Bilyo holds two different kinds of personal data, and answers for them differently. That distinction runs through this whole policy, so it comes first.
01Scope and responsibility
| Data | Who decides how it is used | Our role |
|---|---|---|
| Your account and business detailsYour name, email, business profile, login records | We do | Personal Information Controller |
| Your clients’ detailsClient names, emails, phone numbers, addresses and notes you enter | You do | Personal Information Processor, acting on your instructions |
In plain terms: we answer for what happens to your data. You answer for the client records you put into Bilyo, and we only act on them to run the service for you.
02What we collect
Everything below is data you give us or that the service generates as you use it. We do not buy personal data, and we do not build advertising profiles.
| Category | What it includes | Why |
|---|---|---|
| Account | Name, email address, a bcrypt hash of your password (never the password itself), email verification status | To create and secure your account |
| Security | Two-factor secret (encrypted at rest), recovery code hashes, failed-attempt counts and lockout times | To protect your account, only if you enable 2FA |
| Business profile | Business name, address, email, phone, logo, default currency | To place your details on quotations and PDFs |
| Quotations | Line items, amounts, dates, quotation numbers, and a frozen snapshot of your business and client details as they stood when sent | To produce the document and keep sent quotations accurate |
| Free Demo | Email address, demo quotation items, one-time verification code records, and delivery outcomes | To send the single interactive demo and prevent service abuse |
| Product waitlist | Email address, consent timestamp, legal version, and unsubscribe status | To send launch updates if you opted in during the demo |
| Activity | When a quotation was sent, viewed, accepted or declined, and whether the actor was you or the recipient | To show you a timeline and status |
| Email delivery | Recipient address, subject, and delivery outcome — sent, delivered, bounced, complained | To tell you whether your quotation arrived, and to protect deliverability |
| Usage | Last login, last activity, and server logs including IP address and browser user agent | Security, abuse prevention, and debugging |
| Support and payment | Messages you send us, and the payment reference you supply when topping up | To answer you and to confirm access |
We do not collect sensitive personal information as the Data Privacy Act defines it, and you should not put any into quotation notes.
03Your clients' personal data
When you save a client, you give us their name and, optionally, their email address, phone number, address and your own notes. We store that, show it back to you, place it on the quotations you address to them, and email it to the address you specify. We do nothing else with it. We never contact your clients on our own initiative and never use their details to market anything.
Because you decide what to collect about your clients and why, you are their Personal Information Controller. By entering their details, you confirm that you have a lawful basis under RA 10173 to hold and share them.
If one of your clients contacts us directly about their data, we will refer them to you and tell you, unless the law requires otherwise.
04Why we process it
Under section 12 of the Data Privacy Act, our bases are:
- Performance of a contract — running the service you signed up for: your account, your quotations, and delivering them.
- Legitimate interests — keeping the service secure, preventing abuse and fraud, protecting our email deliverability, and debugging faults; balanced against your rights and interests.
- Legal obligation — where a law or a lawful order requires us to keep or disclose something.
- Consent — for anything outside the above, such as optional product announcements or waitlist updates (which you can withdraw at any time via the unsubscribe link or page).
05Public quotation links
Every quotation you send gets a link that opens without a login. That page shows the quotation, your business details, and your client’s name and details as recorded on it.
The link’s code is long and random, and we ask search engines not to index these pages, but the page is not password-protected: anyone who has the link can open it. Send links only to the people who should see them. You can revoke any link from the quotation page, which immediately stops it from opening.
When someone opens the link, we record the view and, if they respond, the acceptance or decline and its timestamp. We do not know who they are beyond that.
06Email records
We keep a record of each email the service sends on your behalf: recipient, subject, and delivery outcome. We do not keep the message body beyond what is needed to produce it.
If an address hard-bounces or someone marks a message as spam, we stop sending to that address. This protects delivery for every Bilyo user, so it is not something we can switch off per account.
07Who else processes it
We do not sell personal data and we do not share it for anyone else’s marketing. We use a small number of service providers, each bound to process data only on our instructions:
| Provider | What it does | Data it touches |
|---|---|---|
| Vercel | Application hosting and delivery | All data in transit; server logs |
| MongoDB Atlas | Database | All stored data |
| Vercel Blob | File storage | Business logos, and our own contribution QR image |
| Resend | Email delivery | Recipient addresses, message contents, delivery events |
We will update this list before adding a provider that handles personal data. We may also disclose data where a Philippine law, court order or lawful government request requires it, or to establish or defend a legal claim.
08Where data is stored
Bilyo is built for the Philippines, but the providers above operate globally, and your data is stored and processed outside the Philippines. Our database is hosted on Amazon Web Services in the Asia Pacific (Hong Kong) region, ap-east-1. Our hosting and email providers process data on their own infrastructure, which may be located in other countries including the United States.
Under the Data Privacy Act we remain accountable for your data wherever it sits, and we contract with each provider on terms that require a comparable level of protection.
09How long we keep it
| Data | Kept for |
|---|---|
| Demo quotations & verification codes | Verification codes: 15 minutes. Demo quotations: 7 days, then permanently purged. |
| Product waitlist | Retained until you unsubscribe, after which all outreach ceases immediately. |
| Unverified accounts | 7 days from registration, then deleted automatically with everything under them |
| Account, business, client and quotation data | While your account is open |
| After you close your account | Your public links stop working immediately and the account can no longer be used. Remaining records are permanently deleted within 30 days. |
| Email delivery records | 12 months. Bounce and complaint suppressions are kept indefinitely, so that we never re-send to an address that has rejected or reported us. |
| Server logs | For as long as our hosting provider retains them, currently no more than 30 days |
We may keep specific records longer where a law requires it or to defend a legal claim.
10Security
The measures we take include:
- Passwords stored only as bcrypt hashes — we cannot read or recover your password.
- Two-factor secrets encrypted at rest with AES-256-GCM.
- All traffic served over HTTPS.
- Quotation links carrying long random codes, never sequential identifiers, and revocable at any time.
- Every query scoped to the signed-in account, so one user’s data cannot be reached from another’s session.
- Administrative access restricted, protected by two-factor authentication, and written to an audit log.
No system is perfectly secure. Use a strong, unique password and turn on two-factor authentication.
12Your rights
Chapter IV of the Data Privacy Act gives you these rights over your personal data:
To exercise any of these, email [email protected]. We will respond within 15 days and may ask you to confirm your identity first. You can also download a copy of your data at any time from Account › Settings. If you are not satisfied, you can complain to the National Privacy Commission at privacy.gov.ph.
If your request concerns data held by a Bilyo user about you as their client, we will pass it to that user, who is its controller.
13Breach notification
If a security incident affects your personal data in a way that is likely to give rise to a real risk of serious harm, we will notify the National Privacy Commission and the people affected within 72 hours of learning of it, as required by NPC Circular 16-03. The notice will say what happened, what data was involved, and what you should do.
14Children
Bilyo is a business tool and is not directed at anyone under 18. We do not knowingly collect data from minors. If you believe a minor has registered, write to us and we will delete the account.
15Changes and contact
If we change this policy materially, we will email your registered address before the change takes effect and update the date at the top.
Our contact person for data protection is Carls Dale Escalo, Software Developer, reachable at [email protected].
See also our Terms of Service.