Storagerack PH← Back to the store

Republic Act 10173 — Data Privacy Act of 2012

Privacy notice

In plain language: we take your name, number, and address so we can build your rack and bring it to your door. We keep the order as part of our books because tax rules say we must. We don’t sell your details to anybody, we set no advertising cookies, and we don’t text you promos unless you ticked the box asking us to.

Effective 12 August 2026 · Last updated 12 August 2026

1. Who is responsible for your data

JVT Corporation is a corporation registered in the Philippines with the Securities and Exchange Commission. StorageRack PH is a brand of JVT Corporation — the store you are buying from is operated by that company, and that company is the one accountable for your data.

Under the Data Privacy Act, JVT Corporation is the Personal Information Controller for everything described on this page: we decide what is collected and what happens to it, and we answer for it. Our designated Data Protection Officer is reachable at the address below — you do not need a name, the role receives the mail.

jvtcorp20@gmail.comPut “Privacy request” in the subject line. We acknowledge promptly and answer within 15 working days. If a request is complicated enough that we need longer, we will tell you that and explain why, within the same 15 days.


2. What we collect, why, and our lawful basis

We only ask for what an order actually needs. Nothing on this site requires an account, and there is nothing to sign up for.

WhatWhy we need itLawful basis
Your nameSo we know who to greet when we call, and whose rack it is on the workshop floor.Contract
Mobile numberTo confirm your final quote, tell you when the rack is done, and coordinate the delivery. This is how we reach you — that is why it is required.Contract
Email (optional)A backup way to reach you and to send a written copy of the quote. Leave it blank and nothing breaks.Contract
Delivery address and cityTo compute your delivery fee and to actually deliver the rack.Contract
Your rack specification and the priceHeight, width, depth, layers, quantity, powder coat, and your notes — this is the thing we build. We also store the price we quoted and which rate card it came from, so the number cannot change on you after the fact.Contract
Anything you type into the notes boxFree text you choose to add — access instructions, a landmark, a special request. Please keep it to that; see the request below this table.Contract
Your privacy acknowledgement and marketing preferenceThe date and time you confirmed this notice was shown to you, and whether you ticked the optional marketing box. We keep this so we can prove what you were told and what you chose — including proving that we were never permitted to send you promos.Legal obligation / consent (marketing only)
Problem reportsIf you report a fault with the site or an order, we keep what you told us and any contact detail you left, so we can fix it and get back to you.Legitimate interests
Order and delivery recordsKept as our books of accounts. Philippine tax rules require a business to preserve its records of sale — see section 7.Legal obligation
Website and security dataOur hosting automatically records technical information about requests — IP address, time, the page requested, browser and device type, referring page — to serve the site, keep it up, and detect abuse. See section 4.Legitimate interests

Ticking the box is not consent to processing. The required checkbox at checkout only records that this notice was put in front of you before you ordered. We build and deliver your rack because you asked us to — that is a contract — and we keep the sale on file because the law tells us to. Neither of those depends on the box, and unticking it later does not undo an order you placed.

Marketing is different. The second checkbox is separate, optional, and unticked by default. That one really is consent, and you can withdraw it at any time — see section 9. Withdrawing it stops future marketing; it does not affect your order, and it does not make the messages we already sent unlawful.

Please don’t put sensitive data in the notes box. We do not need — and do not want — ID numbers, bank or card details, health information, or anything similar. If you send it anyway, we will delete it from the order when we notice it.


3. How we obtain your data

Directly from you, when you fill in the order form, report a problem, or message or call us afterwards.

From someone ordering on your behalf. If a person orders a rack to be delivered to you, they give us your name, number, and address. If you are that person: please tell the recipient that you gave us their details, and point them at this page. They have the same rights over their data as you do.

Automatically, from your browser and our infrastructure when you load the site — the technical and security data described in section 4.


4. Analytics and cookies

We set no advertising cookies, no tracking pixels, and no advertising profiles. We do not use Meta Pixel, Google Ads tags, or anything of that kind. If that ever changes, this page changes first.

We use Vercel Web Analytics to count visits and see which pages are used. It is cookieless: instead of a cookie, a visitor is recognised by a hash derived from the incoming request. Per Vercel’s published documentation that hash is valid for a single day and is then automatically reset, and the visitor session is not stored permanently but discarded after 24 hours — which is why a returning visitor cannot be recognised from one day to the next, or across other websites. Vercel documents that each data point may include the event timestamp, the URL and dynamic path, the referrer, filtered query parameters, an approximate geolocation (country, region, city), device operating system and version, browser and version, device type, and the analytics script version. It is aggregate reporting — it does not tell us who you are, and it is not joined to your order.

We keep personal data out of URLs, query parameters, and analytics events by design, so it does not end up in analytics in the first place.

The only cookie this site sets is the admin sign-in cookie, which exists so the shop owner can stay signed in to the order screen. It is strictly necessary, it is never set for customers, and it does nothing on the storefront.

Separately from analytics, our host keeps hosting and security logs of requests. These record details such as the request path and method, the response status, your browser’s user agent, and the region the request came from. Your IP address is processed by our host in handling the request, though it is not one of the fields the logs expose to us. They are operational records, not a marketing tool.


5. Who else sees your data

We do not sell, rent, or trade your personal data. Ever. It is shared only with:

  • Vercel Inc. — hosts this website and runs its analytics. Handles the request and log data in section 4.
  • Neon — the managed Postgres service where the order database lives. Holds your order record.
  • Delivery personnel and delivery providers — receive the name, number, and address needed to bring the rack to you, and nothing more.
  • Professional advisers — our accountant or lawyer, where they need to see records to do their job.
  • Government authorities — where we are legally required to disclose, such as to the BIR in a tax examination, or under a valid legal order.

Service providers act on our instructions and are bound to use the data only to provide the service they were engaged for.

We do not collect payment credentials today. This site takes no card numbers, no e-wallet credentials, and no bank details — payment is arranged directly with you after we confirm your order. Before we ever switch on online payment, we will update this notice and the checkout to name the payment processor and say exactly what it receives.


6. Processing outside the Philippines

Our hosting and database providers operate internationally, so your data is processed on servers outside the Philippines.

Sending data abroad does not reduce our responsibility for it: under the Data Privacy Act we remain accountable for personal data transferred to a processor, wherever that processor runs. We rely on the providers’ published data-processing terms, which cover confidentiality, security, use of sub-processors, and handling of any breach. Where the National Privacy Commission’s guidance on cross-border transfers applies — including NPC Advisory No. 2024-01 on contractual clauses — we work to those terms.


7. How long we keep it

WhatHow long
Completed orders and their delivery recordsFive years, as our books of accounts and supporting records. Under current BIR rules the clock runs from the day following the deadline for filing the relevant return — or from the actual filing date if we filed after the deadline — for the tax year in which the last entry was made. It runs longer if a tax protest, a refund or credit claim, an examination, or another law requires it. Because it is tied to tax filings rather than to your order date, we cannot promise to erase an order exactly five years after you placed it.
Quotes and orders that never completedUp to 12 months from the last activity, then deleted.
Messages about an orderUp to 2 years after the order is finished, so we can answer a later question or a warranty claim.
Marketing subscriptionUntil you withdraw it. After that we keep a minimal suppression record — enough to remember not to contact you again.
Problem reportsUntil resolved, then up to 90 days.
Hosting and security logsKept by our host for the short period its plan provides — no more than 30 days — then aged out automatically.
Website analyticsAggregate reporting only. Our plan guarantees us a 12-month reporting window; our provider documents that it may hold the data longer than that, so we state this as the period we can see, not as a promise that it is erased on the 366th day. The daily hash and the 24-hour visitor session in section 4 are separate and much shorter.
BackupsTwo layers. Our database provider keeps a rolling 7-day restore window. Separately, a nightly copy is taken and the 30 most recent are retained, on our own machine and in our offsite storage. Deleted data therefore persists in backups for a short period after deletion, and ages out with the backup that holds it.

When a period ends, the data is deleted or anonymised. If a legal hold, a dispute, or a tax examination applies, we keep what is needed for that and no more, and resume normal deletion afterwards.


8. Security

We describe only the controls we actually have. The site runs over HTTPS. The order screen is behind a password held by the owner. The database is a managed service with access restricted to the application and the owner. Backups run nightly to storage only we can reach, and we have tested restoring one. The order code you receive (SR-1234) is not derived from anything personal, and we do not publish customer details anywhere.

We are a small business and we would rather be honest about that than list controls we have not built. Improving this is ongoing work.

If a personal data breach ever creates a real risk of serious harm to you, we will notify you and the National Privacy Commission within 72 hours of knowing, as the law requires. We would rather tell you ourselves than have you find out some other way.


9. Your rights, and how to complain

Under the Data Privacy Act you have the right to:

  • Be informed — which is what this page is for.
  • Access a copy of the personal data we hold about you.
  • Correct anything inaccurate or out of date.
  • Object to processing, including marketing.
  • Erasure or blocking, where the grounds in the law apply.
  • Data portability, for data processed by electronic means.
  • Damages, where you suffered them through a violation.
  • Lodge a complaint with the National Privacy Commission.

To exercise any of these, email jvtcorp20@gmail.com with “Privacy request” in the subject. We may ask you to confirm your identity — proportionately, using something you already gave us, such as the mobile number on the order. We will not demand more identification than the request warrants, and we will never ask you to send a photo of a government ID for a routine request.

These rights are not absolute. Erasure, objection, and portability each have limits set by the Data Privacy Act, and they do not override a separate legal duty — most often our obligation to keep tax records (section 7). Where we cannot fully act on a request, we will tell you which part we cannot do and why.

To stop marketing, reply STOP to any message, or email jvtcorp20@gmail.com. We stop, no questions asked, and it does not affect your order.

Complaints. Please raise it with us first — write to jvtcorp20@gmail.com and give us a chance to put it right. The National Privacy Commission’s rules of procedure also normally expect a data subject to bring the matter to the business in writing and allow it a reasonable period to respond before filing a complaint, though the Commission can excuse that requirement in appropriate cases. You are always free to go to the NPC — see privacy.gov.ph for its current complaint procedure.


10. Children

This is a steel fabrication business and the site is not aimed at children. We do not knowingly collect data from anyone under 18 and orders should be placed by adults. If a child’s details reached us by accident, email jvtcorp20@gmail.com and we will remove them from anything we are not legally required to keep — noting that where an order was actually fulfilled, the tax-record duty in section 7 still applies to that record.


11. Automated decisions and profiling

We make no automated decisions that produce legal effects on you or similarly significantly affect you, and we do not profile you. The price the configurator shows is a calculation from the dimensions you entered against our published rate card — it is a price display, not a decision about you — and every order is reviewed by a person before we build anything.


12. Changes to this notice

This version is effective 12 August 2026. When something changes how your data is handled — online payment being the next one — we update this page before the change goes live, not after. We do not quietly rewrite it.

Where a change is material, we will say so prominently at the point where we collect your data, and where the law requires your consent for the change, we will ask for it rather than assume it. Dated earlier versions of this notice are kept and are available on request from jvtcorp20@gmail.com.