Privacy Policy

CLT NY INC. ・ Last updated: 2026-09-22

1. About this policy

CLT NY INC. (the “Operator”) handles personal information and data in the business application provided at app.cltny.com (the “Service”) as described in this policy.

2. Information we collect

Information registered by Customers: names, email addresses, phone numbers, member numbers, affiliations and roles, time punches and leave records, invoices and vendors, event sign-ups, orders and similar records.

Information for sign-in and security: sign-in times, IP addresses, browser type, two-step verification settings (phone numbers are masked on screen) and an activity log.

Information from connected services: only when a Customer connects them, that Customer’s QuickBooks Online accounting data (company info, accounts and items, profit and loss reports, transactions the Service creates), payment results and similar.

3. How we use it

Only to provide the Service’s features (sign-in, attendance totals, invoice approvals, postings to accounting and so on), to respond to inquiries, to prevent abuse and investigate incidents, and to improve the Service.

We do not use it for advertising.

4. QuickBooks Online (Intuit) data

QuickBooks Online data is used only for the benefit of the company it belongs to (the Customer that connected it). It is not shown to other Customers or third parties, and it is not aggregated or anonymized for other purposes.

Keys and tokens used to connect to Intuit are stored encrypted and never shown on screen or in logs. When a Customer disconnects, the Service revokes the token with Intuit and deletes the stored tokens.

5. Sharing with third parties

Except as required by law, we do not share information with third parties without the consent of the person or the Customer. To run the Service we use servers (XServer Cloud, Japan), an email delivery service, and the external services a Customer connects (Intuit, payments, calendars, etc.), and share with them only what each feature needs.

6. Storage and security

Data is stored on servers in Japan, with a separate database for each Customer. Traffic is encrypted with HTTPS, and secrets (connection keys, passwords) are stored encrypted. The admin screens use email sign-in codes and two-step verification. Backups are taken nightly.

7. Retention and deletion

Data is kept while the Customer uses the Service. When a Customer ends its use or asks for deletion, the data is deleted (backups expire at the end of their retention period).

8. Access, correction and deletion

To see, correct or delete your information, please contact the administrator of the Customer you belong to first. You may also contact the Operator directly.

9. Changes

Changes to this policy will be posted on this page.

10. Contact

CLT NY INC. yukimoto@cltny.com