Privacy Notice
1. INTRODUCTION & SCOPE
Peddlr Philippines Inc. ("Peddlr", "we", "us", or "our") respects your privacy and is fully committed to protecting your personal data in strict compliance with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and other relevant issuances of the National Privacy Commission (NPC). This Unified Privacy Notice ("Notice") governs the collection, processing, sharing, and retention of personal data across the entire Peddlr Ecosystem, which includes the Peddlr App, Peddlr Lite, Kankolek Services, and the Peddlr Eload API (collectively, the "Services"). By accessing, registering, integrating with, or using any of the Services, you acknowledge that your personal data may be processed in accordance with this Notice and applicable law. Where consent is required under applicable law, you further agree that such consent may be obtained electronically through the Services. This Notice is incorporated by reference into the Peddlr Ecosystem Master Terms & Conditions.
2. THE DATA WE COLLECT
To provide, secure, and optimize the Services, we collect the following categories of information:
- Registration & Verification Data: Name, business name, address, email address, mobile number, government-issued identification documents, business permits, photographs, and identity verification or liveness-check information where reasonably necessary for onboarding, fraud prevention, AML compliance, or account security.
- Transactional & Financial Data: Transaction histories, wallet balances, sales ledger entries, inventory data, payment routing information, bank account details, and digital product dispensation logs.
- Technical & System Logs: IP addresses, device identifiers, API request logs, timestamps, operating system information, and approximate device, network, or regional location data reasonably necessary for security, fraud prevention, analytics, or service delivery.
- End-User Data (Processed on behalf of B2B Partners): Customer phone numbers, payment amounts, and transaction references passed through Kankolek or the Eload API.
Users are responsible for ensuring that the personal data, business information, settlement details, and account information submitted through the Services remain accurate, complete, and up to date. Peddlr limits the collection and processing of sensitive personal information to what is reasonably necessary for identity verification, fraud prevention, regulatory compliance, security, and lawful business operations in accordance with applicable law. Where sensitive personal information is processed, Peddlr shall do so only where authorized by applicable law, including where required for compliance with legal obligations, establishment, exercise, or defense of legal claims, identity verification, fraud prevention, or with the data subject's consent where required.
3. BROAD PROCESSING AUTHORITY & PURPOSES
Peddlr processes personal data pursuant to one or more lawful bases recognized under applicable law, including consent, contractual necessity, compliance with legal obligations, protection of lawful rights and interests, fraud prevention, network and information security, and legitimate business interests that are not overridden by the fundamental rights and freedoms of the data subject.
We process your data for the following legitimate commercial and regulatory purposes:
- Service Provisioning: To execute transactions, dispense digital products, route payments, and maintain your account balance.
- Security & Fraud Prevention: To monitor for unauthorized access, detect fraudulent transactions, and protect system integrity.
- Analytics & Platform Improvement: To analyze usage trends, optimize API performance, and develop new features.
- Legal & Regulatory Compliance: To fulfill our obligations under Philippine law, including tax reporting, anti-money laundering (AML) monitoring, and dispute resolution.
Peddlr may generate, use, process, and disclose aggregated, de-identified, or anonymized information derived from the Services for analytics, research, security, fraud prevention, service improvement, product development, benchmarking, and other lawful business purposes, provided that such information cannot reasonably be used, whether alone or in combination with other information reasonably available to Peddlr, to identify a particular individual.
4. REGULATORY DISCLOSURES & COMPLIANCE
Peddlr may disclose personal, business, transactional, and system-related information to the Bangko Sentral ng Pilipinas (BSP), the Bureau of Internal Revenue (BIR), the Anti-Money Laundering Council (AMLC), the National Privacy Commission (NPC), law enforcement agencies, financial institutions, telecommunications providers, auditors, and compliance partners where reasonably necessary for compliance with applicable law, regulatory obligations, fraud prevention, security, dispute resolution, or the protection and enforcement of lawful rights and legitimate business interests. Peddlr maintains applicable registrations, submissions, and compliance filings with the National Privacy Commission where required under applicable law.
5. CONTROLLER VS. PROCESSOR ROLES (B2B ALLOCATION)
To ensure strict DPA compliance, data processing roles within the Peddlr Ecosystem are legally defined as follows:
- Retail Users (Peddlr App / Peddlr Lite): Peddlr acts as the Personal Information Controller (PIC) regarding the User’s own business and registration data.
- Enterprise & API Partners (Kankolek / Eload API): For end-customer data transmitted through Kankolek Services or the Eload API, Peddlr generally acts as a Personal Information Processor (PIP) on behalf of the relevant Enterprise or API Partner, except to the extent Peddlr independently determines the purposes or means of processing under applicable law. Where necessary to provide the Services, Peddlr may process, access, transfer, store, or disclose personal data in accordance with the documented instructions of the relevant Enterprise or API Partner acting as PIC, subject to applicable law. The Enterprise/API Partner acts as the PIC.
Partner Responsibilities & Indemnity: Enterprise and API Partners warrant that all end-user personal data transmitted through the Services was lawfully obtained and disclosed to Peddlr. Such Partners are responsible for ensuring that they possess an appropriate lawful basis and all necessary notices or consents required under applicable privacy laws before transmitting end-user personal data through the Services. The relevant Partner shall remain responsible for its own compliance with applicable privacy and data protection laws. Enterprise Partners and API Partners shall defend, indemnify, and hold harmless Peddlr against all complaints, investigations, administrative actions, penalties, fines, claims, or damages arising from the Partner's failure to obtain appropriate notice, consent, authority, or lawful basis.
6. DATA RETENTION & DESTRUCTION
Peddlr retains personal and transactional data only for as long as necessary to fulfill the purposes outlined in this Notice and strictly in accordance with our Master Terms. Retention periods may vary depending on the nature of the records and applicable legal requirements.
Upon account termination, deactivation, or a valid request for erasure, Peddlr may retain registration, transactional, verification, and related records for the period required or permitted under applicable laws, regulations, contractual obligations, or dispute resolution requirements, including anti-money laundering compliance, tax obligations, fraud prevention, audit requirements, evidentiary preservation, enforcement of legal claims, and operational security. Where permitted by applicable law, Peddlr may retain limited information necessary to demonstrate compliance with legal obligations, resolve disputes, enforce agreements, prevent fraud, maintain security, or establish, exercise, or defend legal claims. Following the expiration of applicable retention periods, the data shall be securely deleted, anonymized, or destroyed using industry-standard protocols to prevent unauthorized recovery.
7. CROSS-BORDER TRANSFERS & CLOUD HOSTING
Certain personal data may be processed, stored, backed up, or transferred through cloud infrastructure providers, third-party service providers, or technical partners located within or outside the Philippines, subject to appropriate contractual, organizational, technical, and legal safeguards designed to ensure a level of protection consistent with applicable Philippine data protection requirements. By using the Services, the User acknowledges that personal data may be transferred to jurisdictions outside the Philippines where Peddlr's service providers or infrastructure are located, subject to applicable safeguards.
Peddlr may engage third-party subprocessors, service providers, cloud infrastructure partners, analytics providers, communications providers, and technical vendors to support the operation, security, maintenance, and delivery of the Services, subject to reasonable contractual and organizational safeguards.
8. DATA SUBJECT RIGHTS
Subject to limitations provided by law (such as AML retention mandates), you possess the following rights under the DPA:
- Right to be Informed: To know how your data is being processed (as fulfilled by this Notice).
- Right to Access: To request a copy of the personal data we hold about you.
- Right to Rectification: To correct inaccurate or outdated information in your account.
- Right to Erasure Blocking: To request the deletion of your data, subject to Peddlr's legal retention mandates.
- Right to Object: To object to processing for direct marketing or profiling.
- Right to Data Portability: To obtain your data in a structured, commonly used electronic format.
- Right to Damages: To seek compensation for damages suffered due to inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorized use of personal information, subject to applicable law.
- Right to File a Complaint: To escalate privacy concerns to the NPC.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw consent subject to applicable legal and contractual limitations. Withdrawal of consent shall not affect processing conducted prior to such withdrawal or processing based on other lawful grounds.
To exercise any of the foregoing rights, submit a written request via email to dpo@peddlr.ph or by written correspondence to the DPO at the address provided below. Requests submitted to the DPO may require reasonable identity verification and supporting documentation before processing. Peddlr reserves the right to refuse repetitive, manifestly unfounded, excessive, fraudulent, or abusive requests to the extent permitted under applicable law. Peddlr shall respond within the period required under applicable law and relevant NPC issuances, subject to verification requirements, request complexity, and lawful limitations.
Certain rights may be restricted, deferred, or unavailable where permitted or required by applicable law, including anti-money laundering, fraud prevention, security, evidentiary preservation, and regulatory compliance requirements.
9. SECURITY & BREACH RESPONSE
Peddlr maintains reasonable and appropriate organizational, administrative, physical, and technical security measures consistent with applicable NPC regulations, circulars, and industry-standard security practices, including encryption, secure API tokenization, role-based access controls, and regular vulnerability assessments, designed to safeguard personal data against unauthorized access, loss, misuse, alteration, or disclosure.
While Peddlr implements reasonable and appropriate safeguards, no method of electronic transmission, storage, or internet-based infrastructure can be guaranteed to be completely secure. Users likewise share responsibility for maintaining the confidentiality of account credentials, device security, and access controls under their control. To the maximum extent permitted by applicable law, Peddlr shall not be liable, except where caused by Peddlr’s gross negligence, fraud, or willful misconduct, for security incidents, data loss, service interruptions, or unauthorized access arising from third-party telecommunications providers, internet service providers, cloud infrastructure failures, force majeure events, user-side security compromises, or circumstances beyond Peddlr’s reasonable control. Nothing in this Notice shall limit liabilities that cannot be excluded under applicable law.
While Peddlr undertakes reasonable efforts to maintain system integrity and data availability, Users acknowledge that interruptions, synchronization delays, third-party outages, software failures, cyber incidents, and data corruption events may occur. Users are encouraged to maintain independent backups of critical business and operational records.
Breach Response: In the event of a personal data breach that is likely to result in a real risk of serious harm to affected data subjects, Peddlr shall undertake reasonable response, containment, investigation, and notification measures in accordance with applicable law and relevant NPC issuances, including notification obligations where required under applicable law and relevant NPC issuances (including NPC Circular No. 16-03, as may be amended).
10. COOKIES & TRACKING TECHNOLOGIES
Peddlr uses cookies and similar tracking technologies on its website and mobile applications to authenticate sessions, maintain security, analyze platform usage, and optimize user experience. Cookies do not contain personally identifiable information beyond session identifiers. Users may configure their browser or device settings to refuse cookies, provided that doing so may impair the functionality of certain platform features. Peddlr does not presently use third-party advertising cookies or cross-platform behavioral advertising technologies within the Services.
11. AUTOMATED PROCESSING & PROFILING
Peddlr employs automated and semi-automated systems for transaction monitoring, fraud detection, AML screening, and risk scoring. These systems may result in automated decisions affecting your account, including transaction blocks, account suspensions, or reserve impositions. Such automated decisions are subject to reasonable human review upon verified request where applicable and practicable under applicable law. Certain automated decisions may be subject to limitation, delay, or restricted disclosure where reasonably necessary for fraud prevention, AML compliance, security monitoring, legal privilege, law enforcement cooperation, or the protection of Peddlr’s systems and lawful interests. To request a review of an automated decision affecting your account, contact dpo@peddlr.ph.
12. OPERATIONAL COMMUNICATIONS
Peddlr may send transactional, operational, security-related, compliance-related, or account-related communications through email, SMS, in-app notifications, or other contact channels associated with the User’s account. Such communications are considered an integral part of the Services and are not promotional or marketing communications subject to standard opt-out requirements. Marketing or promotional communications, where applicable, shall be subject to applicable consent and opt-out requirements under Philippine law.
13. MINORS
The Services are intended solely for persons who are legally capable of entering into binding agreements under applicable law. Peddlr does not knowingly collect personal data directly from minors without appropriate legal authority or parental consent where required by applicable law. Enterprise and API Partners remain responsible for ensuring compliance with applicable legal requirements relating to minors’ data transmitted through the Services. If Peddlr becomes aware that personal data relating to a minor has been submitted in violation of applicable law, Peddlr reserves the right to delete, restrict, or suspend the relevant account or data.
14. CORPORATE TRANSACTIONS
Peddlr may disclose or transfer relevant information in connection with any merger, acquisition, financing transaction, restructuring, asset sale, or transfer of all or part of its business, where reasonably necessary to evaluate, negotiate, or complete such transaction, subject to applicable confidentiality and data protection obligations.
15. THIRD-PARTY SERVICES
The Services may contain links to, integrations with, or features operated by third-party providers. Peddlr is not responsible for the privacy practices, content, security, or operations of third-party services not controlled by Peddlr. Users are encouraged to review the applicable privacy policies of such third parties before providing information through those services.
16. CHANGES TO THIS PRIVACY NOTICE
Peddlr reserves the right to update or modify this Privacy Notice from time to time to reflect operational, legal, regulatory, or technological changes. Updated versions shall be posted through the Services, Peddlr’s official website, or other official communication channels, including email or in-app notifications where appropriate, together with the revised “Last Updated” date. Continued use of the Services following the effectivity of any updated Privacy Notice may constitute acknowledgment of such updates to the extent permitted under applicable law.
17. CONTACT US
For any inquiries, requests to exercise your data subject rights, or concerns regarding this Unified Privacy Notice, please contact our Data Protection Officer (DPO) at:
Email: dpo@peddlr.ph (Security Reports: Suspected security incidents, unauthorized account access, or privacy concerns may also be reported to this email address or through official Peddlr support channels.)
Mailing Address: Attention: Data Protection Officer Peddlr Philippines Inc. 2nd Floor Senio Concha Miracle Bldg. 1, Corner San Roque Street and Rizal Avenue Ext., Brgy. 12, Catbalogan City, Samar, Philippines