ArkiLaroArkiLaro
05Privacy

Privacy Policy

What personal data ArkiLaro collects, why, who it’s shared with, and the rights you have over it under Philippine law.

Draft — pending legal review
This is a working draft. It has not yet been reviewed by counsel and is not yet in force.
01

Who controls your data

This policy explains how ArkiLaro handles personal data when you use the platform, in line with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its rules.

ArkiLaro is the personal information controller for the data you give the platform directly — your account and profile. Facilities you book with are separate controllers for the data they receive; that distinction is set out below.

For legal review
State the registered controller entity (ArkiLaro Inc.), its business address, and confirm registration with the National Privacy Commission where required.
02

What we collect

Account: your email address and password. Profile: an optional phone number and display details you choose to add. Bookings: the courts you book, when, and what was paid. Contact details on an order: a name and phone number you give at checkout, so a facility can reach you about that booking.

We also collect basic technical data your browser sends when you use the site, such as your approximate location when you search — used to show courts near you.

03

Why we use it, and our lawful basis

We use your data to run your account, take and manage bookings, show courts near you, send the emails a booking needs (confirmations, check-in codes, and account emails), and keep the platform secure.

For legal review
Map each purpose to a lawful basis under the DPA (consent, contract, legitimate interest, legal obligation), and state whether any processing relies on consent that can be withdrawn.
04

Facilities are their own controllers

When you book a court, the facility receives what it needs to honour that booking — including the contact details you gave for it. Those details belong to the order and to that facility, so a number you gave one venue about a late arrival is not shared with another.

Once a facility holds your data, it handles it under its own responsibilities as a controller.

05

Who else we share it with

We share data with the service providers that make the platform work: payment providers (which process your payment into the facility’s account), our email provider (which delivers booking and account emails), and our hosting and infrastructure providers.

We don’t sell your personal data. We share it with authorities only where the law requires it.

For legal review
List the material processors (payment providers, Resend for email, hosting) and confirm data-processing agreements and any cross-border transfer safeguards are in place.
06

How long we keep it

We keep your data for as long as your account is active and as long as we need it for the purposes above, then delete or anonymise it.

Records of staff access are an exception. Where a facility adds, changes, or removes a member of its staff, we keep a record of that change — who made it, who it was about, and what access it granted or took away — for the life of that facility’s account on ArkiLaro. In practice that means we keep it indefinitely. These records are what let a facility answer who had access to bookings and payments at a given time, so we don’t delete or shorten them.

For legal review
Set concrete retention periods per data category (account, bookings, contact details, logs) and the criteria used to decide them. Staff-access records are currently kept indefinitely and are never purged: confirm whether the Data Privacy Act requires a maximum period for this category, and if so what it is. Note that a purge added later applies retroactively, whereas a period set too short destroys the evidence it was meant to govern.
07

Your rights

Under the Data Privacy Act you have the right to be informed, to access your data, to correct it, to object to processing, to have it erased or blocked in the circumstances the law allows, to data portability, and to be indemnified for damage from mishandling.

You can also lodge a complaint with the National Privacy Commission. To exercise any of these rights, contact us and we’ll respond within the time the law allows.

08

Cookies

We use cookies that are needed to run the site — chiefly to keep you signed in and to keep your session secure. Without these the platform can’t remember who you are between pages.

For legal review
If any analytics, advertising, or non-essential cookies are added later, describe them here and add a consent mechanism before they are set.
09

How we protect it

We use reasonable technical and organisational measures to protect your data — passwords are stored hashed, sessions are protected, and access is limited. No system is perfectly secure, but we work to keep the risk low and to act quickly if something goes wrong.

10

Changes to this policy

We may update this policy as the platform changes. When a change is material, we’ll take reasonable steps to let you know.

11

Contact and our Data Protection Officer

For anything about your data or this policy, reach us through the Contact page and we’ll direct it to the right person.

For legal review
Name the Data Protection Officer and give a direct contact channel (email and address), as the DPA requires a reachable DPO.