Legal

Privacy Policy

Effective 24 April 2026

This policy explains what Ruleer collects, why we collect it, who we share it with, and the rights you have over your information. We operate in the Philippines and comply with the Data Privacy Act of 2012 (RA 10173).

§1

Who we are

Ruleer is operated by its founder, Berl Treasure F. Campomanes, Manila, Philippines. For purposes of the Data Privacy Act, Ruleer acts as the Personal Information Controller for the account and usage data described below, and as the Personal Information Processor for the project, payroll, and BIR records your organization uploads.
§2

What we collect

We collect the following categories of information:

  • Account data — name, email address, avatar URL, and organization role. This comes from Google when you sign in with OAuth.
  • Organization data — company name, membership list, and the role each member holds.
  • Operational records — projects, purchase orders, invoices, payroll runs, expense entries, inventory movements, and BIR/SSS/PhilHealth/ Pag-IBIG-related records that you or your team create inside Ruleer.
  • Usage data— request logs, error reports, and feature-usage metrics used to keep the service healthy and improve it over time. We don’t sell this data.
  • Device and session — IP address, user agent, and cookie/session tokens required for authentication and CSRF protection.
§3

Why we collect it

  • Provide the service — authenticate you, render your organization’s data, and run the workflows you configure.
  • Billing and support — communicate about your plan, invoices, and any issues you raise.
  • Security and abuse prevention — detect suspicious activity, rate-limit bad actors, and preserve audit trails.
  • Product improvement — understand which features help teams ship work and which get in the way.
  • Legal compliance — retain records where Philippine law (including BIR and labor-related requirements) obliges us to.
§4

Who we share it with

We share personal information only with vetted service providers that help us run Ruleer, each under contractual data-protection obligations:

  • Google — OAuth sign-in and identity.
  • Supabase — managed Postgres database, authentication, and file storage.
  • Vercel — application hosting and edge delivery.
  • Email provider — transactional email for sign-in confirmations, receipts, and notifications.

We do not sell personal data. We don’t share your records with other tenants, and we enforce tenant isolation at the database level with row-level security.

§5

How we secure it

We use TLS for data in transit and encryption at rest for stored data. Access to production systems is limited to authorized personnel, and every change to operational records leaves an audit trail inside Ruleer. We apply the principle of least privilege to every system that touches your data.

No system is perfectly secure, so we also commit to notifying affected users promptly — and the National Privacy Commission where required — in the event of a breach that could cause real risk to you.

§6

How long we keep it

We retain your account and operational data for as long as your organization is active on Ruleer. If you delete your organization, we remove operational records within 30 days, except where Philippine law requires longer retention (for example, BIR recordkeeping rules for books of account and supporting documents).

Backups are encrypted and cycled out on a rolling basis — usually within 35 days of the deletion date.

§7

Your rights under the Data Privacy Act

As a data subject you have the right to:

  • Be informed about how we process your data.
  • Access the data we hold about you.
  • Objectto processing that isn’t necessary for the service or required by law.
  • Request erasure or blockingof data that’s inaccurate, outdated, or unlawfully obtained.
  • Request rectification of inaccuracies.
  • Request data portabilityof information you’ve provided, in a commonly used format.
  • File a complaint with the National Privacy Commission.

To exercise any of these rights, email us — see Contact below.

§8

Cookies and similar technologies

Ruleer uses strictly necessary cookies for authentication, CSRF protection, and remembering your selected organization. We don’t use advertising cookies or third-party behavioral trackers. A small amount of first-party analytics may be used to measure page performance and error rates.
§9

International transfers

Our infrastructure partners (Google, Supabase, Vercel) may process data in regions outside the Philippines. Where that happens, we rely on industry-standard data-transfer mechanisms and on each provider’s own privacy commitments. Your data remains tenant-isolated regardless of the hosting region.
§10

Children

Ruleer is a business tool for contractors; it isn’t intended for use by anyone under 18. We do not knowingly collect personal information from minors.
§11

Changes to this policy

When we update this policy, we’ll change the Effective Date above and, for material changes, notify you in the app or by email. Continuing to use Ruleer after the change means you accept the updated policy.
§12

Contact

To exercise your rights, request a record, or ask a privacy-related question, reach our Data Protection Officer:

You can also file a complaint with the National Privacy Commission if you believe we’ve mishandled your data.

Your data, your organization, your people.Read the Terms