Who we are
Tiybe is an accounting and compliance platform for businesses and practices. This policy applies to the Tiybe marketing website at tiybe.com and explains what happens to personal information you give us there or that the site records while you use it.
Our registered address is:
12, 18th Avenue, Ashok Nagar, Chennai, Tamil Nadu, India
TODO(legal) — Name the legal entity that operates Tiybe, together with its company registration number and GSTIN. This section must identify the data controller by its registered name, not by the product name.
What this policy covers
This policy covers the public website: the pages you can read without an account, the enquiry form on our contact page, and the information your browser sends while you are on those pages.
The Tiybe application is a separate environment with its own sign-in, and the accounting records you keep inside it are your business's data rather than information the website collects.
TODO(legal) — Decide whether one policy covers both the website and the Tiybe application, and state the controller/processor split for data held inside the application: customer records processed on the customer's instructions, versus account and billing data Tiybe determines the purposes for itself.
Information we collect
Information you give us
The contact form is the only place on this website that asks you for anything. It collects:
| What | Why we ask | Required |
|---|---|---|
| Your name | So a reply is addressed to a person. | Yes |
| Email address | To answer your enquiry. This is where our reply goes. | Yes |
| Phone number and its dialling code | To call you back where a call is what you asked for. | Yes |
| Company name | So the reply is written for the kind of business you actually run. | Yes |
| Country | To route the enquiry and to answer in the right currency and tax context. | Yes |
| Your message | The enquiry itself. | Yes |
| Plan interest | Which of the published plans prompted you to write, if any. It is an expression of interest only and commits you to nothing. | No |
Information the site records with your enquiry
When you submit the form, the following is recorded alongside it. None of it is typed by you, so it is set out here in full:
- Where you came from. Campaign parameters in the link you arrived by (
utm_source,utm_medium,utm_campaign,utm_term,utm_contentand a Google click identifier), the referring website, the first page of ours you landed on, and when that first visit happened. This is stored in a cookie on your device and is described under Cookies below. - Which page and which button. The address of the page you submitted the form from, and an identifier for the call-to-action you clicked to get there.
- Anti-spam signals. A hidden form field that only automated software fills in, and how long elapsed between the form appearing and you submitting it. Both exist to tell a person apart from a script.
- Whether your email is a consumer mailbox. A yes/no flag worked out from the domain of the address you gave, so that whoever replies knows what kind of correspondent they are writing to. It never affects whether your enquiry is accepted.
- Your approximate country. Before you type anything, the page asks our own service which country your internet connection appears to be in, purely so the country field starts on the right value. As with any request to a web service, that lookup involves your IP address.
TODO(legal) — Confirm with the platform team whether IP addresses, user agents or server request logs are stored against an enquiry or retained separately, and for how long. List them here if they are.
Information about the Tiybe application
TODO(legal) — Set out what the Tiybe application itself collects: account and user profile records, the accounting data customers upload or connect, support access to a tenant's environment, and audit logging. This must be written with the platform team from the actual schema, not inferred from the website.
How we use your information
Information collected through this website is used to:
- reply to your enquiry, and follow it up where you have asked us to;
- work out which plan or configuration actually fits what you described;
- understand which campaigns and pages produce genuine enquiries, so we know where to keep publishing;
- detect and block automated submissions.
Submitting the contact form does not sign you up to a mailing list. There is no marketing subscription on this site today, and we do not sell or rent your details to anyone.
TODO(legal) — Decide whether enquiry details may later be used for marketing email, and if so, on what basis, with what opt-out, and whether existing enquirers are in scope. Until that is decided, enquiry data is used only to answer the enquiry.
Our basis for using it
Tiybe operates from India and has customers in New Zealand and the Gulf, so more than one data-protection regime is potentially in play depending on where you are.
TODO(legal) — Determine which data-protection regimes apply to Tiybe (India's DPDP Act 2023 for the home market, and whichever of the GDPR/UK GDPR and New Zealand's Privacy Act 2020 apply to overseas customers), and state the lawful basis for each purpose listed above. This page intentionally claims compliance with no regime until that determination is made and signed off.
Who we share it with
We do not sell personal information. It is shared only in the situations below.
Service providers
- Web font hosting (Google Fonts). This site loads its typeface from Google's font servers, so your browser requests those files directly from Google. That request carries your IP address and the usual browser headers.
- Image hosting (Unsplash). Some article images on our blog pages are served from Unsplash rather than from our own servers, with the same consequence.
- Payment processing (Razorpay). Subscription payments are taken through Razorpay. Card, UPI and net-banking details are entered with Razorpay and processed by them as our payment processor — Tiybe does not receive or store your card details. See our Terms for how billing works.
TODO(legal) — Complete the processor list with the platform team: hosting and cloud provider (and the region data is stored in), transactional email provider, error and performance monitoring, and any CRM or helpdesk that receives enquiries. Decide whether to name each provider or list categories, and keep the list current.
Other situations
We may also disclose information where we are required to by law, by a court or by a regulator, and to our professional advisers where they need it to advise us.
TODO(legal) — Decide the change-of-control wording: what happens to personal information in a merger, acquisition or sale of assets, and whether affected individuals are notified.
How long we keep it
TODO(legal) — Set and publish retention periods, and make sure something actually enforces them. At minimum: unconverted enquiries from the contact form, enquiries that became customers, account and billing records (which have statutory minimums of their own), and server logs. A period cannot be published until deletion is implemented.
One retention period is already fixed and can be stated: the attribution cookie described under Cookies expires 90 days after it is first set.
How we protect it
This website is served over an encrypted connection (HTTPS), and enquiries are submitted to our own API rather than to a third-party form service.
TODO(legal) — Describe the actual security measures (encryption at rest, access control and least privilege, backup and recovery, vendor review, and the incident and breach-notification process, including the timeframe for notifying affected people). Do not claim SOC 2, ISO 27001 or any other certification unless Tiybe holds it and can produce the report.
Your rights and choices
You can ask us for a copy of the personal information we hold about you, ask us to correct it if it is wrong, or ask us to delete it. Write to sales@tiybe.com and your request will be passed to the right person.
TODO(legal) — Enumerate the rights that actually apply once the applicable regimes are settled (access, correction, erasure, objection, portability, withdrawal of consent, grievance redressal under the DPDP Act), the response time committed to, how identity is verified, and how someone complains to a regulator if they are unhappy with the outcome.
Cookies and similar technologies
This site sets one cookie of its own:
| Cookie | Purpose | Expires |
|---|---|---|
tiybe_attribution | Records how you first reached the site — campaign parameters from the link, the referring site, the page you landed on, and when. It is written once and not overwritten on later visits, and it travels with an enquiry so we can tell which campaigns produce real conversations. It holds no name, no identifier and no device fingerprint. | 90 days |
This site runs no analytics, advertising or session-recording tags. There is no Google Analytics, no tag manager and no advertising pixel on tiybe.com today. If that changes, this section will be updated before the tag is added.
Clearing cookies in your browser removes the cookie above. The site works normally without it; we simply lose the ability to attribute your enquiry.
TODO(legal) — Decide whether a consent mechanism is required for visitors in jurisdictions that demand one, and if so, make sure it actually gates the attribution cookie before it is written rather than appearing after the fact.
Where information is processed
Tiybe operates from India and serves customers in other countries, so information you send us may be processed outside the country you are in.
TODO(legal) — State where data is actually hosted, and the mechanism relied on for each cross-border transfer corridor Tiybe uses. Confirm the hosting region with the platform team before publishing anything specific.
Children
Tiybe is a product for businesses and accounting practices. It is not directed at children, and we do not knowingly collect information from them. If you believe a child has sent us personal information, contact us at sales@tiybe.com and we will remove it.
TODO(legal) — Confirm the age threshold to state here once the applicable regimes are settled; India's DPDP Act and the GDPR do not use the same one.
Changes to this policy
We update this policy when what we do with information changes. The date at the top of the page is the date of the current version.
TODO(legal) — Decide how material changes are communicated: posted here only, or notified to customers and enquirers in advance, and with what notice period.
How to contact us
For anything in this policy, including a request about your own information, write to sales@tiybe.com or use the contact form.
Post reaches us at:
12, 18th Avenue, Ashok Nagar, Chennai, Tamil Nadu, India
TODO(legal) — Publish a monitored privacy contact: a grievance officer or equivalent named contact as India's DPDP Act requires, a Data Protection Officer if one is mandatory in any market Tiybe serves, and a support telephone number. Create and staff the inbox before publishing the address — do not publish one that nobody monitors.