Privacy Notice
Last updated July 22, 2026
This notice explains how Chloe Denisse Meat Shop collects, uses, shares, and protects your personal information. It is provided under the Data Privacy Act of 2012 (Republic Act No. 10173) and its implementing rules.
Who is responsible for your data
The personal information controller is the business named below. Any question about this notice, or any request about your own data, goes to our Data Protection Officer.
- Personal information controller
- [Registered name not yet set — add it in Admin → Settings]
- Business address
- [Business address not yet set — add it in Admin → Settings]
- Data Protection Officer
- [DPO name not yet set — add it in Admin → Settings]
- Data privacy email
- [DPO email not yet set — add it in Admin → Settings]
What we collect
We collect only what we need to get your order to your door:
- When you place an order: your name, mobile number, delivery address (house/street, barangay, and city), email address if you give one, and any delivery instructions you write.
- Your order itself: the items, quantities, prices, payment method, and order status history.
- If you create an account: your email address and a securely hashed password. We never see or store your password in readable form.
- Technical data: a session cookie that keeps you signed in. We do not use advertising or analytics trackers.
We do not collect sensitive personal information as defined by the Act, and we never ask for your card details — those go directly to our payment processor and never reach our systems.
Why we use it, and on what basis
- To fulfil your order — name, address, and instructions are needed to prepare and deliver it. Basis: necessary for the performance of our contract with you.
- To price and make your delivery — your city sets the delivery fee, and your mobile number lets our rider reach you on the day. Basis: contract.
- To prevent fraudulent orders — we check your email, mobile number, and IP address against a block list, and count recent orders, so the shop is not flooded with fake cash-on-delivery orders. Basis: our legitimate interest in preventing abuse.
- To take payment — order reference and amount are shared with our payment processor. Basis: contract.
- To keep required business records — sales records are retained for tax and regulatory purposes. Basis: compliance with a legal obligation.
- To protect the service — we log administrative actions and rate-limit abusive traffic. Basis: our legitimate interest in running the shop securely.
Who else sees it
We do not sell your personal information, and we do not share it for anyone else's marketing. We use two service providers:
- Supabase — hosts our database and handles account sign-in. Your order and account records are stored on their infrastructure.
- PayMongo — processes online payments (GCash, Maya, card). When you choose to pay online, we send them your order reference, the amount, and the item names. Your payment credentials are entered on their page, not ours.
We may also disclose information where the law requires it, such as a lawful order from a government agency or a court.
Order links
After checkout we give you a link to your order so you can track it without signing in. Anyone holding that link can see the order, though the name and address are hidden unless you open it from the device you ordered on. Please treat the link as private.
How long we keep it
- Order and sales records: retained for the period required by tax and regulatory rules, then deleted or anonymised.
- Account records: kept while your account is open, and removed on request subject to the retention rule above.
- Administrative logs: kept for a limited period for security and dispute investigation.
How we protect it
We apply organisational, physical, and technical measures consistent with the Act and NPC Circular 2023-06. Traffic is encrypted in transit, database access is restricted by row-level security so customers can only reach their own records, administrative access is limited to authorised staff, and administrative changes are logged.
If a personal data breach occurs that poses a real risk to you, we will notify the National Privacy Commission and affected customers within 72 hours of becoming aware of it, as the Act requires.
Your rights
Under the Data Privacy Act you have the right to:
- be informed that your data is being processed;
- access the personal data we hold about you;
- have inaccurate or incomplete data corrected;
- object to processing, or withdraw consent where consent is the basis;
- have your data erased or blocked, where the law allows;
- obtain a copy of your data in a portable format; and
- be indemnified for damage caused by inaccurate or unlawfully obtained data.
To exercise any of these, email our Data Protection Officer at [DPO email not yet set — add it in Admin → Settings]. We will respond within a reasonable period. Note that we may need to keep certain sales records even after a deletion request, where tax law requires it — we will tell you if that applies.
If you are unsatisfied with our response, you may complain to the National Privacy Commission.
Changes to this notice
If we change how we handle personal data, we will update this page and the date above. Material changes will be announced on the storefront.
See also our Terms of Sale and Returns & Refunds Policy.