JOph
  • How it works
  • For Customers
  • For Providers
  • Download app
Legal

Privacy Policy

This policy explains — in plain language — what personal data JOph collects, why we collect it, who we share it with, and the rights you have over it. It is issued under the Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations.

Last updated: 24 August 2026·Version 1.0
On this page 1. Who we are 2. Data we collect 3. Where data comes from 4. Why we process it 5. Who we share it with 6. How long we keep it 7. How we protect it 8. Your rights 9. Identity verification 10. Ratings & user content 11. Children's data 12. Automated decisions 13. Cookies & tracking 14. International transfers 15. Data breach notification 16. Changes to this policy 17. Contact us
Quick summary: We collect only what the app needs to verify identities, run Job Orders, and keep both sides safe. We never sell your data, and we do not take a cut of your payments — so we never need your money details to hold for you. You can ask us about, correct, or delete your data anytime at dpo@joph.app.

1. Who we are

JOph ("JOph", "we", "us") is a peer-to-peer Job Order and QR booking platform with built-in identity verification, operated in the Republic of the Philippines. For the purposes of the Data Privacy Act of 2012 (RA 10173), we act as the Personal Information Controller (PIC) of the personal data described in this policy.

  • Registered business name: [Registered Business Name — per DTI/SEC registration]
  • Business address: [Complete business address, Philippines]
  • Website: https://joph.app
  • Contact email: support@joph.app
  • Contact phone: [+63 XXX XXX XXXX]

Data Protection Officer (DPO)

We have appointed a Data Protection Officer who oversees our compliance with RA 10173. You can reach the DPO directly for any privacy concern:

  • DPO name: [Name of Data Protection Officer]
  • DPO email: dpo@joph.app
  • DPO phone: [+63 XXX XXX XXXX]

Where registration thresholds under NPC regulations apply, our DPO and data processing systems are registered with the National Privacy Commission (NPC), and we file the required annual reports.

2. Data we collect

We collect the following categories of personal data, depending on how you use JOph:

Identity verification data

  • Full name and date of birth
  • Government-issued ID details (e.g., PhilSys/PhilID, UMID, driver's license, passport, TIN, SSS)
  • Photos of your ID document, captured in-app
  • A live selfie taken during verification, used to match you to your ID
  • Residence or business address you provide

Account & contact data

  • Email address and mobile number
  • Username or display name and profile details
  • Password (stored only as a salted hash — we never see or store your actual password)

Job Order & transaction data

  • Job descriptions, service categories, schedules, and pricing you enter into Job Orders
  • Job Order status, booking, session, and payment logs (e.g., the customer's "Paid" tag with timestamp)
  • Messages exchanged between customer and provider inside a Job Order
  • Ratings and reviews between parties

Note on payments: JOph does not process or hold customer payments. Customers pay providers directly through their own arrangement. We store only the payment record the customer creates (amount, timestamp, notes) — never card numbers, e-wallet credentials, or bank details.

Technical & device data

  • IP address and device information (model, operating system, app version)
  • Approximate or precise location data — only when you use location features, such as pinning your business address or sharing a live Job Order location, and only while that feature is active
  • App usage analytics and log files

Sensitive personal information

Some data we process — government ID numbers and biometric-quality verification selfies — qualifies as sensitive personal information under RA 10173. We apply stricter safeguards to it: it is collected only through the in-app verification flow, encrypted, accessible only to a restricted set of roles, and never used for marketing.

3. Where data comes from

  • Directly from you — registration forms, ID verification capture, profile creation, and Job Order details you enter.
  • Automatically from your device — technical and usage data generated as you use the app.
  • From the other party — ratings, reviews, payment tags, and messages a counterparty creates about a transaction with you.

We do not currently obtain your personal data from third-party verification vendors or government databases. If that changes, we will update this policy and notify you as described in Section 16.

4. Why we process it

PurposeLawful basis (RA 10173)
Verifying the identity of customers, providers, and personnelContract performance; legal obligation; consent (for the capture of verification images)
Creating, matching, and running Job Orders between usersContract performance
Keeping Job Order records (status, booking, session, payment logs) synced for both sidesContract performance; legitimate interests
Account security, fraud prevention, and enforcement of our TermsLegitimate interests; legal obligation
Customer support and dispute assistanceContract performance; legitimate interests
Compliance with legal and regulatory obligations (e.g., BIR record-keeping, NPC)Legal obligation
Service improvement and product analyticsLegitimate interests
Research and developmentLegitimate interests; consent where required
Marketing communicationsConsent — strictly opt-in, and you can withdraw anytime

We do not use your data for any purpose incompatible with the ones above without first informing you and, where required, getting your consent.

5. Who we share it with

We do not sell your personal data. We share it only with the following categories of recipients, and only to the extent needed:

  • Other JOph users — your display name, profile photo (cropped selfie), general service area, and Job Order details relevant to a booking. Verification documents are never shown to other users.
  • Counterparties in a Job Order — during a Personnel QR check, the customer sees the personnel's cropped face photo and name, and whether they match an active Job Order.
  • Cloud hosting and infrastructure providers — [hosting provider, e.g., Supabase/AWS/Google Cloud], which store and deliver the service. Data may be stored outside the Philippines (see Section 14).
  • Analytics and monitoring tools — de-identified usage data to keep the app healthy and improve features.
  • Government agencies — NPC, BIR, or law enforcement, only when legally required or to protect vital interests.
  • Legal advisors and auditors — under confidentiality, when reasonably needed.
  • Successor entities — in the event of a merger or acquisition, after written assurance that your data will be protected at least as strongly as under this policy.

Where we share data with any processor, we do so under a data-sharing or data-processing agreement that binds them to safeguards no weaker than ours.

6. How long we keep it

Data categoryRetentionWhy
Raw ID images & verification selfiesDeleted within 30 days after verification is completed or definitively failsNeeded only to complete verification; the result, not the raw images, is what the account relies on
Verification status / resultLife of account + 1 yearTo avoid re-verifying and to support fraud and dispute checks
Job Order, booking & payment logs10 yearsBIR record-keeping requirements for transactions
In-JO messages2 years after Job Order closureDispute resolution window
Account dataLife of account + 30 days after deletion requestGrace period for recovery of accidental deletion; then erased
Analytics data14 monthsProduct improvement cycles
Data held under legal holdUntil the hold is liftedPending investigation or legal proceedings

When data is no longer needed, we securely delete or anonymize it.

7. How we protect it

Organizational safeguards: internal privacy policies, mandatory data-protection training for staff, signed confidentiality agreements, role-based access control, and a documented security-incident response plan.

Technical safeguards: encryption in transit (TLS 1.2+) and at rest (AES-256); passwords stored only as salted hashes; a mandatory PIN/biometric gate inside the app; multi-factor authentication for administrative access; access logging and monitoring; regular security review of our APIs and infrastructure.

Physical safeguards: our data is hosted on reputable cloud infrastructure operating under recognized physical-security certifications.

8. Your rights

Under Section 16 of RA 10173, you have the right to be informed, to access, to object, to rectify, to erase or block, to damages, to data portability, and to file a complaint with the NPC. To exercise any of these rights, email dpo@joph.app or use the in-app privacy request form. We will verify your identity first (to protect your data from impostors) and respond within 30 days of a complete request.

  • Access & portability — get a copy of your data in a machine-readable format.
  • Rectification — correct inaccurate account or profile details (some verification details require re-verification rather than edit, for integrity reasons).
  • Objection — opt out of secondary processing such as analytics or marketing at any time.
  • Erasure / blocking — request deletion of your account and data, subject to the retention periods in Section 6 (e.g., we must keep transaction records for BIR).
  • Damages — you may claim compensation for damages caused by a violation of your data privacy rights, and you may file a complaint directly with the NPC at any time.

9. Identity verification

JOph's core promise is that both sides of a booking are real and verified. Here is exactly how we handle verification data:

  • Why it's required — trust and safety: verified identities deter scams, protect customers letting providers into their homes, and protect providers from fake bookings.
  • What we store — raw ID photos and verification selfies are used to complete the check and are then deleted within 30 days (Section 6). What remains on your account is the verification result (e.g., "Verified") and a cropped profile selfie.
  • What other users see — only your cropped selfie, display name, and verification badge. Never your ID document, ID number, or full selfie.
  • Personnel checks — when a customer scans a Personnel QR, the customer sees the personnel's cropped face photo and name and whether they match an active Job Order. Nothing more.
  • If verification fails — you may retry or appeal. Repeated fraudulent attempts lead to account refusal under our Terms of Use.
  • Third-party verification — verification is currently performed in-house. If we ever engage a third-party verification provider, we will disclose it here before it takes effect.

10. Ratings & user content

Ratings and reviews you receive are visible to other users as part of your profile. You can respond to reviews, and you may report reviews that are fake, abusive, or unrelated to an actual Job Order — we will investigate and may remove them. Your profile content is processed under the license described in our Terms of Use, and you can request removal of content you no longer want published where the law allows.

11. Children's data

JOph is strictly for users aged 18 and above. We do not knowingly collect personal data from minors. If we learn that an account belongs to a minor, we will suspend it and delete the associated personal data. If you believe a minor has created an account, contact us at dpo@joph.app.

12. Automated decision-making

Some checks in JOph are automated — for example, matching a Personnel QR to an active Job Order, or initial validation of verification captures. These systems check factual conditions only (e.g., "does this personnel match this Job Order?"). No automated decision produces legal effects that significantly affect you without human involvement: failed verifications and fraud flags are reviewed by a human before any account action, and you may always request human review or contest a decision by contacting dpo@joph.app.

13. Cookies & tracking

This website uses only essential cookies and equivalent local storage needed for the site to function (e.g., remembering your preferences). We do not run advertising or third-party marketing trackers on this website, and we do not treat scrolling as consent — if we ever add optional analytics cookies, we will ask for your explicit consent first through a consent banner with granular choices.

In the mobile app, we use privacy-respecting analytics (crash reports and aggregate usage) to keep the service working. You may opt out of optional analytics in the app's privacy settings.

14. International transfers

Your data is primarily hosted on [hosting provider] infrastructure, which may be located in [countries/regions, e.g., Singapore and the United States]. Where personal data leaves the Philippines, we ensure protection consistent with RA 10173 and NPC Circular 2020-16 through contractual safeguards with the receiving provider, including obligations to protect the data no less strictly than required by Philippine law. You may contact dpo@joph.app for a current list of where your data is stored.

15. Data breach notification

If a personal data breach is likely to cause you harm, we will notify the NPC and affected users within 72 hours of becoming aware of the breach, through email and/or in-app notice. Breach notices will describe what happened, what data was involved, the likely consequences, and the measures we are taking — including steps you can take to protect yourself.

16. Changes to this policy

We may update this policy as the service evolves. Material changes will be announced at least 15 days before they take effect through email and/or in-app notice, and the "Last updated" date above will change. Continued use of JOph after the effective date means you accept the updated policy; if you object to a material change, you may terminate your account and request deletion of your data (Sections 6 and 8).

17. Contact us

Data Protection Officer — dpo@joph.app · [+63 XXX XXX XXXX]

Privacy team — privacy@joph.app

Postal — [Complete business address], Philippines

National Privacy Commission — if you believe your rights have been violated, you may escalate directly to the NPC: 5th Floor, Delegation Building, PICC Complex, Roxas Boulevard, Manila · npc.gov.ph

JOph

Smarter Job Order and Booking, powered by QR. © 2026 Joph

Customers Providers FAQ Support Privacy Terms