Privacy

Privacy Policy

What Tumblo collects, why we collect it, and the control you keep over your shop's data and your customers' data.

Last updated 11 August 2026

1. Overview

Tumblo is a laundry shop management platform operated by AVIT.DEV Software Development Services ("AVIT.DEV", "we", "us"). This policy explains what personal data we collect, why we collect it, who we share it with, and the choices you have.

We follow the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), its implementing rules, and the issuances of the National Privacy Commission. If anything here is unclear, email privacy@tumblo.app and we will explain it in plain language.

Short version: we collect what we need to run your shop's account, we do not sell your data, and we never use your customer list to market anything of our own.

2. Two kinds of data, two roles

It matters whose data we are talking about, because our responsibility differs.

Your data — we are the controller
The account details of you and your staff, your store profile, your billing history, and the technical logs of your use of Tumblo. We decide how this is handled, and this policy governs it.
Your customers' data — we are the processor
The customer names, phone numbers, addresses, orders, and payments you record in Tumblo. You are the personal information controller. We only process it to run the service for you, on your instructions. You are responsible for collecting it lawfully and for telling your customers how your shop uses it.

The Data Privacy Act requires the arrangement between a controller and its processor to be set down in writing. Where we act as your processor, we commit to:

  • Process your customers' data only to provide Tumblo to you, and only on your instructions.
  • Keep it confidential and apply the security measures described in this policy.
  • Use only the providers listed below, and hold each of them to the same duties.
  • Help you answer a data subject's request and meet your own breach-notification duty.
  • Return or delete the data when our service to you ends, except where we must keep a copy by law.

3. What we collect

Account details
Your first name, last name, email address, role, and the stores you have access to. Sign-in credentials are held by our authentication provider, Clerk — we never see or store your password.
Store profile
Store name, address, phone number, logo, receipt settings, pricing, service menu, and operating preferences.
Operational records
The orders, customers, payments, expenses, cash movements, inventory, deliveries, form answers, and campaign history you enter or generate while using Tumblo.
Billing information
Your plan, billing cycle, subscription status, and payment history. Card details are collected and stored by our payment provider, not by us — we receive only the result of a charge and the last identifying details needed for receipts.
Technical data
IP address, browser and device type, pages visited, timestamps, and error diagnostics. These come in automatically when you use the site and are used to keep it secure and working.
Messages you send us
The content of your emails to our support, privacy, security, and legal inboxes, so we can answer and keep a record of the request.

We do not knowingly collect sensitive personal information as defined by the Data Privacy Act, and Tumblo has no field that asks for it. Please do not type such information into free-text notes.

4. How we use it

  • To create and run your account, your stores, and the roles you assign.
  • To provide the features you use — taking orders, tracking loads, recording payments, computing reports.
  • To charge you for a paid plan, issue receipts, and manage renewals and SMS credits.
  • To send service messages such as invitations, billing notices, security alerts, and important changes. These are not marketing and you cannot opt out of them while you have an account.
  • To give you support when you ask for it.
  • To keep Tumblo secure — detecting abuse, investigating incidents, and enforcing our Terms.
  • To understand which features are used so we can improve them, using aggregated figures rather than reading individual records.
  • To comply with tax, accounting, and other legal obligations.

Under Section 12 of the Data Privacy Act, we rely on the contract we have with you, our legitimate interests in operating and securing the service, your consent where we ask for it, and our legal obligations. We do not sell personal data, and we do not use your data to train advertising models.

5. The customer data you enter

When you add a customer to Tumblo, you decide what to record. We store it, keep it scoped to your store, and make it available only to the accounts you have given access. We do not contact your customers on our own behalf, and we do not share your customer list with anyone.

Because you are the controller of that data, you are responsible for having a lawful basis to collect it, for telling your customers what you do with it, and for honouring their requests. If a customer asks you to delete their record, you can do that yourself in the app. If you need our help, email privacy@tumblo.app.

6. Text messages to your customers

If you turn on SMS notifications or run a campaign, we pass the recipient's mobile number and your message to Semaphore, a Philippine SMS gateway, so it can be delivered. We keep a delivery record so you can see what was sent and so credits are charged correctly.

You are responsible for the content of every message and for having a lawful basis to send it. Under the Data Privacy Act that basis is usually the customer's consent, and it has to be given freely — so give recipients a way to opt out and stop messaging anyone who asks you to.

7. Who we share data with

We share personal data only with the service providers that Tumblo runs on, each bound to process it on our instructions and to protect it:

Clerk
Authentication and user accounts — sign-in, sessions, invitations, and password handling.
Neon
The managed PostgreSQL database where your store records are stored.
Vercel
Application hosting, request logging, and Vercel Blob storage for uploads such as store logos.
Lemon Squeezy
Payment processing, subscriptions, and invoices for paid plans. They handle card data; we do not.
Semaphore
Delivery of the SMS notifications and campaigns you choose to send.

We may also disclose data when the law requires it, when we must protect our rights or someone's safety, or if the business is involved in a merger or acquisition — in which case we will notify you and the new owner remains bound by this policy. Aside from these, we do not share, rent, or sell personal data.

8. Where your data is stored

Some of the providers above operate servers outside the Philippines. When your data is processed abroad, we remain accountable for it under the Data Privacy Act and rely on contractual protections with each provider to keep the same level of protection wherever it is held.

9. How long we keep it

  • Store records are kept for as long as your account is active, because your business needs its own history.
  • Deleting a record in the app hides it from your screens straight away and marks it as deleted. We keep the marked record in the database so you can recover from a mistake and so your past reports still add up — tell us at privacy@tumblo.app if you need it erased for good.
  • After you close an account, we keep your data for 30 days so you can ask for a copy or change your mind, then erase it.
  • Backups held by our database provider may keep copies for a short period afterwards before they rotate out.
  • Billing records and other documents we must keep by law are retained for the period the law requires, even after your account closes.

10. How we protect it

  • All traffic is encrypted in transit with HTTPS, and data is encrypted at rest by our database and storage providers.
  • Passwords are hashed and managed by our authentication provider — nobody at AVIT.DEV can read them.
  • Every query is scoped to your store, and role-based permissions limit what each account can open.
  • Publicly shareable links, such as customer receipts, are signed so they cannot be guessed or altered.
  • Access to production systems is limited to the people who need it to run and support the service.

No system is perfectly secure. If a breach affects personal data we hold as controller, we will notify the National Privacy Commission and the people affected within 72 hours of knowing about it, as the Data Privacy Act's rules require. If it involves the customer data you control, we will tell you promptly so you can make your own notification on time. To report a vulnerability or a suspected compromise, email security@tumblo.app.

11. Your rights

Under the Data Privacy Act you have the right to:

  • Be informed about how your personal data is processed.
  • Access the personal data we hold about you.
  • Correct anything inaccurate or out of date.
  • Object to processing, and withdraw consent where we relied on it.
  • Have your data erased or blocked when there is a lawful ground for it.
  • Receive a copy of your data in a portable format.
  • Be indemnified for damages caused by inaccurate, false, or unlawfully obtained data.

To exercise any of these, email privacy@tumblo.app. We will check who you are and reply as quickly as we can — normally within 15 working days — or tell you why we need longer. If you are unhappy with our response, you may lodge a complaint with the National Privacy Commission at privacy.gov.ph.

If you are a customer of a laundry shop that uses Tumblo, please contact that shop first — they control your records. Tell us and we will help route your request.

12. Cookies

Tumblo uses only the cookies it needs to work: session cookies from our authentication provider to keep you signed in, and small preference cookies that remember choices such as your active store and view settings.

We do not use advertising cookies, tracking pixels, or third-party analytics that follow you across other websites. Blocking essential cookies in your browser will stop you from staying signed in.

13. Children

Tumblo is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, email privacy@tumblo.app and we will delete it.

14. Changes to this policy

We update this policy when our practices or providers change. The date at the top always shows the current version. For material changes we will notify you by email or inside the app before they take effect.

15. Contact us

AVIT.DEV Software Development Services is the entity responsible for Tumblo. Our Data Protection Officer can be reached at privacy@tumblo.app.

privacy@tumblo.app
Data privacy requests, questions about this policy, and Data Protection Officer matters.
security@tumblo.app
Vulnerability reports, suspected breaches, and account compromise.
support@tumblo.app
Help with your account, billing, and day-to-day use of the app.
legal@tumblo.app
Contracts, formal notices, and questions about our Terms of Service.