๐ŸŽ‰ First trip in Cebu? โ‚ฑ1,000 off with code CEBUFIRST โ€” 363 of 500 left, ends 31 Dec 2026
Data Privacy Act of 2012

Privacy Notice

What personal data Sugbo Rentals collects, why we are allowed to hold it, who else sees it, how long we keep it, and the rights RA 10173 gives you over all of it.

๐Ÿ“„ Version 0.3 โ€” draft๐Ÿ‡ต๐Ÿ‡ญ RA 10173 ยท NPC๐Ÿ•’ All times Asia/Manila (UTC+8)
Draft notice โ€” not yet reviewed, registered, or filed.NPC registration, the appointment of a Data Protection Officer, and the privacy impact assessment are all launch prerequisites that are still outstanding. Contact details below are placeholders. The processing described reflects what the product is designed to do.

01Who this covers

This notice applies to renters, hosts, host staff, and drivers using Sugbo Rentals โ€” on the web or in the app. For the data described here, Sugbo Rentals is the personal information controller under the Data Privacy Act of 2012 (RA 10173).

Host organisations are separate controllers for what they receive

When a booking is confirmed, the host organisation is given a limited set of your details so they can hand over a vehicle. From that point they hold that data in their own right and are responsible for it. Our terms require them to use it only for the booking โ€” but if you want to know what a specific host holds, ask them, and tell us if they will not answer.

02What we collect

Some of this you give us; some is produced by using the service; a little comes from third parties such as our identity checker and the flight-data provider.

Categories of personal data collected
CategoryExamplesWhere it comes from
AccountName, email, mobile number, password hash, language and currency preferenceYou
Identity documents SensitivePassport, PhilID, UMID, PH or foreign driver's licence, IDP, visa entry stamp โ€” including the document image, number, date of birth and expiryYou, checked by our verification provider
Biometric / liveness SensitiveA selfie and liveness capture, matched against your ID photoYou, at verification
Host and businessDTI or SEC registration, mayor's permit, BIR registration and TIN, LTFRB franchise or CPC, bank or e-wallet payout detailsHosts
Vehicle and driverOR/CR, CTPL, plate number, professional driver's licence, driver record screeningHosts and drivers
BookingDates, pick-up and drop-off place, drive mode, nominated driver details, add-ons, price breakdownYou
TravelFlight or vessel reference for airport and seaport pick-ups, and the arrival status attached to itYou and the flight-data provider
PaymentProvider tokens, amounts, status, deposit holds and refunds. We never see or store raw card numbers โ€” those stay with the payment providerPayment provider
Handover recordsChecklist photographs of the vehicle, fuel and odometer readings, signatures, timestamps and the capture locationBoth parties, at handover
CommunicationsIn-app messages on a confirmed booking, support tickets, claim and dispute submissionsYou
ReviewsRatings, written reviews and repliesYou
Device and fraud signalsIP address, device fingerprint, app version, session logs, card BIN, and patterns such as repeated cancellations or chargebacksAutomatically
Two categories are sensitive personal information

Government identifiers and biometric/liveness data get stricter treatment under RA 10173. We process them only with your explicit consent, given separately at verification, and only for identity checking and fraud prevention โ€” never for advertising, and never sold.

03Why we may hold it

To perform the contract
Creating your account, taking and confirming a booking, collecting payment, paying hosts out, and settling deposits โ€” we cannot do any of it without the data.
Explicit consent
Identity documents, liveness capture, and any marketing message. Consent is asked for separately, and can be withdrawn โ€” although withdrawing it for identity documents means you can no longer book or host.
Legal obligation
Tax and BIR record-keeping, receipts, responses to lawful requests from regulators and law enforcement.
Legitimate interests
Fraud detection, platform safety, dispute evidence, service security, and aggregate analytics โ€” balanced against your rights, and never where those rights outweigh them.

04How we use it

  • Verifying who you are โ€” matching your selfie to your ID, checking licence validity and the 90-day foreign-licence window, and confirming a hostโ€™s business registration.
  • Deciding what you can book โ€” which drive modes you are eligible for, based on your verified licence, date of birth and arrival date.
  • Running the booking โ€” quotes, availability, confirmation, the meeting protocol, and reminders.
  • Suspending the no-show clock when your tracked flight is late, using the flight reference you gave.
  • Taking and returning money โ€” rental capture, deposit holds, refunds, host payouts, and BIR-compliant receipts.
  • Settling claims โ€” the handover checklist is the evidence, and it is shown to both sides and to the mediator.
  • Keeping the platform safe โ€” fraud signals, duplicate-device and velocity checks on first bookings from foreign cards, and review moderation. A signal is an observation, never an automatic verdict: only a person can suspend an account.
  • Support and service messages, by push, SMS, email or Viber depending on your settings. Service messages about a live booking cannot be switched off; marketing can.

We do not sell personal data, and we do not use your documents or your face to train anything.

05Who else sees it

Recipients of personal data
RecipientWhat they getWhen
The host organisationYour name, profile photo, verification status, the booking details, and the contact number for handover. Not your ID document images, your date of birth, or your payment detailsOn confirmation โ€” not while a request is pending
The assigned driverYour first name, the meeting point and time, and a contact numberOn assignment
You, about the hostOrganisation name, verification status, responsiveness, and the driver's first name and contact for handoverSymmetrically, on confirmation
Verification providerID document images and liveness capture, for matchingAt verification
Payment providersAmount, currency, booking reference, and the details you enter directly with themAt payment, capture, refund and payout
Flight-data providerThe flight reference and date you suppliedFor airport pick-ups only
Cloud hosting and infrastructureEncrypted storage and processing, under contract, on our instructions onlyContinuously
Regulators and authoritiesWhat a lawful request or a legal obligation requires โ€” BIR, LTO, LTFRB, DTI, NPC, or law enforcementOn lawful request
Insurers and counselBooking, handover and claim records relevant to an incidentWhere a claim or legal matter requires it

Reviews and your first name and profile photo are public on the platform once published. Everything else in this table is not.

06Storage and transfers abroad

RA 10173 does not require personal data to stay in the Philippines, but it does require safeguards and disclosure when it leaves. Our infrastructure is regionally hosted, which means some data is processed and stored outside the Philippines โ€” principally in Singapore โ€” under contractual safeguards that hold the processor to this notice and to Philippine law.

Payment providers, the verification provider, and the flight-data provider may likewise process data outside the country under their own contracts with us. We remain accountable for it either way.

07How long we keep it

Retention periods
DataKept forWhy
Account profileWhile active, then 2 yearsReactivation, and dispute tail
ID document imagesVerification validity, then 1 yearRe-verification and fraud investigation. Deleted earlier on request, which also ends your ability to book
Liveness captureUntil the match is decided, then 90 daysAppeal and false-match review
Bookings, invoices, payments, payouts10 yearsBIR and tax record-keeping
Handover checklists and photos3 years from completionDamage claims and their legal tail
Claims and dispute decisions5 yearsEvidentiary record
Messages and support tickets3 yearsDispute context
ReviewsIndefinitely, once publishedPlatform reputation record
Fraud signals and device logs2 yearsRepeat-abuse detection
Audit log of verification and dispute decisionsRetainedAccountability โ€” this is the record that shows what we decided and why
An erasure request cannot shred a financial or evidentiary record

Closing an account deactivates it rather than deleting it: bookings, payments, payouts and dispute decisions survive, because tax law and the audit trail require them and because they are the evidence protecting the other party to your booking. What an erasure request does remove is the material that has no independent meaning โ€” your profile, preferences, and stored documents beyond their retention period. Where an attribution can be dropped without losing the fact, we drop the attribution and keep the fact.

08Your rights

Under RA 10173 you have the right to:

  • Be informed โ€” that is what this notice is for.
  • Access a copy of the personal data we hold about you, and know who it has been shared with.
  • Object to processing, including to marketing, at any time.
  • Rectify anything inaccurate or out of date.
  • Erasure or blocking, where the data is inaccurate, unlawfully obtained, or no longer necessary โ€” subject to the retention limits above.
  • Data portability โ€” receive your data in a structured, commonly used electronic format.
  • Damages, where you have suffered them through a violation of your rights.
  • Complain to the National Privacy Commission. You do not have to come to us first, although it is usually faster.
How to exercise a right
Account โ†’ Privacy โ†’ Manage my data in the app, or email the Data Protection Officer below.
What we ask for
Enough to confirm it is really you โ€” usually the verified account itself.
Our response time
Within 15 days of a complete request. If it will take longer, we tell you why inside that window.
Cost
Free. A repeated or excessive request may attract a reasonable fee, which we would tell you about first.

09How we protect it

  • TLS 1.3 in transit, and encryption at rest for stored documents.
  • Document images are served through short-lived signed links, never public URLs.
  • Role-based access on internal tools โ€” staff see the minimum their role needs, and admin actions on verification and disputes are written to an audit log.
  • Card data never touches our servers. Payment card handling stays with the hosted payment provider, which keeps our PCI-DSS scope minimal.
  • Structured logging and alerting, with error tracking on payment and payout failures.

No system is perfectly secure, and we do not claim otherwise. What we commit to is the controls above, and honest, prompt notice if they fail.

10GPS trackers in vehicles

Some hosts fit GPS trackers to their vehicles. Where one is fitted, its presence must be declared prominently on the listing before you book โ€” that disclosure is a condition of listing, not a courtesy.

  • Tracking data belongs to the host, for the security of their vehicle. We do not collect a live location feed from a rented vehicle for our own purposes.
  • An undisclosed tracker gets the listing removed and exposes the host to liability under RA 10173.
  • If you find a tracker that was not disclosed, tell us โ€” that is a trust and safety report, and we treat it as one. See trust & safety.

Separately, the handover checklist records the location where the photographs were taken, at the two handover moments only. It is not continuous tracking, and it exists so a later dispute can establish where a car was collected and returned.

11Cookies and analytics

We use cookies and equivalent app storage for sign-in sessions, security, your language and currency choice, and product analytics that tell us where the booking flow is failing. Strictly necessary cookies keep the service working and cannot be turned off; analytics and any marketing cookies are consent-based, and you can change your mind at any time in Account โ†’ Privacy.

12Children

Sugbo Rentals is not for under-18s. Accounts are 18+, and renting requires you to be at least 21 with a yearโ€™s licence held. If we learn that a child has created an account, we close it and delete the data that is not subject to a retention obligation.

13If something goes wrong

In the event of a personal data breach that is likely to give rise to a real risk to your rights โ€” particularly one involving identity documents, biometric data, or payment information โ€” we will notify the National Privacy Commission and the affected individuals within 72 hours of establishing the facts, as the Data Privacy Act requires. The notice will say what happened, what data was involved, what we have done, and what you should do.

14Contact and complaints

Data Protection Officer
dpo@sugborentals.ph (placeholder โ€” appointment pending)
Postal
Data Protection Officer, Sugbo Rentals, Cebu City, Cebu, Philippines (placeholder)
General support
Help centre
Regulator
National Privacy Commission โ€” privacy.gov.ph ยท complaints@privacy.gov.ph
Compliance status, stated honestly

NPC registration, DPO appointment, and the privacy impact assessment are scheduled to complete before launch. Until they do, this notice describes intended practice rather than an operating programme, and this page will be replaced by the reviewed version.

Changes to this notice

We will give notice in the app before this notice changes materially, and where a change extends processing that needs your consent, we will ask for it again rather than assume it.