DinkingBuds Privacy Policy (DRAFT: not yet reviewed by counsel)
Effective date: [DATE]. Last updated: [DATE].
**This is a draft prepared for legal review, written to accurately
describe what the DinkingBuds platform actually collects and does today.
It is not currently in effect. A Philippine lawyer must confirm this
satisfies the Data Privacy Act of 2012 (RA 10173), see
03-legal-review-checklist.md §2, before this is shown to any real
user.**
[LEGAL ENTITY NAME] ("DinkingBuds," "we," "us") respects your privacy.
This policy explains what personal data we collect, why, and what we do
with it.
1. What we collect
From players (account holders):
- Full name, mobile number, home city, self-reported skill level,
optional profile photo (profiles table).
- Booking history: which courts/times you've booked, at which venues,
and their status.
- Payment references: the transaction reference number and payment
method (GCash/Maya/bank) you submit for a booking. **We never collect
or store your card number, e-wallet PIN, bank account credentials, or
any payment instrument itself.** You send money directly to the venue
outside the Platform, and only report the reference number to us.
- Game/tournament/league participation history, attendance, and
no-show records (visible only to venue staff, never to other players
or published publicly).
- Marketing preferences: whether you've opted out of promotional
messages (marketing_optouts), see §4.
From walk-in customers (booked by venue staff, no account):
- Name and mobile number only, entered by venue staff at time of
booking.
From Venue Partners and their staff:
- Staff accounts (name, mobile, role) for the venue's own console
access, scoped to that venue's data only.
We do not collect government-issued ID.
2. Why we collect it
- To create and manage your bookings, and to let the venue confirm your
payment against their own account (see the Marketplace Disclaimer,
04-marketplace-disclaimer.md).
- To show you your own booking/membership/game history.
- To let venue staff operate their court business (front desk,
scheduling, verifying payments, running reports), scoped strictly to
their own venue's data; staff at one venue cannot see another venue's
customer data.
- To send you transactional notices about your own bookings (status
changes, verification results) and, if you haven't opted out,
occasional promotional messages from venues you've booked with.
- Platform administrators (DinkingBuds staff, not venue staff) can look
up account and booking records for support, dispute investigation, and
fraud/abuse prevention. Every platform-admin action is itself logged
in an audit trail.
3. Who can see your data
- The venue(s) you've booked with can see your booking history,
contact info, and payment references at their venue only, not at
other venues, even if you've used the Platform elsewhere. This is
enforced at the database level (row-level security), not just in the
app's interface.
- DinkingBuds platform administrators can look up your account
across venues for support and investigation purposes, subject to
DinkingBuds' own access controls (a named admin list, not open to all
staff) and audit logging of every lookup.
- Other players never see your payment references, mobile number
(beyond what a public game listing shows, e.g. your display name), or
your no-show/attendance history.
- We do not sell your data to third parties. We do not currently share
data with any third-party payment processor, because none is
integrated (see §5).
4. Marketing messages and consent
Signing up implies only transactional messaging (booking confirmations,
payment status, etc.). That's not something you can opt out of while
keeping an account, since it's how the service functions. Separately,
venues can send promotional messages (e.g. a promo code, a "come back"
nudge); you can opt out of these per-venue at any time, and an opt-out
is respected automatically by every future campaign. [⚖ Counsel to
confirm this per-message opt-out model satisfies the "separate and
optional marketing consent" expectation under RA 10173, rather than
requiring a single upfront global toggle.]
5. Payment Data: What We Don't Have
DinkingBuds does not integrate with any payment processor today. All
payments are manual transfers directly between you and the venue
(GCash/Maya/bank), verified by venue staff against their own account. We
only ever see the reference number you choose to submit, never your
wallet or bank credentials. [If a payment processor is integrated in the
future, this section must be rewritten and re-reviewed, including BSP
implications per the legal-review checklist §2.]
6. Data retention and deletion
[⚖ No automated retention/purge policy exists today. A lawyer needs to
confirm the minimum retention period required for transaction records
under BIR rules before this section can commit to specific timeframes.]
There is currently no self-service "delete my account" button. Deletion
or redaction requests are handled manually by a platform administrator.
[SUPPORT CONTACT for deletion requests.]
7. Security
- Access to venue data is restricted by role (player / front desk /
manager / owner / platform admin) and enforced server-side, not just
hidden in the interface.
- [⚖ Describe security practices at a level accurate to what's actually
implemented. Do not claim certifications or practices (e.g. "PCI
compliant") that don't apply, since no payment card data is ever
collected.]
8. Your rights under the Data Privacy Act of 2012
[⚖ Counsel to draft: right to be informed, access, object, erasure/
blocking, damages, data portability, file a complaint with the National
Privacy Commission, and whether DinkingBuds needs to register with the
NPC at pilot scale, per the legal-review checklist §2.]
9. Changes to this policy
[Notice mechanism, to be defined.]
10. Contact
[DATA PROTECTION OFFICER / SUPPORT CONTACT, if required by NPC
registration outcome.]