PlansCompareFeaturesFAQSign in
Sign inPlan my setupPlan setupSetup

Tan-aw · Legal

Privacy Policy

How Tan-aw collects, uses, shares, and protects personal data across the platform and ReadyNa.

Effective June 11, 2026Updated July 5, 2026Version 1.0

On this page

1Summary2Personal data we process3Push notifications4Legal bases for processing5How we use personal data6How we share personal data7Sub-processors and where your data is stored8How long we keep personal data9Your rights10How we protect personal data11Data Protection Officer and contact12Children13Changes to this Policy
On this page tap to open
1Summary2Personal data we process3Push notifications4Legal bases for processing5How we use personal data6How we share personal data7Sub-processors and where your data is stored8How long we keep personal data9Your rights10How we protect personal data11Data Protection Officer and contact12Children13Changes to this Policy

This Privacy Policy explains how Tan-aw Information Technology Services, a sole proprietorship registered with the Department of Trade and Industry (DTI Business Name Reg. No. 8229411), with principal office at Selenia 208, Mirea Residences, Amang Rodriguez Avenue, Santolan, Pasig City ("Tan-aw", "we", "us") collects, uses, shares, and protects personal data when you use:

  • the Tan-aw platform (web app for food and beverage businesses); and
  • ReadyNa, our customer app and the order-tracking web page at tan-aw.com/orders/....

We process personal data in accordance with Republic Act No. 10173 (the Data Privacy Act of 2012, "DPA"), its Implementing Rules and Regulations, and the issuances of the National Privacy Commission ("NPC").

Who controls your data. When you order food, the merchant (the business you are buying from) decides what to collect and is the Personal Information Controller for your order; Tan-aw acts as their Personal Information Processor. For our own operation of the platform — merchant accounts, billing, security, and the app itself — Tan-aw is the controller. This Policy describes both roles. Questions about a specific order should also be directed to the merchant that served you.

1

Summary

  • Customers do not need an account. You can track an order with just a claim code or a link — no name, email, or phone number required.
  • We store a push notification token for your device only if you turn on "Notify me when ready", so we can tell you your order is ready.
  • A merchant may record your name on an order if you give it, and — only if you ask for an official receipt or claim a Senior Citizen / PWD discount — the data the law requires for that (including your government ID number, which we encrypt).
  • We do not sell your personal data. We do not use it for advertising.
  • Your data is hosted on Microsoft Azure in Singapore, and some notification and payment services process it abroad. We explain this in Section 7.

2

Personal data we process

2.1 Customers using ReadyNa / the order tracker

Data When collected Why
App install identifier (a random ID per app installation) When you open ReadyNa Lets us link your device to your orders without identifying you personally.
Push notification token + platform (iOS/Android) Only if you enable order notifications To deliver the "order ready" push notification via Apple/Google.
Order claim code / order link tokens When a merchant creates your order or you scan a QR/link Lets you (and only you, if you hold the link) view the order's status.
Your name (optional) Only if the merchant enters it on the order To label your order at the counter. You may decline to give it.
Order contents and status When the merchant takes your order To show you what you ordered and notify you when it is ready.
Notification delivery logs When we attempt a notification To diagnose delivery problems and reconcile stale device tokens.

We do not require your email address or phone number to use ReadyNa or the tracker.

2.2 Receipts, tax, and statutory-discount data (collected by the merchant)

If you request an official receipt / sales invoice, or claim a Senior Citizen (RA 9994) or PWD (RA 10754 / RA 7277) discount, the merchant must record — and Tan-aw stores on the merchant's behalf — the data the Bureau of Internal Revenue (BIR) and those laws require:

Data Notes
Your name As you provide it for the receipt or discount.
Your address Only for a VAT invoice that requires it.
Your Taxpayer Identification Number (TIN) Only for a VAT invoice; stored encrypted.
For SC/PWD: ID type (OSCA, PWD ID, NAAC, Solo Parent, or other) and ID number Required by law to grant and substantiate the discount. The ID number is stored encrypted and is never written into logs, backups, or exports in readable form.

This is sensitive personal information under RA 10173. We process it because the law obliges the merchant to capture it to grant the discount and to support its tax filings — not for any other purpose.

2.3 Payments

Payments you make to a merchant are not processed by Tan-aw. You pay the merchant directly by whatever means it accepts (cash, its own card terminal, or its own e-wallet), and the merchant records only the payment method, amount, and a reference number in the Service to reconcile its orders. Your card or e-wallet credentials never reach Tan-aw, and we do not store card numbers.

Merchants' subscription payments to Tan-aw are collected through our payment gateway (see Section 7). The merchant's card or e-wallet details are captured and processed by the gateway, not by us; we store only the payment method, amount, and reference number needed for billing and refunds.

2.4 Merchant account holders and staff

For people who log in to the Tan-aw platform (owners, admins, managers, cashiers), we process: name, email address, hashed password or federated identity from Microsoft Entra External ID (including the Entra object/tenant identifiers and multi-factor authentication assurance), role and location assignments, audit logs of actions taken, refresh-token/session records, and technical data such as IP address and timestamps for security.

2.5 Technical and diagnostic data

To operate, secure, and troubleshoot the service, we process technical data such as IP addresses, device/session identifiers, request metadata, application logs, error reports, and performance metrics. Some of this telemetry is shared with our hosting provider (Microsoft Azure) and our application-performance- monitoring provider (New Relic) and may be processed outside the Philippines (see Section 7). We minimize personal data in this telemetry at source, and no payment card numbers are sent to it.

2.6 Data we do not collect

  • We do not build advertising profiles or track you across other apps/websites.
  • We do not collect precise device location.
  • Analytics are aggregate only (order counts, revenue, timing) and are not used to profile individual customers.
  • We do not make automated decisions about you that produce legal or similarly significant effects.

3

Push notifications

The core purpose of ReadyNa is to tell you when your order is ready, replacing a physical buzzer. Notifications are opt-in: we register your device's push token only after you enable them. The notification contains the location name and your claim code — no other personal data. You can turn notifications off at any time in your device settings, after which we stop sending them and the token is pruned during routine maintenance.

4

Legal bases for processing

Under the DPA we rely on:

  • Consent — for push notifications, and for any name you choose to give.
  • Contract / legitimate interest — to create, display, fulfil, and track orders, operate merchant accounts, secure the platform, and bill merchants.
  • Legal obligation — to record and retain fiscal data and SC/PWD discount data required by the BIR, RA 9994, and RA 10754.
5

How we use personal data

We use personal data only to: provide and operate the ordering and notification service; show you your order status; deliver "order ready" notifications; bill merchant subscriptions through our payment gateway; produce receipts and meet the merchant's tax and statutory-discount obligations; secure the platform and prevent abuse (including tenant isolation and least-privilege access controls); provide customer support; and comply with law.

We do not sell personal data and do not use it for third-party advertising.

6

How we share personal data

We share personal data only with:

  • The merchant that served you (for your order, receipt, and discount data).
  • Sub-processors that operate the service on our behalf (see Section 7).
  • Government authorities (e.g. the BIR, NPC, courts) where required by law.
  • Professional advisers and, in a merger/acquisition, a successor entity, subject to the same protections.
7

Sub-processors and where your data is stored

Your personal data is hosted on Microsoft Azure in the Southeast Asia (Singapore) region. We use the following sub-processors:

Sub-processor Role Processing location
Microsoft Azure (Microsoft Corporation) Cloud hosting, database, storage, secrets; optional observability (Azure Monitor / Application Insights / Log Analytics) Singapore (Southeast Asia)
Microsoft Entra External ID Authentication / identity for merchants and (future) verified customers Microsoft global infrastructure
New Relic, Inc. Application performance monitoring, error tracking, and log management — technical telemetry only (PII-minimized) United States (EU region available)
Google Firebase Cloud Messaging (FCM) Push notification delivery Google global infrastructure
Apple Push Notification service (APNs) iOS push notification delivery Apple global infrastructure
PayMongo (PayMongo Philippines, Inc.) Subscription billing — processes merchants' payment methods for Tan-aw subscription fees Philippines (BSP-regulated); with onward transfer to its own US-based sub-processors (e.g. AWS, fraud screening)

Cross-border transfers. Your personal data may be processed and stored outside the Philippines by our service providers — including in Singapore (cloud hosting and infrastructure, via Microsoft Azure) and the United States (application performance monitoring, via New Relic). The Philippines has no data-localization law, and neither provider operates a datacenter within the Philippines, so this offshore processing is necessary to run the service. These transfers are governed by data processing agreements that incorporate the National Privacy Commission's Model Contractual Clauses and/or the EU Standard Contractual Clauses, and we remain accountable for ensuring your data receives a level of protection comparable to that required under Republic Act No. 10173 (Data Privacy Act of 2012). To request a copy of the relevant safeguards, contact our Data Protection Officer at [email protected].

8

How long we keep personal data

Operational data (orders, order-tracking and claim data, device records, and similar service data) is kept only as long as needed to provide the service, according to the merchant's subscription plan, and never longer than the law otherwise requires (see "Tax and legal-hold records" below):

  • Starter plan: up to 31 days (one month).
  • Standard plan and above: up to five (5) years while the subscription is active.

When a merchant unsubscribes or closes an account, we make its operational data available for export for a limited window (target: 30 days), after which we securely delete or irreversibly anonymize it, except records we are legally required to keep. A merchant may ask us to archive a copy of its own data beyond this period — and keep it available for download — as a paid service at fees covering the storage, processing, and retrieval involved; any such archival is purpose-limited, time-bound, revocable, and never extends to personal data belonging to the merchant's end customers — the fee itself is not a basis for keeping data.

Tax and legal-hold records — receipts, invoices, books of accounts and their source documents, Senior Citizen / PWD discount-substantiation records (name, OSCA/PWD/Solo-Parent ID number, discount, date, and receipt/invoice number), and TINs — are required by Philippine tax law to be preserved for the period the BIR requires — currently five (5) years from the applicable return-filing deadline, following the 2024 amendment of NIRC Section 235 by Republic Act No. 11976 (Ease of Paying Taxes Act) and RR 7-2024 — and longer where a tax assessment, protest, refund, or credit claim is pending. The merchant that served you is the accountable taxpayer and the controller of these records. While the merchant's subscription includes fiscal features, we store these records on its behalf, and they cannot be erased on request for as long as we hold them — your erasure request is honored for all other data. If the merchant leaves the platform, these records are delivered to the merchant in its data export for continued preservation, and we delete our copies after the export window unless the merchant purchases archival or we are legally required to keep them (for example under a legal hold).

Other data Retention
Push tokens / device records Kept while notifications are enabled and an order is active; pruned when stale or disabled.
Notification delivery logs Kept for a short troubleshooting window, then pruned.
Merchant account / authentication records Kept for the life of the account; sessions and refresh tokens expire and are deleted.

Where we are legally required to retain specific records, or need them to establish, exercise, or defend legal claims, your erasure request is honored for all other data and those records are kept only for the period required.

9

Your rights

Under the DPA you have the right to be informed, to object, to access your data, to correct inaccurate data, to erasure or blocking of unlawfully processed data, to data portability, to be indemnified for damages, and to file a complaint with the NPC.

To exercise these rights, contact our Data Protection Officer (Section 11). For order or receipt data, you may also need to contact the merchant that served you, since they control that data. Because most customer use is anonymous, we may need information (such as your order link or claim code) to locate your data before we can act on a request.

10

How we protect personal data

We apply appropriate organizational, physical, and technical measures, consistent with our obligations under RA 10173 Section 20 and the National Privacy Commission's security requirements (IRR Rule VI Section 28; NPC Circular 2023-06). These include: encryption in transit (TLS); field-level encryption at rest for sensitive identifiers (TINs and SC/PWD ID numbers); strong password hashing and federated authentication with multi-factor authentication for merchant staff; strict tenant isolation so one merchant cannot access another's data; least-privilege role-based access; and audit logging. No system is perfectly secure; we work to protect your data but cannot guarantee absolute security.

11

Data Protection Officer and contact

  • Data Protection Officer: [email protected]
  • General / support: [email protected]
  • Postal: Selenia 208, Mirea Residences, Amang Rodriguez Avenue, Santolan, Pasig City

If you believe your data privacy rights have been violated, you may also lodge a complaint with the National Privacy Commission (privacy.gov.ph).

12

Children

ReadyNa and the order tracker are not directed at children under 18. We do not knowingly collect personal data from children without the consent of a parent or guardian. Merchants are responsible for age verification on age-restricted goods (e.g. alcohol, tobacco).

13

Changes to this Policy

We may update this Policy. We will post the updated version with a new effective date at tan-aw.com/privacy-policy and, where appropriate, notify merchants. Continued use after the effective date constitutes acknowledgment of the updated Policy.

Related documents

Terms of ServiceThe agreement between Tan-aw and the businesses that subscribe to and use the platform.Read →Refund PolicyHow Tan-aw refunds the subscription fees merchants pay for the platform.Read →Data Processing AddendumThe controller–processor terms governing Tan-aw's processing of personal data on the merchant's behalf.Read →

Questions about this document?

Reach the Tan-aw team — we usually reply within two business days.

[email protected]

© 2026 Tan-aw Information Technology Services · DTI Business Name Reg. No. 8229411 · Selenia 208, Mirea Residences, Amang Rodriguez Avenue, Santolan, Pasig City

The platform that powers seamless order management.

Terms & ConditionsPrivacy PolicyRefund Policy

© 2026 Tan-aw Information Technology Services · Santolan, Pasig City · +63 917 114 4927 · [email protected]. All rights reserved.