Back to Home

Privacy Policy

Last Updated: May 7, 2026 | Effective: May 7, 2026

Compliance Notice

This Privacy Policy is prepared in compliance with Republic Act No. 10173 (Data Privacy Act of 2012), its Implementing Rules and Regulations, and NPC Circular No. 2023-04. Koogigo acts as the Personal Information Controller (PIC) for data processed through this platform.

1. Privacy Principles & Compliance

Koogigo is committed to the data privacy principles of Transparency, Legitimate Purpose, and Proportionality as mandated by the Data Privacy Act of 2012 (Republic Act No. 10173). We also comply with the Internet Transactions Act (RA 11967) by exercising "Ordinary Diligence" in verifying the identity of our student community members.

2. Identity of the Personal Information Controller

The Personal Information Controller for data processed through Koogigo is:

  • Platform Name: Koogigo
  • Email: koogigoreport@gmail.com
  • Data Protection Officer (DPO): The Koogigo Founder (contact via email above)
  • Country of Operation: Republic of the Philippines

3. Information We Collect & Why

We only collect data that is necessary for a specific, declared, and legitimate purpose. In alignment with the **Data Minimization and Proportionality Principles** of RA 10173, we completely avoid collecting physical documents, government IDs, or school ID card photos:

  • Identity Information: Name, official academic email address, school affiliation — Purpose: Account creation and automatic student domain validation via Google SSO
  • Profile Details: Photos, bios, skills, work history — Purpose: Enabling user-to-user gig transactions
  • Device & Usage Data: IP address, browser type, pages visited — Purpose: Security (rate limiting, fraud prevention) and analytics
  • Cookies & Tracking: Google AdSense places cookies for ad personalization. See Section 9 for full details.

4. Legal Basis for Processing

We process your personal data based on the following lawful criteria under Section 12 of RA 10173:

  • Consent: You provide explicit consent upon registration and by accepting our Terms of Service.
  • Contractual Necessity: Processing is necessary to provide you the services you requested (gig posting, applying, messaging).
  • Legal Obligation: We may process data to comply with lawful court orders, NBI subpoenas, or NPC directives.
  • Legitimate Interest: Security monitoring, fraud prevention, and platform integrity.

5. Your Rights as a Data Subject (RA 10173)

Under the Data Privacy Act, you are entitled to the following rights. To exercise any right, email koogigoreport@gmail.com:

  • Right to be Informed: Know how, why, and what data we process (this policy).
  • Right to Access: Request a copy of all personal data we hold about you.
  • Right to Correction / Rectification: Update or correct inaccurate information.
  • Right to Erasure (Right to be Forgotten): Request deletion of your account and all associated personal data.
  • Right to Object: Withdraw consent or object to specific processing activities (e.g., marketing).
  • Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format.
  • Right to Lodge a Complaint: File a complaint with the National Privacy Commission (NPC) at privacy.gov.ph if you believe your rights have been violated.

6. Data Retention Schedule

Data TypeRetention Period
Account / Profile DataUntil account deletion + 30 days grace period
Gig listings & applications24 months after gig completion
Academic SSO Credentials (.edu.ph)Never stored directly (verified in real-time via Google OAuth)
Server / security logs90 days rolling window

7. Third-Party Processors & Data Sharing

We do not sell your data. We share data only with the following service providers necessary to operate the platform:

  • Supabase, Inc. — Database and authentication hosting (servers in Singapore/Asia Pacific)
  • Vercel, Inc. — Web application hosting and edge delivery
  • Google LLC (OAuth 2.0) — Secure, federated authentication portal for academic Google Workspace verification
  • Google LLC (AdSense) — Advertising cookies and ad serving

All processors are contractually bound to handle your data in a manner consistent with this policy.

8. Law Enforcement & Government Requests

Koogigo will cooperate with the PNP Anti-Cybercrime Group (ACG), the NBI Cybercrime Division, or other government authorities by disclosing necessary personal data when required by a valid court order, subpoena, or legal process under the Cybercrime Prevention Act (RA 10175), Anti-Trafficking Act (RA 9208), or other applicable Philippine law. We will notify affected users of such disclosures where legally permissible.

9. Cookies & Tracking Technologies

We use the following types of cookies:

  • Strictly Necessary Cookies: Authentication session cookies managed by Supabase (HttpOnly, Secure). Cannot be disabled.
  • Analytics Cookies: Anonymous usage data to improve platform performance.
  • Advertising Cookies (Google AdSense): Google uses cookies to serve personalized ads based on your browsing history. You can opt out via Google Ads Settings or the Cookie Consent banner on this site.

10. Security Measures

We implement the following technical and organizational security measures to protect your data:

  • End-to-end HTTPS encryption for all data in transit (TLS 1.3)
  • Row-Level Security (RLS) policies on all database tables
  • HttpOnly, Secure, SameSite session cookies — never localStorage
  • Rate limiting on all authentication and write endpoints
  • Content Security Policy (CSP) headers to prevent XSS attacks
  • Complete exclusion of physical document/ID storage, eliminating breach liability

11. Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, Koogigo commits to notifying the National Privacy Commission (NPC) within 72 hours of becoming aware of the breach, and notifying affected data subjects without undue delay, as required under Section 20(f) of RA 10173 and NPC Circular 16-03.

12. Contact Our Data Protection Officer

For any data-related requests, rights exercises, or privacy concerns, please email:

koogigoreport@gmail.com

Subject line: "Data Privacy Request — [Your Name]"

You also have the right to escalate unresolved complaints to the National Privacy Commission at www.privacy.gov.ph.