Privacy Policy
Last updated
This Privacy Policy explains how Pickle OS ("Pickle OS", "we", "us", or "our") collects, uses, discloses, stores, and protects personal data when you use the Pickle OS venue-management platform and our websites at pickleos.app (the "Service").
We process personal data in accordance with the Data Privacy Act of 2012 (Republic Act No. 10173) (the "DPA"), its Implementing Rules and Regulations, and the issuances of the National Privacy Commission (the "NPC").
This Policy forms part of, and should be read together with, our Terms of Service.
1. Our role under the Data Privacy Act
Responsibility for personal data on the Service is split according to whose data it is:
- For account, subscription, billing, and website data, Pickle OS is the *Personal Information Controller* (PIC): we decide the purposes and means of processing.
- For Player and customer data that a venue operator collects through bookings, open play, point of sale, and queues, the operator is the Personal Information Controller and Pickle OS acts as its *Personal Information Processor* (PIP), processing that data only on the operator's documented instructions and as required by law. The operator is responsible for its lawful basis for collection and for issuing its own privacy notice to its customers.
If you are a Player and want to know how a particular venue uses your information, please contact that venue directly. We will assist the venue in responding to your request.
2. Personal data we collect
- Account and operator data — your name, email address, mobile number, role, and your password, which is stored only as a salted hash by our authentication provider and is never visible to us.
- Venue and business data — venue name and address, operating hours, courts, products, prices, and the settlement details you configure for collecting payment (such as the account name, account or wallet number, and QR image), together with any payment proof you upload for subscription billing.
- Player and customer data — where you use booking, open play, or point of sale, we store the information entered: name, mobile number, email address where provided, booking notes, attendance, and payment status.
- Transaction data — subscription plan, amounts, payment references and status returned by our payment partner, and the sales, booking, and session records created in the Service.
- Usage and technical data — device and browser type, pages viewed, performance measurements, approximate location derived from IP address, and server, security, and audit logs used to operate, troubleshoot, and secure the Service.
- Support and communications — the content of messages you send us and our replies.
We do not intentionally collect *sensitive personal information* as defined by the DPA — such as race or ethnic origin, marital status, age, colour, religious or political affiliation, health, education, genetic or sexual life, offences, or government-issued identifiers. Please do not enter such information into free-text fields.
3. How we use personal data, and our lawful basis
We process personal data on the criteria for lawful processing set out in Section 12 of the DPA — your consent, the performance of a contract with you or steps taken at your request, compliance with a legal obligation, and our legitimate interests in operating and securing the Service, where those interests are not overridden by your rights. We use personal data to:
- Provide, operate, maintain, and improve the Service;
- Create and administer your account and venue workspace;
- Process subscriptions and payments and verify them with our payment partner;
- Deliver transactional messages such as email confirmation, password resets, booking confirmations, and service notices;
- Provide customer support and respond to your requests;
- Monitor, detect, prevent, and investigate fraud, abuse, and security incidents, including rate limiting and bot protection;
- Produce aggregated, de-identified analytics about how the Service is used; and
- Comply with legal, tax, accounting, and regulatory obligations.
We do not use personal data for automated decision-making that produces legal or similarly significant effects on you, and we do not sell personal data.
4. Sharing and disclosure
We disclose personal data only in the circumstances below, and only to the extent necessary.
Sub-processors. We use carefully selected service providers who process personal data on our instructions under written agreements requiring confidentiality and appropriate security:
- Supabase — managed database, authentication, and file storage (Asia Pacific — Tokyo region).
- Vercel — application hosting, edge network, server logs, and cookieless performance analytics.
- Our payment partners — processing of QR Ph, GCash, Maya, and other e-wallet and bank payments. Payment credentials are entered on the payment partner's own secure interface; we never receive or store full payment-instrument details.
- Our transactional email provider — delivery of account and booking email.
- Upstash — rate limiting used to protect the Service from abuse.
- Cloudflare — bot protection on sign-in and signup forms.
Between operator and Player. Booking and open-play details are shared with the venue you book with so it can fulfil the booking, and a venue's public information is shown to Players.
Legal and protective disclosure. We may disclose personal data where required by law, court order, subpoena, or lawful request by a public authority, or where necessary to establish, exercise, or defend legal claims, or to protect the rights, safety, and property of Pickle OS, our users, or the public.
Business transfers. If we are involved in a merger, acquisition, reorganisation, or sale of assets, personal data may be transferred as part of that transaction. We will notify you and the transferee will remain bound by this Policy or a policy at least as protective.
5. Cross-border transfer
Some of our sub-processors store or process personal data outside the Philippines, principally in the Asia Pacific (Tokyo) region and, for logs and edge delivery, in other regions operated by our hosting provider. Where personal data is transferred abroad, we remain accountable for it under the DPA and rely on contractual commitments and technical safeguards that afford a comparable level of protection.
6. Data retention
We keep personal data only for as long as necessary for the purposes described in this Policy:
- Account, venue, and operational records — for as long as your account is active, and for up to twelve (12) months after termination to allow reactivation and to resolve disputes.
- Financial, tax, and accounting records — for ten (10) years, as required under the rules of the Bureau of Internal Revenue and the National Internal Revenue Code.
- Security, audit, and server logs — for up to twelve (12) months.
- Support correspondence — for up to twenty-four (24) months.
When personal data is no longer needed we securely delete, dispose of, or irreversibly anonymise it. We action a valid deletion request within thirty (30) days, except where we are required or permitted by law to retain the data.
7. Security measures
We maintain organisational, physical, and technical measures appropriate to the risks presented by our processing, as required by the DPA and NPC issuances. These include tenant isolation enforced at the database level through row-level security, encryption of data in transit, encryption of data at rest by our infrastructure providers, least-privilege and role-based access control, salted password hashing, private storage for uploaded documents, rate limiting and bot protection, audit logging of privileged actions, and regular review of access and dependencies.
No method of transmission or storage is completely secure. We continually review and improve our safeguards, and we ask that you keep your credentials confidential and report any suspected compromise to us immediately.
8. Personal data breach notification
Where a personal data breach meets the notification criteria under the DPA and NPC Circular No. 16-03, we will notify the National Privacy Commission and the affected data subjects within seventy-two (72) hours of knowledge of, or reasonable belief in, the breach, describe the nature of the breach and the measures taken, and take prompt steps to contain and remedy it. Where we act as a Personal Information Processor for an operator, we will notify that operator without undue delay so it can meet its own obligations.
9. Your rights as a data subject
Under the DPA you have the right to:
- Be informed about the collection and processing of your personal data;
- Access the personal data we hold about you;
- Object to processing, or withdraw a consent you have given, without affecting the lawfulness of processing already carried out;
- Have inaccurate, incomplete, or outdated personal data corrected;
- Have your personal data erased or blocked where the conditions under the DPA are met;
- Data portability — obtain a copy of your personal data in a commonly used, machine-readable format;
- Be indemnified for damages sustained due to inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorised use of personal data; and
- Lodge a complaint with the National Privacy Commission.
To exercise any of these rights, contact our Data Protection Officer using the details in Section 11. We may need to verify your identity before acting on a request. We respond within the period required by the DPA and NPC issuances, and in any case within thirty (30) days, extending only where the request is complex and telling you if we do. Exercising your rights is free of charge.
10. Cookies and analytics
We use strictly necessary cookies to sign you in, keep your session secure, and remember your interface preferences. These are required for the Service to function and cannot be switched off from within the Service.
We use privacy-friendly, cookieless product and performance analytics that measure page views and loading performance in aggregate and do not build advertising profiles. We do not use advertising or cross-site tracking cookies, and we do not run third-party advertising networks on the Service. Our bot-protection and rate-limiting providers may set short-lived tokens strictly to distinguish legitimate traffic from automated abuse.
You can block or delete cookies through your browser settings. Blocking strictly necessary cookies will prevent you from signing in.
11. Data Protection Officer
We have designated a Data Protection Officer responsible for our compliance with the DPA. You may contact the DPO about this Policy, your personal data, or to exercise your rights:
- Email: dpo@pickleos.app
- General enquiries: support@pickleos.app
If you are not satisfied with our response, you may lodge a complaint with the National Privacy Commission at privacy.gov.ph.
12. Children and minors
The Service is a business tool intended for venue operators and adult Players. We do not knowingly collect the personal data of a child under eighteen (18) years of age without the consent of a parent or guardian. Where a venue collects information about a minor — for example when enrolling a junior player — the venue is responsible for obtaining that consent. If you believe we hold the data of a minor without proper consent, contact our DPO and we will delete it promptly.
13. Changes to this Policy
We may update this Policy to reflect changes in our practices, technology, or legal requirements. When we do, we revise the "Last updated" date above, and for material changes we will notify you by email or in the Service before the change takes effect. We encourage you to review this Policy periodically.
14. Contact us
For any privacy question, request, or concern, contact our Data Protection Officer at dpo@pickleos.app, or email support@pickleos.app.