This document describes how the platform actually works today. It has not yet been reviewed by a lawyer. If anything here conflicts with Philippine law — in particular the Consumer Act (RA 7394) or the Data Privacy Act (RA 10173) — the law applies and your rights under it are unaffected.
Privacy Notice
How this marketplace handles personal data, under the Data Privacy Act of 2012 (Republic Act 10173).
Who is responsible
The Personal Information Controller for this platform is AICONIC HUSTLERS ONLINE STORE.
For anything about your personal data — a copy of it, a correction, or its erasure — write to aiconichustlers@gmail.com · +63 956 065 4115. Data protection enquiries are handled by our Data Protection Officer.
Each shop on this platform is run by an independent merchant. When you buy from a shop, that merchant is a separate controller of the details needed to fulfil your order.
What we collect, and why
If you open a shop
- Your name, mobile number and, if you give one, your email. To identify your account, to let buyers and couriers reach you, and to recover access.
- A hashed version of your password. We cannot read your password; only a one-way hash is stored.
- Your shop's name, description and location (province, city, barangay). These are shown publicly, because buyers are entitled to know who they are buying from and where it ships from.
- A record of your consent — which document, which version, when, and the IP address it came from. The Act requires consent to be demonstrable.
If you buy something
You do not need an account to buy. When you place an order we collect:
- Your name, mobile number and delivery address. Without these the order cannot be delivered.
- Your email, if you give one. Optional, used only to send a copy of your order.
- What you ordered and what it cost.
Your cart and wishlist are stored in your own browser, not on our servers. We never see them until you place an order.
Payment details
We never see or store your card details. Card and e-wallet payments are handled entirely on the payment provider's own pages — Maya or PayMongo, whichever you choose at checkout. For cash on delivery, no payment details exist at all: you pay the courier.
Cookies and browser storage
We use no advertising cookies and no third-party analytics. What is set:
- A session cookie, only once you sign in as a merchant or an administrator. It identifies your session and nothing else. Buyers never receive one, because buyers never sign in.
- A security token cookie, used to verify that a form submission came from a page we served rather than from somewhere else.
- Your own browser's storage holds your cart, your wishlist and the links to orders you have placed from that device. This never reaches our servers. Clearing your browsing data clears it, and it is not recoverable — which is why the order link matters.
Security and abuse records
- Sign-in attempts are counted to stop password guessing. The identifier used is stored only as a one-way hash, so the counter works without keeping a list of every phone number and email address that has ever attempted to sign in.
- IP addresses are recorded against consent records and in the administrative audit log. Server error logs may also record them.
Automated checking of listings
Product names and descriptions are automatically checked against a list of moderated terms when a merchant publishes them. A match holds the listing for human review and tells the merchant which words matched; it does not reject anything on its own. No decision affecting a person is made automatically without a person being able to look at it.
Who your data is shared with
- The merchant you ordered from — your name, number and address, so they can pack and send your order. Merchants can only see orders placed with their own shop, never another shop's.
- Your courier — the same details, so they can deliver.
- Our payment providers, Maya and PayMongo — if you pay by card or e-wallet, then only the one you chose at checkout, and only for that payment. They receive your name and contact details so the payment can be attributed and disputed if it needs to be. Your card number is entered on their pages and never reaches us.
- Platform administrators — who may access order details to resolve a dispute or investigate misuse. Every such access is logged.
We do not sell personal data, and we do not share it for advertising.
How long we keep it
Order and payment records are kept for ten years. That is what the Bureau of Internal Revenue requires of books of account and their supporting documents, and a sales record is one. It is not a period we chose and it is not one we can shorten on request.
Everything that is not a financial record goes sooner. Your account details last as long as your account. Delivery addresses, phone numbers and names attached to an order are erased when you ask us to, subject only to the paragraph below.
When personal data is erased, the order record survives in anonymised form: the name, phone number and address are irreversibly overwritten and the private order link stops working. The amounts remain, so the merchant's sales history stays correct.
Your rights
Under the Act you have the right to:
- be told what data we hold about you, and get a copy of it;
- have anything inaccurate corrected;
- have your data erased or blocked, where no legal obligation requires us to keep it;
- object to how it is being used;
- be told if your data is compromised;
- seek compensation for damage caused by misuse; and
- complain to the National Privacy Commission.
Merchants can delete their own account from the panel at any time, which erases their personal details immediately. Buyers can request erasure by contacting aiconichustlers@gmail.com or +63 956 065 4115.
An erasure request may be refused while it conflicts with an obligation — for example, while an order you have paid for has not yet been delivered.
How your data is protected
- Passwords are stored only as one-way hashes.
- Merchant payment credentials are encrypted with authenticated encryption, using a key held outside the web server's document root.
- Each shop's data is isolated: a query for one shop cannot return another shop's orders or buyers.
- Administrator access to buyer details is recorded in an audit log.
- Photographs you upload have their embedded location data stripped before they are published, so a picture taken at home does not reveal where that is.
Where it is stored
On servers operated by our commercial web hosting provider. Where those servers are outside the Philippines, the transfer is covered by our contract with that provider, which requires them to keep the data secure and to process it only on our instructions. The Data Privacy Act does not prohibit storing data abroad; it requires that it be disclosed and safeguarded, and this is that disclosure.
Children
This platform is not intended for children. You must be at least 18 to open a shop. We do not knowingly collect personal data from a child; if you believe we have, contact the Data Protection Officer and it will be removed.
Changes to this notice
If this notice changes materially, its version identifier changes with it and you will be asked to agree again. The version you agreed to is recorded against your account.
Complaints
Contact our Data Protection Officer first. If you are not satisfied, you may complain to the National Privacy Commission at privacy.gov.ph.
Version 2026-09-04. This identifier is stored against every consent, so it stays provable which wording a person actually agreed to. A material change to either document moves it.