Costarax is a closed B2B platform. We collect only the business information required to verify your company and operate the service. We do not sell your data, share it with third parties for advertising, or make it visible to other platform users including suppliers.
1. Who We Are
Costarax ("we", "us", "our") is a B2B procurement intelligence platform serving the Philippine foodservice industry. We operate under Philippine law, including the Data Privacy Act of 2012 (Republic Act No. 10173) and the implementing rules of the National Privacy Commission (NPC).
For privacy inquiries, contact us at: privacy@costarax.com
2. Information We Collect
We collect information in two ways: information you provide directly, and information generated automatically when you use the platform.
Information you provide:
- Business name, address, and type of business
- Business email address and contact name
- BIR/TIN number (used for identity and business verification only)
- Supporting documents you upload (BIR Certificate, DTI/SEC registration, Mayor's Permit, etc.)
- For suppliers: price lists and product catalog data you upload
- Messages and quote requests sent through the platform
Information collected automatically:
- Platform activity logs (searches, quote requests, page visits)
- Browser type, device type, and IP address
- Session timestamps and feature usage data
3. How We Use Your Information
- To verify your business identity against BIR/TIN records before granting platform access
- To operate and maintain your account on the platform
- To display your supplier profile and product catalog to verified buyers (suppliers only)
- To facilitate quote requests and replies between buyers and suppliers
- To send transactional emails (account approval, quote notifications, system alerts)
- To improve the platform through aggregated, anonymized usage analytics
- To comply with applicable laws and resolve disputes
We do not use your information for advertising, profiling for marketing purposes, or any automated decision-making that produces legal effects.
4. Information Sharing
We do not sell, rent, or trade your personal information. We share data only in the following limited circumstances:
- Between buyers and suppliers: When a buyer sends a quote request to a supplier, the buyer's business name and message content are shared with that supplier. No personal contact details are shared without your explicit action.
- Service providers: We use Supabase (database and file storage) and Vercel (hosting). These processors handle data under contractual data processing agreements and are not permitted to use your data for their own purposes.
- AI processing: Supplier price list content (product names and prices, no personal data) may be processed by Groq AI to extract and structure catalog data.
- Legal requirements: We may disclose information when required by Philippine law, court order, or to protect the rights and safety of Costarax or its users.
5. Data Storage and Security
Your data is stored on Supabase infrastructure. Supabase operates data centers in multiple regions. Data may be stored or processed outside of the Philippines. By using Costarax, you consent to this cross-border data transfer under the safeguards of the Data Privacy Act of 2012.
We implement appropriate technical and organisational security measures including:
- Encrypted connections (HTTPS/TLS) for all data in transit
- Row-level security policies restricting data access by user role
- Access tokens with short expiry periods
- Supplier price data visible only to verified buyers on the platform
6. Data Retention
- Account data: Retained for the duration of your active account, plus 2 years after account closure for dispute resolution purposes.
- Access request documents (BIR, DTI, etc.): Retained for 12 months from the date of submission, then securely deleted.
- Quote and message history: Retained for 2 years from the date of the transaction.
- Platform activity logs: Retained for 12 months and then purged.
7. Your Rights
Under the Data Privacy Act of 2012, you have the following rights regarding your personal information:
- Right to be informed: To know what personal data we hold about you and how it is processed.
- Right to access: To obtain a copy of your personal data held by Costarax.
- Right to rectification: To request correction of inaccurate or incomplete personal data.
- Right to erasure: To request deletion of your personal data, subject to legal retention obligations.
- Right to object: To object to the processing of your data on legitimate grounds.
- Right to data portability: To receive your data in a structured, machine-readable format.
- Right to lodge a complaint: To file a complaint with the National Privacy Commission (NPC) at privacy.gov.ph.
To exercise any of these rights, email us at privacy@costarax.com with the subject "Privacy Rights Request". We will respond within 15 business days as required by the NPC.
8. Cookies and Tracking
Costarax uses minimal browser storage:
- Session tokens: Stored in localStorage to keep you logged in. These expire automatically.
- Language preference: Stored in localStorage to remember your language setting.
We do not use third-party advertising cookies, tracking pixels, or analytics services that share data with third parties. We do not use Google Analytics or similar tools.
9. Minors
Costarax is a professional B2B platform. We do not knowingly collect personal information from individuals under 18 years of age. If you believe a minor has submitted information to us, please contact us immediately at privacy@costarax.com.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify active users by email and update the effective date above. Continued use of the platform after notification constitutes acceptance of the revised policy.
11. Contact Us