Privacy Policy
How LakBai collects, uses, discloses, and protects your personal information.
LAKBAI TECHNOLOGIES, INC. PRIVACY POLICY
Effective: July 7, 2026 Last updated: July 7, 2026
LakBai Technologies, Inc. ("LakBai," "we," "us," or "our") is committed to protecting your privacy and ensuring compliance with Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012 (DPA), its Implementing Rules and Regulations (IRR), and issuances of the National Privacy Commission (NPC).
This Privacy Policy applies to all users of our mobile application ("the App"), website, and associated transport services.
1. Overview and Definitions
This policy explains how we collect, use, disclose, and protect your personal information. As a Personal Information Controller (PIC), we ensure the lawful, fair, and transparent processing of your data.
To keep this policy clear, we use the following definitions:
- Platform / App: The software application, website, and digital infrastructure operated by LakBai that formalizes carpooling by delivering software services while preventing unlawful profit gains by drivers.
- Users: Any registered individual utilizing the LakBai app.
- Passengers: Users who utilize the platform to discover, match with, and secure independent transport arrangements with other users, and who utilize our escrow system to fund transactions.
- Drivers: Users who utilize the platform to post their vehicle availability, accept ride requests, and receive payouts via the platform’s escrow system.
- Escrow-like Services: The secure transaction feature of the platform that holds a Passenger’s trip contribution in a temporary state until the peer-to-peer transit arrangement is mutually completed, before transferring the reimbursement to the Driver.
- Integrated Payment Gateway: The independent, central bank (BSP)-regulated financial technology partner whose secure checkout system is embedded directly within the App interface. They collect and process all financial data natively; LakBai never processes or retains your raw financial credentials.
2. Data Collection and Use
2.1 Types of Data Collected
Depending on your role and interaction with the App, we collect personal and sensitive personal information categorized below:
A. From All Registered Users (Passengers and Drivers)
- Account Information: Full legal name, residential/billing address, verified email address, mobile number, account credentials (encrypted and salted), and profile photo.
- Demographic Data: Date of birth (to verify legal age eligibility) and gender/sex.
- Verification Data: Government-issued identification (e.g., Passport, National ID, Driver’s License), school-issued identification (provided that government ID is not available), and real-time facial biometric scans ("selfie verification") to prevent fraud and identity theft.
B. Specific to Drivers
- Professional & Vehicle Information: Driver’s license details, Professional Driver’s License status, vehicle registration documents (OR/CR), vehicle make, model, year, color, and license plate number.
- Background Check Data: Police Clearance, and driving history records to ensure public safety.
C. Data Generated During App Usage
- Approximate Location Data: We collect approximate real-time geographic coordinates from your mobile device.
- For Passengers: Collected when the App is running in the foreground or background during an active trip from the moment the driver reached the origin point until completion
- For Drivers: Collected continuously when the App is open, in the foreground, or running in the background during an active trip.
- Transaction and Trip Data: Complete trip details including pickup and drop-off points, routes taken, distance covered, timestamps, cost breakdowns, payment methods, and transaction reference IDs.
- Communications Data: Text messages and in-app call logs generated when Users communicate with each other or with customer support through the App.
- Feedback and Reviews: Texts submitted by the users to provide information or opinions about the drivers, other trip participants, and services offered to them.
- Telematics & Device Data: Hardware model, operating system, IP address, device event logs (crashes, system activity), and telematics data (e.g., acceleration, braking patterns, and speed to monitor safe driving behavior).
2.2 Purpose of Data Processing
We process your data strictly under the following lawful basis:
| Purpose of Processing | Data Used | Legal Basis (DPA) |
|---|---|---|
| Account & Service Management: Creating accounts, trip listing, trip filtration, displaying vehicle details, and calculating ETA/fares. | Name, Preferences, Phone, Vehicle Info, Location Data | Contractual Necessity |
| Identity Verification & Security: Verifying driver credentials, conducting background checks, and running facial recognition matching. | Government IDs, Biometric Selfies, Clearances | Consent / Legitimate Interest |
| Payment Processing: Facilitating secure cash, credit card, e-wallet, or digital payment settlements and issuing digital receipts. | Payment tokens, Transaction logs | Contractual Necessity |
| Safety & Incident Resolution: Tracking live trips for emergency response, monitoring driving behavior, and investigating accidents or disputes. | Telematics, Live GPS, Comm Logs | Legitimate Interest / Vital Interest |
| Regulatory Compliance: Reporting to government bodies, tax compliance, or fulfilling court subpoenas. | Trip history, Transaction logs | Legal Obligation |
3. Data Sharing and Disclosure
We do not sell your personal data. To provide our services seamlessly, data is shared under strict security protocols with the following entities:
3.1 Sharing Between Users
- Passengers Data Shared with Trip Participants: Name, pickup/drop-off locations, profile photo, preferences, interests, ratings, number of completed rides, recent feedback, and in-app communication.
- Driver Data Shared with Passengers: Name, profile photo, full trip details, vehicle make/model/color, license plate, live location, ratings, number of completed rides, recent feedback, and aggregate reviews.
3.2 Sharing with Third-Party Providers
We partner with certified third-party vendors who process data on our behalf under strict Data Processing Agreements (DPAs):
- Payment Gateways & E-Wallets: To securely process cashless fares.
- Cloud Infrastructure: Data hosting and security monitoring servers (e.g., AWS, Google Cloud).
- KYC Vendor: To securely verify user identification.
3.3 Legal and Regulatory Disclosures
LakBai implements a strict Zero-Data-Sharing-Without-Due-Process policy. We will never voluntarily disclose, hand over, or grant access to any User’s Personally Identifiable Information (PII), precise geolocation data, trip histories, or verification records to any law enforcement authority, government agency, or third-party litigant based on informal requests, letters, or administrative notices.
We will only disclose personal data when strictly compelled by law and only after the requesting party has satisfied the highest legal due process standards. Disclosures are exclusively restricted to the following conditions:
- Judicial Cybercrime Warrants: In compliance with Republic Act No. 10175 (The Cybercrime Prevention Act) and its governing procedural rules, law enforcement authorities must present a valid, specific, and court-issued Warrant for Disclosure of Computer Data (WDCD) or a Warrant for Search, Seizure, and Examination of Computer Data (WSSECD) signed by a competent judge.
- Mandatory Court Orders and E-Discovery: We will comply only with explicit, non-appealable orders for digital e-discovery issued by a Philippine court of competent jurisdiction, or legally binding statutory subpoenas where refusal would constitute contempt of court.
- Exigent Life-Threatening Exceptions: The sole exception to a prior judicial warrant is an emergency request where law enforcement proves an immediate, demonstrable, and verifiable threat to human life or physical safety (e.g., active kidnappings or immediate bodily harm), and where obtaining a warrant prior to data extraction is physically impossible.
Platform Indemnity and Scope of Compliance: Any digital data released under a valid judicial warrant will be minimized. LakBai will only yield the specific data parameters explicitly itemized in the warrant itself, ensuring that no overbroad or sweeping e-discovery sweeps occur on our servers.
4. Choice, Transparency, and User Rights
4.1 Device Permissions & Control
You can manage how your device shares data through your system settings:
- Location Access: You may toggle off location access, but doing so will severely limit the App's functionality.
- Camera/Storage Access: Required solely for uploading profile photos, updating trip participants for meetup landmarks, submitting verification documents, or reporting issues to customer support.
4.2 Data Subject Rights Under the DPA
As a data subject under Philippine law, you hold the following rights:
- Right to be Informed: Knowing whether your data is being processed.
- Right to Access: Requesting a copy of your personal data stored in our systems.
- Right to Rectification: Demanding the correction of inaccurate or outdated information.
- Right to Erasure/Blocking: Requesting the deletion or suspension of your account and personal data (subject to our legal retention requirements).
- Right to Object: Declining data processing based on legitimate interest or direct marketing.
- Right to Data Portability: Obtaining an electronic copy of your data for transfer to another controller.
- Right to File a Complaint: Elevating data misuse grievances directly to the National Privacy Commission (https://privacy.gov.ph/).
5. Data Security, Retention, and International Transfers
5.1 Data Security Measures
LakBai implements industry-standard technical, organizational, and physical security controls. All data transmitted between the App and our servers is encrypted using Transport Layer Security (TLS) and stored using Advanced Encryption Standard (AES-256). Access to your personal data is strictly compartmentalized to authorized personnel under confidentiality agreements.
5.2 Data Retention Period
- Active Accounts: Personal data is retained for as long as your account remains active.
- Inactive/Deleted Accounts: Upon a deletion request, LakBai will anonymize or delete your records within thirty (30) days, except where retention is required by law (e.g., Bureau of Internal Revenue regulations mandate keeping financial transaction logs for up to ten (10) years; LTFRB safety disputes may require retaining trip logs).
5.3 Cross-Border Transfers
If your data is processed outside the Philippines (e.g., via international cloud servers), LakBai ensures that recipient jurisdictions provide an equivalent or higher standard of privacy protection using Standard Contractual Clauses (SCCs) approved under NPC guidelines.
6. Policy Updates and Contact Information
6.1 Policy Updates
We may update this Privacy Policy from time to time to align with new features or regulatory changes. Material changes will be communicated via in-app banner alerts or push notifications. Continued use of the platform following an update constitutes your acknowledgment and acceptance of the revised policy.
6.2 Contact
LakBai Technologies, Inc. Address: Citihomes Subdivision, Molino IV, Bacoor, Cavite Email: [email protected] Website: https://lakbai.co Legal hub: /legal
Related policies: Terms & Conditions, Cancellation and Reimbursement Policy, Cookie Policy.