and API keys stored as cryptographic hashes (bcrypt)
  • Optional two-factor authentication (TOTP)
  • Private, access-controlled document storage

6. How long we keep your data

We retain your data for as long as your account is active. Accounting records may be retained for up to 5 years after the relevant financial year, consistent with Singapore statutory record-keeping requirements (e.g. under the Income Tax Act and GST Act), even after account closure. Other personal data is deleted or anonymised within a reasonable period after your account is closed.

7. Your rights

Under the PDPA (and the GDPR, where it applies), you may:

  • Request access to the personal data we hold about you
  • Request correction of inaccurate or incomplete personal data
  • Withdraw consent to our collection, use, or disclosure of your personal data
  • Request deletion of your account and associated personal data (subject to legal retention requirements)
  • Export your accounting data

To exercise any of these rights, contact our Data Protection Officer at support@claify.app. We will respond within the timeframes required by the PDPA.

8. Cookies

We use only cookies that are strictly necessary for the Service to function — session authentication and security. We do not use advertising or cross-site tracking cookies.

9. Children

The Service is intended for business use and is not directed at individuals under 18. We do not knowingly collect personal data from children.

10. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified via the Service or by email. The "Last updated" date above reflects the latest revision. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.

11. Contact us

Data Protection Officer
Homeauto Solution Pte Ltd
Email: support@claify.app

© 2026 Claify · A Homeauto Solution Pte Ltd projectsupport@claify.app