Privacy Policy
Effective date: 9 July 2026 · Last updated: 12 September 2026
This Privacy Policy explains how HomeAuto Solutions Pte Ltd (UEN 202014984H) ("Claify", "we", "us", "our") collects, uses, discloses, and protects personal data when you use the Claify accounting platform at claify.homeauto.sg and related services (the "Service"). We are committed to complying with the Singapore Personal Data Protection Act 2012 ("PDPA") and, where applicable, the EU General Data Protection Regulation ("GDPR").
1. Data we collect
Account data
- Name and email address (including via Google sign-in, if you choose it)
- Password (stored only as a cryptographic hash — we never see or store your plain password)
- Business name, GST registration status, and organisation settings
Business and financial data you enter
- Contacts (your customers and vendors): names, emails, addresses
- Quotations, invoices, payments, receipts, and journal entries
- Bank transaction data you import (e.g. CSV exports from DBS, OCBC, UOB) or that a connected bank feed delivers
- Documents you upload (e.g. receipts and supporting files)
Data from connected accounting platforms
If you connect a third-party accounting platform such as Xero or QuickBooks Online, we access the accounting data you authorise strictly to provide the Service. From QuickBooks Online we read your chart of accounts, customers and vendors, and open invoices and bills, and we write draft bills that you have asked Claify to create (for example from a scanned receipt); we do not read payroll, payment card, or banking credentials held by the platform. Connection tokens are encrypted at rest with AES-256-GCM and are used only to make the calls you have authorised. You can disconnect a platform at any time from Settings, which stops all further access; you can also revoke Claify from within the platform itself. Data already copied into Claify remains in your organisation until you delete it.
Data from connected bank accounts
If you connect a bank account (OCBC, DBS or UOB), Claify receives statement lines for the accounts you nominate: date, description, amount, and the bank's reference. We never see or store your internet banking password. Depending on the bank, access uses either a login you complete at the bank (OCBC), which issues Claify a short-lived token, or application credentials and a certificate that your company obtains from the bank (DBS, UOB). Tokens and credentials are encrypted at rest with AES-256-GCM. You can remove a bank feed at any time from Bank Accounts.
Data processed by AI features
Some features use a large language model provided by Anthropic (Claude): reading receipts you upload, suggesting an account for a bank transaction, and answering questions you ask Maya, our finance assistant, about your books. Only the content needed for the task is sent (for example the receipt image, or the transaction description and your chart of accounts). Anthropic processes this data under its commercial API terms: it does not use it to train its models and retains it only for a limited period (currently up to 30 days) for abuse monitoring. Claify keeps a record of each AI suggestion and whether you accepted it, so we can report accuracy to you. AI features never change your ledger on their own: every posting, match or settlement happens only after you confirm it.
Payment data
Card and payment processing is handled by Stripe. We do not receive or store your full card details — we receive only confirmation of payment and limited metadata (e.g. amount, status, reference).
Technical data
- Log data: IP address, browser type, pages visited, timestamps
- Cookies strictly necessary to keep you signed in and secure the Service, plus your language and theme preference
- An audit trail of changes to your accounting records (who did what, and when), and plan usage counts (e.g. number of AI uploads this month)
2. How we use your data
- To provide, operate, and maintain the Service (invoicing, accounting records, GST computation, reports)
- To send transactional emails you initiate or configure (e.g. invoices, receipts, overdue payment reminders) via our email provider
- To authenticate you and secure your account (including optional two-factor authentication)
- To process payments and subscriptions
- To respond to support requests
- To comply with legal obligations, including Singapore tax and accounting record-keeping requirements
We do not sell your personal data. We do not use your accounting data for advertising.
3. Who we share data with
We share data only with service providers needed to run the Service:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, and file storage | Singapore (ap-southeast-1) |
| Vercel | Application hosting | Global edge network |
| Stripe | Payment processing | Global |
| Resend | Transactional email delivery | Global |
| Optional sign-in (OAuth) | Global | |
| Xero / Intuit (QuickBooks) | Optional accounting platform connections you authorise | Global |
| OCBC / DBS / UOB | Optional bank feeds you authorise | Singapore |
| Anthropic | AI processing for receipt reading, transaction categorisation and Maya | Global (no training on your data) |
| Telegram | Optional Maya chat channel, only if you link it | Global |
We may also disclose personal data where required by law, regulation, or a valid request from a public authority.
4. Where your data is stored
Your account and accounting data are stored in Supabase's Singapore region (ap-southeast-1). Where a provider processes data outside Singapore, we ensure a comparable standard of protection as required by the PDPA's transfer limitation obligation.
5. How we protect your data
- Encryption in transit (TLS) for all connections
- Encryption at rest for stored data; third-party platform tokens encrypted with AES-256-GCM
- Row-level security so each organisation can only access its own records
- Passwords and API keys stored as cryptographic hashes (bcrypt)
- Optional two-factor authentication (TOTP)
- Private, access-controlled document storage
6. How long we keep your data
We retain your data for as long as your account is active. Accounting records may be retained for up to 5 years after the relevant financial year, consistent with Singapore statutory record-keeping requirements (e.g. under the Income Tax Act and GST Act), even after account closure. When you delete an organisation, its live data is removed immediately and a single encrypted snapshot is retained for 30 days solely so we can restore it if the deletion was a mistake, after which it is purged. Other personal data is deleted or anonymised within a reasonable period after your account is closed.
7. Your rights
Under the PDPA (and the GDPR, where it applies), you may:
- Request access to the personal data we hold about you
- Request correction of inaccurate or incomplete personal data
- Withdraw consent to our collection, use, or disclosure of your personal data
- Request deletion of your account and associated personal data (subject to legal retention requirements)
- Export your accounting data
You can exercise most of these yourself: Settings → Export downloads your accounting data (CSV, Excel, XML), Settings → Organisation lets the owner delete the organisation and every document in it, and Settings → Security deletes your login.
For anything else, contact our Data Protection Officer at dpo@homeauto.sg. We will respond within the timeframes required by the PDPA.
8. Cookies
We use only cookies that are strictly necessary for the Service to function (session authentication and security) and two preference cookies for your chosen language and theme. We do not use advertising or cross-site tracking cookies.
9. Children
The Service is intended for business use and is not directed at individuals under 18. We do not knowingly collect personal data from children.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified via the Service or by email. The "Last updated" date above reflects the latest revision. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
11. Contact us
Data Protection Officer
HomeAuto Solutions Pte Ltd (UEN 202014984H)
Email: dpo@homeauto.sg
General support: support@claify.app