Owner: GuiHub Digital Solutions Incorporated Version: 1.0 — [EFFECTIVE DATE] Data Protection Officer (DPO): Dave Ricablanca, patcherrom@gmail.com
⚠️ Template notice (internal document). This is an internal compliance/governance template tailored to how GuiHub Delivery processes data. It is not legal advice. Validate it with Philippine counsel and against current NPC issuances. It is meant to support (not replace) your NPC registration, privacy management program, and Google Play Data safety declarations.
This document records how GuiHub Delivery ("the App") complies with the Philippine Data Privacy Act of 2012 (RA 10173), its IRR, and NPC issuances, and with the platform/advertising policies that apply to the App.
and why personal data is processed.
contactable at patcherrom@gmail.com. Responsible for oversight, breach response, and data-subject requests.
number and date once obtained. Registration is required for PICs that meet the NPC thresholds; assess your headcount and sensitive-data processing.]
| Category | Examples | Source | Sensitivity |
|---|---|---|---|
| Account & identity | name, username, phone, email, hashed password, birthdate, age, profile photo | user | Personal |
| Location | delivery addresses, saved locations, GPS coordinates, driver live/background location during deliveries | user / device | Personal |
| Orders & finance | order contents, prices, fees, wallet balance, top-ups, payouts, remittances, driver earnings & cash-on-hand | user activity | Personal / financial |
| Driver operations | shift time in/out records, daily earnings, debt status | app activity | Personal |
| Marketplace | listings (incl. photos & location), buyer–seller chats & images, seller reputation signals | user | Personal |
| Support | Help Centre messages and screenshots | user | Personal (may contain more) |
| Device & technical | push token (FCM), app version, device/OS, diagnostics/crash data | device | Personal |
| Advertising | device advertising identifier (via AdMob, where enabled) | device | Personal (identifier) |
Sensitive personal information (as defined by the DPA) is not intentionally collected. Free-text fields are monitored/moderated to discourage users from submitting it.
Processing relies on: contract (to provide the ordered service), consent (e.g. marketing, precise location, ads personalization), legitimate interests (fraud prevention, safety, service improvement — balanced against user rights), and legal obligation (financial recordkeeping, lawful requests). A basis is mapped to each purpose in the Privacy Policy (§4).
We honour the DPA rights: be informed, access, object, rectify, erase/block, data portability, damages, and complaint to the NPC.
logged.
changing data.
required by the DPA/NPC. [Insert your internal SLA, e.g. 15 working days.]
and write — users can only access their own data (own orders, own profile), stores/drivers/customers see only what a transaction requires, and administrative access is gated by a server-verified admin allow-list. Reads of order data are scoped per role so no client can bulk-read others' personal data.
identity; sensitive server logic runs in Cloud Functions.
roles (e.g. a driver sees the customer's delivery details only for an active order).
abuse/fraud investigation; admin panels record moderation actions.
are still performed client-side and are on the roadmap to be enforced entirely server-side (Cloud Functions). Track and close these as "Stage 3" hardening.
immediately.
data subjects within 72 hours** of knowledge of a breach that meets the notification criteria (sensitive/financial data, real risk of serious harm).
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| Google Firebase (Auth, Firestore, Cloud Functions, Cloud Messaging) | hosting, auth, database, push | most app data | Google data centers (may be outside PH) |
| Google AdMob | in-app advertising (where enabled) | advertising identifier, device/usage signals | Google (outside PH) |
| Google Play Services / Play Integrity | app distribution & integrity | device/app integrity signals | |
| Map & geocoding (e.g. OpenStreetMap / Nominatim, Leaflet tiles) | maps & reverse-geocoding | coordinates queried | provider infra |
| Payment gateway [NAME, once integrated] | wallet top-ups / payouts | payment/transaction data | provider infra |
Cross-border transfers are covered by the safeguards in the Privacy Policy (§7). Maintain data-processing/sub-processor agreements with each provider as required.
| Data | Retention |
|---|---|
| Active account data | While active + [X] after closure |
| Financial/transaction records | [Longer period for tax/legal — insert] |
| Marketplace chats | [Insert] |
| Support tickets & screenshots | [Insert] |
| Driver shift/earnings records | [Insert] |
| Diagnostics/logs | [Insert] |
After the period, data is deleted or anonymized.
The App is for users 18+. We do not knowingly process children's data; if discovered, it is deleted.
declare the data collected/shared above (identity, location incl. background location for drivers, financial info, photos, messages, device IDs) and the purposes.
camera, and notifications are declared and used only for their stated purpose, with a prominent in-app disclosure and consent for background location.
with the Families/most-users ad policies. Provide a working Privacy Policy URL.
account and data deletion (Play now requires this). [Insert the URL / in-app path.]
tracking and financial data.