Privacy Policy
Effective Date: August 19, 2026 · Last Updated: August 19, 2026
1. Introduction
This Privacy Policy explains how ACRET ("Hapag," "we," "us," or "our"), the operator of the Hapag digital menu platform available at hapag.ph (the "Service"), collects, uses, discloses, and protects information in connection with the Service.
Hapag is a QR-code digital menu platform for small and medium food businesses in the Philippines. A Business Owner signs up, builds a digital menu, and receives a unique QR code that Customers scan to browse the menu on their own phones — no app download and no customer account required.
This Policy is issued in compliance with Republic Act No. 10173, the Data Privacy Act of 2012 ("DPA"), its Implementing Rules and Regulations, and applicable issuances of the National Privacy Commission (NPC).
By registering for or using the Service, you agree to the collection and use of information as described in this Policy. If you do not agree, please do not use the Service.
Quick Summary: If you're a Business Owner, we collect your account, business, and payment-verification details to run your menu and subscription. If you're a Customer scanning a QR code, we don't collect anything beyond a language-preference cookie. We never sell your data. Full details, your rights, and how to contact us are below.
2. Who We Are
Hapag is operated by ACRET Philippines Incorporated, with its principal place of business at 14th Floor, Latitude Corporate Center, Cebu Business Park, Lahug, Cebu City, 6000 Cebu, Philippines.
For purposes of the DPA, ACRET acts as the Personal Information Controller for account and business data of Business Owners, and as a Personal Information Processor/Controller for the limited data described below in relation to Customers browsing a menu.
3. Who This Policy Applies To
Hapag has two categories of users, and we collect very different amounts of information from each:
- Business Owners — restaurant, café, or food-stall operators who register for a Hapag account, build a menu, and pay a subscription fee. Business Owners create an account and provide personal and business information.
- Customers / Diners — the public who scan a QR code to view a menu. Customers do not create an account, do not log in, and are not required to provide any personal information to browse a menu.
4. Information We Collect
Information Business Owners Provide Directly
When you register and use Hapag as a Business Owner, we collect:
- Account credentials: email address and password (stored and hashed via our authentication provider — we never store your password in plain text).
- Business profile information: business name, menu URL slug, business logo, contact phone number, contact email address, and business address.
- Menu content: category and item names, descriptions, prices, and photos that you upload. If you use our Pro-tier AI description or translation features, we also store metadata about which descriptions were AI-generated versus manually written, and the keywords you supplied to generate them.
- Subscription and payment verification data: your selected plan, the amount due, your chosen payment method (bank transfer or GCash), and the screenshot of proof of payment you upload. Because Hapag currently only supports manual bank transfer and GCash "send money" payments (we do not use a payment gateway), this screenshot may show details such as your bank/e-wallet name, reference number, and the last digits of an account number. We use this solely to verify and activate your subscription and to maintain financial records.
- Support communications: the content of any support ticket or message you send us, and our replies.
Information We Collect Automatically
- Cookies: we set a single functional cookie, hapag_lang, to remember a menu viewer's language preference. This cookie lasts up to one year, contains no personal identifiers, and is not used for advertising or cross-site tracking. See Section 7.
- Technical/log data: like most web services, our hosting and content-delivery providers automatically log standard technical information such as IP address, browser type, device type, and timestamps, for security, abuse prevention, and service reliability purposes.
- Analytics (if enabled): we may use privacy-respecting, aggregate analytics to understand overall traffic patterns (e.g., page views, general device type). As of the date of this Policy, this data is aggregate and is not used to build individual customer profiles. If this changes to include more granular tracking, we will update this Policy and, where required by law, obtain your consent.
Information We Do Not Collect from Customers
Because browsing a Hapag menu does not require an account, we do not knowingly collect a Customer's name, email address, phone number, order history, or payment information through the menu-viewing experience itself. Hapag does not currently process food orders or diner payments.
5. How We Use Your Information
We use the information described above to:
- Create and manage Business Owner accounts and authenticate logins
- Generate, host, and display your digital menu and QR code
- Provide Pro-tier features such as AI-assisted menu descriptions and machine translation
- Verify proof-of-payment submissions and activate, renew, or suspend subscriptions
- Send transactional communications (e.g., welcome emails, payment confirmations, renewal reminders, and responses to support tickets)
- Detect, investigate, and prevent fraud, abuse, and security incidents
- Comply with our legal, tax, and regulatory obligations (e.g., issuing BIR-compliant receipts and maintaining financial records)
- Improve and maintain the reliability of the Service
We do not sell, rent, or trade your personal information to third parties for their own marketing purposes.
6. Legal Basis for Processing
Under RA 10173, we process personal information on the following bases:
- Consent — for optional features such as Pro-tier language preferences and any future marketing communications
- Performance of a contract — to create your account, deliver the Service, and process your subscription
- Compliance with a legal obligation — for tax, accounting, and regulatory record-keeping
- Legitimate interest — for fraud prevention, service security, and platform improvement, balanced against your rights as a data subject
9. Data Storage, Security, and International Transfer
We implement reasonable organizational, physical, and technical security measures appropriate to the nature of the data we hold, including:
- Encryption in transit (TLS) and at rest for stored data
- Row-level access controls so that each Business Owner can only access their own business data
- Restricted, logged access for ACRET admin staff
- Regular backups
Some of our service providers may process or store data on servers located outside the Philippines. Where this occurs, we take reasonable steps to ensure that such providers maintain a comparable standard of protection, consistent with RA 10173's requirements for cross-border data transfers.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
10. Data Retention
- Active accounts: we retain your account and business data for as long as your account remains active.
- Subscription and payment records: retained for at least five (5) years, consistent with the record-keeping requirements of the Electronic Commerce Act (RA 8792) and BIR regulations.
- After account deletion: we retain a limited set of data for up to thirty (30) days after a deletion request, to allow for account recovery and to satisfy legal, tax, and fraud-prevention obligations, after which it is deleted or irreversibly anonymized, except where longer retention is legally required (e.g., financial records under item above).
- Support tickets: retained for as long as reasonably necessary to resolve your inquiry and for our quality and record-keeping purposes.
11. Your Rights as a Data Subject
Under RA 10173, you have the right to:
- Be informed that your personal data will be, is being, or has been processed
- Access your personal data that we hold
- Object to the processing of your data, including for direct marketing
- Correct inaccurate or outdated personal data (you can update most business profile information directly from your account)
- Erasure or blocking of your data, subject to our legal retention obligations described in Section 10
- Data portability — request a copy of your data in a structured, commonly used format (e.g., CSV/JSON export of your menu and business data)
- Damages for harm sustained due to inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorized use of personal data
- File a complaint with the National Privacy Commission (privacy.gov.ph) if you believe your rights have been violated
To exercise any of these rights, contact us using the details in Section 15. We will respond within the timeframe required by applicable law.
12. Children's Privacy
Hapag's Business Owner accounts are intended only for individuals who are at least 18 years old and legally authorized to operate a food business. We do not knowingly collect personal information from children. Since Customers browse menus without creating an account or submitting personal data, no age-gating is applied to menu browsing.
13. Third-Party Links and Content
A Business Owner's menu page may display business information (such as an address) that links to third-party services (e.g., a maps application) outside of Hapag's control. This Policy does not apply to such third-party sites, and we encourage you to review their own privacy policies.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, features, or legal requirements. We will post the updated Policy on this page with a revised "Last Updated" date, and for material changes, we will provide additional notice (e.g., by email or an in-app notice) where required by law.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact:
ACRET — Hapag
Address: 14th Floor, Latitude Corporate Center, Cebu Business Park, Lahug, Cebu City, 6000 Cebu, Philippines
You may also file a complaint with the National Privacy Commission at privacy.gov.ph.
Email: [email protected]
