Privacy Policy
Effective Date: July 2, 2026 Last Updated: July 2, 2026
This Privacy Policy describes how Lechon Labs LLC, a Wyoming limited liability company ("Lechon Labs," the "Company," "we," "us," or "our"), collects, uses, shares, stores, and protects personal information in connection with Servicebook.ph (the "Service"). It applies to the mobile application, our websites at servicebook.ph and lechonlabs.com, the public booking pages we host for providers, and all related services we operate.
This Policy is intended to comply with the Data Privacy Act of 2012 (Republic Act No. 10173) of the Republic of the Philippines, its Implementing Rules and Regulations, and the issuances of the National Privacy Commission of the Philippines ("NPC"). It also addresses requirements under the Google Play Store policies and the policies of the sign-in providers we support.
This Policy combines what some services publish as separate "Privacy Policy" and "Data Privacy" pages. Both topics are addressed here in a single document.
We encourage you to read this Policy carefully. By using the Service, you acknowledge that you have read and understood this Policy.
1. Who This Policy Applies To
The Service has two distinct categories of users, and this Policy addresses both. The protections, rights, and obligations described in this Policy may differ depending on which category applies to you.
Providers. Individuals who create an account and use the Service to manage their service business, including staff members they invite to their organization. When we refer to "you" or "your" in this Policy without qualification, we generally mean Providers, except where otherwise specified.
Customers. Individuals who book services from a Provider through the Provider's public booking page. Customers do not create accounts with us and do not set passwords; their bookings are managed through unique, private booking links. Their personal information is processed because they have requested a booking from a Provider who uses our Service.
Important note for Providers regarding your customers. When you use the Service, you act as the personal information controller of your customers' personal data (as that term is defined under the Data Privacy Act of 2012), and we act as your personal information processor. This means you are primarily responsible for ensuring that your customers have been properly informed about how their data is processed and that you have a lawful basis under the Data Privacy Act to process their data through the Service. By using the Service, you confirm that you have such a lawful basis. The terms governing this processor relationship are described throughout this Policy and in our Terms of Service.
2. Information We Collect
2.1 Information We Collect from Providers
When you register for and use the Service, we collect:
Authentication Information. Depending on the sign-in method you choose: your Google profile name, email address, profile picture, and Google account identifier (Google sign-in); your email address (email one-time passcode); or your Philippine mobile number (+63 one-time passcode). We use these to identify you and secure your account.
Business Profile Information. Information you provide about your business, including business name, category, city or municipality, public page address (slug), services offered with descriptions, durations and prices, staff member names and roles, weekly availability and time off, GCash or Maya payment details you choose to display to customers, and an optional payment QR image.
Account Activity. Logs of your interactions with the Service, including login events, feature usage, booking actions, synchronization events, and error events. This information is used to operate the Service and to diagnose issues.
Subscription Information. Records of your plan (free or Team), trial status, and — if you upgrade — the payment method, amount, and transaction reference number you submit for verification. We do not collect or store payment card numbers; Team plan payments are made through your own e-wallet application.
Device and Technical Information. Device model, operating system version, app version, language preference, time zone, push notification token, and approximate IP-based location. This information is used for authentication, security, debugging, and analytics.
Communications with Us. If you contact us by email, through the Service, or through any other channel, we retain records of those communications and any information you provide in them.
2.2 Information We Collect About Customers (Through Providers' Use of the Service)
When a customer books through a Provider's public booking page, or when a Provider records a booking arranged elsewhere, the Service receives:
Booking Information. The service requested, the selected staff member (if any), the requested date and time, and any notes the customer includes.
Customer Contact Information. The customer's name and Philippine mobile number, and — where the service is performed at the customer's location — the address the customer provides. This information is stored as part of the booking record so the Provider can deliver the service.
Booking History and Reviews. Records of bookings associated with each customer within a Provider's organization, including status, payment status recorded by the Provider, and any review the customer submits after a completed booking (a 1–5 rating and optional text, published on the Provider's public page).
We do not collect customer location data beyond the address they provide, and we do not access customers' contact lists, photos, or messages. Customers do not create accounts, and we do not track customers across different Providers.
2.3 Information from Third Parties
We receive information from the following third parties:
- Google LLC. Basic profile information when you choose Google sign-in.
- SMS delivery providers (currently Semaphore). Delivery status of one-time passcodes sent to Philippine mobile numbers. We share the destination number solely to deliver the passcode.
- Supabase. Our cloud database, authentication, and storage provider. Supabase processes data on our behalf as a sub-processor under its own data processing terms.
- Expo. Push notification delivery service for the provider app.
- PostHog. Product analytics service that helps us understand feature usage. Events are associated with account identifiers, not advertising profiles.
- Sentry. Error reporting and performance monitoring service. Sentry receives anonymized or pseudonymized error data when the application encounters bugs or crashes.
- Cloudflare. Web hosting for booking pages and bot-protection challenges (for example, before sending an SMS passcode). Cloudflare may process IP addresses and connection metadata to provide these protections.
3. Why We Process Personal Information (Lawful Bases)
Under the Data Privacy Act of 2012, we process personal information only when we have a lawful basis to do so. The bases on which we rely are:
For Providers' Personal Data:
- Contract Performance. Processing is necessary to fulfill our agreement with you to provide the Service (Section 12(b), DPA 2012).
- Legitimate Interests. Processing is necessary for our legitimate interests in operating, securing, improving, and promoting the Service, where those interests are not overridden by your rights (Section 12(f), DPA 2012).
- Legal Obligation. Processing is necessary to comply with our legal obligations, including tax laws and regulatory requirements (Section 12(c), DPA 2012).
- Consent. For specific processing activities that require consent under applicable law, we will request your consent at the time the activity is initiated, and you may withdraw that consent at any time (Section 12(a), DPA 2012).
For Customers' Personal Data:
When we process Customer Data, we do so as a personal information processor on behalf of the Provider. The lawful basis for processing Customer Data is established by the Provider, who is the controller. The Provider is responsible for ensuring that an appropriate lawful basis exists, which may include:
- The customer's consent (for example, by submitting a booking request through the Provider's page);
- The processing being necessary to schedule and deliver the service the customer requested;
- The processing being necessary for the Provider's legitimate business interests in operating their service business.
4. How We Use Personal Information
We use personal information for the following purposes:
To Provide and Operate the Service:
- Authenticate Providers and maintain their accounts and organizations;
- Publish the Provider's public booking page and compute available time slots;
- Receive, store, and route booking requests to the right Provider and staff member;
- Send booking-related notifications to Providers, and make booking status, payment instructions, and calendar files available to customers through their private booking link;
- Display bookings, customers, and payment status to Providers within the Service;
- Synchronize data between the Provider's mobile device and our cloud infrastructure, including while the device is offline.
To Communicate with Providers:
- Send service-related notifications (booking events, reminders, trial and subscription events, system alerts);
- Respond to support requests;
- Send important changes to these terms or to this Policy;
- With your consent or where permitted by law, send product updates, feature announcements, and marketing communications. You may opt out of marketing communications at any time.
To Improve the Service:
- Analyze how Providers use the Service to identify usability issues and feature opportunities;
- Monitor performance, debug errors, and prevent abuse, including abuse of one-time-passcode delivery.
To Comply with Legal Obligations:
- Respond to lawful requests from regulatory authorities, including the National Privacy Commission and law enforcement;
- Maintain records required by tax law and consumer protection law;
- Investigate and respond to suspected violations of our Terms of Service or applicable law.
To Protect Our Legal Interests:
- Detect, prevent, and address fraud, security incidents, or abuse;
- Enforce our agreements;
- Establish, exercise, or defend legal claims.
We do not sell personal information. We do not use personal information for behavioral advertising targeting Providers or Customers.
5. Automated Processing
The Service uses automated processing to compute available time slots from Providers' schedules and to assign bookings among a team's qualified staff when a customer selects "any available" (assignment favors the least-booked available staff member). Providers retain full control: no booking is confirmed to a customer until the Provider (or their staff) confirms it, and Providers may reassign bookings.
We do not make decisions about Providers or Customers based solely on automated processing in a way that produces legal or similarly significant effects.
6. How We Share Personal Information
We share personal information only as described below.
Service Providers (Sub-processors). We share personal information with third-party service providers who help us operate the Service. These providers are bound by contractual obligations to protect personal information and to use it only for the purposes we direct. Our current sub-processors include:
| Sub-processor | Purpose | Data Categories |
|---|---|---|
| Supabase, Inc. | Database, authentication, file storage | All Provider and Customer data |
| Google LLC | Google sign-in | Authentication identifiers, basic profile |
| Semaphore | SMS delivery of one-time passcodes | Philippine mobile numbers |
| Expo (650 Industries, Inc.) | Push notification delivery | Push tokens, device platform |
| PostHog, Inc. | Product analytics | Pseudonymized usage events |
| Functional Software, Inc. (Sentry) | Error reporting and performance monitoring | Pseudonymized error data |
| Cloudflare, Inc. | Web hosting, bot protection | IP addresses, connection metadata |
We may add or change sub-processors as the Service evolves. Material changes to sub-processor relationships will be reflected in updated versions of this Policy.
Providers (with respect to Customer Data). Customer Data submitted through a Provider's booking page is shared with that Provider and, where relevant, the staff member assigned to the booking. The Provider is the controller of that data and uses it to deliver the booked service.
The Public (with respect to Provider pages and reviews). A Provider's business profile, services, prices, aggregate rating, and customer reviews are published on the Provider's public booking page, visible to anyone with the link. Reviews display the content the customer submitted; customers should avoid including personal information they do not wish to publish.
Legal Compliance. We may disclose personal information if we believe in good faith that disclosure is necessary to:
- Comply with applicable law, regulation, court order, or legal process (including from authorities in the Philippines and the United States);
- Protect the rights, property, or safety of Lechon Labs, our users, or the public;
- Detect, prevent, or address fraud, security, or technical issues;
- Enforce our Terms of Service.
Business Transfers. If Lechon Labs is involved in a merger, acquisition, asset sale, or similar transaction, personal information may be transferred to the acquiring party, subject to a continuing obligation to protect the data in accordance with this Policy or a successor policy at least as protective.
With Your Consent. We may share personal information for purposes not listed above with your consent or at your direction.
We do not sell personal information to third parties. We do not share personal information with third parties for their own marketing purposes.
7. International Transfers of Personal Information
Lechon Labs is operated from outside the Philippines and uses cloud infrastructure that may be located in multiple jurisdictions, including Singapore (Supabase), the United States (Google, Expo, PostHog, Sentry, Cloudflare), and the Philippines (SMS delivery). As a result, your personal information may be transferred to, stored in, and processed in jurisdictions outside the Philippines.
When personal information of Philippine data subjects is transferred outside the Philippines, we comply with the cross-border transfer requirements of the Data Privacy Act of 2012 and any applicable NPC issuances. We rely on contractual safeguards, sub-processor commitments, and where applicable, the recipient country's privacy framework.
By using the Service, you acknowledge that your personal information may be transferred to and processed in countries outside the Philippines that may have different data protection standards than your country of residence.
8. Data Retention
We retain personal information for as long as necessary to provide the Service and to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law.
Active Accounts. While a Provider's account is active, we retain the Provider's account information, business profile, services, availability, team records, booking records, customer records, reviews, and analytics.
Closed Accounts. When a Provider closes their account, we delete or anonymize the Provider's account information within ninety (90) days, except for:
- Records required for tax, accounting, or legal compliance, which we retain for the period required by applicable law;
- Records reasonably necessary to defend against potential legal claims, which we retain for the applicable statute of limitations period;
- Aggregated, anonymized data used for service improvement, which is no longer associated with any identifiable individual.
Customer Data. Customer Data is retained as long as the associated Provider account is active and may be deleted by the Provider through the Service. Providers are responsible for honoring customer data subject requests under the Data Privacy Act with respect to Customer Data.
Booking Links. A customer's private booking link remains active so the customer can view their booking, cancel or reschedule per the Provider's policy, and submit a review within the review window after completion.
Backup Storage. Personal information may persist in encrypted backup systems for up to one hundred eighty (180) days after deletion from production systems before being automatically purged.
9. Security
We take reasonable organizational, physical, and technical measures to protect personal information from unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit using industry-standard TLS;
- Encryption of data at rest within our cloud database and storage systems;
- Row-level access controls that isolate each organization's data;
- Private, unguessable booking links for customers, with rate limiting on lookups;
- Bot-protection challenges and rate limits on one-time-passcode delivery;
- Authentication and access controls limiting personnel access to personal information on a need-to-know basis;
- Logging and monitoring to detect unauthorized access or unusual activity.
No method of transmission over the internet or method of electronic storage is one hundred percent (100%) secure. We cannot guarantee absolute security. Providers are responsible for keeping their sign-in methods and devices secure, and customers are responsible for not sharing their private booking links.
In the event of a personal data breach involving sensitive personal information or information likely to give rise to a real risk of serious harm, we will notify the National Privacy Commission and affected data subjects in accordance with the Data Privacy Act of 2012 and applicable NPC issuances.
10. Your Rights as a Data Subject
Under the Data Privacy Act of 2012, data subjects in the Philippines have the following rights with respect to their personal information:
- Right to Be Informed. You have the right to be informed about the collection and processing of your personal information. This Policy is intended to fulfill that right.
- Right to Access. You have the right to reasonable access to your personal information, including a description of the data, the recipients, the manner of processing, and how the data was obtained.
- Right to Object. You have the right to object to the processing of your personal information, including for purposes of direct marketing, automated processing, or profiling.
- Right to Correct (Rectification). You have the right to dispute and have corrected any inaccuracy or error in your personal information.
- Right to Erasure or Blocking. You have the right to suspend, withdraw, or order the blocking, removal, or destruction of your personal information from our filing systems under certain circumstances.
- Right to Damages. You have the right to be indemnified for damages sustained due to inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorized use of personal information.
- Right to Data Portability. Where applicable, you have the right to obtain a copy of your personal information in an electronic, structured, and commonly used format.
- Right to File a Complaint. You have the right to file a complaint with the National Privacy Commission. The NPC's contact information is available at privacy.gov.ph.
To exercise any of these rights, contact us at kumusta@servicebook.ph. We will respond within fifteen (15) business days, or sooner where required by law. We may need to verify your identity before responding to a request, and we may decline requests in limited circumstances permitted by law (for example, if the request is manifestly unfounded or excessive, or if fulfilling it would violate the rights of others).
Important note for Customers (data subjects of Providers). If you are a customer who has booked with a Provider using Servicebook.ph, the Provider is the personal information controller of your data. You should direct data subject requests primarily to the Provider. We will assist Providers in responding to such requests where required, but the Provider remains the primary point of contact. If you cannot reach the Provider or believe the Provider is not responding appropriately, you may contact us at kumusta@servicebook.ph and we will assist where we can.
11. Children's Privacy
The Service is not intended for individuals under the age of eighteen (18). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us at kumusta@servicebook.ph and we will delete the information promptly.
Providers must not use the Service to accept bookings from individuals known to be under eighteen (18) years of age, except where the booking is placed by a parent or legal guardian on behalf of a minor (for example, a parent booking a tutoring session for their child).
12. Cookies and Similar Technologies
The Servicebook.ph mobile application uses local device storage to provide offline functionality. The servicebook.ph website and hosted booking pages use minimal cookies and browser storage necessary for site functionality, bot protection, and product analytics. We do not use third-party advertising cookies or behavioral tracking cookies on our properties.
The Service integrates with third-party services (such as Google and Cloudflare) that may use their own cookies and similar technologies under their respective privacy policies. We do not control these third-party technologies.
13. Data Protection Officer and Contact
Lechon Labs has designated a Data Protection Officer (DPO) responsible for ensuring compliance with the Data Privacy Act of 2012 and related regulations.
Data Protection Officer: Attn: Data Protection Officer, Lechon Labs LLC. Contact Email: kumusta@servicebook.ph
You may contact the DPO at the email address above for any matter related to:
- Exercising your rights as a data subject;
- Filing a privacy concern or complaint;
- Asking questions about how we process your personal information;
- Requesting clarification of any provision of this Policy.
We will acknowledge receipt of your message within five (5) business days and provide a substantive response within fifteen (15) business days, except where applicable law specifies a different timeline.
14. Changes to This Policy
We may update this Policy from time to time. Material changes will be notified through the Service or by email at least fifteen (15) days before they take effect, where reasonably practicable. The "Last Updated" date at the top of this Policy reflects the most recent revision. Your continued use of the Service after the effective date of any change constitutes your acceptance of the modified Policy.
15. Regulatory Information and Lawful Basis Summary
This Section summarizes key regulatory disclosures required under the Data Privacy Act of 2012:
- Personal Information Controller (for Provider Data): Lechon Labs LLC, a Wyoming limited liability company.
- Personal Information Processor Role: Lechon Labs acts as a personal information processor on behalf of Providers with respect to Customer Data.
- Purposes of Processing: As described in Section 4.
- Lawful Bases: As described in Section 3.
- Categories of Recipients: As described in Section 6.
- International Transfers: As described in Section 7.
- Retention Periods: As described in Section 8.
- Data Subject Rights: As described in Section 10.
- Data Protection Officer: As described in Section 13.
Where we process personal information of data subjects of more than one thousand (1,000) individuals, we register with the National Privacy Commission as required by NPC Circular No. 2022-04 and applicable issuances. Our NPC registration status will be displayed in this Policy once registration is completed.
16. Contact
For questions about this Policy or to exercise your rights as a data subject, contact:
Lechon Labs LLC A Wyoming limited liability company Attn: Data Protection Officer Email: kumusta@servicebook.ph
You may also file a complaint with the National Privacy Commission of the Philippines at privacy.gov.ph if you believe your rights under the Data Privacy Act of 2012 have been violated.

