1. Data we collect
When you use Luuko, we collect:
- Account data — business name, Client Code, SSM number, name, email, phone number, password (stored as a bcrypt hash — we cannot read it).
- Your business operations data — products, POS sales, storefront orders, staff you invite, module settings.
- Your storefront customers' data — name, email and orders of customers who buy through your public storefront. You are the controller of this data; Luuko processes it on your behalf.
- Technical data — audit logs (actions, IP address, browser) for security and support.
2. How we use it
- To provide and improve the Luuko service.
- To send operational email (OTP codes, staff invites, notifications) — not marketing without consent.
- Security: abuse detection, audit logs, sign-in rate limiting.
- Legal compliance (e.g. LHDN e-Invoice where relevant).
3. Storage & security
Data is stored in a managed database (Supabase/PostgreSQL) over an encrypted connection (TLS). Passwords are hashed; sessions are protected by httpOnly cookies; every request is isolated by tenant so your business data cannot be accessed by another business.
4. Data sharing
We do not sell your data. Data is only shared with the infrastructure providers required to run the service (hosting, database, email delivery) and with authorities when required by law.
5. Your rights (PDPA)
- Access & correction — update your information in Settings; request a full copy of your data via Export Data in your business Settings.
- Deletion — contact us to close your account and delete your data.
- Withdraw consent — possible at any time; some features may be affected.
6. Cookies & sessions
Luuko uses essential cookies only: the sign-in session (30 days), a "remember me" token, and a CSRF security token. There are no advertising or third-party tracking cookies.
7. Contact us
Any privacy questions: luuko@skrichgroup.com.