Privacy Policy

Effective Date: July 2, 2026 Last Updated: July 2, 2026

This Privacy Policy describes how Lechon Labs LLC, a Wyoming limited liability company ("Lechon Labs," the "Company," "we," "us," or "our"), collects, uses, shares, stores, and protects personal information in connection with Servicebook.ph (the "Service"). It applies to the mobile application, our websites at servicebook.ph and lechonlabs.com, the public booking pages we host for providers, and all related services we operate.

This Policy is intended to comply with the Data Privacy Act of 2012 (Republic Act No. 10173) of the Republic of the Philippines, its Implementing Rules and Regulations, and the issuances of the National Privacy Commission of the Philippines ("NPC"). It also addresses requirements under the Google Play Store policies and the policies of the sign-in providers we support.

This Policy combines what some services publish as separate "Privacy Policy" and "Data Privacy" pages. Both topics are addressed here in a single document.

We encourage you to read this Policy carefully. By using the Service, you acknowledge that you have read and understood this Policy.

1. Who This Policy Applies To

The Service has two distinct categories of users, and this Policy addresses both. The protections, rights, and obligations described in this Policy may differ depending on which category applies to you.

Providers. Individuals who create an account and use the Service to manage their service business, including staff members they invite to their organization. When we refer to "you" or "your" in this Policy without qualification, we generally mean Providers, except where otherwise specified.

Customers. Individuals who book services from a Provider through the Provider's public booking page. Customers do not create accounts with us and do not set passwords; their bookings are managed through unique, private booking links. Their personal information is processed because they have requested a booking from a Provider who uses our Service.

Important note for Providers regarding your customers. When you use the Service, you act as the personal information controller of your customers' personal data (as that term is defined under the Data Privacy Act of 2012), and we act as your personal information processor. This means you are primarily responsible for ensuring that your customers have been properly informed about how their data is processed and that you have a lawful basis under the Data Privacy Act to process their data through the Service. By using the Service, you confirm that you have such a lawful basis. The terms governing this processor relationship are described throughout this Policy and in our Terms of Service.

2. Information We Collect

2.1 Information We Collect from Providers

When you register for and use the Service, we collect:

Authentication Information. Depending on the sign-in method you choose: your Google profile name, email address, profile picture, and Google account identifier (Google sign-in); your email address (email one-time passcode); or your Philippine mobile number (+63 one-time passcode). We use these to identify you and secure your account.

Business Profile Information. Information you provide about your business, including business name, category, city or municipality, public page address (slug), services offered with descriptions, durations and prices, staff member names and roles, weekly availability and time off, GCash or Maya payment details you choose to display to customers, and an optional payment QR image.

Account Activity. Logs of your interactions with the Service, including login events, feature usage, booking actions, synchronization events, and error events. This information is used to operate the Service and to diagnose issues.

Subscription Information. Records of your plan (free or Team), trial status, and — if you upgrade — the payment method, amount, and transaction reference number you submit for verification. We do not collect or store payment card numbers; Team plan payments are made through your own e-wallet application.

Device and Technical Information. Device model, operating system version, app version, language preference, time zone, push notification token, and approximate IP-based location. This information is used for authentication, security, debugging, and analytics.

Communications with Us. If you contact us by email, through the Service, or through any other channel, we retain records of those communications and any information you provide in them.

2.2 Information We Collect About Customers (Through Providers' Use of the Service)

When a customer books through a Provider's public booking page, or when a Provider records a booking arranged elsewhere, the Service receives:

Booking Information. The service requested, the selected staff member (if any), the requested date and time, and any notes the customer includes.

Customer Contact Information. The customer's name and Philippine mobile number, and — where the service is performed at the customer's location — the address the customer provides. This information is stored as part of the booking record so the Provider can deliver the service.

Booking History and Reviews. Records of bookings associated with each customer within a Provider's organization, including status, payment status recorded by the Provider, and any review the customer submits after a completed booking (a 1–5 rating and optional text, published on the Provider's public page).

We do not collect customer location data beyond the address they provide, and we do not access customers' contact lists, photos, or messages. Customers do not create accounts, and we do not track customers across different Providers.

2.3 Information from Third Parties

We receive information from the following third parties:

3. Why We Process Personal Information (Lawful Bases)

Under the Data Privacy Act of 2012, we process personal information only when we have a lawful basis to do so. The bases on which we rely are:

For Providers' Personal Data:

For Customers' Personal Data:

When we process Customer Data, we do so as a personal information processor on behalf of the Provider. The lawful basis for processing Customer Data is established by the Provider, who is the controller. The Provider is responsible for ensuring that an appropriate lawful basis exists, which may include:

4. How We Use Personal Information

We use personal information for the following purposes:

To Provide and Operate the Service:

To Communicate with Providers:

To Improve the Service:

To Comply with Legal Obligations:

To Protect Our Legal Interests:

We do not sell personal information. We do not use personal information for behavioral advertising targeting Providers or Customers.

5. Automated Processing

The Service uses automated processing to compute available time slots from Providers' schedules and to assign bookings among a team's qualified staff when a customer selects "any available" (assignment favors the least-booked available staff member). Providers retain full control: no booking is confirmed to a customer until the Provider (or their staff) confirms it, and Providers may reassign bookings.

We do not make decisions about Providers or Customers based solely on automated processing in a way that produces legal or similarly significant effects.

6. How We Share Personal Information

We share personal information only as described below.

Service Providers (Sub-processors). We share personal information with third-party service providers who help us operate the Service. These providers are bound by contractual obligations to protect personal information and to use it only for the purposes we direct. Our current sub-processors include:

Sub-processor Purpose Data Categories
Supabase, Inc. Database, authentication, file storage All Provider and Customer data
Google LLC Google sign-in Authentication identifiers, basic profile
Semaphore SMS delivery of one-time passcodes Philippine mobile numbers
Expo (650 Industries, Inc.) Push notification delivery Push tokens, device platform
PostHog, Inc. Product analytics Pseudonymized usage events
Functional Software, Inc. (Sentry) Error reporting and performance monitoring Pseudonymized error data
Cloudflare, Inc. Web hosting, bot protection IP addresses, connection metadata

We may add or change sub-processors as the Service evolves. Material changes to sub-processor relationships will be reflected in updated versions of this Policy.

Providers (with respect to Customer Data). Customer Data submitted through a Provider's booking page is shared with that Provider and, where relevant, the staff member assigned to the booking. The Provider is the controller of that data and uses it to deliver the booked service.

The Public (with respect to Provider pages and reviews). A Provider's business profile, services, prices, aggregate rating, and customer reviews are published on the Provider's public booking page, visible to anyone with the link. Reviews display the content the customer submitted; customers should avoid including personal information they do not wish to publish.

Legal Compliance. We may disclose personal information if we believe in good faith that disclosure is necessary to:

Business Transfers. If Lechon Labs is involved in a merger, acquisition, asset sale, or similar transaction, personal information may be transferred to the acquiring party, subject to a continuing obligation to protect the data in accordance with this Policy or a successor policy at least as protective.

With Your Consent. We may share personal information for purposes not listed above with your consent or at your direction.

We do not sell personal information to third parties. We do not share personal information with third parties for their own marketing purposes.

7. International Transfers of Personal Information

Lechon Labs is operated from outside the Philippines and uses cloud infrastructure that may be located in multiple jurisdictions, including Singapore (Supabase), the United States (Google, Expo, PostHog, Sentry, Cloudflare), and the Philippines (SMS delivery). As a result, your personal information may be transferred to, stored in, and processed in jurisdictions outside the Philippines.

When personal information of Philippine data subjects is transferred outside the Philippines, we comply with the cross-border transfer requirements of the Data Privacy Act of 2012 and any applicable NPC issuances. We rely on contractual safeguards, sub-processor commitments, and where applicable, the recipient country's privacy framework.

By using the Service, you acknowledge that your personal information may be transferred to and processed in countries outside the Philippines that may have different data protection standards than your country of residence.

8. Data Retention

We retain personal information for as long as necessary to provide the Service and to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law.

Active Accounts. While a Provider's account is active, we retain the Provider's account information, business profile, services, availability, team records, booking records, customer records, reviews, and analytics.

Closed Accounts. When a Provider closes their account, we delete or anonymize the Provider's account information within ninety (90) days, except for:

Customer Data. Customer Data is retained as long as the associated Provider account is active and may be deleted by the Provider through the Service. Providers are responsible for honoring customer data subject requests under the Data Privacy Act with respect to Customer Data.

Booking Links. A customer's private booking link remains active so the customer can view their booking, cancel or reschedule per the Provider's policy, and submit a review within the review window after completion.

Backup Storage. Personal information may persist in encrypted backup systems for up to one hundred eighty (180) days after deletion from production systems before being automatically purged.

9. Security

We take reasonable organizational, physical, and technical measures to protect personal information from unauthorized access, alteration, disclosure, or destruction. These measures include:

No method of transmission over the internet or method of electronic storage is one hundred percent (100%) secure. We cannot guarantee absolute security. Providers are responsible for keeping their sign-in methods and devices secure, and customers are responsible for not sharing their private booking links.

In the event of a personal data breach involving sensitive personal information or information likely to give rise to a real risk of serious harm, we will notify the National Privacy Commission and affected data subjects in accordance with the Data Privacy Act of 2012 and applicable NPC issuances.

10. Your Rights as a Data Subject

Under the Data Privacy Act of 2012, data subjects in the Philippines have the following rights with respect to their personal information:

To exercise any of these rights, contact us at kumusta@servicebook.ph. We will respond within fifteen (15) business days, or sooner where required by law. We may need to verify your identity before responding to a request, and we may decline requests in limited circumstances permitted by law (for example, if the request is manifestly unfounded or excessive, or if fulfilling it would violate the rights of others).

Important note for Customers (data subjects of Providers). If you are a customer who has booked with a Provider using Servicebook.ph, the Provider is the personal information controller of your data. You should direct data subject requests primarily to the Provider. We will assist Providers in responding to such requests where required, but the Provider remains the primary point of contact. If you cannot reach the Provider or believe the Provider is not responding appropriately, you may contact us at kumusta@servicebook.ph and we will assist where we can.

11. Children's Privacy

The Service is not intended for individuals under the age of eighteen (18). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us at kumusta@servicebook.ph and we will delete the information promptly.

Providers must not use the Service to accept bookings from individuals known to be under eighteen (18) years of age, except where the booking is placed by a parent or legal guardian on behalf of a minor (for example, a parent booking a tutoring session for their child).

12. Cookies and Similar Technologies

The Servicebook.ph mobile application uses local device storage to provide offline functionality. The servicebook.ph website and hosted booking pages use minimal cookies and browser storage necessary for site functionality, bot protection, and product analytics. We do not use third-party advertising cookies or behavioral tracking cookies on our properties.

The Service integrates with third-party services (such as Google and Cloudflare) that may use their own cookies and similar technologies under their respective privacy policies. We do not control these third-party technologies.

13. Data Protection Officer and Contact

Lechon Labs has designated a Data Protection Officer (DPO) responsible for ensuring compliance with the Data Privacy Act of 2012 and related regulations.

Data Protection Officer: Attn: Data Protection Officer, Lechon Labs LLC. Contact Email: kumusta@servicebook.ph

You may contact the DPO at the email address above for any matter related to:

We will acknowledge receipt of your message within five (5) business days and provide a substantive response within fifteen (15) business days, except where applicable law specifies a different timeline.

14. Changes to This Policy

We may update this Policy from time to time. Material changes will be notified through the Service or by email at least fifteen (15) days before they take effect, where reasonably practicable. The "Last Updated" date at the top of this Policy reflects the most recent revision. Your continued use of the Service after the effective date of any change constitutes your acceptance of the modified Policy.

15. Regulatory Information and Lawful Basis Summary

This Section summarizes key regulatory disclosures required under the Data Privacy Act of 2012:

Where we process personal information of data subjects of more than one thousand (1,000) individuals, we register with the National Privacy Commission as required by NPC Circular No. 2022-04 and applicable issuances. Our NPC registration status will be displayed in this Policy once registration is completed.

16. Contact

For questions about this Policy or to exercise your rights as a data subject, contact:

Lechon Labs LLC A Wyoming limited liability company Attn: Data Protection Officer Email: kumusta@servicebook.ph

You may also file a complaint with the National Privacy Commission of the Philippines at privacy.gov.ph if you believe your rights under the Data Privacy Act of 2012 have been violated.