Legal

Privacy policy.

Last updated

Contents
  1. The short version
  2. Who we are
  3. What this policy covers
  4. What we collect
  5. Where it comes from
  6. What we use it for
  7. Cookies
  8. The providers we use
  9. Where your data goes
  10. Your customers’ data
  11. How we protect it
  12. How long we keep it
  13. Your rights
  14. Emails from us
  15. Children
  16. Changes to this policy
  17. Contact

The short version

Luca holds your books, so we hold data that matters. We collect what an accounting service needs and nothing more. We do not sell personal data, we do not run ads, and your customers’ details are used for exactly one thing: keeping your books. Your documents are stored in Singapore. We count visits to our public website using analytics we run on our own server in Singapore — no cookies, no third-party analytics service, nothing that identifies a person — and there is no tracking of that kind inside the app at all; the only cookies we set are the ones that sign you in and keep you signed in. The rest of this page is the detail behind those sentences — and the person accountable for all of it is reachable at dpo@luca.pro.

Who we are

Luca is operated by LUCA TECH PTE. LTD. (UEN 202633929H), a company incorporated in Singapore. Under the Personal Data Protection Act (PDPA), we are the organisation responsible for the personal data described on this page. Our Data Protection Officer is reachable at dpo@luca.pro — a monitored address whose job is answering exactly the questions this policy raises.

What this policy covers

This policy covers the luca.pro website, the application at app.luca.pro, and our API. It does not cover services you connect to Luca or follow links out to — Google, Stripe and the rest have their own policies, which apply when you use them. And if you are reading this as someone whose data was entered into Luca by a business you deal with, the section on your customers’ data below is written for you.

What we collect

  • Your account: name, email address, and a password we store only as a hash. Sign in with Google and we receive your name and email from Google instead.
  • Your business records: the companies, invoices, bills, quotations, contacts, bank entries and journal lines you and your team enter. These will include personal data about your customers, suppliers and staff — that is the nature of books.
  • Documents you upload: bills, receipts, statements.
  • Payment details: your card goes directly to Stripe at signup and for Pro billing. Full card numbers never touch our servers — we hold only what Stripe returns: a token, the card’s last four digits, and its expiry.
  • Server logs, which include IP addresses and basic browser information, kept for security and troubleshooting. When something breaks, an error report records the page you were on and what your browser sent with the request.
  • Website visit statistics: when you read the public website at luca.pro, we record the page visited, the site you arrived from, an approximate location worked out from your connection and no finer than a city, and the type of browser and device — counted by analytics running on our own server, which sets no cookies and holds nothing that identifies you as a person. None of this exists in the app at app.luca.pro.
  • Records the product keeps in order to run: how many bills AI capture has processed for your entity, which is how that feature is metered and billed, and an activity trail of document actions. These exist to run and bill the product, not to study how you use it.
  • Support conversations: whatever you send to hello@luca.pro stays attached to the thread so we do not ask you to repeat yourself.
  • What we deliberately do not collect: NRIC numbers. We never ask for them, and we ask you not to store them in Luca either — the PDPC restricts their collection, and bookkeeping does not need them.

Where it comes from

  • Mostly from you and your team, directly: registration, the records you enter, the documents you upload.
  • From Google, if you choose Google sign-in or connect Gmail — limited to what the connection needs.
  • From Stripe, as payment confirmations and card metadata.
  • Automatically, as you use the product: the server logs and the operational records above.
  • We do not buy data about you, enrich your profile from data brokers, or scrape anything.

What we use it for

  • Running Luca: hosting your books, generating your reports, delivering your invoices.
  • Billing: Pro subscriptions and AI credit top-ups, through Stripe.
  • Verifying you are a real business at signup — this is what the card check on the Free plan is for. It never results in a charge on Free.
  • Security and abuse prevention: spotting compromised accounts, stopping spam senders, enforcing fair use.
  • Support: answering you, with your history in front of us.
  • Improving the product: what you tell us directly, in support conversations and feedback.
  • Improving the public website: the visit statistics tell us which pages actually get read and where visitors arrive from, so that luca.pro does a better job of explaining what Luca is. They are never joined to an account and never used to build a picture of a person — they tell us about pages, not about people.
  • Meeting legal obligations: tax, accounting and corporate law leave us no choice about some retention.
  • Under the PDPA these uses rest on your consent or on the specific grounds the Act provides. Two things we never do: sell personal data, or use your data for third-party advertising. There are no ad networks in Luca.

Cookies

The only cookies we set are the ones that sign you in and keep you signed in. There are no advertising or tracking cookies on this site or in the app, and our website analytics use no cookies at all — which is why nothing on this site asks you to accept any.

  • Sign-in session cookies, set by app.luca.pro — essential; the app cannot work without them. They expire with your session.
  • A CSRF protection cookie (XSRF-TOKEN) — essential; it protects your session from forged requests.
  • Stripe sets its own cookies, which it uses to detect fraud. They appear wherever a card payment is taken or confirmed: signing up, changing your card, upgrading, and confirming a top-up of AI credit. Stripe describes them in its own privacy policy.
  • Nothing we set follows you to other sites.

The providers we use

Luca runs on a short list of providers, each under contract, each receiving only what its job requires:

  • DigitalOcean (Singapore region) — hosts our infrastructure and stores your uploaded documents. Your documents live in Singapore.
  • Stripe (United States) — processes card payments and the signup card verification. Your card details go to Stripe, not to us.
  • Mailgun (United States / EU) — delivers invoice emails and system emails, including mail sent from custom domains you verify.
  • Google (United States) — only if you choose Google sign-in or connect Gmail. Our use of data from Google’s APIs follows the Google API Services User Data Policy, including its Limited Use requirements: Gmail data is used solely to provide the feature you connected — never for advertising, and never sold.
  • One disclosure for completeness: our pages load fonts from Google Fonts, which means your browser makes a standard font request to Google, which includes your IP address.
  • OpenRouter (United States) — used only by the statutory financial statements engine, which sends short excerpts of your ledger (business-activity wording, balance-sheet account names) for phrasing and classification. It never receives your documents or full books.
  • One thing that is deliberately not on this list: AI bill capture. It runs on our own capture service, built and operated by us — the bill documents you submit are not sent to a third-party AI product for extraction.
  • The other thing deliberately not on this list: website analytics. Visits to luca.pro are counted by Umami, analytics software we run on our own server in Singapore — no analytics company receives your visit.
  • Beyond providers, we disclose personal data only: where the law requires it (a court order, or a request a public agency is lawfully entitled to make); to our professional advisers under confidentiality; or, with notice to you, as part of a sale or restructuring of the business.

Where your data goes

Your documents are stored in Singapore, and some providers above process data in the United States or the European Union. Section 26 of the PDPA allows personal data to leave Singapore only when the recipient is legally bound to protect it to a comparable standard — so that is how we arrange it: every provider that touches personal data is under a data processing agreement with contractual safeguards before anything reaches them. The website visit statistics never make that trip at all — they stay on our own server in Singapore.

Your customers’ data

The people who appear in your books — your customers, your suppliers, your staff — did not sign up to Luca. You entrusted us with their details so we can keep your records, and that defines the entire boundary: their data is used to run your books, and for nothing else. It never receives marketing from us, and never goes anywhere except the providers listed above, in service of your books.

Under the PDPA, you are responsible for having the right to store their data in Luca. If one of them asks you what is held about them, or asks you to correct it, we will help you answer — most of it you can view and edit directly, and dpo@luca.pro covers the rest.

How we protect it

  • Everything moves over encrypted connections (HTTPS) — between your browser and Luca, and between Luca and every provider above.
  • Passwords are stored only as hashes. Email sign-up is verified with one-time codes.
  • Inside your account, roles and permissions control who on your team sees what. Inside our team, access is limited to people who need it to do their jobs.
  • Backups are taken so that a failure on our side does not become a hole in your books.
  • No honest company claims to be unhackable, so we will not. What we commit to: if a breach ever puts you at risk, we will notify you and the PDPC as the Data Breach Notification obligations require.
  • Spotted a security problem? Tell us first — hello@luca.pro — and give us a reasonable window to fix it. We are grateful to people who report responsibly.

How long we keep it

  • We keep the records that make your books work, while your account is open and after it closes. Singapore law requires businesses to retain accounting records for five years, and much of what we hold falls under that. It covers your accounting records and account profile, server logs, website visit statistics, error reports (which include your IP address and the page you were on), the AI capture ledger, and the document activity trail.
  • If you want something erased, or want to know exactly what is held about you, write to dpo@luca.pro. We will tell you what exists, item by item, and remove what the law does not require us to keep.

Your rights

  • Access: ask what personal data of yours we hold and how it has been used — you will get a copy.
  • Correction: fix anything inaccurate. Most of your data you can edit yourself, in the app, right now.
  • Withdrawal of consent: withdraw consent to uses of your data with reasonable notice. Some withdrawals have consequences — withdraw consent for data processing entirely and an accounting service has nothing left to run on — and we will tell you what breaks before you decide.
  • Deletion: ask us to delete what the law does not require us to keep.
  • Send any of these to dpo@luca.pro. We respond within 30 days; if a request needs longer, we tell you why and when.
  • If you believe we have fallen short of the PDPA, you can complain to the Personal Data Protection Commission at pdpc.gov.sg. We would genuinely rather hear it from you first — but the right is yours either way.

Emails from us

Some email is part of the service and arrives regardless: security codes, billing receipts, renewal problems, material changes to this policy or the terms and conditions. Product news and tips are different — every one of those carries an unsubscribe link that works the first time. Unsubscribing from news never stops the service emails, because a payment failure you did not hear about is worse than an email you did not want.

Children

Luca is business software. Account holders must be at least 18, and we do not knowingly collect personal data from children. If you believe a child has created an account, tell us at dpo@luca.pro and we will close it.

Changes to this policy

When our practices change, this page changes, and the effective date at the top moves. For material changes — a new category of data, a new provider, a new kind of sharing — we will tell you by email or in the app at least 30 days before they take effect, so the change is never something you discover by rereading a legal page.

Contact

Privacy questions, requests and complaints: dpo@luca.pro — the Data Protection Officer, published here as the PDPA requires. Everything else: hello@luca.pro. On paper, we are LUCA TECH PTE. LTD. (UEN 202633929H), Singapore.

This policy works alongside our terms and conditions, which govern your use of Luca itself.