Privacy Policy
Last updated 4 August 2026 · Version 2026-08-04
1. Who we are
RonOS is business management software for small and medium businesses in the Philippines. It is operated from the Philippines.
You can contact us about anything in this policy at ronosapp@gmail.com.
2. Two different relationships
This policy covers two different kinds of information, and it matters which one is being talked about.
The first is information about our customers — the businesses that use RonOS, and the people who hold accounts with us.
The second is information a customer's business puts into RonOS about its own people — its employees, and its own customers. For that information, the business decides what is collected and why. We process it on that business's instruction.
3. What we hold
Account holders
- Name, username and email address
- Password — stored only as an irreversible hash, never as the password itself
- Role
- Records of actions taken in the system
Employees of a business using RonOS
- Name, date of birth, address, contact details and emergency contact
- SSS, TIN, PhilHealth and Pag-IBIG numbers
- Bank name and account number
- Salary, deductions, contributions, loans and cash advances
- Attendance and clock times
- A 4–6 digit clock PIN — stored only as a hash
- Clock-in photographs, where the business has enabled them
- Approximate location at clock-in, where the business has enabled it
- Performance reviews and disciplinary records
- Employment documents
A customer's own customers
- Booking name and contact details
- Amounts owed
- Payment references
- Uploaded payment screenshots
Suppliers and purchases
- Supplier names, and TINs where they have been entered
- Receipt photographs
Technical information
- IP address
- Session identifiers
- Error diagnostics
Two things we want to be explicit about
There is no facial recognition and no automatic identification of any kind.
It is not continuous tracking, and it is captured only where the business has enabled it.
4. Why we hold it
- To provide the service
- For security
- To meet record-keeping obligations
- To diagnose faults
Plainly: we do not sell it. We do not use it for advertising. We do not share it beyond the providers listed below.
5. Where the information goes
| Provider | What it is used for | What goes there | Where |
|---|---|---|---|
| Railway | Application and database | All business data | United States (US West) |
| Cloudflare R2 | Uploaded files | Receipt photographs, clock-in photographs, documents | Asia-Pacific |
| Anthropic | Only when an AI feature is used | The receipt image being scanned, or the figures being asked about | United States |
| Loyverse | Point-of-sale sync | Nothing is sent — sales data is copied one way into RonOS | — |
| Sentry | Error diagnostics | Request contents, form data and files are stripped; the user is reduced to an identifier | United States |
| Apple / Google push services | Notifications | Notification text, where enabled | United States |
| GitHub | Nightly database backups | Backups, encrypted before upload | United States |
Personal information is therefore transferred outside the Philippines. This is because the infrastructure RonOS runs on is operated by these providers from those locations. They may not use it for their own purposes.
6. How long we keep it
- Clock-in photographs — 90 days by default, and a business can shorten this. They are deleted automatically.
- Backups — 30 days.
- Everything else — for as long as the business uses RonOS, and for twelve months after it stops being used. We will warn you before deletion so there is time to take a copy or to object. We will delete sooner on request.
- Records of actions — kept for security and accountability.
7. Your rights
Under the Data Privacy Act of 2012 (Republic Act No. 10173) you have the right to:
- see the information held about you
- correct it
- object to how it is used
- have it deleted
- receive a portable copy
- be told if it has been compromised
Where to ask. If you are an employee or a customer of a business that uses RonOS, please ask that business first. It decides what is held about you and it can act immediately. If you hold an account with us, contact us directly.
You may also complain to the National Privacy Commission at privacy.gov.ph.
8. How we protect it
- Information is encrypted in transit.
- Passwords and PINs are stored only as irreversible hashes.
- Each business's data is separated from every other's. This is enforced in software and verified by automated tests on every change.
- Sign-in attempts are rate limited.
- Backups are encrypted before they leave our systems.
- Access is restricted by role, and logged.
Honestly: no system is perfectly secure. If a breach occurs that puts people at risk, we will notify those affected and the National Privacy Commission as the law requires.
9. Children
RonOS is for business use. It is not intended for children.
10. Changes
If we make material changes to this policy we will notify you rather than make them silently.