1. Scope and roles
This Privacy Policy describes how Gicho.tech (“Gicho.tech,” “we,” “us,” or “our”) handles personal information through gicho.tech, Gicho.tech OS, and related support and integration services.
For information a martial-arts school enters or collects in its workspace, the school generally decides why and how the information is used. Gicho.tech processes that information for the school to provide the service. For platform accounts, beta inquiries, billing, security, and our own website operations, Gicho.tech determines the applicable processing purposes. Contact the school first about a school record; contact Gicho.tech about the platform or this policy.
2. Information we handle
Platform and account information
- Name, email, phone, organization, role, authentication, invitation, and preference information.
- Beta inquiries, support communications, service selections, and account administration.
- Browser, device, session, IP-derived security, audit, diagnostic, and usage information.
School operational information
- School identity, locations, schedules, programs, ranks, curriculum, instructors, and website content.
- Family, guardian, student, emergency-contact, enrollment, waiver, attendance, progression, and communication-preference records.
- Products, memberships, orders, inventory, invoices, payment status, refunds, and reporting evidence.
- Announcements, events, private lessons, templates, messages, delivery status, and consent history.
Schools choose which information to maintain. Some school records may concern minors. Gicho.tech does not ask children to create public consumer accounts independently; school or guardian-authorized workflows control student access.
3. QuickBooks data
When an authorized school administrator connects QuickBooks, Intuit presents the requested permissions. Gicho.tech OS may then receive and maintain the minimum data needed for the enabled workflows, including:
- QuickBooks company and connection identifiers;
- customer identifiers and customer matching information;
- Products and Services, names, descriptions, SKUs, prices, and active status;
- invoice identifiers, amounts, balances, dates, status, and hosted invoice links;
- payment, refund, and reconciliation references and status; and
- OAuth access and refresh credentials required to maintain the authorized connection.
We use QuickBooks data only to connect school records to QuickBooks, import or map catalog items, create and send authorized invoices, show invoice and payment status, reconcile records, maintain the connection, troubleshoot authorized workflows, and meet security, audit, and legal obligations. QuickBooks OAuth credentials are encrypted and are not shown to school users after connection.
Intuit-hosted authorization and invoice-payment pages handle Intuit credentials and payment entry. Gicho.tech OS does not receive full card numbers, bank-account numbers, or card security codes from those hosted pages.
4. Sources of information
We receive information from:
- school owners, staff, instructors, parents, guardians, students, and public registrants;
- authorized uploads, forms, websites, imports, and AI-assisted proposals reviewed by a school owner;
- connected providers such as Intuit QuickBooks, Stripe, Brevo, and domain services; and
- the browser, device, and technical systems used to operate and secure the service.
5. How we use information
- Provide, personalize, maintain, and support Gicho.tech OS.
- Authenticate users and enforce school, role, and record permissions.
- Run school-selected enrollment, scheduling, attendance, progression, commerce, communication, and reporting workflows.
- Connect and synchronize authorized third-party services.
- Process subscriptions, document transactions, and provide customer support.
- Detect abuse, protect accounts, troubleshoot failures, audit important actions, and improve reliability.
- Comply with law, enforce agreements, and protect the rights and safety of users, schools, Gicho.tech, and others.
- Analyze aggregated or de-identified service performance and feature use.
We do not use one school’s identifiable data to train a general-purpose model for another school. AI-assisted setup produces reviewable proposals and follows the permissions of the requesting user.
6. When information is disclosed
We may disclose information:
- to the school and its authorized users according to configured roles and workflows;
- to service providers that host, store, secure, monitor, communicate, automate, support, or process transactions for Gicho.tech OS;
- to Intuit, Stripe, Brevo, and other providers when a school authorizes a connection or transaction;
- to professional advisers under confidentiality obligations;
- when required by law or reasonably necessary to protect rights, security, or safety; or
- as part of a merger, financing, reorganization, acquisition, or sale, subject to appropriate protections.
We do not sell personal information for money, share it for cross-context behavioral advertising, or permit one school to access another school’s identifiable records.
7. Retention, disconnection, and deletion
We retain information for as long as needed to provide the service, maintain the school’s operational and transaction history, secure accounts, resolve disputes, enforce agreements, and meet legal, tax, accounting, audit, and provider obligations. Retention varies by record:
- Active account and school records are retained while the workspace is active.
- Orders, invoices, payments, waivers, consent, audit, and security records may be retained longer because they document historical obligations and actions.
- Backups are removed through scheduled rotation and are not used as an active source after deletion.
- De-identified information may be retained when it can no longer reasonably identify a person or school.
Disconnecting QuickBooks revokes or removes the stored connection credentials and stops new QuickBooks API access. It does not automatically delete historical order, invoice, payment, mapping, and audit evidence already stored in Gicho.tech OS. An authorized school owner may request deletion of imported QuickBooks data that is no longer required, subject to legal, security, backup, dispute, and accounting retention needs.
Before closing a school workspace, an owner can request or use available exports. After a verified deletion request, we delete or de-identify eligible active data within a reasonable period and allow protected backups to expire through normal rotation.
8. Security
We use reasonable administrative, technical, and organizational measures designed to protect information, including encrypted transport, protected credentials, tenant and role boundaries, audit records, and restricted administrative access. No system can guarantee absolute security. Users should protect their credentials and promptly report suspected unauthorized access through our contact form.
9. Choices and privacy rights
Depending on location and applicable law, individuals may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information. Parents and students should normally submit school-record requests to their school because the school controls those records. Gicho.tech will assist schools with verified requests where required.
Users can update certain profiles and communication preferences in Gicho.tech OS. Email and text recipients can use available unsubscribe or opt-out methods. School owners can manage provider connections and authorized user access in protected settings.
10. Processing locations
Information may be processed in the United States and other locations where Gicho.tech or its service providers operate. Where required, we use appropriate contractual or legal safeguards for cross-border processing.
11. Changes and contact
We may update this policy as the service, providers, or law changes. The effective date identifies the latest version, and we will provide additional notice when a change is material.
Privacy questions, verified requests, or concerns may be submitted through the public Gicho.tech contact form. Please identify the relevant school and do not send passwords, payment-card information, API keys, or other secrets.