Privacy notice
Version 2026-09-03. Last updated 2026-09-03.
This notice explains how OtterFlow handles personal data in the appointment booking service at this website. It is written to meet the transparency requirements of the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its implementing rules.
Two different roles
OtterFlow is used by businesses to take bookings from their own customers. That means personal data here falls into two groups, and the same law treats them differently.
- Account data. When a business signs up, we hold the owner's name, email address and contact details. For this data OtterFlow is the personal information controller, and this notice applies directly.
- Customer data. When someone books an appointment with a business that uses OtterFlow, the booking belongs to that business. The business decides why it collects the data and how long to keep it, so the business is the personal information controller. OtterFlow only processes that data on the business's instructions, which makes us a personal information processor. If you booked an appointment and want your data corrected or removed, contact the business you booked with. Their details appear on the booking page and in the notice shown when you booked.
What we collect
From business owners with an account
- Name, email address, and optionally a phone number and business address.
- A password, stored only as a salted PBKDF2-SHA256 hash. We never hold the password itself.
- Records of administrative actions on the account, such as when it was created or its password reset.
From people booking an appointment
- Name, email address and mobile number.
- The street address, but only for services carried out at your address.
- Anything typed into the notes field on the booking form.
- The content of a chat, if the business has switched on the AI assistant.
We do not ask for government identification numbers, health records, financial account details or any other category the Act classifies as sensitive personal information. The notes field is free text, so please do not enter anything you would not want the business to hold.
Technical records
We keep counters used to block abuse of the booking form and the chat. IP addresses are never stored as we receive them. They are converted to a salted one-way hash that can be compared but not reversed, and those rows are deleted after 48 hours.
Why we process it, and on what basis
| Purpose | Basis under section 12 |
|---|---|
| Creating, changing and cancelling an appointment you asked for | Necessary to fulfil a contract with you, or to take steps at your request before entering one |
| Sending a confirmation and reminders about that appointment | The same contractual relationship |
| Running and securing the service, including blocking abuse | Legitimate interests of the business and of OtterFlow |
| Marketing messages and recurring reminders not tied to a booking | Your consent, given separately and withdrawable at any time |
Who else receives it
We do not sell personal data and we do not share it for anyone else's marketing. Data reaches these processors only where the relevant feature is switched on for the business you booked with.
| Recipient | What reaches them | Why |
|---|---|---|
| Semaphore, an SMS gateway in the Philippines | Your mobile number and the text of the message | To deliver confirmations and reminders |
| OpenAI | What you type in the chat, and your name and number if you give them | To generate the assistant's replies, only if the business uses it |
| Google Calendar | The appointment time, the service, and any notes you added | To place the booking in the business's calendar, only if connected |
| Our hosting provider | Everything stored by the service | Hosting and backups. Ask us for the current provider. |
OpenAI and Google process data outside the Philippines. Where personal data is transferred abroad, we remain accountable for it under section 21 of the Act.
How long we keep it
Booking records are kept while the business needs them for its own records and for any claim that could arise from the appointment. Retention periods are set for this service as a whole rather than by each business individually, and when they are switched on the booking page states the periods then in force. Once a period is reached the personal details are removed from the record and the appointment itself is kept without them. Short-lived technical records, such as abuse counters and queued webhook deliveries, are deleted automatically within 48 to 72 hours.
Your rights
Under sections 16 and 18 of the Act you may:
- be told what is held about you and why, which is what this notice is for;
- get a copy of your data, and receive it in a portable electronic format;
- have inaccurate data corrected;
- object to processing, including withdrawing consent to marketing messages;
- have data removed or blocked where it is incomplete, outdated, false, or no longer needed for the purpose it was collected for;
- be told if a security incident affects your data, and claim damages for a violation of your rights.
The right to have data removed is not absolute. A business may keep what it needs to defend a legal claim or to meet its own record-keeping obligations. In that case we remove the identifying details and keep only the record of the appointment itself.
To exercise any of these rights over a booking, contact the business you booked with. To exercise them over an OtterFlow account, contact us using the details below. You can also complain to the National Privacy Commission at privacy.gov.ph.
How we protect it
These are the measures actually in place, not a general assurance:
- Traffic is served over HTTPS, with HSTS set in production.
- Passwords are stored as salted PBKDF2-SHA256 hashes. Changing a password signs out every existing session for that account.
- Session cookies are marked HttpOnly, Secure and SameSite, and expire after seven days.
- Each business can reach only its own records. Access is checked on every request.
- The booking form, the chat and the login form are rate limited.
- Client IP addresses are stored only as salted one-way hashes.
- Administrative actions on accounts are recorded with who did them and when.
Security incidents
If a breach is likely to give rise to a real risk to you, we will notify the National Privacy Commission and the people affected within 72 hours of learning about it, as section 20 requires.
Contact
Email: hello@otterflow.ph
Changes
When this notice changes, the version number at the top changes with it. The version shown to you at the time you booked is recorded with your booking, so it stays clear which text applied.