Privacy Policy
What ChequeKo collects, what it deliberately does not collect, and what you can do about it.
Draft — pending legal review. This document describes how ChequeKo is built and operated, but it has not yet been reviewed by counsel. It must be reviewed against Philippine data privacy and consumer law before public launch. The few measures still marked Planned are not live yet; everything else described here is.
1. What we never collect
ChequeKo has no field, form, or database column for any of the following, so we cannot hold them:
- Bank usernames, passwords, PINs, or one-time passwords.
- Full bank account numbers. An optional last four digits is the maximum.
- Signature images or signature data of any kind.
- Payment card details. ChequeKo is free and asks for no payment information.
- MICR or routing information.
2. What we collect
Account information: your email address, your display name, your account preferences, and the account identifier Google uses for you. ChequeKo never holds a password, because sign-in is delegated to Google.
Cheque data you enter: payee names, issue dates, amounts, memos, and your own internal reference fields such as voucher number, category, project, and department. This is stored so your cheque register works. It is yours, it is isolated to your account, and it is never used for advertising.
Setup data: the cheque templates, printer profiles, and payees you save.
Operational data: print job counts and timestamps, sign-in sessions, and security events such as rate limit trips. IP addresses and browser user-agent strings are stored only as salted one-way hashes, so the abuse controls cannot double as a visitor log.
3. Guest sessions
If you use ChequeKo without an account, we set a signed, HTTP-only cookie to identify your anonymous session so the free print allowance can be enforced on our servers. We store only a hash of that cookie's value. We do not fingerprint your device. If you later sign in, your drafts, templates, printer profiles, and payees move to your account and the guest session is retired.
4. Calibration images stay on your device
If you use a photograph or scan of your own cheque as an alignment overlay, it is processed in your browser only. There is no upload endpoint for it. It is discarded when you leave the page, never published or converted into a shared template, and never used for analytics or AI training. We ask you to cover your account number and MICR line before scanning.
5. What is kept out of logs and analytics
Payee names, cheque amounts, memo text, account nicknames, and calibration images never appear in application logs, analytics events, or administrative reporting. Analytics is limited to counts and aggregates.
6. What administrators can see
Haturiko administrators manage bank names, announcements, operational limits, and abuse controls. Administrative queries exclude cheque content entirely — administrators do not see your payee names, amounts, memos, account nicknames, or calibration images, and the API will not return those fields to an administrative endpoint even if a screen asked for them.
We keep a security log of events affecting accounts — sign-ins, sign-outs, exports, deletions, rate-limit trips, and administrative actions. It records that something happened and to which account, never what that account was doing with a cheque. It is deleted automatically after 180 days.
7. Sharing
We do not sell your data and we do not use it for advertising. We share data only with service providers necessary to operate ChequeKo — and where required by law. Signing in sends you to Google, which handles the credential; ChequeKo receives back only your email address, name, and a stable account identifier. Our email delivery provider receives your email address in order to send account-security notices — a new sign-in, an account deletion, a data export.
We do not email cheque details: no payee, no amount, no memo, ever. Mail is the one channel that reliably ends up in an inbox someone else can read, and none of that information helps a security notice do its job. Any message claiming to be from ChequeKo that lists cheque details, or asks for a bank login, PIN, or OTP, is not from us.
8. Retention
Anonymous guest session records are deleted automatically 90 days after they are created, and the templates, printer profiles, and cheque details saved against them are deleted with them — sign in before then if you want to keep that work. Cheque records on an account are kept while the account is active, because a cheque register is only useful as a history. Security events are retained for a limited period for abuse investigation.
9. Your rights
Under the Philippine Data Privacy Act you may access, correct, and erase your personal data, and object to its processing. You can export everything ChequeKo holds for you and permanently delete your account from Account Settings, without contacting us and without waiting for anyone to approve it.
10. Security
Authorisation is enforced on the server for every request, and each account's records are isolated from every other account's. ChequeKo holds no passwords at all — sign-in is delegated to Google, so there is nothing to hash and nothing to leak. Session cookies are HTTP-only, Secure, and SameSite=Lax, and every state-changing request additionally carries a CSRF token bound to that session. Session tokens are stored only as one-way hashes, so nothing in our database can be replayed as a credential. See the Security page for detail.
11. Contact
Privacy questions can be raised through the Help Center. Haturiko Services Inc. is the data controller for ChequeKo.