Effective date: [TODO: effective date, e.g. 1 September 2026] · Last updated: [TODO: last updated date] · Version: 1.0
Applies to the Suki Business mobile application (Android and iOS) and the Suki Business web console at business.sukiperks.com. Both share the same backend and data practices.
This policy covers you as a business partner. It also explains your obligations for the customer data you receive through the platform — which is the part that matters most, and the part most business policies leave out.
1. Who we are
[TODO: registered entity name] ("Suki", "we", "us").
| Registered address | [TODO: registered business address] |
| SEC registration | [TODO: SEC registration number] |
| Data Protection Officer | [TODO: Data Protection Officer name] |
| Privacy enquiries | [TODO: privacy@…] |
| Business support | [TODO: businesses@…] |
2. Information we collect about you
2.1 Business and owner information
| Data | Why |
|---|---|
| Business name, description, category | Your public business page |
| Business address and map location | Customer discovery, delivery-fee calculation |
| Business hours | Show when you are open |
| Business registration and permit details | Verification |
| Owner name, email, mobile number | Account, verification, communication |
| Logo and banner images | Your business page |
| Fulfilment methods offered | Order routing |
Note on public visibility. Your business name, description, category, address, map location, hours, logo, banner, rating, and business contact details are visible to anyone browsing the platform, including people without an account. This is how customers find you, and it is the same information you would put on a shopfront or a listing.
If you do not want a particular contact number published, use a business line rather than a personal one.
2.2 Catalogue and operational data
| Data | Visibility |
|---|---|
| Product names, descriptions, images, prices | Public |
| Product cost of goods | You and authorised Suki staff only — never shown to customers or other businesses |
| Stock and availability | Public |
| Orders received | You and the customer |
| Sales and profit reports | You only |
| Loyalty programme configuration | Earning rate is public; the records are yours |
2.3 Financial information
| Data | How it is protected |
|---|---|
| Wallet balance and transaction ledger | Visible only to you and authorised Suki staff |
| Payout destination — GCash number or bank account | Encrypted with AES-256-GCM. Stored beside a masked form (•••• 1234). Decrypted only when staff process your withdrawal |
| Withdrawal requests and history | You and authorised staff |
| Commission and fee records | You and authorised staff |
2.4 Security and device information
| Data | Why |
|---|---|
| Device model, OS, app version | Compatibility, support |
| Registered devices | Let you see and revoke device access |
| Biometric or PIN configuration | Stored only on your device. We never receive your biometric data or your PIN |
| Login history | Security |
| Connected thermal printers | Receipt printing |
2.5 Location
We collect your business location — set once during onboarding — to show your business on the map and calculate delivery fees.
We do not track your personal location, and we do not collect location in the background.
3. Customer data you receive — your obligations
This section is important. You become a Personal Information Controller for the customer data you receive, with your own obligations under the Data Privacy Act.
3.1 What you receive
For each order placed with you: customer name, customer mobile number, delivery address (delivery orders only), order contents and notes, and the customer's loyalty points balance at your business.
You do not receive customer email addresses, other addresses, order history with other businesses, payment credentials, or any account details.
3.2 What you must do
You agree to:
| Obligation | Meaning |
|---|---|
| Use it only to fulfil the order | Nothing else |
| Never sell or share it | With anyone, for any reason |
| Never use it for your own marketing | No SMS blasts, no adding customers to your own list, unless they separately consent to you directly |
| Keep it secure | Reasonable technical and organisational measures |
| Delete it when no longer needed | Once the order is complete and any warranty or dispute period has passed |
| Report breaches to us within 24 hours | So we can meet our own notification obligations |
| Comply with RA 10173 | The Data Privacy Act applies to you too |
3.3 What happens if you do not
Misuse of customer data is a material breach of your agreement. We may suspend or terminate your account immediately, and you may be independently liable to the customer and to the National Privacy Commission.
4. How we use your information
| Purpose | Lawful basis |
|---|---|
| Create and manage your business account | Contract |
| Display your business and catalogue publicly | Contract |
| Route orders to you | Contract |
| Calculate and pay out your earnings | Contract |
| Calculate commission and fees | Contract |
| Verify your business | Legal obligation / legitimate interest |
| Prevent fraud | Legitimate interest |
| Provide support | Contract |
| Improve the platform | Legitimate interest |
| Send operational notifications | Contract |
| Send marketing about Suki services | Consent |
| Meet tax and regulatory obligations | Legal obligation |
5. Who we share your information with
We do not sell your information.
| Recipient | What they receive |
|---|---|
| Customers and the public | Business name, description, category, address, hours, logo, banner, rating, products, prices, business contact details |
| Riders | Business name, pickup address, order details — for orders they are delivering |
| Cloud hosting providers | Account and application data — infrastructure |
| PayMongo | Deposit and payout transaction data |
| Mapping providers | Coordinates for mapping and routing |
| Authorities | Where required by law |
6. Retention
| Data | Period |
|---|---|
| Account, business information, and catalogue | While active; removed from public view on closure |
| After account closure | Erased immediately on confirmation — there is no holding period |
| Transaction, order, and financial records | 10 years — tax and accounting |
| Payout destinations | While active, plus 1 year, held encrypted |
| Chat and support correspondence | 2 years |
7. Your rights
You have the rights described in RA 10173: to be informed, to access, to object, to erasure or blocking, to rectification, to data portability, to damages, and to complain to the National Privacy Commission.
We respond to requests within 30 days.
Note: we cannot delete transaction records we are legally required to keep, and we cannot delete order records that also form part of a customer's own order history.
Closing your account
In the app: Profile → Account & Security → Delete Account. On the web: Profile → Delete account. We email a confirmation link, and nothing is deleted until you click it.
Confirming the link deletes your account immediately. There is no grace period and no waiting time: your login, your business profile, your products and your storefront images are erased as soon as you confirm, and the account cannot be recovered afterwards. Orders, wallet ledger entries and withdrawal records are retained — we are legally required to keep them, and they are also part of your customers' own order history — with your business no longer linked to them as an account.
Withdraw your wallet balance before you close your account. An unwithdrawn balance is held for 12 months, during which you may contact [TODO: businesses@…] to claim it. We will write to your registered email before that period ends.
8. Security
- Encryption in transit — TLS on every connection
- Encryption at rest — all stored data
- Application-layer encryption — payout destinations, AES-256-GCM
- Access controls — you can only access your own business's data
- Biometric or PIN lock — optional, configured on your device
- Device management — view and revoke registered devices
- App attestation — requests are verified as coming from genuine Suki apps
- Staff access controls — role-based, with an approval queue for sensitive changes and an audit trail for approvals
If a breach affects your information and is likely to give rise to a real risk, we will notify you and the National Privacy Commission within 72 hours of becoming aware.
9. Analytics and reporting
We process your order and sales data to generate your reports — sales, product performance, and gross profit.
We also use aggregated, anonymised data across businesses to understand platform trends and improve the service. Aggregated data cannot identify you or your business individually and is never shared in a way that reveals your performance to other businesses.
10. International transfers
Infrastructure runs on secure cloud servers in Southeast Asia. Some providers may process data elsewhere, under contractual safeguards requiring protection comparable to the Data Privacy Act.
11. Changes
Material changes will be notified in-app and by email at least 30 days before they take effect.
12. Contact
| Data Protection Officer | [TODO: Data Protection Officer name] |
| Privacy | [TODO: privacy@…] |
| Business support | [TODO: businesses@…] |
| Address | [TODO: registered business address] |
National Privacy Commission — privacy.gov.ph · info@privacy.gov.ph