Skip to content

Privacy Policy

Plain language on purpose. Last updated June 29, 2026.

The short version

We collect only what Riri needs to run your business workspace. Your business data belongs to you; your customers', patients', and employees' data belongs to them. We sell data to no one, and we process it only to provide the service to you.

Who we are, and your privacy rights

Riri is operated by Rangtay Tawo OPC, based in Laguna, Philippines. We act as a data PROCESSOR for the personal data your business puts into Riri (your customers, patients, and employees) and as a data CONTROLLER for your own account data. We comply with the Data Privacy Act of 2012 (RA 10173) and its implementing rules. Our Data Protection Officer can be reached at dpo@rangtaw.com.

What we collect

Your account email and password (passwords are hashed — we never see them); the business information you enter; and the operational records your business creates: products, sales, bookings, customers, suppliers, and accounting/ledger records. Depending on the modules you turn on, this can include sensitive personal information you enter — clinic patient records, employee payroll and government-ID numbers (SSS, PhilHealth, Pag-IBIG, TIN), and tax records. We collect only what each module needs to function.

Patient records are consent-first

Clinic patient records are built around RA 10173: your clinic accepts a Data Processing Agreement before real-patient mode unlocks, consent is recorded before records are kept, edits are soft-deleted with a full audit trail, and access is limited to your clinic's own staff. Our team does not browse your records; access for support happens only with your explicit permission.

Employee and payroll data

If you use payroll, the compensation, contributions, and government-ID numbers (SSS, PhilHealth, Pag-IBIG, TIN) you enter for your employees are sensitive personal information. You are responsible for having a lawful basis to process your employees' data and for informing them; Riri processes it solely on your instruction, to run payroll and produce your statutory filings. Payroll records are access-restricted to authorized payroll roles, isolated per business, and retained only as the law requires (see Retention).

Tax and accounting records

Riri can generate working-draft BIR forms (VAT returns, summary lists, journals) and accounting statements from the books you keep in the product. These contain financial data and tax identification numbers. Riri is not a BIR-accredited Computerized Accounting System and does not file on your behalf — draft outputs are for your accountant to review before filing. We retain these records for the period Philippine tax law requires (see Retention).

Where your data lives, and who helps us run it

Your data is stored in a managed database in Singapore, isolated per business at the database level and encrypted in transit and at rest, and backed up before every system change. To run the service we rely on a small set of sub-processors, each bound to protect your data: Supabase (database and authentication hosting, Singapore region), Vercel (application hosting and content delivery), Resend (outbound transactional email), and Cloudflare (DNS and email routing). We do not use advertising or third-party analytics processors. We will tell you before adding a sub-processor that materially changes how your data is handled.

How long we keep it

While your workspace is active, we keep your data for as long as you need it to run your business — we do not delete your live records out from under you. Retention periods apply when you DELETE your workspace: at that point we delete your operational data (sales, inventory, customers, bookings, and the like) promptly, keeping only the records the law requires us to retain — tax and accounting records (including BIR records) for 10 years, and payroll and labor records for 5 years. Those legally-retained records are isolated, access-restricted, and permanently purged once their retention period lapses.

Cookies

Riri uses only the cookies needed to keep you logged in. No advertising trackers, no third-party analytics cookies on the app.

Your rights

Under RA 10173, you — and the people whose data you hold — have the rights to be informed, to access, to correct, to object, to erasure or blocking, to data portability, to lodge a complaint with the National Privacy Commission, and to damages for a violation. In the product you can export your data as CSV any time, correct it inline, and leave with it. To exercise any right, or to ask a privacy question, contact our DPO at dpo@rangtaw.com or support@rangtaw.com, and a real person will answer.

If something goes wrong

If a personal-data breach occurs that is likely to put affected individuals at real risk, we will notify the National Privacy Commission and the affected parties within the timeframe RA 10173 requires (within 72 hours of knowing about the breach), and we will tell you promptly so you can meet your own obligations.

Changes

If this policy changes in a way that matters, we will tell you inside the product before it takes effect, and update the date below.