Legal
Privacy Policy
What we collect, what we do not, and what you can make us do about it.
Last reviewed DATE
The short version
- We set no cookies. None at all.
- We run no analytics, no advertising pixels and no tracking of any kind.
- Your bag lives in your own browser and is never sent to us until you check out.
- We never see your card, wallet or banking credentials. You pay in your own app.
- You send us a screenshot of your payment. We store it, and Google's Gemini reads it to check the amount. That is the one image we hold about you.
- Nothing third party loads when you browse. The fonts are ours, the scripts are ours.
- We do not sell your information, and we never will.
Everything below is the same thing said properly. If any of it stops being true, this page changes on the same day.
1. Who is responsible for your data
REGISTERED BUSINESS NAME, REGISTERED ADDRESS, is the Personal Information Controller for the purposes of the Data Privacy Act of 2012 (RA 10173). Our Data Protection Officer is DATA PROTECTION OFFICER, reachable at PRIVACY EMAIL.
2. What we collect
What you give us
Your name, email address, delivery address, phone number and what you ordered, when you buy something or contact us. If you write to us, we keep the message.
The payment screenshot
You upload a screenshot of your own payment confirmation. We store that image in a private Google Drive folder and send a copy to Google's Gemini API, which reads the amount, the reference number and which app it came from so we can match it to your order. Nothing else is done with it and it is not used to train anything.
That screenshot is whatever your banking app put on your screen, so it may show your own name and a partial account number. We do not ask for it and do not use it. We never receive and cannot store your card number, your wallet credentials or your bank login.
Receipts are kept with the order for RETENTION PERIOD and then deleted.
Where the order is written down
Placing an order writes a row to a Google Sheet we control, through Google Apps Script. That row holds the date, an order reference, your name, mobile number, email address, delivery address and region, what you bought and what it cost. The confirmation email is sent from the same place.
What the server records
Our host, HOSTING PROVIDER, keeps ordinary web server logs, which include the IP address of the device requesting a page, the page requested, and the browser's user agent string. These are operational and security records. We do not build profiles from them.
If you join the list
Your email address, and only if you asked us to have it.
3. What we do not collect
This site sets no cookies. There is no analytics package, no tag manager, no advertising or social media pixel, no session recording, and no fingerprinting. We do not know how many pages you looked at or where you came from, and we have decided we would rather not know than collect it because we could.
If we ever add measurement, it will be a privacy-respecting tool, it will be named here before it goes live, and this section will stop saying what it currently says.
4. Where your bag actually lives
Adding a paddle to your bag writes it to your browser's local storage on your own device. It is not a cookie and it is not sent to us with each request. It sits there until you check out, clear it, or clear your browser data. If you never check out, we never learn it existed.
The same is true of the order summary shown on the confirmation page after a purchase. That copy is local to your browser so the page can show you what you bought.
5. Why we use it, and on what basis
- To take payment and deliver what you ordered, and to handle returns and warranty claims. Basis: performance of our contract with you.
- To answer you when you write to us. Basis: our legitimate interest in running a business people can talk to.
- To detect and prevent fraud and abuse, and to keep the site up. Basis: legitimate interest.
- To send you email about AGOS. Basis: your consent, which you can withdraw in one click at the bottom of any of them.
- To meet tax, accounting and record keeping obligations. Basis: legal obligation.
6. Who else touches it
We do not sell, rent or trade personal information. We share it only with providers who need it to get your order to you:
- Runs Apps Script and the sheet your order is written to, stores your payment screenshot in Drive, and sends the confirmation email.
- Google Gemini
- Reads the payment screenshot once, to pull out the amount and reference. It is sent the image and nothing else about you.
- GCash, Maya, RCBC, GoTyme
- Receive your payment. What they see is between you and them; we only ever see the screenshot you send us.
- HOSTING PROVIDER
- Hosts the site and keeps the server logs described above.
- GoGo Xpress, nationwide.
- Receives your name, address and phone number so the parcel can be delivered.
- EMAIL PLATFORM
- Sends the mailing list, if you are on it.
None of them is contacted by simply reading this site. Every font, script, stylesheet and image here is served from our own domain, so browsing these pages tells no third party that you were here. Our checkout is the first moment anything leaves, and only because you asked it to.
We may also disclose information where the law requires it, or to establish or defend a legal claim.
7. How long we keep it
- Order records
- RETENTION PERIOD, to meet BIR and accounting requirements
- Support messages
- Two years from the last reply
- Mailing list
- Until you unsubscribe
- Server logs
- As long as our host retains them; we do not archive them ourselves
8. Your rights
The Data Privacy Act gives you the right to be informed about what we hold, to access it, to have it corrected, to object to how we use it, to have it erased or blocked where the law allows, to receive a copy in a portable form, and to be compensated for damage caused by mishandling it. You can withdraw consent to marketing at any time without giving a reason.
Write to PRIVACY EMAIL and we will act within the period the law requires. If we get it wrong, you can complain to the National Privacy Commission, which is the regulator for this in the Philippines.
If you are buying from the European Union, the United Kingdom or California, the rights you have at home apply to your order too, and the same address handles them.
9. Data leaving the Philippines
Some of the providers above run infrastructure outside the Philippines, so your information may be processed abroad. Where that happens we rely on the contract with that provider to hold it to a standard comparable to the Data Privacy Act.
10. Children
This site is not aimed at children and we do not knowingly collect information from anyone under 18. If you believe a child has given us something, write to PRIVACY EMAIL and we will delete it.
11. How we protect it
The site is served over HTTPS. No page here has a field that asks for card details, which keeps card data off this origin entirely. We ship a content security policy that blocks scripts, styles, fonts and images from anywhere but our own domain, we load no third-party JavaScript, and everything read back out of your browser's storage is validated before it can reach the page.
The detail, and how to tell us if you find a hole in it, is on the Security page. No system is perfectly secure and we are not going to claim ours is.
12. Changes
We will update this page when what we do changes, and the date at the top will move. If a change is material we will say so on the site rather than hope you reread it.
13. Contact
Anything at all about your data: PRIVACY EMAIL. Post: REGISTERED ADDRESS.
Bag (0)