1.Responsibility and contact
[OPERATOR_LEGAL_NAME], of [OPERATOR_BUSINESS_ADDRESS], [OPERATOR_COUNTRY], operates Counterpart and is responsible for personal information processed for the platform purposes described here. Contact [PRIVACY_CONTACT_EMAIL] or submit a privacy request through Support. You can use the email route without an active account. Proposed effective date: [EFFECTIVE_DATE].
This notice explains processing; it is not a request to consent to every use. Where consent is the appropriate basis, we seek a specific choice separately. A builder, employer or external service may act as a separate controller for information it receives and uses for its own purposes.
2.Information and where it comes from
You provide account details such as name, email, roles and optional profile details; listings and product images; application answers and evidence links; offer terms and responses; work reports and chat; deal, commission and fee evidence; payment references; support requests and cofounder-document references. Other participants provide their messages, offers, reports, payment assertions and review evidence involving you.
The service creates password hashes, session and account-recovery records, timestamps, agreement versions and fingerprints, notifications, delivery attempts, moderation history and technical security records. Hosting and infrastructure services may process IP addresses, browser or device metadata, request logs and error information. Avoid including unrelated personal data in free-text fields or linked documents.
3.Purposes and lawful grounds
Account access, requested applications, offers, work records and service communications use information needed to provide the service and take steps you request in connection with a contract. Security, abuse prevention, reliability, evidence preservation and proportionate support review may rely on legitimate interests after considering the effects on individuals. Legal disclosures and records required by law rely on the relevant legal obligation.
We do not treat these grounds as interchangeable permission for any use. Sensitive personal information requires a separate applicable condition under law. Consent, where used, must be informed and specific and can be withdrawn for future consent-based processing. Withdrawing consent does not invalidate prior lawful processing or remove an independent legal retention duty. We do not sell personal information or use private engagement content for unrelated advertising.
4.Public content and private records
Published venture and job listings, including their images and business claims, are public and may appear in search engines and link previews. Product-image uploads are intended for public display. Do not upload IDs, private contracts or confidential payment evidence as listing images.
Applications are shared with the relevant builder or hiring manager. Engagement messages, agreements, compensation and evidence are available to the parties and authorized administrators as needed for operations, security or review. Investor status alone does not give access to private engagement records. Support requests are visible to their requester and authorized administrators; an engagement review may be visible to both parties. Administrative case notes are not shown in the member request view, subject to lawful disclosure and access rights.
An external evidence or signed-document link has its own permissions. A private screen does not make a publicly accessible linked file private. Limit external sharing to the intended recipients and consider redaction before submitting a link.
5.Service providers and overseas processing
The platform uses Vercel and Northflank for hosting, Neon for its database, Cloudflare for network services and R2 object storage, Upstash for queue or rate-limit infrastructure, Ably for real-time messaging and ZeptoMail for email delivery. Each receives information relevant to its function; email providers receive recipients and message content, for example. Provider operations and support may involve countries outside the Philippines.
Provider use must be covered by appropriate contractual, security and access arrangements. Overseas processing does not remove our responsibility under applicable privacy law. We may also disclose necessary information to professional advisers, lawful authorities or a business successor where legally permitted, with suitable safeguards and notice where required. We do not give prospective investors blanket access to member records.
6.Optional identity verification
When enabled, optional identity verification uses a Didit-hosted flow. The configured checks may involve identity documents, photographs, liveness or biometric processing. The exact checks, controller and processor roles, storage locations, retention and any consent request must be explained before you start. Ordinary account use does not require optional identity verification; email verification is a separate security step for making or accepting offers.
The current Counterpart integration sends an internal user reference and workflow identifier and retains verification-session identifiers, a provider-flow link, status, timestamps and webhook receipt references. It does not persist identity-document images or the full verification payload in its application database. This does not describe everything the provider may collect or retain. Do not send identity documents through support, chat or listing uploads. A verification result does not prove company authority or commercial reliability, and you can request human review of a related concern.
7.Cookies, notifications and calculated results
The cp_session cookie maintains signed-in access. Sessions expire after 14 days unless revoked earlier; logout or account-security action can revoke a session. Browser cookie controls may prevent sign-in. This notice does not authorize advertising trackers or optional analytics: assess and disclose any such addition, and obtain a choice where required, before enabling it.
We send transactional messages about account security and activity. Marketing would require a separate appropriate basis and an opt-out. The service calculates fees, commissions, performance summaries and illustrative vesting from recorded inputs. Those calculations and verification statuses do not automatically issue shares, establish legal employment status or conclusively resolve a dispute. Ask for correction or human review if a result appears wrong.
8.Retention and account closure
We retain identifiable information only while reasonably necessary for the specified purpose, applicable legal duties or the establishment, exercise or defence of claims. Closing an account starts a review of what may be deleted, anonymized or restricted. Accepted agreements, compensation evidence and relevant dispute records may need to outlast account access; unnecessary profile content and unrelated attachments should not be retained simply because some financial records must remain.
An internal retention schedule must define review dates, deletion owners and provider and backup expiry. Until those controls are approved and implemented, we do not promise an automatic deletion deadline. We explain material reasons for refusing or delaying a request where lawful, review legal holds, and remove or anonymize information when no valid reason remains. External recipients may have their own lawful records; we cannot recall every prior public copy.
9.Security and incident handling
Controls include password hashing, hashed and revocable session tokens, access checks, protected recovery flows and signed integration callbacks. We limit operational access to people who need it, and must maintain suitable provider, incident and access-review procedures. These safeguards reduce risk; they do not guarantee that every system or recipient is secure.
Report suspected exposure promptly to [PRIVACY_CONTACT_EMAIL], including the affected record and time without sending additional sensitive data. We assess incidents, preserve appropriate evidence, contain exposure, and notify affected people and authorities when required by applicable law. We do not require you to wait for an internal investigation before seeking help from an authority.
10.Your rights and requests
Depending on applicable law and the circumstances, you may request information about processing, access, correction, objection, erasure or blocking, portability, withdrawal of consent and available remedies, and file a complaint with the Philippine National Privacy Commission or another competent authority. These rights have lawful conditions and exceptions; a disagreement with a payment claim is not by itself grounds to erase another person's evidence.
Send your account email, the relevant request and a safe reply address to [PRIVACY_CONTACT_EMAIL] or Support. We may ask for proportionate verification, and will avoid collecting a full identity document when a less intrusive method is sufficient. An authorized representative may need evidence of authority. We will assess the request within applicable legal periods, explain necessary clarification or a lawful limitation, and protect other people's information in any response.
11.Children and updates
Counterpart accounts and engagements are intended for adults aged 18 or older. If you believe a child has supplied personal information, contact us so we can assess removal and any protective steps. This age restriction does not erase rights children have under applicable law.
We identify material revisions with a new date and version and communicate them as appropriate. A new notice does not retrospectively create consent or authorize incompatible new uses. The operative notice and previous versions should remain available after adoption.