Home About us Privacy policy Terms and condition Contact us Vendor registration Deliveryman registration

Privacy policy

1. Introduction
Welcome to HatidGo (the "App", "Platform", "we", "us", or "our"), a multi-service mobile application operated by Nueva Technology ("Company") that connects users with ride-hailing, delivery, and marketplace services within the Philippines. We are committed to protecting your privacy and handling your personal data responsibly, lawfully, and transparently.
This Privacy Policy explains what personal information we collect, why we collect it, how we use and share it, how long we keep it, and the rights you have over it. It applies to all users of the HatidGo mobile applications (including customer, rider, and merchant apps), our website, and any related services (collectively, the "Services").
This Policy is issued in compliance with the Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and the issuances of the National Privacy Commission ("NPC") of the Philippines.
By creating an account, downloading, accessing, or using the Services, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, processing, and disclosure of your personal data as described herein. If you do not agree with this Policy, please do not use the Services.


2. Definitions
•    Personal Information — any information from which the identity of an individual is apparent or can be reasonably and directly ascertained, or when put together with other information would directly and certainly identify an individual, as defined under RA 10173.
•    Sensitive Personal Information — personal information about an individual’s race, health, education, genetic or sexual life, government-issued identifiers, and other categories defined under Section 3(l) of RA 10173.
•    Processing — any operation performed upon personal data, including collection, recording, organization, storage, updating, retrieval, use, consolidation, blocking, erasure, or destruction.
•    Data Subject — an individual whose personal information is processed — in this Policy, that means you, the user.
•    Personal Information Controller (PIC) — Nueva Technology, which controls the collection and processing of your personal data through HatidGo.
•    Personal Information Processor (PIP) — any third party to whom we outsource the processing of personal data (e.g., cloud hosting, payment gateways, analytics providers).


3. Information We Collect
3.1 Information You Provide Directly
•    Account and Profile Information — your full name, email address, mobile/contact number, residential or delivery address, date of birth, gender (optional), profile photo, and account password when you register for a HatidGo account.
•    Identity Verification Data (Riders and Merchants) — for rider-partners and merchant-partners, we may collect government-issued IDs, driver’s license details, vehicle registration (OR/CR), business permits, and selfie verification photos.
•    In-App Messages and Communications — the content of messages, chats, and calls exchanged through the App’s in-app messaging feature between customers, riders, merchants, and our customer support team, including timestamps and delivery status.
•    Files and Photos — images, documents, and other files you upload or share through the App, such as proof-of-delivery photos, product images, receipts, attachments sent through in-app chat, and photos submitted for support tickets or disputes. The App will request permission before accessing your device’s camera, photo gallery, or file storage, and you may grant or deny this permission through your device settings.
•    Payment Information — details needed to process transactions, such as your selected payment method, e-wallet or bank account references, and billing details. Full debit/credit card numbers are collected and processed directly by our licensed third-party payment gateways; we do not store your complete card details on our servers.
•    Feedback and Support Data — ratings, reviews, survey responses, complaints, and any information you provide when contacting our support channels.
3.2 Information Collected Automatically
•    Location Data — with your permission, we collect your device’s precise (GPS) and approximate location in order to match you with nearby riders and merchants, calculate fares and delivery fees, provide real-time tracking of bookings and deliveries, improve routing, and ensure the safety of users and rider-partners. Location may be collected while the App is in use and, for rider-partners on an active booking, in the background. You may disable location access through your device settings, but doing so will prevent core features of the Services from functioning.
•    Device and Technical Information — device model, operating system and version, unique device identifiers, mobile network information, IP address, app version, language settings, and time zone.
•    Usage Data — in-app activity such as pages viewed, features used, search queries, booking and order history, session duration, and interaction logs.
•    Crash Reports and Diagnostics — we use application performance and crash-monitoring tools to automatically collect diagnostic information when the App crashes, freezes, or encounters errors. This includes crash logs, stack traces, device state at the time of the crash, device model, OS version, app version, and anonymized event data. This information is used solely to identify, reproduce, and fix bugs, improve app stability, and enhance overall performance. Crash data is pseudonymized wherever possible and is not used to profile you for marketing purposes.
•    Cookies and Similar Technologies — where applicable (e.g., on our website), we use cookies, SDKs, and similar technologies to remember your preferences, maintain sessions, and gather aggregate analytics.
3.3 Information from Third Parties
We may receive information about you from third parties, such as payment gateways (transaction confirmations), social login providers (if you register via Google or Facebook), our merchant and rider partners (order fulfillment details), marketing partners, and publicly available sources, in each case consistent with their own privacy policies.


4. Legal Bases for Processing
We process your personal data only when there is a lawful basis to do so under Sections 12 and 13 of RA 10173, including:
•    Consent — you have given specific, informed, and freely given consent (e.g., permission for location access, camera and file access, or marketing communications).
•    Contractual Necessity — processing is necessary to fulfill our contract with you — to create your account, process bookings and orders, facilitate deliveries, and process payments.
•    Legal Obligation — processing is required for compliance with laws and regulations, such as tax laws, transport regulations, and lawful orders from government authorities.
•    Legitimate Interests — processing is necessary for our legitimate business interests — such as fraud prevention, platform security, crash monitoring, service improvement, and dispute resolution — where such interests are not overridden by your fundamental rights.
•    Vital Interests — processing necessary to protect your life and health or that of another person, such as in emergencies during a ride or delivery.
5. How We Use Your Information
We use the personal data we collect for the following purposes:
•    To create, verify, and manage your HatidGo account and profile;
•    To provide, personalize, and operate the Services — matching you with riders and merchants, processing bookings, orders, and deliveries, and enabling real-time tracking;
•    To enable communication between customers, riders, merchants, and support through in-app messaging, and to review such communications where necessary for safety, fraud investigation, and dispute resolution;
•    To process payments, refunds, and payouts, and to maintain transaction records;
•    To send you service-related notifications, such as booking confirmations, order status updates, receipts, and important account or policy announcements;
•    To monitor, diagnose, and fix technical issues through crash reporting and performance analytics, and to improve app stability, features, and user experience;
•    To detect, prevent, and investigate fraud, unauthorized access, abuse, and violations of our Terms of Service;
•    To ensure the safety and security of users, rider-partners, and merchant-partners, including incident investigation;
•    To send you marketing, promotions, and offers, only where you have consented, and you may opt out at any time;
•    To comply with legal and regulatory obligations and respond to lawful requests from government authorities; and
•    To produce anonymized and aggregated statistics for business analysis, which can no longer identify you.


6. In-App Messaging, Files, and Photos
The App includes an in-app messaging feature that allows communication between customers, rider-partners, merchant-partners, and HatidGo support. Message content, attachments, and metadata are transmitted through and stored on our systems to enable delivery of the messages, provide message history, and support safety and dispute-resolution functions.
We do not routinely read your in-app messages. Access to message content is restricted to authorized personnel and occurs only when reasonably necessary — for example, to investigate a reported safety incident, a fraud complaint, a dispute between parties, or as required by law.
When you attach photos or files, the App will request access to your device’s camera, gallery, or storage. This permission is used only to let you capture or select the content you choose to share (e.g., proof of delivery, product photos, support attachments). We do not scan, copy, or upload other files or photos on your device beyond what you explicitly select or capture within the App.


7. Crash Monitoring and Analytics
To keep the App stable and reliable, we use third-party crash-reporting and analytics services (such as Firebase Crashlytics, Google Analytics for Firebase, or similar tools). When the App experiences an error or crash, these tools automatically transmit diagnostic data to us, including the crash log, device model, operating system version, app version, and the state of the App at the time of the incident.
This data is used exclusively for debugging, quality assurance, performance monitoring, and improving the Services. These providers process data on our behalf as Personal Information Processors under contractual obligations of confidentiality and security. Analytics data is collected on an aggregate or pseudonymized basis wherever feasible, and we do not attempt to re-identify anonymized analytics data.


8. How We Share Your Information
We do not sell your personal data. We share personal data only as described below and only to the extent necessary:
•    Between Users of the Platform — to fulfill a booking or order, limited information is shared between the parties involved — e.g., a rider-partner sees the customer’s name, pickup/delivery address, contact option, and order details; the customer sees the rider’s name, photo, vehicle details, and live location. Contact numbers are masked or limited where technically feasible.
•    Merchant-Partners — merchants receive order details necessary to prepare and fulfill your order.
•    Payment Providers — licensed payment gateways, e-wallet providers, and banks process your payment transactions under their own regulatory and security obligations (including PCI-DSS).
•    Service Providers (PIPs) — cloud hosting, SMS/email delivery, push notification, mapping, customer support, crash reporting, and analytics providers who process data on our behalf under data processing/outsourcing agreements as required by NPC Circulars.
•    Legal and Regulatory Disclosure — government agencies, law enforcement, courts, or regulators when required by law, subpoena, or lawful order, or where disclosure is necessary to protect the rights, property, or safety of HatidGo, our users, or the public.
•    Business Transfers — in the event of a merger, acquisition, financing, or sale of assets, personal data may be transferred to the successor entity, subject to this Policy and applicable law.
Where personal data is transferred to or accessed from outside the Philippines (e.g., cloud servers located abroad), we ensure that comparable levels of protection are contractually required in accordance with RA 10173 and NPC guidelines on cross-border transfers.


9. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, to comply with legal, regulatory, tax, and accounting requirements, and to establish or defend legal claims. As a general guide:
•    Account and profile data is retained while your account is active and for up to five (5) years after account closure, unless a longer period is required by law;
•    Transaction and payment records are retained in accordance with applicable tax and financial regulations;
•    In-app messages and attachments are retained for a limited period sufficient for safety, dispute, and fraud-investigation purposes, after which they are deleted or anonymized;
•    Crash logs and diagnostic data are retained only as long as needed for debugging and stability analysis; and
•    Location history is retained only as long as necessary for the purposes described in this Policy.
When retention periods lapse, personal data is securely deleted, destroyed, or irreversibly anonymized.


10. Data Security
We implement reasonable and appropriate organizational, physical, and technical security measures to protect your personal data against accidental or unlawful destruction, alteration, disclosure, and unauthorized access, consistent with Section 20 of RA 10173. These measures include encryption of data in transit (TLS/HTTPS), encryption or hashing of sensitive data at rest, role-based access controls, authentication safeguards, network and server hardening, regular security assessments, and confidentiality obligations for personnel.
While we work hard to protect your data, no method of transmission or storage is completely secure. You are responsible for keeping your account credentials confidential and for notifying us immediately of any suspected unauthorized use of your account.


11. Personal Data Breach Notification
In the event of a personal data breach that is likely to give rise to a real risk of serious harm to affected data subjects, we will notify the National Privacy Commission and the affected users within seventy-two (72) hours of knowledge of the breach, in accordance with NPC Circular No. 16-03 and related issuances. The notification will describe the nature of the breach, the personal data involved, and the measures taken to address it.


12. Your Rights as a Data Subject
Under RA 10173, you have the following rights with respect to your personal data:
•    Right to Be Informed — to be informed whether your personal data is being or has been processed, and of the details of that processing.
•    Right to Access — to obtain reasonable access to your personal data that we hold, upon demand.
•    Right to Rectification — to dispute inaccuracies or errors in your personal data and have them corrected promptly. You may edit most profile information directly in the App.
•    Right to Erasure or Blocking — to suspend, withdraw, or order the blocking, removal, or destruction of your personal data where it is incomplete, outdated, false, unlawfully obtained, used for unauthorized purposes, or no longer necessary.
•    Right to Object — to object to processing, including for direct marketing, automated processing, or profiling, subject to legal and contractual limitations.
•    Right to Data Portability — to obtain a copy of your personal data in a commonly used electronic format, where processing is by electronic means.
•    Right to Damages — to be indemnified for damages sustained due to inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorized use of your personal data.
•    Right to File a Complaint — to lodge a complaint with the National Privacy Commission (privacy.gov.ph) if you believe your rights have been violated.
To exercise any of these rights, contact our Data Protection Officer using the details in Section 16. We will respond within a reasonable period and in accordance with the timelines prescribed by the NPC. We may need to verify your identity before acting on your request. Note that withdrawing consent or requesting erasure of data essential to the Services (such as your account or location data) may mean we can no longer provide the Services to you.


13. Children’s Privacy
The Services are not directed at children, and users must be at least eighteen (18) years old to create an account. We do not knowingly collect personal data from minors. If we learn that we have collected personal data from a person under 18 without valid parental or guardian consent, we will delete that data promptly. If you believe a minor has provided us with personal data, please contact our Data Protection Officer.


14. Device Permissions Summary
The App requests the following device permissions. Each permission is optional at the operating-system level, but denying certain permissions will limit or disable core features:
•    Location (GPS) — for matching, fare/fee computation, live tracking, navigation, and safety. Core feature — required for bookings and deliveries.
•    Camera — to capture profile photos, proof-of-delivery photos, product images, and chat attachments.
•    Photos / Storage / Files — to let you select and upload images and documents you choose to share in the App.
•    Notifications — to deliver booking updates, order status, messages, and important announcements.
•    Microphone (if applicable) — only when you use in-app voice calling features.
You may review and change these permissions at any time through your device settings.


15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or the Services. When we make material changes, we will notify you through the App, by email, or by other prominent means, and update the "Last Updated" date above. Your continued use of the Services after the effective date of an updated Policy constitutes acceptance of the changes. We encourage you to review this Policy periodically.
16. Contact Us – Data Protection Officer
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, you may contact our Data Protection Officer:
Company: Nueva Technology – HatidGo
Address: Baliuag Bulacan
Email: privacy@hatidgo.com