TallyPass

Privacy Policy

Effective 5 July 2026

SOLARA HK operates TallyPass, a platform that lets businesses ("merchants") issue and manage digital prepaid passes, memberships, and attendance passes for their own customers.

This policy explains what personal data we handle, why, and the choices you have. For a merchant's customers, the merchant decides what data to collect and is responsible for it; TallyPass processes that data on the merchant's behalf to run the service.

Data we handle

Merchant accounts: the name and email of staff logins, and business details such as name, logo, and branding.

Customer records (entered by the merchant): a customer's name, and optionally a phone number used to share their pass. Each pass carries its balance, membership level, expiry, and a history of scans.

Usage and security data: sign-in activity, two-factor authentication factors, rate-limit counters, and audit logs, kept to operate the service securely.

How we use it

To provide the service: issuing passes, recording redemptions, showing balances, and letting merchants manage their customers.

To secure accounts: authentication, two-factor verification, abuse and fraud prevention, and audit trails.

We do not sell personal data, and we do not use it for advertising.

Digital wallets

When a customer chooses to add a pass to Google Wallet (or, in future, Apple Wallet), the details needed to show that pass — such as the customer's name, balance, and membership level — are sent to the wallet provider so the card appears and stays up to date. That data is then also handled under the wallet provider's own privacy policy.

A customer who does not add a wallet pass is never sent to a wallet provider.

Sharing and processors

We share personal data only with service providers that host and run TallyPass on our behalf — our database, authentication, and file storage provider, and our application hosting provider — under agreements that limit their use of the data to providing those services.

We may disclose data if required by law, or to protect the rights, safety, and security of our users and the service.

Where data is stored

Application data is stored on managed infrastructure in the Singapore region. Because our providers and wallet integrations operate internationally, data may be processed in other locations in the course of delivering the service.

Retention

We keep personal data for as long as a merchant's account is active and the data is needed to provide the service, and as required to meet legal, accounting, or security obligations. A merchant can delete a customer or a pass; deletion removes the customer-facing record, while non-identifying ledger history may be retained for the merchant's records.

Security

Access to customer data is restricted to a merchant's own authorised staff. We use encrypted connections, row-level access controls, optional two-factor authentication, and per-account rate limits to protect data. No system is perfectly secure, but we work to protect personal data against unauthorised access, loss, or misuse.

Your rights

You may request access to, correction of, or deletion of your personal data. If you are a customer of a merchant, please contact that merchant first, as they control their customer data; we will support them in responding. Residents of Hong Kong have rights under the Personal Data (Privacy) Ordinance; residents elsewhere may have similar rights under local law.

Children

TallyPass is a tool for businesses and is not directed at children. Merchants are responsible for any consent required to hold a customer's data.

Changes

We may update this policy from time to time. Material changes will be reflected by updating the effective date at the top of this page.

Contact

For any privacy question or request, contact SOLARA HK at solarahk123@gmail.com.

This policy is provided in English and Traditional Chinese. If there is any inconsistency, the English version prevails.