Legal

Privacy Policy

Last updated: August 27, 2026

This explains what iSerbe collects, why, and what you can do about it. It covers the iSerbe app and the website at iserbe.com.

The terms you agree to when you use iSerbe are separate, in our Terms of Service.

01What we collect

Your account — the name and email address of the owner, and of any staff accounts you create. If a staff member uses a PIN, we store it as a one-way hash, never as the digits themselves.

Your business — its name, type, address, phone and email, as you enter them.

What you record in the app — products, add-ons, stock levels, sales, discounts, and staff time logs. This is your business's own record-keeping.

Customers, if you choose to keep them — Customers is off unless you switch it on. When you do, we store the name, short code and note youtype for each one, and which of your sales were rung up against them. If you set up rewards, we also store which of those sales your staff marked as counting towards one, how far along each customer is, and what they were given — the item, discount or note, and what it was worth — so the same reward isn't handed out twice. We never collect any of it from the customer, and we never contact them.

Billing — if you subscribe, we keep the card brand and last four digits so you can tell which card is on file. We never see or store the full card number — our payment processor, Creem, handles that directly.

Messages you send us — when you contact support from inside the app, we receive your message along with your name, email, role, business name and plan, so we can answer you.

Technical information — standard data generated as you use the app, such as browser type and general activity, used to keep it running and to understand in aggregate how it's used.

02What we don't collect

We don't build a profile of your customers ourselves.A sale is recorded as items, amounts and payment method. Nothing about a shopper reaches us unless your shop types it in — a name on one receipt, or a customer you created yourself. Where rewards are switched on, the app counts a customer's visits so your staff know when one has earned something; that count is worked out from the sales your own shop recorded, and it is only ever for that shop to see. We never gather it from the customer, never use it outside your own business, and never share it with another shop or anyone else.

Where a discount is recorded for senior citizens or PWDs, we store how many people it applied to, not who they were.

We don't sell your information. We don't use your business records to advertise to you or to anyone else.

03How we use it

To run the app and your account; to process subscription payments and tell you about your billing; to send the notifications you've switched on (low stock, discount alerts) and the ones your account needs (billing reminders, staff invitations); to keep the service secure; to answer you when you get in touch; and, in aggregate, to work out what to improve.

04Cookies

We use cookies to keep you signed in and to remember your session. That's it — no advertising cookies, no third-party tracking pixels.

05Who else touches your data

We use a small number of providers to run iSerbe, and each sees only what it needs:

  • Supabase — hosts the database and handles sign-in.
  • Creem — processes subscription payments. Their own privacy policy covers your card details.
  • Resend — delivers our email (alerts, invitations, billing notices).

We may also disclose information if the law requires it, or to protect our rights or someone's safety. If the business is ever sold or merged, your data may transfer with it — we'd tell you first.

06Where your data is held

Our providers may store and process data on servers outside the Philippines. When that happens, we rely on those providers' contractual safeguards to protect it.

07How long we keep it

We keep your data while your account is active.

Deleting your business account erases everything immediately and permanently — products, stock, sales history and every staff account. We cannot recover it afterwards, so export anything you need first. Some records may stay in backups for a limited period, and we may keep what the law requires us to keep, such as billing records.

08Security

Passwords are hashed by our authentication provider and are never stored in readable form; staff PINs are hashed the same way. Access to each business's data is restricted at the database level, so one business cannot read another's. Data travels over encrypted connections.

No system is perfectly secure, and we can't guarantee absolute security — but if a breach ever affects your personal information, we'll notify you and the National Privacy Commission as the law requires.

09Your rights

Under the Philippine Data Privacy Act (RA 10173), you can ask us to show you the personal information we hold about you, correct it if it's wrong, delete it, or object to how we use it. You can also withdraw consent, and complain to the National Privacy Commission (privacy.gov.ph) if you think we've mishandled your data.

Email hello@iserbe.com and we'll respond.

One thing worth being clear about: for the information you enter about your staff and your business, you are the one deciding what gets collected — we hold it on your behalf. If a staff member asks about their own records, that request goes to you first.

10Children

iSerbe is a business tool and isn't meant for children. We don't knowingly collect information from anyone under 18. If we learn we have, we'll delete it.

11Changes

If we change this policy, the date at the top changes, and for anything significant we'll tell you in the app or by email.

12Contact us

If you have questions about how this applies to you, contact us at hello@iserbe.com.