top of page

DATA PRIVACY STATEMENT AND PRIVACY POLICY

Privacy Policy

​

This Privacy Policy explains how Tubo.ph (“Tubo,” “we,” “us,” “our”) collects, uses, stores, shares, and protects personal data when you access our website (Tubo Site), mobile applications (Tubo App), and related services (collectively, the “Services”). By using the Services, you acknowledge that you have read and understood this Policy.

We process personal data in accordance with the Data Privacy Act of 2012 (RA 10173), its Implementing Rules and Regulations, and applicable NPC issuances

 

1) Key Definitions


Personal Information (PI): Any information that identifies you, or from which your identity can be reasonably and directly ascertained.
Sensitive Personal Information (SPI): As defined under RA 10173 (e.g., race, marital status, government IDs like SSS/GSIS/Pag-IBIG, health, etc.).


Processing: Any operation performed on personal data (collection, recording, organizing, storing, using, sharing, retention, deletion, etc.).


Data Subject: The individual to whom the PI/SPI relates (e.g., employee/end-user).


Subscriber/Enterprise: The company/agency that creates the enterprise account and authorizes users.

 

​

2) What We Collect

We may collect the following categories of data, either directly from you, from your employer/agency, or automatically when you use the Services:


2.1 Account & Identity Data

Name, email, mobile number, company name, business details, job title/role; employer-provided info (employment status, department, site assignment); optional IDs required for compliance.

 


2.2 Attendance & Operational Data

 

Time-in/out logs; site/work location identifiers; device name; approver actions; appeals/requests; audit trails.

 


2.3 Geolocation Data

 

Approximate or precise location (GPS, IP-based, or device-based) used for location-gated timekeeping and fraud prevention. You may control location permissions in your device settings; however, disabling may affect functionality.

 


2.4 Biometric-Related Use (Face Recognition on Shared Devices)

 

For Tubo Timekeeper (shared device), face recognition is used to verify identity for time-in/out. We do not store raw face images for longer than necessary to complete verification and sync; templates (if used) are stored/secured per Documentation and only for authentication. We do not use biometric data for any purpose other than secure timekeeping.

 


2.5 Device/Usage Data (Cookies & SDKs)

 

IP address, device identifiers, OS/browser type, pages viewed, timestamps, crash logs, performance metrics, and cookie data. We may use Google Maps Platform APIs; see Google’s Privacy Policy for details.

 


2.6 Beneficiary/Contact Data (If Provided by Employer)

 

Where lawfully provided by the employer: emergency contact or beneficiary data strictly for employer HR purposes.

 

We rely on the employer’s representation that they have the necessary notices and consents to provide employee data to Tubo.

 

 

3) Why We Process Your Data (Purposes)

We process PI/SPI for the following legitimate purposes:
Provide & operate the Services (account creation, authentication, role management, timekeeping, approvals, reporting, device management).
Fraud prevention & compliance (verify identity; prevent buddy punching; maintain audit trails; comply with legal/regulatory requests).


Service improvement & support (customer support, troubleshooting, analytics, service quality, new features, user experience improvements).


Communications (service announcements, security notifications, product updates; you may opt out of marketing emails).


Integrations (third-party biometric uploads, payroll exports, maps services, or other tools you connect to Tubo).


Research & statistics (aggregated/anonymized analytics, provided no individual is identified).

​

We will not use your data for purposes incompatible with the above without notifying you and, where required, obtaining your consent.

 

 

4) Lawful Bases for Processing

Depending on the context, we rely on one or more of the following bases under Philippine law:


Contract: To deliver the Services to you/your employer.
Legal obligation: To comply with laws and lawful orders.
Legitimate interests: To operate, secure, and improve the Services (balanced against your rights).
Consent: When required by law (e.g., certain marketing, specific sensitive processing). You may withdraw consent at any time (see “Your Rights”).

​

 

5) Data Sharing & Recipients

We may share data with:


Your employer/agency (Subscriber) per their role-based access and policies.
Service providers/contractors (hosting, security, analytics, support, communications, KYC/verification, mapping, device management), bound by confidentiality and data protection obligations.


Affiliates/subsidiaries (Ventaja International Corp., Ventaja Solutions Pte. Ltd.) for operations and support.
Authorities and regulators where required by law, court order, or to protect rights and safety.
Business transfers (merger, acquisition, or asset sale), subject to continuity of protections.

We do not sell personal data.

 

 

6) Cookies & Similar Technologies

We use cookies/SDKs to run the Services, remember settings, improve performance, and measure usage. You can manage cookies in your browser/mobile OS. Some features may not work if cookies/location are disabled.

 

7) Security Measures

We implement reasonable and appropriate organizational, physical, and technical safeguards (access controls, encryption in transit/at rest where applicable, network protections, logging/monitoring, least-privilege access, employee training). No method of transmission or storage is 100% secure; if a breach occurs, we will notify the NPC and affected individuals in accordance with law.

 

8) Data Retention & Deletion

We retain personal data only for as long as necessary to fulfill the purposes described above, comply with legal obligations, resolve disputes, and enforce agreements. When data is no longer needed, we delete or anonymize it using industry-standard methods.


Operational logs and audit trails are retained per statutory/contractual requirements.
Trial/temporary data may be purged after a defined window if not converted to a live account.
You may request deletion subject to legal or contractual retention obligations.

Your earlier draft mentioned a fixed “three (3) months” period. If you keep that, add: “We may retain certain records beyond three (3) months where required by law or for legitimate business needs (e.g., audit, dispute resolution).”

​

9) International Transfers

Your data may be processed in the Philippines and other jurisdictions where we or our processors operate. Where required, we implement appropriate safeguards to protect your data in cross-border transfers.

 

10) Your Rights as a Data Subject

Subject to the DPA and applicable law, you have the right to:


Be informed about our processing activities;
Access your personal data;
Rectify inaccurate or incomplete data;
Object to processing based on legitimate interests (where applicable);
Withdraw consent (for consent-based processing);
Erase/block data when legally permissible;
Data portability where applicable; and
Lodge a complaint with the National Privacy Commission.

 

​

To exercise rights, contact us (see “Contact Us”). We may need to verify your identity and coordinate with your employer (Subscriber) where the employer is the primary controller of employee data.

 

 

11) Children’s Privacy

The Services are not intended for individuals under 18. We do not knowingly collect data from minors. If we learn we have collected data from a minor without appropriate consent, we will delete it.

 

12) Marketing Communications

You can unsubscribe from marketing emails at any time via the link in our emails or by contacting us. You will still receive service/transactional communications necessary to operate your account.

 

13) Changes to This Policy

We may update this Policy from time to time. Material changes will be posted on the Tubo Site with an updated “Last updated” date. Continued use of the Services after changes means you accept the updated Policy.

 

14) Contact Us (and DPO)

For questions, requests, or complaints about this Policy or your personal data, contact:


Email: privacy@tubo.ph / mtabulog@tubo.ph

 

 

You may also contact the National Privacy Commission (www.privacy.gov.ph) for concerns.

 

 

 

15) Consent Language (for in-app/web prompts)

By clicking “Agree & Continue,” creating an account, or using the Services, you acknowledge that you have read and understood this Privacy Policy and, where required by law, you consent to the collection, use, storage, and sharing of your personal data as described herein. You may withdraw consent at any time, without affecting the lawfulness of processing prior to withdrawal.

bottom of page