Privacy Policy
What personal information Resibo holds, why, who can see it, and how long it stays.
Version 0.1 · In effect August 25, 2026
1. Who is responsible, and for what
Tri-Point Axis operates Resibo and is responsible for the information described here. This policy is written under the Data Privacy Act of 2012 (Republic Act 10173) and its implementing rules.
We wear two different hats, and it matters which one applies to you.
- For sellers, we are the personal information controller. Your account, your BIR profile and your billing are ours to answer for.
- For your buyers, you are the controller and we are your processor. We hold what your marketplace hands us about a buyer only so we can produce your invoice. If you bought something from a seller who uses Resibo, section 11 tells you where to go.
2. What we hold about a seller
| What | Examples |
|---|---|
| Account | Name, email address, password (stored hashed, never in readable form) |
| BIR profile | TIN, registered taxpayer name, registered address, tax type, taxpayer classification |
| Business | Trading name, the marketplace accounts you connect |
| Subscription | Plan, usage against it, invoices we issue to you |
| Marketplace access | The access tokens your consent produces, stored encrypted and never shown to anyone |
| Usage | Sign-in events, sync runs, errors, and the actions taken in your account |
The BIR profile is the sensitive part of this list. It is required because it prints on every invoice we generate for you, and it is why the product asks for it before it will do anything else.
3. What we hold about a buyer
When we read a seller's orders, an order carries whatever the marketplace chooses to give us about the person who bought. In practice that is a name, sometimes masked, and occasionally a delivery address. Shopee, TikTok Shop and Lazada all mask or withhold most buyer identity as their own privacy compliance, and we take what is left rather than trying to get around it.
We use it for one thing: putting the buyer fields on an invoice, which the tax rules require. We do not build profiles of buyers, we do not market to them, and we never sell any of it.
4. Where it comes from
- From you, when you sign up, fill in your BIR profile, invite someone or write to us.
- From the marketplaces you connect, once you have authorised them, and only within the scope that authorisation grants.
- From a file you import yourself, when you have no API access to a marketplace.
- From our own systems, which record what happened in your account.
5. Why we process it
| Purpose | Basis under the Data Privacy Act |
|---|---|
| Running your account and producing your invoices | Necessary to perform our contract with you |
| Producing and keeping records the tax rules require | Compliance with a legal obligation |
| Billing you, and collecting what is owed | Necessary to perform our contract |
| Keeping the service secure, and investigating misuse | Our legitimate interests, weighed against yours |
| Support, and telling you about changes that affect you | Legitimate interests |
| Marketing email about Resibo | Your consent, given separately and withdrawable |
6. Who can see it inside Resibo
Access is restricted by the database itself rather than by a promise in a document: every table is protected by row-level security scoped to the signed-in user, so one seller's data is not reachable from another seller's session.
Our own staff can read seller data through an internal admin application, which exists for support and oversight. Three things constrain it, and all three are enforced in code:
- Every administrator signs in with a password and a second factor. There is no exemption for any role, and no administrator can sign up: an account exists only because another administrator created it.
- Buyer personal information is never included in an ordinary list or search. Reading it requires a deliberate action that demands a stated reason, and the audit entry is written before the data is returned.
- Exporting a seller's data re-asks for the administrator's password, however recently they signed in, and is recorded.
No member of staff can sign in as you, change your email or reset your password from the inside.
8. Processing outside the Philippines
Some of the providers on the subprocessors page store or process data outside the Philippines. Where that happens we require contractual protection consistent with the Data Privacy Act, and we remain accountable for the data regardless of where it sits.
9. How long it stays, and the part where nothing is deleted
An issued invoice is a tax record and is retained for the period tax law requires. In practice this means the invoice archive is permanent from your point of view: closing your account does not remove it, and neither does asking us to.
| What | How long |
|---|---|
| Issued invoices and the order data behind them | The retention period tax law sets |
| Audit records of internal access | Kept, because a log that can be deleted is not a log |
| Account and profile data | While the account is open, then only what the invoice archive depends on |
| Marketplace access tokens | Until you withdraw the authorisation or ask us to remove them |
| Marketing contact details | Until you unsubscribe |
We would rather state this bluntly than let it be discovered later. If a permanent archive is a problem for you, it is a problem to raise before connecting a shop.
10. How it is protected
- Marketplace access tokens are encrypted before they are stored, and the key is never held in the database with them.
- Data is separated per account by row-level security in the database, not by application code that could forget.
- Administrator accounts require two factor authentication, with no exceptions.
- Sensitive administrator actions are audited, and the audit cannot be written or altered from a browser.
- Traffic is encrypted in transit.
No system is perfect. If we become aware of a breach that affects you, we will tell you and the National Privacy Commission as the law requires.
11. Your rights
Under the Data Privacy Act you may ask to be told what we hold, to get a copy of it, to have it corrected, to object to certain processing, and to complain. The data request page explains how to ask and what happens next.
The right to erasure is real but limited here, and we would rather be clear than encouraging: we cannot delete an invoice that tax law requires us to keep. Everything outside that archive is a different matter and we will act on it.
If you are a buyer rather than a seller, the seller you bought from is the controller of your information. Write to them first. If they use Resibo and need our help to answer you, we will give it.
You can also complain to the National Privacy Commission. We would rather you wrote to us at privacy@resibo.ph first, but that is your choice and not a precondition.
12. Marketing email
Marketing consent is asked separately and is never bundled into anything else. Booking a demo does not subscribe you: the opt-in is its own checkbox and it starts unticked.
When you do opt in, your name and email address are added to a contact list held by our email provider, named on the subprocessors page. Every message carries an unsubscribe link, and unsubscribing removes you from that list.
Email we send because you have an account, a sync failed, an invoice was issued, your plan is about to renew, is not marketing and is not covered by that consent.
14. Children
Resibo is a product for registered businesses and is not directed at children. We do not knowingly collect information from a child.
15. Changes to this policy
This policy carries a version and an effective date at the top. A change that affects what we do with your information is announced rather than made quietly, and the version is bumped.
16. Reaching us
Privacy questions and data requests go to privacy@resibo.ph. Our registered details are on the contact page.