Skip to content

Privacy policy

Last updated 30 September 2026

Draft — pending legal review

These terms describe how we actually operate and are provided in good faith, but they have not yet been reviewed by a lawyer. If anything here matters to a decision you are making, please ask us and we will confirm it in writing.

What this covers

This explains what personal data WEBLAB-PH INFORMATION TECHNOLOGY SERVICES collects, why, and what you can do about it. It is written to the Philippine Data Privacy Act of 2012 (RA 10173).

WEBLAB-PH INFORMATION TECHNOLOGY SERVICES, STA. CRUZ, MANILA, is the personal information controller for the data described here.

Data Protection Officer

We have a designated Data Protection Officer. Questions about your personal data, requests under your rights below, and reports of a suspected breach go to support@weblab.ph.

What we collect, and why

We collect the minimum each purpose actually needs, rather than everything we could ask for.

  • Account details — your name and email address, so you can sign in and so we can contact you about your services.
  • Billing details — your billing name and address, because an invoice must carry them.
  • Registrant details — name, address, email and phone, if you register a domain. This is required by the registry, not by us. We pass it to the registrar, who passes it to the registry.
  • Sign-in records — IP address, browser and time, kept so we can show you your own active sessions and detect someone else using your account.
  • Support messages — what you send us, so we can answer it.
  • Partner payout details — only if you join the partner programme: your GCash number or bank account and the name on it, so we can pay your commission. Stored encrypted, shown to our staff only when they send a payout, and you are emailed whenever they change.

We never see or store your card details. Payments are handled on our payment provider's own hosted page; card numbers do not pass through our systems at all.

WHOIS and domain privacy

Registrant details for a domain are published in the public WHOIS record by default — that is a registry requirement rather than a choice we make. Where the extension supports it we enable WHOIS privacy, which substitutes a proxy contact so your home address is not in a public database.

Even with privacy enabled, the registry and registrar hold your real details, and can be compelled to disclose them in a dispute.

Who else sees your data

Only the parties who need it to deliver what you bought:

  • Our domain registrar, for registrations and renewals.
  • Our hosting and email provider, to create and run your services.
  • Our payment provider, to take payment.
  • Our email delivery provider, to send you invoices and notices.

We do not sell your data, and we do not share it for anyone else's advertising. We also disclose data where the law requires it, for example to comply with a court order or a lawful request from a government authority.

Data stored outside the Philippines

Most of the providers above operate outside the Philippines, so your data is transferred to and stored in other countries, including the United States and India, and our backups are held with a cloud storage provider abroad. Domain registrant details also go to the registry for the extension, wherever it is based.

We only use providers who protect the data under their own security and privacy commitments, and we remain responsible to you for data we transfer to them.

How long we keep it

  • Account and service data: while you have an account, and for up to one year after you close it, so we can answer billing or abuse questions about it.
  • Invoices and payment records: as long as Philippine tax law requires (currently at least ten years). We cannot delete these on request, and neither can anyone else. Partner payout records, including the account each payout was sent to, are kept on the same basis.
  • Audit and sign-in logs: up to two years, so we can investigate a security question later, which is the only reason they are useful.
  • Backups: data deleted from our systems can remain in our backups until those backups expire in the normal rotation, and is not restored from them except to recover from a failure.

Your rights

Under the Data Privacy Act you can ask us to:

  • tell you what we hold about you;
  • correct anything that is wrong;
  • give you a copy in a portable format;
  • delete what we are not legally required to keep;
  • object to a particular use.

Email our Data Protection Officer at support@weblab.ph and we will respond. If you are not satisfied, you can complain to the National Privacy Commission.

Security

Passwords are stored hashed and are not readable by us or by anyone else. Two-factor authentication is available on every account and required for staff. Provider credentials and secrets are never written to logs, never stored in the database in plaintext, and never sent to the browser.

If a breach puts your personal data at real risk, we will notify you and the National Privacy Commission within 72 hours of learning of it, as the law requires.

Cookies

We use the cookies the site needs to work: one to keep you signed in, and one to protect forms against cross-site request forgery. There is no advertising or cross-site tracking here, which is why there is no consent banner — there is nothing to consent to.

Questions about this document? Contact us.