Privacy Policy
Last updated · September 5, 2026
1. Who we are
This Privacy Policy describes how Bacolod Information Technology Solutions (a sole proprietorship registered with the Department of Trade and Industry of the Philippines), operating the product “Pinoy Reviewer Hub”(the “Service”), collects, uses, stores, and protects your personal data when you use our website (pinoyreviewerhub.com) or mobile applications.
We are committed to protecting your personal data in compliance with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and applicable issuances of the National Privacy Commission (NPC).
- Business name: Bacolod Information Technology Solutions (DBA Pinoy Reviewer Hub)
- Address: Manila, Metro Manila, Philippines
- Email: pinoyreviewerhub@gmail.com
- Personal Information Controller (PIC): Joselito Bacolod
- NPC registration status: Pending
2. Data Protection Officer (DPO)
As a sole proprietorship, our Data Protection Officer is the proprietor himself:
- Name: Joselito Bacolod
- Role: Proprietor and Data Protection Officer
- Contact: pinoyreviewerhub@gmail.com
The DPO is responsible for ensuring our compliance with the Data Privacy Act and handling all privacy-related concerns from data subjects. For privacy questions, complaints, or data access requests, please contact the DPO directly via email.
3. What personal data we collect
When you use Pinoy Reviewer Hub, we collect the following:
3.1 Account information
- Email address
- Display name (chosen by you)
- Profile photo, if you choose to add one (from your Google account or a photo you pick from your device)
- Exam goal and, for LET reviewers, the majorship you select
- Password (stored as a one-way cryptographic hash via Firebase Authentication; we cannot read or recover your password)
- Account creation date and last login timestamps
3.2 Usage data
- Exams selected, questions answered, scores, and time spent
- Learning streaks, XP, and progress milestones
- Preferences (e.g., daily reminder settings, dark mode)
- Notes and bookmarks you save inside the app, and the names of the devices you sign in from (used to keep one active session)
3.3 Device and technical data
- Device type, OS version, and app version
- IP address (for security and fraud prevention only)
- Browser type and language (for the web)
- Crash reports and diagnostic logs (no personal content)
3.4 Payment data
- For web subscriptions: handled entirely by Stripe, Inc. We receive only confirmation of successful payment, the transaction ID, and the subscription tier purchased. We never see, store, or have access to your credit card, debit card, or bank account numbers.
- For mobile subscriptions: handled by Google Play Billing (Android) or the Apple App Store (iOS). We do not handle your payment details directly.
3.5 Optional data
- Communications you send to us via email, Discord, or Facebook (we retain these for support and reference)
- Feedback, suggestions, or content you voluntarily share with us
4. Lawful basis for processing
Under the Data Privacy Act, we process your personal data based on the following lawful grounds:
- Consent: You expressly agree to this Privacy Policy when you create an account or subscribe.
- Contractual necessity: Processing is necessary to provide the subscription service you purchased.
- Legal obligation: Retention of payment records for compliance with Bureau of Internal Revenue (BIR) regulations.
- Legitimate interests: Fraud prevention, security monitoring, and service improvement, provided these do not override your rights as a data subject.
5. How we use your data
We use your personal data for the following purposes only:
- To create and maintain your user account
- To provide, personalize, and improve the reviewer service
- To sync your progress across web and mobile devices using your single account
- To process and manage your subscription (billing, renewals, cancellations, refunds)
- To send transactional emails: email verification, password reset, payment receipts, subscription notifications, and important service updates
- To enforce subscription access and prevent unauthorized account sharing or abuse
- To respond to your inquiries and provide customer support
- To detect and prevent fraud, security incidents, or violations of our Terms of Service
- To comply with our legal obligations (e.g., BIR record-keeping, NPC inquiries, court orders)
What we DO NOT do with your data:
- We do not sell your personal data to anyone, ever.
- We do not share your personal data with third parties for advertising purposes.
- We do not use your usage data to train external AI models.
- We do not display third-party advertisements on our website or apps.
6. Minors and parental consent
Pinoy Reviewer Hub is intended for users 13 years of age and older. Users between 13 and 17 require verifiable parental or guardian consent to use the Service.
For users under 13: We do not knowingly collect personal data from children under 13. If we discover such data has been collected, we will promptly delete it, terminate the account, and notify the parent or guardian if known.
For minors aged 13-17: We collect only the minimum necessary information needed to provide the Service. We do not engage in targeted advertising directed at minors, and we do not sell or share their data beyond the disclosures in Section 7 (Third-party service providers).
Parents or guardians who believe a child has provided personal data without proper consent should contact our DPO immediately at pinoyreviewerhub@gmail.com for deletion. Parents or guardians may also request access to or deletion of their child’s data, subject to proof of guardianship.
7. Third-party service providers
We rely on a small number of trusted, contractually-bound service providers to operate. Each has been chosen for their strong data protection standards:
- Google Firebase(Google LLC) — authentication, database (Cloud Firestore), cloud functions, crash reporting, and push notifications. Data is processed primarily in Google’s data centers in the United States and other regions, governed by Firebase’s privacy and security commitments.
- Stripe, Inc. — web subscription payment processing. Subject to Stripe’s Privacy Policy.
- RevenueCat — mobile subscription management (Android and iOS). Subject to RevenueCat’s Privacy Policy.
- Google Generative AI (Google LLC) — generation of mock examinations, practice questions, rationales, and explanations. Subject to Google’s Privacy Policy.
- Google Play Store / Apple App Store — mobile app distribution and billing.
- Firebase App Hosting(Google LLC) — website hosting infrastructure. Subject to Google’s Privacy Policy.
8. International data transfers
Some of our service providers (notably Google Firebase, Stripe, RevenueCat, and Vercel) process data outside the Philippines, including in the United States, European Union, and Asia-Pacific regions. By using our Service, you consent to the transfer of your personal data to these jurisdictions for the purposes described in this Policy.
We require all third-party processors to maintain data protection standards at least equivalent to those required by the Philippine Data Privacy Act, including through contractual safeguards and adherence to internationally recognized frameworks.
9. Cookies and tracking technologies
Our website uses a minimal set of cookies and similar technologies:
- Strictly necessary cookies: Required for the Service to function (e.g., authentication session, cart state). These cannot be disabled.
- Functional cookies: Remember your preferences (e.g., language, theme).
- Analytics cookies (limited): Aggregated, non-identifying usage statistics to help us improve the Service. We use privacy-respecting analytics (no cross-site tracking, no advertising IDs).
We do not use advertising cookies, third-party tracking pixels (e.g., Facebook Pixel, Google Ads), or behavioral retargeting tools.
You may control cookies through your browser settings. Note that disabling necessary cookies will prevent the Service from functioning properly.
10. Security measures
We implement reasonable and appropriate technical, organizational, and physical safeguards to protect your personal data:
- Encryption in transit: All data exchanged between your device and our servers is encrypted via HTTPS (TLS 1.2+).
- Encryption at rest: Personal data stored in Firebase is encrypted at rest using industry-standard algorithms.
- Access controls: Only authorized personnel (the proprietor) can access user data, and only when necessary for support or service operations.
- Password hashing: Passwords are stored as one-way cryptographic hashes; we never store or transmit passwords in readable form.
- Security monitoring: Our infrastructure providers (Firebase, Vercel, Stripe) maintain industry-standard security monitoring and apply security patches at the infrastructure level. We review application-level security as part of routine maintenance.
However, no system is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
11. Data breach notification
In the unlikely event of a personal data breach that is likely to give rise to a real risk of serious harm to affected data subjects, we will:
- Notify the National Privacy Commission (NPC) within 72 hours of becoming aware of the breach, as required by Section 38 of the Data Privacy Act IRR.
- Notify affected data subjects promptly via email with a description of the nature of the breach, the data involved, the measures taken, and recommended actions.
- Cooperate fully with the NPC and law enforcement during any investigation.
12. Data retention
We retain personal data only as long as necessary for the purposes for which it was collected:
- Active accounts: Data is retained for the duration your account remains active.
- Inactive accounts: Accounts with no login activity for 24 consecutive months may be flagged for archival or deletion (with prior email notification).
- Deleted accounts: Upon your deletion request, personal data is removed from active systems within 30 days, and from backups within 90 days.
- Payment records: Retained for at least 10 years in compliance with BIR record-keeping requirements (NIRC and BIR Revenue Regulations).
- Anonymized usage analytics: May be retained indefinitely as they no longer identify you.
13. Your rights as a data subject
Under the Philippine Data Privacy Act, you have the following rights:
- Right to be informed: About how your data is collected and processed (this Policy fulfills that).
- Right to access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure (deletion): Request deletion of your data, subject to legal retention obligations.
- Right to object: Object to processing based on legitimate interests.
- Right to data portability: Request your data in a structured, commonly-used, machine-readable format.
- Right to withdraw consent: Withdraw consent at any time (note: this may end your access to the Service).
- Right to damages: Claim compensation for damages suffered due to inaccurate, incomplete, outdated, false, or unlawfully processed personal data.
- Right to file a complaint: Lodge a complaint with the National Privacy Commission if you believe your rights have been violated. Visit privacy.gov.ph.
How to exercise your rights: Email our DPO at pinoyreviewerhub@gmail.com with the subject “Data Subject Request” and a clear description of your request. We will respond within 15 working days as required by the NPC, and may require identity verification to protect your data.
14. Marketing communications
We send transactional emails (account verification, payment receipts, important service updates) as part of providing the Service. These cannot be opted out of while you maintain an active account.
We may occasionally send product update emails (new exams, new features, important announcements). If you do not wish to receive these, you may opt out at any time by replying to any such email with “UNSUBSCRIBE” in the subject line, or by emailing pinoyreviewerhub@gmail.com. Opting out does not affect transactional emails.
We do not send promotional emails from third parties.
15. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service offerings. When we make material changes, we will:
- Update the “Last updated” date at the top of this page.
- Provide notice through reasonable means, which may include email, in-app notifications, a prominent notice on our website, or announcements through our official Discord or Facebook community channels.
- For substantial changes affecting your rights, we will endeavor to provide at least 30 days’ advance notice and an opportunity to discontinue use of the Service if you disagree.
Continued use of the Service after the effective date constitutes acceptance of the revised Policy.
16. How to contact us
For any privacy-related concerns, requests, or complaints:
- Data Protection Officer: Joselito Bacolod
- Email: pinoyreviewerhub@gmail.com
- Subject line:“Data Privacy Request” or “Privacy Concern”
- Response time: Within 15 working days
You may also file a complaint with the National Privacy Commission:
- Website: privacy.gov.ph
- Email: complaints@privacy.gov.ph