Privacy Policy
Last Updated: May 7, 2026 | Effective: May 7, 2026
Compliance Notice
This Privacy Policy is prepared in compliance with Republic Act No. 10173 (Data Privacy Act of 2012), its Implementing Rules and Regulations, and NPC Circular No. 2023-04. Koogigo acts as the Personal Information Controller (PIC) for data processed through this platform.
1. Privacy Principles & Compliance
Koogigo is committed to the data privacy principles of Transparency, Legitimate Purpose, and Proportionality as mandated by the Data Privacy Act of 2012 (Republic Act No. 10173). We also comply with the Internet Transactions Act (RA 11967) by exercising "Ordinary Diligence" in verifying the identity of our student community members.
2. Identity of the Personal Information Controller
The Personal Information Controller for data processed through Koogigo is:
- Platform Name: Koogigo
- Email: koogigoreport@gmail.com
- Data Protection Officer (DPO): The Koogigo Founder (contact via email above)
- Country of Operation: Republic of the Philippines
3. Information We Collect & Why
We only collect data that is necessary for a specific, declared, and legitimate purpose. In alignment with the **Data Minimization and Proportionality Principles** of RA 10173, we completely avoid collecting physical documents, government IDs, or school ID card photos:
- Identity Information: Name, official academic email address, school affiliation — Purpose: Account creation and automatic student domain validation via Google SSO
- Profile Details: Photos, bios, skills, work history — Purpose: Enabling user-to-user gig transactions
- Device & Usage Data: IP address, browser type, pages visited — Purpose: Security (rate limiting, fraud prevention) and analytics
- Cookies & Tracking: Google AdSense places cookies for ad personalization. See Section 9 for full details.
4. Legal Basis for Processing
We process your personal data based on the following lawful criteria under Section 12 of RA 10173:
- Consent: You provide explicit consent upon registration and by accepting our Terms of Service.
- Contractual Necessity: Processing is necessary to provide you the services you requested (gig posting, applying, messaging).
- Legal Obligation: We may process data to comply with lawful court orders, NBI subpoenas, or NPC directives.
- Legitimate Interest: Security monitoring, fraud prevention, and platform integrity.
5. Your Rights as a Data Subject (RA 10173)
Under the Data Privacy Act, you are entitled to the following rights. To exercise any right, email koogigoreport@gmail.com:
- Right to be Informed: Know how, why, and what data we process (this policy).
- Right to Access: Request a copy of all personal data we hold about you.
- Right to Correction / Rectification: Update or correct inaccurate information.
- Right to Erasure (Right to be Forgotten): Request deletion of your account and all associated personal data.
- Right to Object: Withdraw consent or object to specific processing activities (e.g., marketing).
- Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format.
- Right to Lodge a Complaint: File a complaint with the National Privacy Commission (NPC) at privacy.gov.ph if you believe your rights have been violated.
6. Data Retention Schedule
| Data Type | Retention Period |
|---|---|
| Account / Profile Data | Until account deletion + 30 days grace period |
| Gig listings & applications | 24 months after gig completion |
| Academic SSO Credentials (.edu.ph) | Never stored directly (verified in real-time via Google OAuth) |
| Server / security logs | 90 days rolling window |
7. Third-Party Processors & Data Sharing
We do not sell your data. We share data only with the following service providers necessary to operate the platform:
- Supabase, Inc. — Database and authentication hosting (servers in Singapore/Asia Pacific)
- Vercel, Inc. — Web application hosting and edge delivery
- Google LLC (OAuth 2.0) — Secure, federated authentication portal for academic Google Workspace verification
- Google LLC (AdSense) — Advertising cookies and ad serving
All processors are contractually bound to handle your data in a manner consistent with this policy.
8. Law Enforcement & Government Requests
Koogigo will cooperate with the PNP Anti-Cybercrime Group (ACG), the NBI Cybercrime Division, or other government authorities by disclosing necessary personal data when required by a valid court order, subpoena, or legal process under the Cybercrime Prevention Act (RA 10175), Anti-Trafficking Act (RA 9208), or other applicable Philippine law. We will notify affected users of such disclosures where legally permissible.
9. Cookies & Tracking Technologies
We use the following types of cookies:
- Strictly Necessary Cookies: Authentication session cookies managed by Supabase (HttpOnly, Secure). Cannot be disabled.
- Analytics Cookies: Anonymous usage data to improve platform performance.
- Advertising Cookies (Google AdSense): Google uses cookies to serve personalized ads based on your browsing history. You can opt out via Google Ads Settings or the Cookie Consent banner on this site.
10. Security Measures
We implement the following technical and organizational security measures to protect your data:
- End-to-end HTTPS encryption for all data in transit (TLS 1.3)
- Row-Level Security (RLS) policies on all database tables
- HttpOnly, Secure, SameSite session cookies — never localStorage
- Rate limiting on all authentication and write endpoints
- Content Security Policy (CSP) headers to prevent XSS attacks
- Complete exclusion of physical document/ID storage, eliminating breach liability
11. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, Koogigo commits to notifying the National Privacy Commission (NPC) within 72 hours of becoming aware of the breach, and notifying affected data subjects without undue delay, as required under Section 20(f) of RA 10173 and NPC Circular 16-03.
12. Contact Our Data Protection Officer
For any data-related requests, rights exercises, or privacy concerns, please email:
koogigoreport@gmail.com
Subject line: "Data Privacy Request — [Your Name]"
You also have the right to escalate unresolved complaints to the National Privacy Commission at www.privacy.gov.ph.