Skip to content
Kabesera Café

Legal

Privacy notice

Data Privacy Act of 2012 (R.A. 10173) and its 2016 IRR. We keep what we need to seat you, pay you, write the farm on the ticket, and answer you when you ask.

Updated 18 August 2026

This notice is for guests of Kabesera Café and Kabesera Bed & Coffee (together, “Kabesera”, “the house”). It is written for the Philippine Data Privacy Act. European guests receive the same rights we publish on Privacy rights. This is a house notice, not a lawyer’s opinion — counsel should still stamp it before a public launch.

1. Who we are

Personal information controller: Kabesera Café / Kabesera Bed & Coffee, Eastridge Village (Block 2–3, San Roque, Angono and the Bed & Coffee side, Golf Courses, Binangonan), Rizal, Philippines.

Public desk: cafe@kabesera.com · 0966 762 5352.

Bookings, reservations, shop, sales, member activity, and payments: booking@kabesera.com. That inbox is the landing mailbox for every automated house letter.

We have not yet named a Data Protection Officer on this site or finished NPC registration. Until then, write cafe@kabesera.com or booking@kabesera.com and we answer in fifteen working days. NPC complaints: complaints@privacy.gov.ph.

2. What we collect

You give us a name, a mobile number, an email, a party size, a date and hour, a note (allergens, occasion, access), and sometimes a payment proof.

If you stay, Cloudbeds also holds room, dates, and billing for that stay. We do not copy full card numbers onto this site.

If you join rewards, we keep a member file: stamps, Green Points, a hashed device token, and any birthday you type.

If you apply for work, we keep the role, the file you upload, and the email you used — only for hiring.

If you become a partner, we keep a business name, a contact, and the permit file you upload to qualify. Merkle hashes on the partner ledger are house proofs, not a public chain.

We do not scrape your phone book. Bring-a-friend never opens Text, Viber, Messenger, or TikTok. We mint a short code and a device token here.

We do not store full card PAN, CVV, or the magnetic stripe. Payments ride PayMongo / QR Ph / GCash / Maya.

3. Why we collect it (lawful bases)

Contract (R.A. 10173 s. 12 / GDPR Art. 6(1)(b)): to hold a table, a package, a room, a merch order, or a wallet load you asked for.

Legitimate interest (s. 12(f) / Art. 6(1)(f)): house safety, anti-self-referral on loyalty, fraud alerts, and keeping a guest book so the floor can recognise a regular.

Consent (s. 12 / Art. 6(1)(a)): optional UTM analytics cookies, Locally Yours notes (email / WhatsApp / Viber / Text), and sharing a bring-a-friend link.

Legal obligation: official receipts, tax, and any NPC or DTI request we must answer.

4. Who sees it

Floor and desk staff who need to seat you or write you back.

Processors who sit outside this house: PayMongo (pay), Cloudbeds (stay), WhatsApp / Meta (if you tap a wa.me link), Viber, your SMS carrier, GoDaddy (if we sync a marketing list you consented to), and our hosting (Vercel) plus database (Neon or the instance store).

We do not sell a guest list. We do not run advertising pixels. We do not trade your number for a boost.

5. How long we keep it

Open table holds and UTM events on this desk: 90 days, unless you ask sooner.

Opened bring-a-friend invites: 60 days. Completed referral visits: 90 days.

Paid dining, shop, and stay records that we need for tax: as long as the NIRC and BIR require (commonly 10 years for books).

Job files we did not hire: 6 months, then erase unless the law says keep.

Cart, rewards, and complaint drafts in your browser: until you clear them.

Fraud alerts: 90 days.

6. Your rights

You may access, correct, erase, restrict, object, or port the file we hold. You may withdraw consent for notes and analytics without losing a table.

Ask cafe@kabesera.com or use the tools on Privacy rights. We answer in fifteen working days.

Loyalty scoring (kb-fraud-v2) is a published rule set, not a trained model. It may withhold promotional Green Points. It does not refuse a table, a stay, or a statutory senior/PWD right. Ask for a human review.

NPC: complaints@privacy.gov.ph. Circulars we try to meet — consent (2023-04), security (2023-06), breach (16-03), DPO (Advisory 2017-01), registration (2022-04) — live on NPC guidelines.

7. Security

Visitor tokens are hashed (SHA-256, daily salt) before they leave the browser. We store a short digest, not a raw id.

Admin seats sit behind sign-in. Payments never land a PAN in localStorage.

A written Privacy Management Program, access-control policy, and NPC registration are still owed by the house. Engineering is not a PMP. See the legal checklist.

8. Cookies and messages

Essential storage (session, cart, rewards, desk) always. Analytics UTM cookies only after you Accept. Details on Cookies.

WhatsApp, Viber, and SMS deep links open the app on your phone. Until a Business API is live, the house does not send carrier messages by itself — a person taps Send.

9. Children

We do not knowingly build a member file for anyone under 13. A parent may book a family table. Wine and sparkling are 18+ on the floor.

10. Changes

We date this notice at the top of the page. Material changes will be posted here. Keeping a booking after a change is not a new consent for marketing — notes still need the tick.

GDPR / DPA tools

Your file

Current consent: unset. Analytics UTM is off unless you accepted. Visitor id is hashed daily; we never see the raw token.

This is a house notice, not legal advice. Counsel should stamp Privacy and Booking terms before a public launch.

File a complaint

0966 762 5352

Get the app