Privacy Policy

Last Updated: June 12, 2026

PisoCare Philippines (“PisoCare,” “we,” “us”) is committed to protecting your personal data in accordance with Republic Act No. 10173 (Data Privacy Act of 2012) and its Implementing Rules and Regulations.

1. Information We Collect

When you use PisoCare, we may collect the following personal information:


Account Information — Full name, email address, and password hash when you register an account.


Donation Information — Name, email address, donation amount, campaign selected, payment method, transaction reference, and timestamp.


Guest Donations — If you donate without an account, we collect the name and email you provide for receipt and verification purposes.


Device & Usage Data — IP address, browser type, device type, pages visited, and referring URLs. This data is collected automatically through cookies and analytics tools.


Communications — If you contact us via email or social media, we retain those messages to improve support.

2. How We Use Your Information

We use your personal data for the following purposes:


  • Processing donations and issuing tax-deductible receipts
  • Verifying your identity to prevent fraud and money laundering
  • Displaying donations on the public wall (unless you opt for anonymity)
  • Sending transactional emails — donation confirmations, receipts, and account updates
  • Improving our platform through analytics and usage patterns
  • Complying with legal obligations under Philippine law, including BIR reporting and the Data Privacy Act of 2012 (RA 10173)
  • Communicating campaign updates and impact reports (with your consent)
  • 3. Information Sharing & Disclosure

    We do not sell, rent, or trade your personal data. We may share information with:


  • NGO Partners — Aggregated donation data (not personal details) for fund utilization reporting
  • Payment Processors — PayMongo processes your payment; they have their own privacy policy
  • Government Authorities — When required by law, including BIR for tax reporting and NPC for data privacy compliance
  • Third-Party Services — Analytics (Google Analytics), hosting (Vercel), and database (Supabase) providers who process data on our behalf under strict data processing agreements
  • Public Donation Wall — Your first name and donation amount appear publicly unless you check "anonymous"
  • 4. Data Security

    We implement industry-standard security measures:


  • Encryption — All data in transit is encrypted via TLS/SSL. Database at rest uses AES-256 encryption.
  • PCI-DSS Compliance — Payment processing is handled by PayMongo, a PCI-DSS Level 1 certified processor. We never store card or bank credentials.
  • Access Controls — Only authorized personnel access donor data, with role-based permissions and audit logging.
  • Regular Audits — We conduct quarterly security reviews and annual penetration testing.
  • 5. Data Retention

    We retain your personal data for as long as necessary to fulfill the purposes outlined in this policy:


  • Donation records — Retained for 10 years to comply with BIR record-keeping requirements
  • Account data — Retained while your account is active, plus 2 years after deletion request
  • Analytics data — Aggregated and anonymized after 26 months
  • Communication records — Retained for 3 years after last interaction

  • You may request early deletion subject to our legal obligations.

    6. Your Rights Under the Data Privacy Act

    Under RA 10173 (Data Privacy Act of 2012), you have the right to:


  • Access — Request a copy of the personal data we hold about you
  • Correction — Request corrections to inaccurate or incomplete data
  • Erasure — Request deletion of your data (subject to legal retention requirements)
  • Object — Object to processing of your data for marketing purposes
  • Portability — Request your data in a structured, machine-readable format
  • Lodge a Complaint — File a complaint with the National Privacy Commission (NPC)

  • To exercise these rights, email privacy@pisocare.com with your request. We respond within 30 days.

    7. Cookies

    We use essential cookies to maintain your session and preferences. We also use analytics cookies to understand how visitors use our site. For full details, see our Cookie Policy.


    You can manage cookie preferences in your browser settings. Disabling essential cookies may affect platform functionality.

    8. Children's Privacy

    PisoCare does not knowingly collect personal data from children under 18. If a minor wishes to donate, they should do so with parental or guardian consent. If we discover we have collected data from a child without consent, we will delete it promptly.

    9. Changes to This Policy

    We may update this policy from time to time. Material changes will be communicated via email to registered users and posted on this page with a revised "Last Updated" date. Continued use of PisoCare after changes constitutes acceptance.

    10. Contact Us

    For privacy-related inquiries:


    Data Protection Officer

    PisoCare Philippines

    Email: privacy@pisocare.com


    National Privacy Commission

    Website: https://www.privacy.gov.ph