Privacy Policy

Last updated: March 2, 2026

1. Introduction

PryviTalk Inc. ("PryviTalk," "we," "our") is committed to protecting your privacy. This Privacy Policy describes how we collect, use, store, and share your personal information when you use the PryviTalk platform ("the Platform"). This policy complies with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations.

2. Information We Collect

2.1 Information You Provide

  • Account information: email address, password (encrypted), username, display name, bio, and profile photo.
  • Payment information: payment method details are processed by our payment provider Xendit. We do not store your full payment card details.
  • Payout information: GCash number, Maya number, or bank account details provided by creators for receiving payouts.
  • Messages and content: text messages, images, and videos you send or receive on the Platform.

2.2 Information Collected Automatically

  • Usage data: pages visited, features used, time spent on the Platform.
  • Device information: browser type, operating system, device type.
  • IP address: stored as a one-way hash for analytics and security purposes. Your raw IP address is not stored.
  • Cookies: session cookies for authentication and user preferences.

3. How We Use Your Information

We use your personal information for the following purposes:

  • Provide services: operate and maintain the Platform, process messages, handle payments and payouts.
  • Communications: send transactional emails (message notifications, credit confirmations, weekly digests), respond to support requests.
  • Security: detect and prevent fraud, abuse, and unauthorized access.
  • Analytics: understand usage patterns to improve the Platform. Analytics data is aggregated and anonymized.
  • Legal compliance: comply with applicable laws and regulations.

4. Cookies

PryviTalk uses the following types of cookies:

  • Essential cookies: required for authentication and core functionality (session tokens, CSRF protection).
  • Analytics cookies: anonymous visitor IDs for page view tracking. These do not contain personal information.
  • Preference cookies: store user settings and display preferences.

You can disable cookies in your browser settings, but this may affect your ability to use the Platform.

5. Third-Party Services

We share limited information with the following third-party service providers:

  • Supabase: our database and authentication provider. Stores user accounts, messages, and application data. Data is hosted on secure cloud infrastructure. Supabase Privacy Policy
  • Xendit: our payment processor for credit purchases and creator payouts. Processes payment information in compliance with PCI-DSS standards. Xendit Privacy Policy
  • Resend: our email delivery provider for transactional emails. Receives recipient email addresses for delivery purposes only. Resend Privacy Policy
  • Vercel: our web hosting provider. Processes web requests and may log IP addresses for security purposes. Vercel Privacy Policy

We do not sell your personal information to any third party.

6. Data Retention

  • Account data: retained as long as your account is active. Upon account deletion, personal data is deleted within 30 days.
  • Messages: retained as long as the conversation exists. Messages in deleted accounts are anonymized.
  • Payment records: retained for 5 years to comply with Philippine tax and financial regulations.
  • Analytics data: page view and profile view data is retained for 2 years in anonymized form.
  • Security logs: retained for 1 year for fraud prevention and security purposes.

7. Data Security

We implement appropriate security measures to protect your personal information:

  • All data in transit is encrypted using TLS/HTTPS.
  • Passwords are hashed using industry-standard algorithms (bcrypt).
  • IP addresses are stored as one-way hashes.
  • Access to personal data is restricted to authorized personnel only.
  • Row-Level Security (RLS) policies ensure users can only access their own data.

8. Your Rights Under the Philippine Data Privacy Act

As a data subject under the Data Privacy Act of 2012, you have the following rights:

  • Right to be informed: you have the right to know how your data is collected, used, and processed.
  • Right to access: you may request a copy of your personal data held by PryviTalk.
  • Right to correction: you may request correction of inaccurate or incomplete personal data.
  • Right to erasure: you may request deletion of your personal data, subject to legal retention requirements.
  • Right to object: you may object to the processing of your personal data, including for marketing purposes.
  • Right to data portability: you may request your personal data in a machine-readable format.
  • Right to file a complaint: you may file a complaint with the National Privacy Commission if you believe your data privacy rights have been violated.

To exercise any of these rights, contact us at privacy@pryvitalk.com.

9. Children's Privacy

PryviTalk is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from minors. If we discover that a user is under 18, we will terminate their account and delete their data.

10. International Data Transfers

Your data may be processed on servers located outside the Philippines. In such cases, we ensure appropriate safeguards are in place to protect your data in accordance with the Data Privacy Act.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification. The "Last updated" date at the top reflects the most recent revision.

12. Contact Information

For privacy-related inquiries or to exercise your data rights:

National Privacy Commission (NPC)
www.privacy.gov.ph