1. Who we are
MicroBiz by VES ("MicroBiz", "the Service", "we", "us", "our") is a business-management web application built
for small business owners, GCash/e-wallet agents, and similar micro-entrepreneurs in the Philippines. The Service
is operated by Hipolito B. Binos Jr., doing business as "Via Express Solutions." For purposes of Republic Act No.
10173 (the Data Privacy Act of 2012), we act as the Personal Information Controller for the data
described in this policy.
2. Scope of this policy
This policy applies to the MicroBiz web application at this domain, and to our public marketing pages (Home,
About, Contact). It does not apply to third-party websites you may reach through links on our site — read their
own privacy policies before providing them any information.
3. Data we collect
We only collect what we need to run the Service and support your account.
3.1 Information you give us directly
- Account data: your name, email address, and password (stored as a one-way hash — we never
see or store your plain-text password).
- Business data you enter: sales, expenses, withdrawals, capital movements, wallet/e-wallet
transaction records, load/bills-payment entries, inventory and product records, customer debt (utang) records,
loan and recurring-expense records, and any notes or reference numbers you type into these forms. This is your
business data — we store it so the app can show it back to you; we do not use it to build advertising profiles.
- Payment request data: if you request a Premium plan upgrade, we store the billing cycle, the
amount due, and the GCash reference number you submit, so an administrator can manually verify your payment.
We do not collect or store your GCash PIN, mobile wallet balance, or full GCash account credentials — only the
reference number you choose to type in.
- Contact form submissions: if you use the Contact page, we collect your name, email, phone
number (optional), business type/name (optional), and message.
- Optional Telegram linking: if you choose to link a Telegram account (Settings → Notifications)
to receive reminders, we store your Telegram chat ID and send you the notifications you've enabled through
Telegram's messaging platform. This is entirely optional and off by default.
3.2 Information collected automatically
- Session data: a session cookie that keeps you logged in (see our Cookie Policy).
- Device/log data: standard web server logs (IP address, browser type, pages requested,
timestamps) generated automatically by our hosting infrastructure for security and troubleshooting.
- Local preferences: your light/dark theme choice and sidebar layout preferences, stored in
your browser's local storage, not sent to our servers.
We do not currently use Google Analytics, Meta/Facebook Pixel, or any other analytics or
advertising-tracking service. If that changes, we will update this policy and our Cookie Policy
first, and — where consent is legally required — ask for it before any such tracking is activated.
4. How we use your data
- To create and maintain your account and authenticate your logins.
- To provide the core functionality of the Service — recording, calculating, and displaying your business data.
- To process and manually verify Premium plan payment requests.
- To send you service communications: verification emails, password resets, due-date and low-stock reminders,
and — if you opt in — Telegram notifications.
- To respond to messages you send through the Contact page.
- To detect, investigate, and prevent fraud, abuse, or security incidents.
- To comply with legal obligations (e.g., responding to a lawful government request).
5. Legal basis for processing
Under the Data Privacy Act, we process your personal data on these bases:
- Consent — you agree to this policy and our Terms & Conditions when you create an account.
- Contract performance — processing your business data and payment requests is necessary to provide the Service you signed up for.
- Legitimate interest — for basic security logging and fraud prevention, balanced against your privacy rights.
- Legal obligation — where processing or disclosure is required by Philippine law.
6. Who we share data with
We do not sell, rent, or trade your personal data. We share it only in these limited situations:
- Service providers (data processors): our hosting provider, email delivery provider, and —
only for users who opt in — Telegram Messenger LLP (Telegram Bot API), each of which processes data on our
behalf and only to the extent needed to provide their service to us.
- Content delivery / library providers: when you load a MicroBiz page, your browser also
requests fonts and open-source code libraries from Google Fonts, jsDelivr, and unpkg, and — only on the
Community map feature — map tiles from OpenStreetMap. These providers may see your IP address and browser
information as a normal part of serving those files; we do not send them your MicroBiz account or business data.
See our Cookie Policy for the full list.
- Legal requirements: if required to do so by law, court order, or a valid request from a
Philippine government authority.
- Business transfers: if the Service is ever transferred as part of a merger, acquisition, or
sale of assets, your data may transfer with it — we will notify you before your data becomes subject to a
different privacy policy.
7. Where your data is stored
Our application and database are hosted with third-party cloud infrastructure providers, which may store data
on servers located outside the Philippines. Where this occurs, we take reasonable steps to ensure your data
continues to receive a comparable level of protection, consistent with the Data Privacy Act's requirements for
cross-border data transfers.
8. How long we keep it
We keep your account and business data for as long as your account remains active, plus a reasonable period
after closure to comply with legal, accounting, and dispute-resolution needs (generally up to a period consistent
with the Bureau of Internal Revenue's record-keeping requirements for business records, where applicable). If you
delete your account, we will delete or anonymize your personal data within a reasonable period, except where we
are legally required or permitted to retain it longer (for example, records of a payment dispute).
9. How we protect it
We apply reasonable organizational and technical security measures appropriate to a service of this size,
including password hashing, encrypted connections (HTTPS), and access controls limiting who can view your data
administratively. No online service can guarantee absolute security, and we cannot promise that unauthorized
access, hacking, or data loss will never occur — but we take reasonable steps to reduce that risk and will notify
you as described in Section 12 if a breach affecting you occurs.
10. Your rights
Under the Data Privacy Act of 2012, you have the right to:
- Be informed that your personal data will be, is being, or was processed.
- Access your personal data that we hold.
- Correct inaccurate or outdated personal data.
- Erase or block your personal data under certain conditions (e.g., if it was unlawfully obtained, or you withdraw consent).
- Object to processing of your personal data, including processing for direct marketing.
- Data portability — request a copy of your data in an electronic format.
- Damages for harm caused by inaccurate, incomplete, or unlawfully obtained personal data.
- File a complaint with the National Privacy Commission (NPC) if you believe your rights have been violated.
To exercise any of these rights, contact us using the details in Section 14. Most account data can also be
viewed and edited directly from your account settings, and you can request full account deletion at any time.
11. Children's privacy
MicroBiz is intended for business owners and is not directed at children. We do not knowingly collect personal
data from anyone under 18. If you believe a minor has provided us personal data, contact us and we will delete it.
12. Data breach notification
If a security incident occurs that is likely to give rise to a real risk of serious harm to you, we will notify
the National Privacy Commission and affected users within the timeframe required by the Data Privacy Act and its
implementing rules, and describe the nature of the breach and the steps we're taking in response.
13. Changes to this policy
We may update this policy from time to time. If we make material changes, we will update the "Effective date"
above and, where appropriate, notify you by email or an in-app notice before the changes take effect. Continuing
to use the Service after a change takes effect means you accept the updated policy.
Questions, requests, or complaints about this policy or your data can be sent to:
viaexpresssolutions@gmail.com, or via our
Contact page. We aim to respond within 24–48 hours on business days.