Privacy Policy
Effective date: [PRIVACY_EFFECTIVE_DATE] • Version 2.0
Previous versions are available upon written request to our Data Protection Officer.
1. Introduction and Scope
[LEGAL_ENTITY_NAME] ("Camps PH," "we," "us," or "our"), a corporation duly organized and existing under Philippine law with principal office at [BUSINESS_ADDRESS], operates the Camps PH platform (the "Platform") — an online marketplace connecting campsite hosts with campers across the Philippines.
This Privacy Policy describes how we collect, use, store, share, and protect personal information in accordance with Republic Act No. 10173 (the Data Privacy Act of 2012, "DPA"), its Implementing Rules and Regulations ("IRR"), and all relevant NPC Circulars and Advisories, including NPC Circulars 16-03, 2022-04, 2023-04, and 2023-06, and NPC Advisories 2024-01 and 2024-03.
This Policy applies to all persons who interact with the Platform, including registered campers, campsite hosts, and anonymous visitors. It covers personal information collected through our website, mobile applications, and any related services.
By accessing or using the Platform, you acknowledge that you have read and understood this Policy. If you do not agree with any part of it, please discontinue use of the Platform.
2. Personal Information We Collect
2.1 Information Provided by Campers
- Account data: Full name, email address, mobile number, and password (hashed) upon registration via Clerk authentication.
- Profile data: Profile photo, bio, and stated outdoor interests.
- Booking data: Check-in and check-out dates, number of guests, special requests, and emergency contact name and number.
- Payment tokens: Tokenized payment method references returned by our PCI-DSS compliant payment processors. We do not store raw card numbers, full bank account numbers, or full GCash/Maya wallet credentials on our servers.
- Reviews and ratings: Content submitted about campsites or other users.
- Messages: Communications exchanged with hosts through our in-platform messaging system.
- Support correspondence: Inquiries and feedback submitted to our support team.
2.2 Additional Information Provided by Hosts
In addition to all data collected from campers, hosts provide:
- Government-issued ID: A clear copy of a valid Philippine government ID (e.g., PhilSys National ID, passport, driver's license, SSS/GSIS card) for identity verification.
- Selfie/biometric image: A live selfie used to verify the ID holder's identity during KYC onboarding.
- Banking and payout details: Bank account name and number, GCash-registered mobile number, or Maya account details necessary to disburse booking payouts.
- Property documents: Land title, lease agreement, or barangay clearance submitted to verify authority over the listed campsite.
- Listing content: Campsite name, address (including GPS coordinates), description, photographs, pricing, amenities, and availability calendar.
- Tax identification: TIN (Tax Identification Number) where required for BIR withholding tax compliance.
2.3 Information Collected Automatically
- Device and usage data: IP address, browser type and version, operating system, device identifiers, pages visited, referral URLs, and interaction timestamps.
- Location data: Approximate location inferred from IP address; precise GPS coordinates only when you explicitly grant permission for map features.
- Cookies and similar technologies: Session tokens, preference identifiers, and analytics identifiers as described in our Cookie Policy.
- Server and access logs: System-generated logs recording access events, API calls, and error events for security monitoring purposes.
2.4 Information Received from Third Parties
- Social sign-in providers: Name, email address, and profile photo from Google or other OAuth providers, limited to what you authorize during sign-in.
- Payment processors: Transaction confirmation, payment status, last-four digits of card/account, and fraud screening signals.
- Clerk authentication: Session tokens, MFA status, and sign-in activity from our authentication provider.
3. How We Collect Your Personal Information
- Account registration and profile updates — processed through Clerk's authentication system.
- Booking and payment forms — submitted directly on the Platform.
- Host KYC flows — ID upload and selfie capture during host onboarding.
- Payment processors — tokenized data returned after payment authorization.
- Cookies and analytics — automatic collection when you visit or interact with the Platform, subject to your consent preferences for non-essential cookies.
- Third-party sign-in — data shared by OAuth providers at your direction.
- Customer support channels — email, in-app chat, or support forms.
4. Purposes and Lawful Criteria for Processing
We process personal information only when at least one lawful criterion under Section 12 (general personal data) or Section 13 (sensitive personal information) of the DPA is satisfied. The table below maps each major processing activity to its purpose and applicable criterion.
| Data Category | Purpose | Lawful Criterion (DPA) |
|---|---|---|
| Account data (name, email, phone) | Account creation, authentication, user communication | Consent (Sec. 12(a)); Contractual necessity (Sec. 12(b)) |
| Booking data | Facilitate and manage reservations | Contractual necessity (Sec. 12(b)) |
| Payment tokens | Process payments, payouts, refunds | Contractual necessity (Sec. 12(b)); Legal obligation (Sec. 12(c)) |
| Host government ID and selfie (SPI) | Identity verification and trust & safety | Consent (Sec. 13(a)); Contractual necessity (Sec. 13(b)) |
| Host bank/GCash/Maya details (SPI) | Payout disbursement; KYC for financial settlement | Contractual necessity (Sec. 13(b)); Legal obligation (Sec. 13(c)) |
| TIN and tax records | BIR withholding tax compliance | Legal obligation (Sec. 12(c)) |
| In-platform messages | Host-camper communication; dispute resolution | Contractual necessity (Sec. 12(b)); Legitimate interests (Sec. 12(f)) |
| Device, IP, and log data | Fraud prevention, security monitoring, platform analytics | Legitimate interests (Sec. 12(f)) — subject to balancing test |
| Location data (GPS) | Map-based campsite search and display | Consent (Sec. 12(a)) |
| Profile photo | User identity within platform community | Consent (Sec. 12(a)) |
| Marketing email and push notifications | Promotional communications and offers | Consent (Sec. 12(a)) — withdrawable at any time |
| Non-essential cookies and analytics | Platform improvement, usage analysis | Consent (Sec. 12(a)) per NPC Circular 2023-04 |
Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing. The withdrawal mechanism is as easy to use as the original consent mechanism. For marketing emails, use the unsubscribe link in any message. For non-essential cookies, reopen the consent banner via the link in our footer.
5. Sensitive Personal Information
Under Section 3(l) of the DPA, the following information we process constitutes Sensitive Personal Information ("SPI") and is subject to heightened legal protection:
- Government-issued ID numbers and ID document images (hosts)
- Biometric data (selfie captured during host KYC)
- Bank account details, GCash/Maya mobile numbers used for payouts (hosts)
- Financial information sufficient to constitute a financial account identifier
SPI is processed only where we have obtained explicit consent or another applicable criterion under Section 13 of the DPA is satisfied. SPI is never processed for purposes incompatible with the original collection purpose, is stored in encrypted form with access restricted to authorized personnel, and is subject to enhanced deletion protocols upon account closure.
6. Data Retention Schedule
We retain personal information only as long as necessary for the declared purpose or any applicable legal or regulatory requirement. Upon expiry of the retention period, data is securely deleted or irreversibly anonymized.
| Data Type | Retention Period | Legal Basis for Period | Disposal Method |
|---|---|---|---|
| Active account data | Duration of account + 1 year post-closure | Contractual; consumer protection law | Cryptographic erasure; secure deletion |
| Booking and payment records | 5 years from transaction date | BIR tax record obligation | Cryptographic erasure |
| Host KYC documents (ID, selfie, property docs) | 5 years from end of hosting relationship | AMLA / regulatory KYC obligation | Secure deletion from encrypted storage |
| In-platform messages and support records | 2 years | Legitimate interests (dispute resolution) | Cryptographic erasure |
| Server and access logs | 1 year minimum; 3 years maximum | Security monitoring; legitimate interests | Secure deletion from log storage |
| Cookie consent records | 3 years | Accountability obligation (NPC Circular 2023-04) | Secure deletion |
| Marketing consent records | 3 years from last consent event | Accountability; NPC Circular 2023-04 | Secure deletion |
7. Data Sharing and Sub-Processors
We do not sell your personal information. We share personal information only in the circumstances described below, and only to the extent necessary for the stated purpose.
7.1 Between Campers and Hosts
When a booking is made or accepted, we share the minimum information necessary to facilitate the reservation — such as the camper's name, contact number, and arrival details with the host, and the host's campsite address and directions with the camper.
7.2 Named Third-Party Processors (Sub-Processors)
All sub-processors are bound by written Data Processing Agreements that require them to protect personal data at a standard consistent with the DPA and to process data only for documented purposes.
| Processor | Country | Service | Data Processed | Safeguard |
|---|---|---|---|---|
| Clerk | USA | Authentication & user management | Email, name, phone, session tokens, MFA status | DPA; NPC MCCs; Clerk SOC 2 Type II |
| Supabase | Configurable (data residency options available) | Database & file storage | All user data, KYC documents, booking records, messages | DPA; SOC 2 Type II; data residency election |
| Mapbox | USA | Mapping & geocoding | Location queries, map tile requests | DPA; NPC MCCs (NPC Advisory 2024-01) |
| Payment processors (to be named) | Various | Payment processing, fraud screening | Payment method tokens, booking amount, transaction status | DPA; PCI-DSS Level 1; MCCs where applicable |
7.3 Legal and Regulatory Disclosure
We may disclose personal information to comply with applicable Philippine laws, regulations, legal process, or lawful requests from government authorities — including the NPC, the Bureau of Internal Revenue (BIR), the Anti-Money Laundering Council (AMLC), or Philippine courts.
7.4 Business Transfers
In the event of a merger, acquisition, or sale of all or substantially all assets, personal information may be transferred as part of the transaction. Affected users will be notified and the same privacy protections will continue to apply.
7.5 Platform Safety
We may share personal information where we have a good-faith belief that disclosure is necessary to prevent imminent harm to the rights, property, or safety of Camps PH, our users, or the public, including cooperation with law enforcement.
8. Cross-Border Data Transfers
Some of our sub-processors (Clerk and Mapbox, both headquartered in the United States) process personal data outside the Philippines. Under NPC Advisory No. 2024-01, cross-border transfers must be subject to adequate safeguards. The safeguards we apply include:
- Model Contractual Clauses (MCCs): We adopt the NPC's MCCs as the primary contractual safeguard for transfers to Clerk and Mapbox.
- Supabase data residency: Where technically available and operationally feasible, we configure Supabase to host data within Philippine or ASEAN-adjacent regions to minimize cross-border exposure.
- Sub-processor security certifications: We select sub-processors that hold recognized security certifications (SOC 2 Type II, PCI-DSS) as evidence of equivalent data protection standards.
You may request a copy of the relevant contractual safeguards by contacting our Data Protection Officer at the address in Section 14.
9. Cookies and Tracking Technologies
We use strictly necessary cookies (e.g., Clerk session tokens) that are essential for the Platform to function. With your prior, freely given, specific, and informed consent in accordance with NPC Circular No. 2023-04, we also use functional and analytics cookies. We currently do not deploy marketing or advertising cookies.
You may manage your cookie preferences at any time via the cookie consent banner. Withdrawing consent for non-essential cookies will cause those cookies to be removed; this does not affect cookies strictly necessary for authentication and security.
For a full inventory of cookies by name, provider, purpose, and retention period, please see our Cookie Policy.
10. Your Eight Data Subject Rights
Under Section 16 of the DPA, you have eight enforceable rights with respect to your personal information held by Camps PH. All rights may be exercised by submitting a Data Subject Request (DSR) as described in Section 10.9 below or by visiting our Data Protection page. We will acknowledge your request within 5 business days and provide a substantive response within 15 calendar days (extendable with prior notice if additional time is required).
Right 1 — Right to be Informed
You have the right to be informed, at or before the point of collection, of the identity of the Personal Information Controller, the purposes and legal basis of processing, the categories of recipients, retention periods, and all other rights available to you. This Privacy Policy, together with our in-product collection notices, fulfills this obligation.
Right 2 — Right of Access
You may request a copy of all personal information we hold about you, the processing history, data sources, and a list of third parties to whom your data has been disclosed. Submit a DSR to [DPO_EMAIL] specifying "Access Request." We will provide the data in a readable format, free of charge for the first request each year.
Right 3 — Right to Object
You may object at any time to processing based on legitimate interests (e.g., analytics, fraud monitoring) or direct marketing. Upon receipt of a valid objection, we will cease processing unless we demonstrate compelling legitimate grounds that override your interests. To opt out of marketing communications, use the unsubscribe link in any marketing email or submit a DSR.
Right 4 — Right to Erasure or Blocking
You may request deletion or blocking of personal data that is (a) incomplete, outdated, false, or unlawfully obtained; (b) no longer necessary for the purposes for which it was collected; or (c) used for unauthorized purposes. We will honor erasure requests subject to legal retention obligations (e.g., BIR tax records, AMLA-mandated KYC retention). Where full deletion is not immediately possible, we will block the data while the request is under review.
Right 5 — Right to Rectification
You may request correction of inaccurate, incomplete, or outdated personal information. Basic profile information (name, email, phone) can be corrected directly in your account settings. For corrections to identity documents or banking details, submit a DSR to [DPO_EMAIL] with supporting documentation.
Right 6 — Right to Data Portability
You may request that we provide personal information you supplied to us in a structured, commonly used, and machine-readable electronic format (e.g., JSON or CSV), so that you can transfer it to another service. Submit a DSR specifying "Portability Request." We will provide the data within 15 calendar days.
Right 7 — Right to Damages
You have the right to seek indemnity for damages sustained due to inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorized use of personal information under Section 16(g) of the DPA. If you believe you have suffered harm as a result of a violation of the DPA by Camps PH, you may contact our DPO or file a complaint with the NPC.
Right 8 — Right to File a Complaint with the NPC
If you are unsatisfied with how we have handled your personal information or responded to a DSR, you have the right to lodge a complaint with the National Privacy Commission (NPC) at www.privacy.gov.ph or at complaints@privacy.gov.ph. The NPC's address is 5th Floor Delegation Building, PICC Complex, Pasay City, Metro Manila.
10.9 How to Submit a Data Subject Request (DSR)
- Send an email to [DPO_EMAIL] with the subject line indicating your request type (e.g., "Access Request," "Erasure Request").
- State the email address associated with your Camps PH account and a brief description of your request.
- For sensitive requests (erasure of KYC data, banking details), include a copy of a valid government-issued ID to verify your identity. This copy will be used solely for identity verification and will not be retained beyond the DSR process.
- Alternatively, submit by postal mail to [BUSINESS_ADDRESS], Attention: Data Protection Officer.
- You will receive an acknowledgement within 5 business days and a substantive response within 15 calendar days. Where additional time is needed, we will notify you in advance.
11. Children's Privacy
The Platform is intended for use by persons who are at least 18 years of age. We do not knowingly collect personal information from persons under 18. Users must declare their age at registration, and we implement age-assurance mechanisms consistent with our Terms of Service and NPC Advisory Opinion No. 2024-03 (Child-Oriented Transparency Guidelines).
The highest protection tier under the DPA applies to children under 13. If we discover or are notified that a person under 18 has created an account without verifiable parental or guardian consent, we will promptly suspend the account and delete the associated personal information. If you believe a minor has registered on the Platform, please notify us immediately at [DPO_EMAIL].
12. Security Measures
Camps PH implements organizational, physical, and technical security measures consistent with NPC Circular No. 2023-06 (Security of Personal Data) to protect against unauthorized access, alteration, disclosure, or destruction of personal information.
Technical Measures
- Encryption in transit using TLS 1.2 or higher for all data communications.
- Encryption at rest using AES-256 equivalent via Supabase and cloud storage.
- Role-based access control and least-privilege principles across Supabase and internal systems.
- Multi-factor authentication (MFA) required for all administrative accounts.
- Intrusion detection, audit logging, and monitoring of access to personal data.
- Regular vulnerability assessments and penetration testing.
- Secure software development lifecycle (SSDLC) practices.
- Pseudonymization or anonymization where operationally feasible.
Organizational Measures
- Designated Data Protection Officer (DPO) with executive sponsorship.
- Documented Privacy Management Program (PMP).
- Data Privacy Impact Assessments (DPIA) for high-risk processing activities (host KYC, payment data).
- Privacy-by-design and privacy-by-default embedded in product development processes.
- Mandatory data privacy training for all personnel with access to personal data, with periodic refreshers.
- Written data retention and disposal schedule.
- Business continuity and disaster recovery plan covering personal data systems.
- Written Data Processing Agreements with all sub-processors.
- Internal breach response procedure and Breach Register.
Physical Measures
- Platform data hosted on SOC 2-certified cloud infrastructure (Supabase); no personal data held in uncontrolled on-premises environments.
- Clean-desk and screen-lock policies for all personnel.
- Secure disposal of any physical media containing personal data.
While we employ reasonable security safeguards, no method of electronic transmission or storage is completely secure. We encourage you to use a strong, unique password and to keep your account credentials confidential.
13. Data Breach Notification
In the event of a personal data breach, Camps PH will comply with NPC Circular 16-03 (Personal Data Breach Management):
- We will notify the NPC and affected data subjects within 72 hours of knowledge of, or reasonable belief that, a breach has occurred — without delay when 100 or more data subjects are affected or when sensitive personal information is involved and disclosure is likely to cause harm.
- A full written report will be submitted to the NPC within 5 calendar days of the initial notification, including the nature of the breach, categories of data involved, approximate number of affected individuals, likely consequences, and remedial measures taken or planned.
- We maintain an internal Breach Register recording all incidents and our responses.
- Our DPO is the primary contact for breach reporting. To report a suspected breach or security vulnerability, contact [DPO_EMAIL].
14. Data Protection Officer and Contact Information
[LEGAL_ENTITY_NAME] has designated a Data Protection Officer in accordance with NPC Circular No. 2022-04. The DPO oversees compliance with the DPA, handles data subject requests, coordinates with the NPC, and serves as the primary contact for all data privacy matters.
Data Protection Officer
Name: [DPO_NAME]
Email: [DPO_EMAIL]
Phone: [DPO_PHONE]
Address: [BUSINESS_ADDRESS]
The DPO email is a monitored, dedicated inbox for privacy and data subject request inquiries.
For general customer support inquiries (non-privacy), please contact [SUPPORT_EMAIL].
National Privacy Commission (NPC)
If you are unsatisfied with our response to your privacy concern, you may escalate to:
National Privacy Commission
5th Floor Delegation Building, PICC Complex, Pasay City, Metro Manila
Website: www.privacy.gov.ph
Complaints: privacy.gov.ph/file-a-complaint
Email: complaints@privacy.gov.ph
15. NPC Registration
Camps PH ([LEGAL_ENTITY_NAME]) is registered with the National Privacy Commission of the Philippines as a Personal Information Controller pursuant to NPC Circular No. 2022-04. Our NPC Registration Number is [NPC_REGISTRATION_NO].
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, or NPC guidance. When we make material changes, we will notify you by:
- Posting the updated Policy on the Platform with a revised effective date;
- Sending a notification to your registered email address at least 14 days before the changes take effect (for material changes); and
- Where required by law (e.g., changes to processing purposes), obtaining fresh consent before the new processing begins.
Previous versions of this Policy are available on request from our DPO at [DPO_EMAIL]. Continued use of the Platform after the effective date of a non-material update constitutes acknowledgement of the revised Policy.