Privacy Policy

Last updated [Effective date: Month DD, YYYY]

Initial draft prepared under Philippine law for review by legal counsel. Complete the [bracketed] details and have it reviewed before relying on it.

This Privacy Policy describes how [Operator Legal Entity, e.g. ABC Technologies Inc.] (“Pickle OS”, “we”, “us”, or “our”) collects, uses, discloses, stores, and protects personal data when you use the Pickle OS venue-management service and our websites at pickleos.app (the “Service”). We are committed to protecting your privacy in accordance with the Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and the issuances of the National Privacy Commission (NPC).

1. Our role under the Data Privacy Act

Under the Data Privacy Act (“DPA”), the roles are split depending on the data:

  • For your account, subscription, and billing data, Pickle OS is the Personal Information Controller (PIC) that decides how and why the data is processed.
  • For the customer and player data that you (the venue operator) collect through bookings and open-play queues, you are the Personal Information Controller and Pickle OS acts as your Personal Information Processor (PIP), processing that data only on your documented instructions. You are responsible for having a lawful basis to collect it and for providing your own privacy notice to your customers.

2. Personal data we collect

  • Account & operator data — your name, email address, mobile number, and password (stored only as a salted hash by our authentication provider).
  • Venue & business data — venue details, operating hours, products and services, and the payment-collection details you configure (e.g. GCash/Maya/bank account name and number, QR images), including payment-proof screenshots you upload for subscription billing.
  • Your customers’ data — when you take bookings or run open-play queues, we store the information you enter: customer/player name, mobile number, and (for bookings) email address and notes.
  • Transaction data — subscription payments, plan, amount, and payment references; sales and booking records you create in the Service.
  • Usage & technical data — device, browser, page-view and performance information, and server logs used to operate and secure the Service. Your IP address is processed by our hosting and analytics providers.

We do not intentionally collect sensitive personal information as defined by the DPA (such as race, health, religious or political affiliations, government-issued identifiers, or records of offenses). Please do not enter such information into free-text fields.

3. How we use your data and our lawful basis

We process personal data on the criteria for lawful processing under Section 12 (and, where applicable, Section 13) of the DPA — namely your consent, the performance of a contract with you, compliance with a legal obligation, and our legitimate interests in running a secure service. We use personal data to:

  • Provide, operate, maintain, and secure the Service;
  • Create and manage your account and venue workspace;
  • Process your subscription and verify your payments;
  • Send transactional messages (e.g. email confirmation, password reset, booking confirmations);
  • Provide customer support and respond to your requests;
  • Detect, prevent, and investigate fraud, abuse, and security incidents; and
  • Comply with legal, tax, and regulatory obligations.

4. Sharing and disclosure

We do not sell your personal data. We share it only with service providers (sub-processors) that help us run the Service, each bound to protect it and to process it only on our instructions:

  • Supabase — database, authentication, and file storage.
  • Vercel — application hosting, server logs, and privacy-friendly usage analytics.
  • PayMongo— payment processing. Card and e-wallet details are entered on PayMongo’s own secure checkout; we do not store full payment-instrument data.
  • [Email/SMTP provider, if configured] — delivery of transactional email.

We may also disclose personal data when required by law, court order, or a lawful request by a public authority, or to protect rights, safety, and property.

5. Cross-border transfer

Some of our sub-processors store and process data outside the Philippines (for example, in the [Asia Pacific — Tokyo/Singapore] region). Where we transfer personal data abroad, we remain accountable for it under the DPA and use providers that afford a comparable level of protection through contractual and technical safeguards.

6. Data retention

We keep personal data only for as long as necessary to fulfil the purposes above, while your account is active, and as required by law. Financial, tax, and accounting records are retained for the period required by the Bureau of Internal Revenue and other applicable regulations [generally up to 10 years — confirm]. When data is no longer needed, we securely delete, dispose of, or anonymize it [e.g. within 30 days of a valid request, subject to legal retention].

7. Security measures

We maintain reasonable and appropriate organizational, physical, and technical measures to protect personal data against accidental or unlawful destruction, alteration, disclosure, or access, as required by the DPA. These include tenant isolation (database row-level security), encryption of data in transit, least-privilege access controls, private storage for sensitive uploads, and audit logging. No method of transmission or storage is perfectly secure, but we work continually to protect your data.

8. Personal data breach notification

In the event of a personal data breach that meets the notification criteria under the DPA and NPC Circular No. 16-03, we will notify the National Privacy Commission and the affected data subjects within seventy-two (72) hours of knowledge of, or reasonable belief in, the breach, and take steps to mitigate its effects.

9. Your rights as a data subject

Under the DPA, you have the right to:

  • Be informed about the processing of your personal data;
  • Access your personal data that we hold;
  • Object to or withdraw consent to processing;
  • Have inaccurate or outdated data rectified;
  • Have your data erased or blocked under certain conditions;
  • Data portability — obtain a copy of your data in an electronic format;
  • Be indemnified for damages due to unlawful processing; and
  • Lodge a complaint with the National Privacy Commission.

To exercise any of these rights, contact our Data Protection Officer (below). We will respond within the period required by the DPA and the NPC.

10. Data Protection Officer

We have designated a Data Protection Officer (DPO) responsible for our compliance with the DPA. You may contact our DPO at [DPO name], [dpo@pickleos.app], [postal address]. For general queries you may also reach us at support@pickleos.app.

11. Children and minors

The Service is a business tool intended for venue operators and is not directed to minors. We do not knowingly collect the personal data of a minor without the consent of a parent or guardian. Where customer data of minors is collected by an operator, the operator is responsible for obtaining the appropriate consent.

12. Cookies and analytics

We use strictly-necessary cookies for sign-in and session security, and privacy-friendly product analytics to understand usage and performance [confirm whether analytics are cookieless; list any non-essential cookies and the consent mechanism].

13. Changes and how to contact us

We may update this Policy from time to time and will revise the effective date above. For any privacy question, request, or concern, contact our DPO or email support@pickleos.app. You also have the right to complain to the National Privacy Commission (privacy.gov.ph). See also our Terms of Service.