RAM-YUM Korean and Japanese Store logoRAM-YUM Korean and Japanese Store
Privacy PolicyTerms & Conditions
Data protection notice

RAM-YUM Korean and Japanese Store Privacy Policy

Effective Date: August 23, 2026   Version: 1.0

This Privacy Policy explains how RAM-YUM Korean and Japanese Store processes personal information through its financial management system. It should be read with applicable Philippine privacy laws and is not a certification of compliance.

1. Introduction

RAM-YUM Korean and Japanese Store is committed to protecting personal information processed through the system. Processing is intended to follow transparency, legitimate purpose, proportionality, and other applicable requirements of the Philippine Data Privacy Act of 2012.

Legal Reference: Republic Act No. 10173, Sections 1–2.
Source: National Privacy Commission.
Republic Act No. 10173 – Data Privacy Act of 2012

2. Information We Collect

Based on the current RAM-YUM Korean and Japanese Store implementation, the system may process:

  • Username, display name, email address, assigned role, and department.
  • A password hash for authentication; RAM-YUM Korean and Japanese Store does not store a plain-text password.
  • Google OAuth subject identifier, verified email used for account matching, and optional profile-picture URL.
  • Financial and administrative records entered by authorized users, including ledger, payables, receivables, disbursements, collections, budgets, cash, tax, inventory, and COGS records.
  • PHP session data and local browser device-trust/session values used for authentication and security.

RAM-YUM Korean and Japanese Store does not request or store a Google password. The system does not currently provide a public registration form.

Legal Reference: Republic Act No. 10173, Section 3 – Definitions.
Source: National Privacy Commission. Official text

3. Purpose of Processing

Information is processed for account authentication and authorization, role-based user management, authorized financial and administrative operations, reporting, security, audit-related administration, and maintenance. Financial summaries may be used by the AI Assistant when a user chooses that feature.

Processing must have an appropriate lawful basis under applicable law. Depending on the activity, that basis may include consent, contract-related necessity, legal obligation, or legitimate interests; consent is not asserted as the basis for every activity.

Legal Reference: Republic Act No. 10173, Sections 11–12.
Source: National Privacy Commission. Official text

4. Data Accuracy and Minimization

Users should provide accurate and current information and correct information that is no longer accurate. RAM-YUM Korean and Japanese Store is intended to process information that is adequate, relevant, and not excessive for the declared purpose.

Legal Reference: Republic Act No. 10173, Section 11(a)–(d).
Source: National Privacy Commission. Official text

5. Data Retention

RAM-YUM Korean and Japanese Store does not currently declare a fixed retention period in its application configuration. Records should be retained only as long as necessary for their declared purposes, legitimate business purposes, legal claims, or as otherwise provided by law. The organization should establish and document an appropriate retention and secure-disposal schedule.

Legal Reference: Republic Act No. 10173, Section 11(e)–(f); NPC Implementing Rules and Regulations, Rule IV, Section 19.
Source: National Privacy Commission. Official IRR

6. Data Security

Controls visible in RAM-YUM Korean and Japanese Store include password hashing, PHP sessions with HttpOnly and SameSite settings, session ID regeneration, server-side authentication and role authorization, prepared SQL statements, API input sanitization, restricted environment-file access, and server-side protection of AI and Google OAuth secrets through configuration. These controls are not a guarantee of security and should be reviewed and maintained.

Legal Reference: Republic Act No. 10173, Section 20; NPC Implementing Rules and Regulations, Rule VI, Sections 25–29.
Source: National Privacy Commission. Official IRR

7. Data Subject Rights

Subject to applicable conditions, limitations, and lawful grounds, data subjects may have the right to be informed, access their personal information, dispute and correct inaccurate information, object to processing, request erasure or blocking where applicable, seek data portability where applicable, and seek damages where provided by law. A data subject may also lodge a complaint with the National Privacy Commission. Requests should be made through the configured privacy contact; identity verification and lawful retention may apply.

Legal Reference: Republic Act No. 10173, Sections 16–19; NPC Implementing Rules and Regulations, Rule VIII, Sections 34–37.
Source: National Privacy Commission. Official IRR

8. Google/Gmail Authentication

Google OAuth requests OpenID, email, and profile scopes and may provide a subject identifier, email, verification status, token expiry, and optional profile-picture URL. RAM-YUM Korean and Japanese Store does not request or store a Google password. The client ID, client secret, and redirect URI are configuration-based. The server exchanges the authorization code, validates the issuer, audience, verified email, and expiry, then establishes a PHP session.

9. AI Assistant

When used, the AI Assistant sends a financial snapshot containing counts and totals for ledger, payables, receivables, disbursements, collections, budgets, inventory, COGS, and revenue to the configured AI service. Chat mode also sends the user’s chat message and limited chat history. The snapshot does not include passwords, password hashes, database credentials, OAuth secrets, session IDs, or API keys. Users should avoid entering unnecessary personal or confidential information in chat.

Important: AI output is an operational aid, not a financial, legal, tax, or employment decision. Review it before relying on it.

10. Third-Party Services

RAM-YUM Korean and Japanese Store currently uses Google OAuth for optional authentication and a configured AI service for the AI Assistant. These services may process information under their own terms and privacy policies.

11. Data Sharing

RAM-YUM Korean and Japanese Store may disclose information to Google only as needed for the features described above, and may disclose information where authorized or required by law. The organization remains responsible for information under its control or custody and should maintain appropriate safeguards for transfers and processors.

Legal Reference: Republic Act No. 10173, Sections 11–13 and 20–21; NPC Implementing Rules and Regulations, Rule IV, Section 20 and Rule X.
Source: National Privacy Commission. Official IRR

12. Privacy Contact

RAM-YUM AI-Driven Financial Management System
No privacy contact has been configured yet. Please ask the system administrator for the designated privacy contact.

Contact details are configuration-driven and are not displayed unless supplied by the organization.

Official References

  • Republic Act No. 10173 – Data Privacy Act of 2012
  • Implementing Rules and Regulations of RA 10173
  • NPC: The Data Privacy Act and its IRR

Legal notice: This page is a privacy and security improvement aligned with RA 10173 and applicable NPC guidance. It should be reviewed by the organization’s privacy officer or legal counsel.

Next
RAM-YUM AI-Driven Financial Management SystemPrivacy Policy · Terms & Conditions