On this page tap to open
This Privacy Policy explains how Tan-aw Information Technology Services, a sole proprietorship registered with the Department of Trade and Industry (DTI Business Name Reg. No. 8229411), with principal office at Selenia 208, Mirea Residences, Amang Rodriguez Avenue, Santolan, Pasig City ("Tan-aw", "we", "us") collects, uses, shares, and protects personal data when you use:
- the Tan-aw platform (web app for food and beverage businesses); and
- ReadyNa, our customer app and the order-tracking web page at
readyna.tan-aw.com/orders/....
We process personal data in accordance with Republic Act No. 10173 (the Data Privacy Act of 2012, "DPA"), its Implementing Rules and Regulations, and the issuances of the National Privacy Commission ("NPC").
Who controls your data. When you order food, the merchant (the business you are buying from) decides what to collect and is the Personal Information Controller for your order; Tan-aw acts as their Personal Information Processor. For our own operation of the platform (merchant accounts, billing, security, and the app itself), Tan-aw is the controller. This Policy describes both roles. Questions about a specific order should also be directed to the merchant that served you.
Summary
- You do not need an account to track an order. ReadyNa and the order-tracking page work with just a claim code or a link. No name, email, or phone number is required to use them.
- We store a push notification token for your device only if you turn on "Notify me when ready", so we can tell you your order is ready.
- A merchant may record your name on an order if you give it, and (only if you ask for an official receipt or claim a Senior Citizen / PWD discount) the data the law requires for that (including your government ID number, which we encrypt).
- Joining a merchant's rewards programme or customer list is separate and opt-in. If you choose to join, you give that merchant your contact details (and, if you want a birthday offer, the month and day of your birthday), and it keeps a record of your visits and points with it. That record belongs to that merchant alone. See Section 2.6.
- No marketing is sent through Tan-aw. A merchant can record that you agreed to hear about its offers by SMS or email, but the platform has no way to send those messages today.
- We do not sell your personal data. We do not use it for advertising.
- Your data is hosted on Microsoft Azure in Singapore, and some notification and payment services process it abroad. We explain this in Section 7.
Personal data we process
2.1 Customers using ReadyNa, the order tracker, or a merchant's customer directory
| Data | When collected | Why |
|---|---|---|
| App install identifier (a random ID per app installation) | When you open ReadyNa | Lets us link your device to your orders without identifying you personally. |
| Push notification token + platform (iOS/Android) | Only if you enable order notifications | To deliver the "order ready" push notification via Apple/Google. |
| Order claim code / order link tokens | When a merchant creates your order or you scan a QR/link | Lets you (and anyone who holds the link) view the order's status. If you sign in to ReadyNa and claim the order, you can make the link private, so that only your signed-in account can open it; you can make it public again at any time, and the merchant's staff can restore access if you lose it. |
| Your name (optional) | Only if the merchant enters it on the order | To label your order at the counter. You may decline to give it. |
| Order contents and status | When the merchant takes your order | To show you what you ordered and notify you when it is ready. |
| Notification delivery logs | When we attempt a notification | To diagnose delivery problems and reconcile stale device tokens. |
| Your phone number (optional) | Only if you give it to a merchant — to join its rewards programme or customer list, or to hold a booking | So that merchant can find your record at the counter and reach you about your order or booking. In its customer directory it is stored encrypted and found through a one-way lookup code rather than by reading the stored numbers; on a booking it is held as you gave it, for that booking. |
| Your email address (optional) | Only if you give it to a merchant for the same reasons | Same purposes as the phone number, and stored encrypted in the customer directory with the same one-way lookup. |
| Your birthday — month and day only (optional) | Only if you give it to a merchant | So that merchant can offer you a birthday perk. We never ask for the year, so this cannot be used to work out your age. |
| Marketing consent record (per channel: SMS, email, push) | When a merchant records that you agreed to hear about its offers, and again if you withdraw | To evidence your choice — what you agreed to, when, through which channel, and who recorded it. Withdrawals are added as new entries, so the history can prove you opted out. |
| Notes a merchant's staff write about serving you | Only if staff type one on your record | To serve you better on a return visit (for example an allergy or a usual order). Visible only to that merchant's staff. |
| Labels ("tags") the merchant attaches to your record | Only if the merchant applies them | To group its customers (for example "regular" or "VIP") so its staff can recognize and serve you consistently. Visible only to that merchant's staff. |
| Your visit history and rewards points with a merchant | Each time that merchant settles a sale against your record | To count your visits and spend with that merchant, and to award, hold, and spend rewards points in its programme. |
We do not require your email address or phone number to use ReadyNa or the order tracker. They are asked for only if you choose to join a merchant's rewards programme or customer list, or give them to a merchant for a booking — see Section 2.6.
2.2 Receipts, tax, and statutory-discount data (collected by the merchant)
If you request an official receipt / sales invoice, or claim a Senior Citizen (RA 9994) or PWD (RA 10754 / RA 7277) discount, the merchant must record (and Tan-aw stores on the merchant's behalf) the data the Bureau of Internal Revenue (BIR) and those laws require:
| Data | Notes |
|---|---|
| Your name | As you provide it for the receipt or discount. |
| Your address | Only for a VAT invoice that requires it. |
| Your Taxpayer Identification Number (TIN) | Only for a VAT invoice; stored encrypted. |
| For SC/PWD: ID type (OSCA, PWD ID, NAAC, Solo Parent, or other) and ID number | Required by law to grant and substantiate the discount. The ID number is stored encrypted and is never written into logs, backups, or exports in readable form. |
This is sensitive personal information under RA 10173. We process it because the law obliges the merchant to capture it to grant the discount and to support its tax filings, not for any other purpose.
2.3 Payments
Payments you make to a merchant are not processed by Tan-aw. You pay the merchant directly by whatever means it accepts (cash, its own card terminal, or its own e-wallet), and the merchant records only the payment method, amount, and a reference number in the Service to reconcile its orders. Your card or e-wallet credentials never reach Tan-aw, and we do not store card numbers.
Merchants' subscription payments to Tan-aw are collected through our payment gateway (see Section 7). The merchant's card or e-wallet details are captured and processed by the gateway, not by us; we store only the payment method, amount, and reference number needed for billing and refunds.
2.4 Merchant account holders and staff
For people who log in to the Tan-aw platform (owners, admins, managers, cashiers), we process: name, email address, hashed password or federated identity from Microsoft Entra External ID (including the Entra object/tenant identifiers and multi-factor authentication assurance), role and location assignments, audit logs of actions taken, refresh-token/session records, and technical data such as IP address and timestamps for security.
2.5 Technical and diagnostic data
To operate, secure, and troubleshoot the service, we process technical data such as IP addresses, device/session identifiers, request metadata, application logs, error reports, and performance metrics. Some of this telemetry is shared with our hosting provider (Microsoft Azure) and our application-performance- monitoring provider (New Relic) and may be processed outside the Philippines (see Section 7). We minimize personal data in this telemetry at source, and no payment card numbers are sent to it.
2.6 A merchant's customer directory and rewards programme
Merchants on some plans can keep a customer directory — that merchant's own record of the diners it serves — and can run a rewards programme that awards points on a sale and lets you spend them on a later one. Both are opt-in: nothing goes into a directory or a programme unless you give a merchant your details or ask to join.
The merchant decides what to keep in its directory and is the Personal Information Controller for it. Tan-aw stores and processes that record on the merchant's instructions as its Personal Information Processor. Each merchant's directory stands alone: a merchant sees only the diners it captured itself, and joining one merchant's programme never adds you to another's.
The data such a record can hold is listed in the table in Section 2.1 — your name, phone number, email address, the month and day of your birthday, notes staff write about serving you, labels ("tags") the merchant attaches to your record, whether you agreed to hear about that merchant's offers, and the history of your visits, spend, and points with that merchant.
Some points worth stating plainly:
- Your phone number and email address are encrypted at rest. So that staff can still look you up, we also keep a one-way code derived from each. The code is specific to that merchant, so the same number held by two merchants produces two unrelated codes and cannot be used to connect your activity across businesses. When staff search, contact details are shown masked (for example, only the last four digits of a number).
- We never ask for your birth year — only the month and day, so the record cannot be used to work out your age.
- No marketing is sent through the platform today. A merchant can record, per channel and as a separate opt-in choice, that you agreed to hear about its offers, so that the agreement is evidenced if and when a sending feature exists. No such message can be sent through Tan-aw now. If that changes we will update this Policy and name the sending provider in Section 7 before any message goes out. Agreeing to marketing is never a condition of joining a rewards programme, and withdrawing it never costs you points.
- Rewards points are not money. They are a discount you can use in that merchant's own programme. Points are held in an append-only ledger, so an award, a redemption, or a correction is always recorded as a new entry rather than by editing or deleting an old one.
- You can ask to be removed. A merchant can erase your directory entry. When it does, your name, contact details, birthday, staff notes, tags, and marketing agreement are deleted and any unused points are forfeited. What remains — past receipts, points-ledger entries, and the record that a marketing choice was made and withdrawn — no longer identifies you and is kept only so the merchant's books stay internally consistent.
Ask the merchant first, since it controls this record. If you cannot reach it, contact our Data Protection Officer (Section 11) and we will help.
2.7 Your ReadyNa account (only if you choose to sign in)
You can use ReadyNa and the order tracker without an account — everything in Section 2.1 works anonymously, and it is the normal way to use the service. If you do choose to sign in, we create a ReadyNa account for you. Signing in is handled by Microsoft Entra External ID, and we receive only what that sign-in returns.
| Data | When collected | Why |
|---|---|---|
| Your email address | When you sign in | Identifies your account across devices, so your orders follow you. |
| Your display name | When you sign in, if your sign-in provides one | To greet you and label your account in the app. |
| Sign-in identifiers (the identity-provider identifiers for your account and its directory) | When you sign in | So we recognize the same person on the next sign-in without storing a password. We never receive or store your password. |
| Sign-in session records | While you stay signed in | To keep you signed in and to let you sign out everywhere. Each record is a session, not a location history. |
| A link between your account and each device you sign in on | When you sign in on a device | So an order claimed on one phone appears on another device you signed in on. |
| The date you last signed in | Each sign-in | For account housekeeping and security. |
| Your tracking choice (Section 2.6) and, if you set it, the date you made it | Only if you change it | To honour it on every future visit and to evidence when it took effect. |
| A record of each change to that choice, and of your account being linked to, moved between, or unlinked from a device | When the change happens | To show that we honoured your choice from the moment you made it, and to keep past orders coherent when devices change hands. These records survive account deletion in de-identified form — see Deleting it below. |
What your account does for you: orders you claim gather in one place, you can make a claimed order's link private so only you can open it, and you can turn off being recognized by merchants across visits.
What your account is not: it is not a merchant's record of you. Merchants never see your account's email address, display name, or sign-in identifiers, and never receive an identifier that would let two merchants work out that you are the same person. What a merchant can learn is described in Section 2.6.
Deleting it. You can delete your ReadyNa account in the ReadyNa app at any time, without giving a reason, and you can always ask us to delete it instead (Section 11). Deleting it erases your email address, display name, and sign-in identifiers — including the copies held by the sign-in provider, which we instruct to delete your user as part of the same deletion — ends every session immediately, and detaches your account from your devices and from every merchant's directory record.
Some things deliberately survive, and none of them identifies you afterwards: a de-identified account row, so that past orders and any receipts a merchant is legally required to keep stay internally consistent; the de-identified records of tracking-choice changes and device links described in the table above, which are the evidence that we honoured your choices while the account existed; and each merchant's own directory record, which is that merchant's record of a diner rather than yours to delete — Section 9 explains how to have that erased too. Deleting your account does not by itself erase you from a merchant's customer directory; if you want both, make both requests.
2.8 Data we do not collect
- We do not build advertising profiles or track you across other apps/websites.
- We do not collect precise device location.
- Tan-aw's own analytics are aggregate only (order counts, revenue, timing). We do not use them to profile an individual customer, and we never combine one merchant's customers with another's.
- To be clear about the limit of that last point: a merchant does see its own customers individually where it keeps a customer directory or runs a rewards programme — your visits, spend, and points with that merchant (Section 2.6). We do not do the same for ourselves. That record is the merchant's, it covers only your dealings with that business, and it is not used for advertising.
- We do not make automated decisions about you that produce legal or similarly significant effects.
Push notifications
The core purpose of ReadyNa is to tell you when your order is ready, replacing a physical buzzer. Notifications are opt-in: we register your device's push token only after you enable them. The notification contains the location name and your claim code, and no other personal data. You can turn notifications off at any time in your device settings, after which we stop sending them and the token is pruned during routine maintenance.
Legal bases for processing
Under the DPA we rely on:
- Consent: for push notifications; for any name you choose to give; and for joining a merchant's customer directory or rewards programme and giving the contact details and birthday that go with it.
- Consent for marketing: separately, and per channel (such as SMS or email), for agreeing to hear about a merchant's offers. This is always its own opt-in choice — it is never bundled into joining a rewards programme, we keep a record of when and how it was given, and you can withdraw it at any time without losing points or membership.
- Contract / legitimate interest: to create, display, fulfil, and track orders, operate merchant accounts, secure the platform, and bill merchants; and, for a merchant that keeps a customer directory, to recognize a returning diner and run the rewards programme you joined.
- Legal obligation: to record and retain fiscal data and SC/PWD discount data required by the BIR, RA 9994, and RA 10754.
How we use personal data
We use personal data only to: provide and operate the ordering and notification service; show you your order status; deliver "order ready" notifications; bill merchant subscriptions through our payment gateway; produce receipts and meet the merchant's tax and statutory-discount obligations; keep, on a merchant's instructions, that merchant's own record of its customers so it can recognize and serve a returning diner; operate the rewards programme a merchant runs, including counting visits and spend and awarding, holding, spending, and correcting points; record and evidence your per-channel marketing choices and their withdrawal (we send no marketing); secure the platform and prevent abuse (including tenant isolation and least-privilege access controls); provide customer support; and comply with law.
We do not sell personal data and do not use it for third-party advertising.
How we share personal data
We share personal data only with:
- The merchant that served you (for your order, receipt, and discount data, and for its own customer-directory and rewards records about you). We do not share any of it with another merchant.
- Sub-processors that operate the service on our behalf (see Section 7).
- Government authorities (e.g. the BIR, NPC, courts) where required by law.
- Professional advisers and, in a merger/acquisition, a successor entity, subject to the same protections.
Sub-processors and where your data is stored
Your personal data is hosted on Microsoft Azure in the Southeast Asia (Singapore) region. We use the following sub-processors:
| Sub-processor | Role | Processing location |
|---|---|---|
| Microsoft Azure (Microsoft Corporation) | Cloud hosting, database, storage, secrets; optional observability (Azure Monitor / Application Insights / Log Analytics) | Singapore (Southeast Asia) |
| Microsoft Entra External ID | Authentication / identity for merchants, and for customers who sign in to ReadyNa (Section 2.7) | Microsoft global infrastructure |
| New Relic, Inc. | Application performance monitoring, error tracking, and log management (technical telemetry only, PII-minimized) | United States (EU region available) |
| Google Firebase Cloud Messaging (FCM) | Push notification delivery | Google global infrastructure |
| Apple Push Notification service (APNs) | iOS push notification delivery | Apple global infrastructure |
| PayMongo (PayMongo Philippines, Inc.) | Subscription billing; processes merchants' payment methods for Tan-aw subscription fees | Philippines (BSP-regulated); with onward transfer to its own US-based sub-processors (e.g. AWS, fraud screening) |
Cross-border transfers. Your personal data may be processed and stored outside the Philippines by our service providers, including in Singapore (cloud hosting and infrastructure, via Microsoft Azure) and the United States (application performance monitoring, via New Relic). The Philippines has no data-localization law, and neither provider operates a datacenter within the Philippines, so this offshore processing is necessary to run the service. These transfers are governed by data processing agreements that incorporate the National Privacy Commission's Model Contractual Clauses and/or the EU Standard Contractual Clauses, and we remain accountable for ensuring your data receives a level of protection comparable to that required under Republic Act No. 10173 (Data Privacy Act of 2012). To request a copy of the relevant safeguards, contact our Data Protection Officer at dpo@tan-aw.com.
How long we keep personal data
Operational data (orders, order-tracking and claim data, device records, customer-directory profiles, rewards memberships and points ledgers, and similar service data) is kept only as long as needed to provide the service, according to the merchant's subscription plan, and never longer than the law otherwise requires (see "Tax and legal-hold records" below):
- Starter plan: up to 31 days (one month).
- Standard plan and above: up to five (5) years while the subscription is active.
When a merchant unsubscribes or closes an account, we make its operational data available for export for a limited window (target: 30 days), after which we securely delete or irreversibly anonymize it, except records we are legally required to keep. A merchant may ask us to archive a copy of its own data beyond this period (and keep it available for download) as a paid service at fees covering the storage, processing, and retrieval involved; any such archival is purpose-limited, time-bound, revocable, and never extends to personal data belonging to the merchant's end customers. The fee itself is not a basis for keeping data.
Tax and legal-hold records are required by Philippine tax law to be preserved for the period the BIR requires. These records comprise receipts, invoices, books of accounts and their source documents, Senior Citizen / PWD discount-substantiation records (name, OSCA/PWD/Solo-Parent ID number, discount, date, and receipt/invoice number), and TINs. The required period is currently five (5) years from the applicable return-filing deadline, following the 2024 amendment of NIRC Section 235 by Republic Act No. 11976 (Ease of Paying Taxes Act) and RR 7-2024, and longer where a tax assessment, protest, refund, or credit claim is pending. The merchant that served you is the accountable taxpayer and the controller of these records. While the merchant's subscription includes fiscal features, we store these records on its behalf, and they cannot be erased on request for as long as we hold them. Your erasure request is honored for all other data. If the merchant leaves the platform, these records are delivered to the merchant in its data export for continued preservation, and we delete our copies after the export window unless the merchant purchases archival or we are legally required to keep them (for example under a legal hold).
| Other data | Retention |
|---|---|
| Push tokens / device records | Kept while notifications are enabled and an order is active; pruned when stale or disabled. |
| Notification delivery logs | Kept for a short troubleshooting window, then pruned. |
| Merchant account / authentication records | Kept for the life of the account; sessions and refresh tokens expire and are deleted. |
| ReadyNa customer account (email address, display name, sign-in identifiers, session records, device links, tracking choice) | Kept while the account exists; sessions expire and are deleted. Removed when you delete the account (Section 2.7): the identifiers are erased both here and at the sign-in provider, every session ends immediately, and what survives is a record with no identifying data in it, together with the de-identified evidence of your tracking choices and device links. |
| Customer-directory profiles (name, contact details, birthday month/day, staff notes, tags, marketing-consent history, visit and spend totals) | Kept while the merchant keeps the record and its plan's retention window allows. Removed sooner if the merchant erases you: every identifier and tag is deleted and only a record with no identifying data in it survives, so past receipts and ledger entries still resolve. Deleted with the merchant's other operational data when it leaves the platform and the export window closes. |
| Rewards memberships and points ledger | Kept for the merchant's plan retention window and deleted with its other operational data on exit. The ledger is append-only, so a mistake is corrected by a further entry rather than by editing or deleting one; erasing you forfeits unused points and leaves the remaining entries attached to a record that no longer identifies anyone. |
Where we are legally required to retain specific records, or need them to establish, exercise, or defend legal claims, your erasure request is honored for all other data and those records are kept only for the period required.
Your rights
Under the DPA you have the right to be informed, to object, to access your data, to correct inaccurate data, to erasure or blocking of unlawfully processed data, to data portability, to be indemnified for damages, and to file a complaint with the NPC.
To exercise these rights, contact our Data Protection Officer (Section 11). For order, receipt, customer-directory, or rewards data you may also need to contact the merchant that served you, since it controls that data.
How we find your data depends on how you used the service. Most use of the order tracker is anonymous, so for those records we need something that points at them — your order link or claim code — and without it we may be unable to identify any data as yours. If you are in a merchant's customer directory or rewards programme, that merchant can find your record from the phone number or email address you gave it, so a request there is usually straightforward. It must go to that merchant, and covers only that merchant's records: each directory stands alone and we keep no index that would let us find you across merchants. Before we act, we will ask for enough information to be satisfied the request is really yours, and we will not create new personal data about you just to answer it.
How we protect personal data
We apply appropriate organizational, physical, and technical measures, consistent with our obligations under RA 10173 Section 20 and the National Privacy Commission's security requirements (IRR Rule VI Section 28; NPC Circular 2023-06). These include: encryption in transit (TLS); field-level encryption at rest for sensitive and contact identifiers (TINs, SC/PWD ID numbers, and the phone numbers and email addresses held in a merchant's customer directory); lookup of those encrypted contact details through a keyed one-way index rather than by reading the stored values, salted per merchant so the same detail held by two merchants cannot be matched across them, with the values shown masked in staff-facing search results; strong password hashing and federated authentication with multi-factor authentication for merchant staff; strict tenant isolation so one merchant cannot access another's data; least-privilege role-based access; and audit logging. No system is perfectly secure; we work to protect your data but cannot guarantee absolute security.
Data Protection Officer and contact
- Data Protection Officer: dpo@tan-aw.com
- General / support: hello@tan-aw.com
- Postal: Selenia 208, Mirea Residences, Amang Rodriguez Avenue, Santolan, Pasig City
If you believe your data privacy rights have been violated, you may also lodge a complaint with the National Privacy Commission (privacy.gov.ph).
Children
ReadyNa and the order tracker are not directed at children under 18. We do not knowingly collect personal data from children without the consent of a parent or guardian. Merchants are responsible for age verification on age-restricted goods (e.g. alcohol, tobacco).
Changes to this Policy
We may update this Policy. We will post the updated version with a new effective
date at tan-aw.com/privacy-policy and, where appropriate, notify merchants. Continued
use after the effective date constitutes acknowledgment of the updated Policy.