Privacy Policy
Effective Date: September 3, 2025
1. Introduction and Data Controller
This Privacy Policy establishes the parameters under which LowPriceDito.com ("Company," "we," "us," or "our") collects, processes, and secures personal data across our website, applications, and electronic communications. LowPriceDito.com operates as the designated Data Controller in compliance with the Philippine Data Privacy Act of 2012 (DPA) and applicable international data protection frameworks. Continued access or use of our services constitutes acknowledgment of the data practices detailed in this document.
2. Scope of Data Collection
We collect explicit categories of data to operate our services. We strictly do not collect Special Categories of Personal Data (e.g., racial origin, political opinions, health data).
2.1 Personal Identification Information (PII)
- Contact Data: Name, email address, telephone number, shipping and billing addresses.
- Account Data: Username, password, membership tier, account preferences, invitation source.
- Transaction and Financial Data: Purchase history and payment details (credit/debit card numbers, expiration dates, refund bank accounts, e-wallet IDs). Full payment credentials are processed securely by accredited third-party providers and are not stored on our local servers.
- Technical Data: Internet Protocol (IP) address, login credentials, browser specifications, time zone, operating system, and device metrics.
- Profile Data: Consumer preferences, survey responses, and documented customer support interactions.
- Usage Data: URL clickstreams, product views, page response latency, interaction metrics (scrolling, clicks), and exit parameters.
2.2 Automated Data Technologies
- Cookies: Session and persistent files deployed to user devices for operational functionality. Browser refusal of cookies may restrict site capabilities.
- Web Beacons: Pixel tags utilized for site traffic analytics and user engagement tracking.
- Log Files: Server logs capturing IP addresses, browser types, Internet Service Providers, referring/exit pages, and operational timestamps.
3. Data Collection Methodology
We acquire data through the following verifiable channels:
- Direct Interaction: Data explicitly provided via forms, account registration, transactions, or direct correspondence.
- Automated Technologies: Technical and Usage Data harvested programmatically during active site navigation.
- Third-Party Sources: Data procured from analytics providers (e.g., Google Analytics), advertising networks, payment gateways, delivery partners, and accredited demographic data brokers. Third-party data is utilized strictly to calibrate our algorithmic membership model.
4. Data Utilization and Legal Basis
We process personal information under the following defined legal bases:
| Operational Purpose | Legal Basis (Philippine DPA) |
|---|---|
| Present site interface and deliver requested products or services. | Performance of a Contract |
| Process orders, authorize payments, and recover outstanding debts. | Performance of a Contract; Legitimate Interest |
| Administer customer relations and issue mandatory policy updates. | Performance of a Contract; Legal Obligation; Legitimate Interest |
| Maintain IT infrastructure, network security, and business continuity. | Legitimate Interest |
| Execute data analytics to optimize services, marketing, and user experience. | Legitimate Interest |
| Deploy direct marketing and personalized commercial recommendations. | Consent (where mandated); Legitimate Interest |
| Execute algorithmic membership models and assign operational tiers. | Legitimate Interest; Performance of a Contract |
5. Data Disclosure Protocols
Data sharing is strictly limited to legitimate business operations involving the following entities:
- Service Providers: Contracted third parties facilitating payment processing, order fulfillment, marketing, and hosting. These entities operate under binding data processing agreements ensuring confidentiality.
- Business Transfers: Successor entities resulting from corporate mergers, acquisitions, or asset liquidations.
- Legal Authorities: Disclosure mandated by valid legal processes, regulatory audits, or urgent circumstances requiring the protection of legal rights or public safety.
- Consent-Based Transfers: Any external entity subject to the data subject's explicit, prior consent.
We strictly prohibit the sale of Personal Identification Information to unauthorized third parties for independent marketing purposes.
6. International Data Transfers
Data processing may necessitate cross-border transfers outside the jurisdiction of the Philippines. Under such operational requirements, we enforce strict compliance mechanisms, utilizing adequacy decisions or approved standard contractual clauses, to guarantee a standard of data protection equivalent to Philippine law.
7. Data Security Standards
We enforce technical and organizational safeguards, including strict firewall configurations and SSL/TLS encryption for financial transactions, to prevent unauthorized access, alteration, or data breach. While rigorous security protocols are active, the absolute security of internet-based transmissions cannot be legally guaranteed. Users initiate data transmission at their own inherent risk.
8. Data Retention Policy
Personal data is retained exclusively for the duration required to execute the operational purposes of its collection. Mandated by statutory tax and audit regulations, fundamental customer records (Contact, Identity, Financial, and Transaction Data) are securely archived for a period of six (6) years following the termination of the customer relationship, after which they are systematically purged.
9. Data Subject Rights
Pursuant to the Philippine Data Privacy Act of 2012, users possess the following enforceable rights:
- Right to Be Informed: To receive clear documentation on data processing methodologies.
- Right to Access: To demand copies of active personal records.
- Right to Rectification: To mandate the correction of inaccurate or incomplete data.
- Right to Erasure: To compel the deletion of personal data under statutory conditions.
- Right to Restrict Processing: To suspend data processing under specific legal disputes.
- Right to Data Portability: To extract data in a structured, machine-readable format.
- Right to Object: To refuse data processing for direct marketing or specific operational grounds.
- Right to Withdraw Consent: To revoke prior authorization without nullifying the legality of pre-withdrawal processing.
- Right to Lodge a Complaint: To escalate unaddressed grievances directly to the National Privacy Commission (NPC).
10. Minor Privacy Restrictions
Platform services are legally restricted to individuals eighteen (18) years of age or older. We do not knowingly process data from minors. Any data verified as belonging to a minor will be subjected to immediate systemic deletion.
11. Policy Modifications
Revisions to this Privacy Policy will be published at this exact URL, indicated by the revised Effective Date. Material alterations to data processing protocols will be communicated via direct email or prominent site notification. Users retain the responsibility of maintaining accurate contact details and reviewing this document periodically.
12. Contact Details and Data Protection Officer
To exercise statutory data rights or submit formal inquiries regarding these protocols, direct all correspondence to our assigned Data Protection Officer (DPO):
LowPriceDito.comForest Drive St., Country Homes
City of Biñan, Laguna, Philippines
[Temporary address]
Attn: Data Protection Officer
Email: dpo@lowpricedito.com
General Privacy Inquiries: privacy@lowpricedito.com
All identity-verified requests will be processed within the legally mandated timeframe.