AAbtivo

Pilot privacy notice

This notice explains how personal information is handled in the Abtivo controlled private pilot: what is collected, why, who can see it, where it is processed, how long it is kept, and how you can use your privacy rights. It applies to everyone taking part: customers, store staff, riders and the operator's admin staff.

Draft — requires review by the pilot owner and a legal adviser before the pilot starts.

Notice version: pilot-2026-09-v1

Who is responsible

Abtivo is a project and product name. It is not a separately incorporated company or registered legal entity. The Abtivo controlled private pilot is operated by Mervin Sarsale, who decides how and why pilot participants' personal information is used and is the personal information controller for the pilot. In this notice, “we”, “us” and “our” mean the operator, Mervin Sarsale, and anyone he authorises to help run the pilot.

Operated by Mervin Sarsale

Email
hatodhelp@yahoo.com
Phone
+63 964 139 0726
Hours
Monday–Friday, 9:00 AM–6:00 PM Philippine Time

What the pilot is

Abtivo is currently operated as a controlled private pilot. Pilot participants are real people, but orders, payments, refunds and payouts shown in Abtivo are simulated for testing purposes only. No real goods are purchased, sold or delivered through Abtivo during this phase, and Abtivo must not be used to conduct real commercial transactions. Never enter real card, bank or e-wallet details anywhere in the pilot.

What we collect

  • Account details: your name, email address, password (stored only as a one-way hash that can't be read back), your role in the pilot (customer, store staff, rider or operator staff), whether your account is active or suspended (with the reason recorded for a suspension), and which version of this notice you accepted and when.
  • Invitations: the email address an invitation was issued for, who created it, any note the operator added to it, and when it was used. Invitation codes are stored only as a one-way hash.
  • Delivery addresses: label, recipient name, street address, city, province, postal code, map pin, and the optional mobile number and delivery notes you add. A copy of the delivery address is kept with each order.
  • Orders and after-sales: what is in your cart, items, store, simulated amounts, simulated payment and refund records, order status history, cancellation reasons, return requests and their descriptions, ratings and optional review comments, and in-app notifications.
  • Delivery records: delivery status history, the name of the person who received the order (entered by the rider), reasons for a failed delivery, and the pickup and delivery codes used to confirm handovers.
  • Store staff: your name, email address, store role, and the actions you take for your store (for example confirming, cancelling or handing over orders). For the store itself we keep the details given at onboarding: store name and legal name, branch address, map location and phone number, and a support email address. The support email is the store owner's own email address unless another one is given.
  • Riders: name, email address, mobile number, vehicle type, plate number and service area given at onboarding; your verification status and any note the operator adds when approving, rejecting or suspending you; whether you are online and when you were last active; your job history (including jobs you declined and simulated earnings) and ratings; and your phone's location (see “Rider location” below). Before approving a rider, the operator checks the rider's driver's licence, vehicle registration (OR/CR) and ID offline. These documents are not uploaded to or stored in Abtivo.
  • Proof photos: optional pickup and delivery photos taken by riders. They may show the package, the place and anyone in the frame. The rider app saves them without the photo's location data.
  • Your browsing area: if you share your device location or choose an area on the website to see nearby stock, it is kept in a cookie on your device for up to 30 days, not in our database (unless you save it as a delivery address).
  • Audit records: a record of important actions, such as sign-ups, notice acceptance, invitations, suspensions, rider and store verification, store team changes, password resets by the operator, order cancellations (including whether a simulated refund was started), return decisions and retention clean-ups, with who did them and when. Entries can include the reason or note entered for the action (for example a suspension or cancellation reason). Some include a partly hidden email address (first letter and domain).
  • Technical information: sign-in session records (including IP address and browser or device details), and request, application and error logs kept by our hosting provider. These logs can include your IP address, the page or API address you used, browser or device details, and short technical entries that may include an account or order reference.
  • Support and privacy requests: the messages you send to the operator by email, phone or messaging, and the operator's own records of requests and incidents (for example a reference, dates, what was asked, how your identity was checked and what was done).

We don't use advertising or analytics trackers, and we don't sell personal information or use it for marketing.

Rider location

While you are online in the rider app, it sends your location when you go online and then about every 3 minutes; during an active delivery, about every 20 seconds and at each delivery step. We keep your latest position and the time it was sent (each update replaces it). During an active delivery we also keep a trail of your positions: a position is saved whenever at least 30 seconds have passed, or you have moved at least 150 metres, since the last saved one. In practice that is about every 20 to 40 seconds while the delivery screen is open. We also save your position at each delivery step. The app uses location only while it is open; it doesn't track you in the background. Going offline stops location sharing (you can't go offline during an active delivery).

Customer location

Your device's location is used only when you choose to share it, for example to show stores near you or to fill in a delivery address. In the Android app, turning your location into a street address uses your phone's built-in address lookup, which is provided by your phone's platform services (for example Google).

Why we use it

  • To run the pilot: create, check and approve accounts (including verifying riders and stores before they can take part), keep accounts secure, send invitations, suspend accounts when needed, and keep you signed in.
  • To show stores and stock near you, take and track simulated orders, offer delivery jobs to nearby riders, show customers where their delivery is, and handle cancellations, returns and simulated refunds.
  • To keep proof and records of what happened, so problems, disputes, misuse and security incidents can be looked into.
  • To support you and answer your requests.
  • To find and fix problems, and to learn whether the service works.

We process your information because you agreed to it when you joined the pilot, because it is needed to run the pilot you take part in and keep it secure, and where the law requires it.

Who can see your information

Each person sees only the information that goes with their part in the pilot, as described below.

  • You: your own account, addresses, orders, returns, notifications and delivery status, including the proof photos of your deliveries.
  • Store staff (orders placed with their own store only): items, simulated amounts, your first name, your delivery area (the city only, not your street address or mobile number), your cancellation and return reasons and the rider's reason for a failed delivery, the delivering rider's full name, vehicle and plate number, and the rider's proof photos for those orders, which may show the place of delivery and anyone in the frame.
  • Riders: before accepting a job, only the store, the items ordered and the general delivery area (the city and a point accurate to about 1 km). After accepting: the recipient's name, delivery address and notes, and the exact drop-off point; the recipient's mobile number is shown in the app only from pickup until delivery. If the rider calls you, the call goes through the rider's phone and mobile network, and your number may stay in the rider's call history after the delivery. Once the delivery has ended, the rider sees only a summary without the street address, notes or exact drop-off point.
  • Customers see the delivering rider's first name, vehicle type and plate number, and the rider's live position while the delivery is active.
  • Store details: anyone using the pilot sees a store's name and its branches' names, city and distance. Customers see the store and branch of their orders and the branch's location on the tracking map; the order information sent to their website or app also includes the branch's address and phone number. Riders see the store's name and address for a job, and the branch's phone number once they have accepted it.
  • Your store's team: everyone on a store's team sees the team members' names and store roles and, depending on their role, the names of team members who acted on the store's orders and stock. Within the store, only owners see team members' email addresses, and owners and managers also see the store's activity log of staff actions. Customers and riders don't see store staff names.
  • Operator admin staff: the operator can access all pilot information, including through the hosting and database accounts. Anyone else the operator gives an admin role sees only what that role allows. Support, operations and finance staff can open orders, including the customer's full name and email address, the proof photos and the rider's position at each delivery step. Support and operations staff can also look up accounts and rider profiles. Support, operations and catalogue staff can see store teams (names and email addresses). Operations and finance staff can read the audit log. For example, support staff can view accounts and orders; operations staff can also suspend accounts and cancel or recover orders (cancelling a paid order starts a simulated refund); finance staff can view orders and decide return requests, which can start a simulated refund; the super admin can do all of these. Admin access is used only to operate the pilot, support participants, keep it secure, investigate problems and incidents, and administer accounts.
  • Service providers: Vercel (application hosting) and Neon (database hosting) store and process pilot information to provide their services to the operator, under their own terms and privacy policies. Vercel also keeps its own records of requests, which may include IP addresses. If you contact support by email, your message is handled by the operator's email provider (Yahoo Mail); by phone or messaging, by the phone or messaging service you use. On the website's order-tracking map, your browser loads map images from OpenFreeMap, which receives your IP address and the map area shown. When a rider taps “Open customer in maps” (or “Open store in maps”) in the Android rider app, the exact drop-off point (or the store's location) is passed to the navigation app the rider chooses on their phone, for example Google Maps, and that app's provider may receive it.
  • Anyone else only when the law requires it or to protect someone's safety.

Developers and AI assistants

Apart from the service providers listed above, we don't routinely give identifiable participant information to developers, AI assistants (such as ChatGPT or Claude) or any other third party. Abtivo is built and maintained with the help of an AI coding assistant (currently Claude Code, provided by Anthropic), which can technically reach the pilot's hosting and database accounts. It is used there to deploy the app, check that it is running and, with the operator's approval, run checks that return only counts. It is not used to read identifiable participant records. Developers and AI assistants use synthetic, redacted or anonymised data for development, testing and troubleshooting; the operator uses real information only as described above, to support participants and investigate problems. Any exceptional need to look at real participant information must be specifically justified, authorised by the operator and limited to the minimum needed. If an approved exceptional need involves an AI assistant, the information it sees is also processed by that assistant's provider (for example Anthropic).

Where it is processed

Abtivo's main pilot infrastructure is in Singapore. The application runs on Vercel in its Singapore region (sin1), and the database is hosted by Neon in its Singapore region (AWS ap-southeast-1). Vercel and Neon are third-party service providers, so your information is transferred to and processed in Singapore. Requests between your device and Abtivo may pass through Vercel's global network in other countries on the way. Some information also goes to, or is copied in, other places, which may be outside Singapore and the Philippines: your own device; the operator's email provider (Yahoo Mail) and the phone or messaging service you use to contact support; the operator's devices while handling support; backup copies made by the operator; our hosting provider's own logs; OpenFreeMap, which receives your IP address and the map area shown when the website's order-tracking map loads; and, on Android phones, your phone's platform services (for example Google) when your location is turned into an address, and the maps app a rider chooses when opening navigation. We don't claim that all pilot information is stored only in the Philippines or only in Singapore.

How long we keep it

  • Automatic deletions are carried out by a clean-up that runs every few minutes while Abtivo is being used. Each deletion happens at the first clean-up after its deadline, so it can come later than the deadline if nobody uses Abtivo for a while.
  • Proof photos attached to an order: the image is deleted automatically 30 days after the order is completed (delivered, or closed as failed or cancelled). We keep a record that a photo was taken, its type (pickup or delivery), when it was taken, and which order and delivery it belongs to.
  • Proof photos that were never attached to a delivery, for example a retake: deleted automatically after 24 hours.
  • Rider location: position snapshots and the positions recorded with delivery steps are deleted automatically 30 days after the delivery ends; the delivery record itself is kept without them. A rider's last known position is cleared automatically after 30 days without a location update.
  • Everything else (accounts, addresses, orders, delivery records, audit and support records): kept for the duration of the controlled pilot plus 90 days. The operator will tell participants the date the pilot ends; the 90 days count from that date. After that, the operator deletes or anonymises it. This end-of-pilot step is carried out by the operator; it isn't automatic.
  • Exceptions: information may be kept longer only while it is genuinely needed for an unresolved security incident, an unresolved privacy request, an unresolved operational investigation, a legal requirement, or another documented and justified reason. If an order still has an open return or cancellation request, or a refund that is pending or still owed, its proof photos and the rider location for its delivery are kept until that is resolved. They are then deleted automatically, once their 30 days have passed. For an incident, the operator records a retention hold on the order with a reason; photos and rider location for that order are then kept until the hold is released, and deleted automatically afterwards.
  • Backups: our database provider keeps a short restore history of about 6 hours. Backup copies of the pilot database made by the operator are kept for no more than 30 days and are then securely deleted or replaced. This means information removed from the live Abtivo system can remain for about 6 more hours in the database provider's restore history and, if an existing backup copy already contains it, for up to 30 more days in that copy, until the copy expires.
  • Hosting logs: kept by our hosting provider for a limited period under its standard settings.
  • On your device: the browsing-area cookie expires after 30 days. You stay signed in on the website and in the apps until you sign out, or until about 7 days pass without using Abtivo.
  • Proof photos on a rider's phone: the proof photos a rider takes (the camera's original and the smaller copy that is uploaded) stay in the rider app's temporary storage on the rider's phone, and Abtivo's 30-day deletion doesn't reach them. The phone may clear them by itself; clearing the rider app's cache or uninstalling the app removes them. Depending on the phone's camera app, a copy may also be saved in its photo gallery. Riders: please don't copy or share these photos.

Your privacy rights

Under the Philippine Data Privacy Act of 2012 you have the right to be informed, to access your personal information, to object, to have it corrected, to have it erased or blocked, to data portability, to be indemnified for damages, and to file a complaint with the National Privacy Commission. In the pilot, requests are handled manually by the operator:

  • Access and a copy: you can see much of your own information yourself in the website or app: your account, saved addresses, orders, returns and notifications. For other information we hold about you, ask the operator, who prepares a summary by hand from the pilot's records and sends it only to the email address or phone number on your account. The pilot has no self-service download or export tool, so a fuller copy may take longer to prepare, and we will tell you if it does.
  • Correction: the operator can correct your name, email address, mobile number or vehicle details for you. Past order, delivery and audit records, including the copy of the delivery address kept with each order, record what happened at the time and aren't rewritten. You can delete a saved delivery address yourself and add a corrected one.
  • Deletion or closing your account: when the operator handles your request (during support hours), your account is suspended straight away, so it can no longer be used, and you are signed out everywhere. The operator then anonymises your account: your password and sign-in sessions, saved addresses, cart, notifications, phone numbers, plate number and store team memberships are deleted; your name and email address are replaced with a placeholder; the recipient details, street address and notes kept with your orders and deliveries, the reasons, descriptions and comments you wrote, and the proof photos of your orders or taken by you are removed; the rider location records of your deliveries are deleted; and exact delivery points are rounded to about 1 km. What stays, without your name or contact details, is the record that the orders and deliveries happened: order numbers, items, statuses, simulated amounts, ratings, dates and times, the city and province, and the pilot's protected order and audit history. If one of your orders is still open, or is on hold because of an unresolved return, refund or incident, this step waits until it is resolved, and we will tell you. Information deleted this way can remain for a short time in the database provider's restore history and in backup copies, as described under “Backups” above. We will tell you what has been deleted, what is still kept and why, and when it will be deleted. Records that have to be kept, for example because of an unresolved incident or because they are part of the pilot's protected order and audit history, are kept only as long as necessary.
  • Withdrawing consent or objecting: you can stop using the pilot at any time and ask us to close your account. Riders can stop location sharing by going offline when they are not on a delivery. Customers can choose not to share device location.
  • Complaints: please contact us first. You can also contact the National Privacy Commission (privacy.gov.ph).

How to make a request

Email hatodhelp@yahoo.com with “Privacy request” in the subject, or call +63 964 139 0726 during support hours (Monday–Friday, 9:00 AM–6:00 PM Philippine Time). Tell us your name, the email address of your Abtivo account, your role in the pilot and what you are asking for. We may ask you to confirm your identity, but we will never ask for your password. Requests sent outside support hours are handled during the next support hours. We will acknowledge your request and respond as soon as reasonably possible, and tell you if we need more time.

Abtivo was previously called Hatod; the support address keeps its earlier name.

Security

Passwords are stored only as one-way hashes, connections are encrypted (HTTPS), access is limited by role, important actions are recorded in an audit log, and accounts can be suspended immediately. The pilot never collects real card or bank details. No system is perfectly secure. If a personal data breach affects you, the operator will notify you and the National Privacy Commission where the law requires it.

Who can take part

The pilot is only for invited adults aged 18 or over. The operator invites only people aged 18 or over; please don't invite or register anyone younger.

Notifications

During the pilot, Abtivo's notifications appear only inside the website and the apps: Abtivo doesn't send automatic text messages (SMS), notification emails or push notifications. The operator may contact you personally, for example to send your invitation or first password, or to answer a support request.

Changes to this notice

If this notice changes materially, its version number changes. Customers, store staff and riders must then read and accept the new version before they can keep using their account: the website or app asks the next time you use it, even if you are already signed in. Operator admin accounts are not asked to accept it in Abtivo; the operator tells admin staff about changes directly.