Controller
TallyHub Gh
Products Covered
Landing, Dashboard, POS, APIs
Response Target
< 2 business hours
Scope
This policy applies to our websites, product interfaces, APIs, customer support channels, and business operations where TallyHub Gh determines the means and purpose of processing personal and business data.
Information We Collect
We collect account and profile details (such as name, email, organization, and role), operational records you create in the app (inventory, transactions, customers, locations, reports), billing and subscription details, and technical/security metadata (such as device, IP address, and user-agent) necessary to secure and run the service.
- Account data: names, email, role, tenant/workspace metadata.
- Commercial records: products, stock, invoices, orders, customer profiles.
- Support data: ticket/contact information and communication history.
- Telemetry/security data: session events, IP, user-agent, activity logs.
How We Use Information
- Provide core product features across web, POS, onboarding, reporting, and support.
- Authenticate users, enforce tenant access, and prevent abuse or unauthorized activity.
- Process payments, invoices, and subscription lifecycle events.
- Maintain service reliability, auditability, fraud detection, and security monitoring.
- Respond to support requests and product inquiries.
Legal Bases for Processing
- Contract: to provide the services you request.
- Legitimate interests: security, product improvement, fraud prevention.
- Legal obligations: accounting, tax, and regulatory requirements.
- Consent: where local law requires it (for example certain marketing communications).
Payments and Billing Data
TallyHub Gh integrates with Paystack for payment processing and subscription operations. Payment-related records may include plan metadata, invoices, references, authorization metadata, billing contact details, and transaction status needed for reconciliation, support, and compliance.
Security and Access Controls
We use JWT-based authentication, tenant-aware authorization controls, password hashing, verification flows, and audit/security event logging. Refresh-token cookie handling uses strict cookie controls in production. No system can be guaranteed 100% secure, but we continuously improve safeguards.
Data Sharing
We share data only as needed to deliver services, such as payment processing providers, cloud/storage providers, and selected messaging/integration channels you use. We do not sell your personal data.
When third parties process data on our behalf, they are contractually required to protect it and use it only for permitted service purposes.
International Transfers
Your information may be processed in countries outside your own. Where required, we implement contractual and organizational safeguards designed to maintain equivalent protection levels.
Retention
We retain data for operational, legal, accounting, and security purposes. Some records have explicit expiry or cleanup logic (for example session artifacts, temporary tokens, and stale notification subscriptions), while core business records are retained per tenant lifecycle and legal obligations.
Your Privacy Rights
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, port, or object to processing of your personal data. You may also lodge a complaint with your local supervisory authority.
Your Choices
You may request access, correction, or deletion where applicable, subject to legal and contractual requirements. Account administrators are responsible for accuracy and lawful use of business/customer data entered into the platform.
Children's Data
TallyHub Gh is designed for business users and is not directed to children. We do not knowingly collect personal information from children where prohibited by law.
Policy Changes
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date and, where appropriate, by additional notice in-product or by email.
Contact
For privacy questions or requests, contact us through /contact.