RAM-YUM Korean and Japanese Store Privacy Policy
This Privacy Policy explains how RAM-YUM Korean and Japanese Store processes personal information through its financial management system. It should be read with applicable Philippine privacy laws and is not a certification of compliance.
1. Introduction
RAM-YUM Korean and Japanese Store is committed to protecting personal information processed through the system. Processing is intended to follow transparency, legitimate purpose, proportionality, and other applicable requirements of the Philippine Data Privacy Act of 2012.
Source: National Privacy Commission.
Republic Act No. 10173 – Data Privacy Act of 2012
2. Information We Collect
Based on the current RAM-YUM Korean and Japanese Store implementation, the system may process:
- Username, display name, email address, assigned role, and department.
- A password hash for authentication; RAM-YUM Korean and Japanese Store does not store a plain-text password.
- Google OAuth subject identifier, verified email used for account matching, and optional profile-picture URL.
- Financial and administrative records entered by authorized users, including ledger, payables, receivables, disbursements, collections, budgets, cash, tax, inventory, and COGS records.
- PHP session data and local browser device-trust/session values used for authentication and security.
RAM-YUM Korean and Japanese Store does not request or store a Google password. The system does not currently provide a public registration form.
Source: National Privacy Commission. Official text
3. Purpose of Processing
Information is processed for account authentication and authorization, role-based user management, authorized financial and administrative operations, reporting, security, audit-related administration, and maintenance. Financial summaries may be used by the AI Assistant when a user chooses that feature.
Processing must have an appropriate lawful basis under applicable law. Depending on the activity, that basis may include consent, contract-related necessity, legal obligation, or legitimate interests; consent is not asserted as the basis for every activity.
Source: National Privacy Commission. Official text
4. Data Accuracy and Minimization
Users should provide accurate and current information and correct information that is no longer accurate. RAM-YUM Korean and Japanese Store is intended to process information that is adequate, relevant, and not excessive for the declared purpose.
Source: National Privacy Commission. Official text
5. Data Retention
RAM-YUM Korean and Japanese Store does not currently declare a fixed retention period in its application configuration. Records should be retained only as long as necessary for their declared purposes, legitimate business purposes, legal claims, or as otherwise provided by law. The organization should establish and document an appropriate retention and secure-disposal schedule.
Source: National Privacy Commission. Official IRR
6. Data Security
Controls visible in RAM-YUM Korean and Japanese Store include password hashing, PHP sessions with HttpOnly and SameSite settings, session ID regeneration, server-side authentication and role authorization, prepared SQL statements, API input sanitization, restricted environment-file access, and server-side protection of AI and Google OAuth secrets through configuration. These controls are not a guarantee of security and should be reviewed and maintained.
Source: National Privacy Commission. Official IRR
7. Data Subject Rights
Subject to applicable conditions, limitations, and lawful grounds, data subjects may have the right to be informed, access their personal information, dispute and correct inaccurate information, object to processing, request erasure or blocking where applicable, seek data portability where applicable, and seek damages where provided by law. A data subject may also lodge a complaint with the National Privacy Commission. Requests should be made through the configured privacy contact; identity verification and lawful retention may apply.
Source: National Privacy Commission. Official IRR
8. Google/Gmail Authentication
Google OAuth requests OpenID, email, and profile scopes and may provide a subject identifier, email, verification status, token expiry, and optional profile-picture URL. RAM-YUM Korean and Japanese Store does not request or store a Google password. The client ID, client secret, and redirect URI are configuration-based. The server exchanges the authorization code, validates the issuer, audience, verified email, and expiry, then establishes a PHP session.
9. AI Assistant
When used, the AI Assistant sends a financial snapshot containing counts and totals for ledger, payables, receivables, disbursements, collections, budgets, inventory, COGS, and revenue to the configured AI service. Chat mode also sends the user’s chat message and limited chat history. The snapshot does not include passwords, password hashes, database credentials, OAuth secrets, session IDs, or API keys. Users should avoid entering unnecessary personal or confidential information in chat.
10. Third-Party Services
RAM-YUM Korean and Japanese Store currently uses Google OAuth for optional authentication and a configured AI service for the AI Assistant. These services may process information under their own terms and privacy policies.
11. Data Sharing
RAM-YUM Korean and Japanese Store may disclose information to Google only as needed for the features described above, and may disclose information where authorized or required by law. The organization remains responsible for information under its control or custody and should maintain appropriate safeguards for transfers and processors.
Source: National Privacy Commission. Official IRR
12. Privacy Contact
No privacy contact has been configured yet. Please ask the system administrator for the designated privacy contact.
Contact details are configuration-driven and are not displayed unless supplied by the organization.
Official References
- Republic Act No. 10173 – Data Privacy Act of 2012
- Implementing Rules and Regulations of RA 10173
- NPC: The Data Privacy Act and its IRR
Legal notice: This page is a privacy and security improvement aligned with RA 10173 and applicable NPC guidance. It should be reviewed by the organization’s privacy officer or legal counsel.
