Privacy Policy

Last Updated: August 26, 2026

KLARO Solutions Inc. ("KLARO," "Company," "we," "us," or "our") is committed to protecting your privacy and handling your personal and business data with transparency and care. This Privacy Policy explains what information we collect, how we use and store it, with whom we share it, and what rights the user ("Subscriber," "you") has over their data when using the KLARO platform (the "Service").

This Policy is issued in compliance with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations (IRR), and applicable issuances of the National Privacy Commission (NPC), and applies to all users who access or use the Service.

If you use KLARO on behalf of a business, some of the information below belongs to that business and to the people it deals with — its outlet team, customers, and suppliers — rather than to you personally. Section 7 explains how responsibility for that data is shared between KLARO and the business.

1. Information We Collect

We collect the following categories of information in the course of operating the Service, including data points manually entered, uploaded, or ingested through OCR and related processing workflows:

a. Personal Account Data

  • First name and last name
  • Username (unique identifier chosen at registration)
  • Email address (stored in lowercase)
  • Password (stored as a cryptographic hash — never in plain text)
  • Unique user code (system-generated UUID)
  • Account creation date and last login timestamp
  • Role within your outlet (Owner, Admin, or Staff), and, where configured, your feature-level view/edit permissions
  • If you register or log in using Google: your name and email address as provided by Google

b. Outlet Information

  • Outlet name, description, and industry type
  • Outlet location details (for example region, area, locality/city or municipality, and barangay)
  • Date of business establishment and date joined KLARO
  • Configured operational parameters (e.g., fixed expenses, lead times, review periods, inventory settings)
  • Outlet members or team members: names, usernames, email addresses, assigned roles, and feature-level permissions

c. Product and Supply Catalogue

  • Product names, categories, SKUs, unit selling prices, and product descriptions
  • Supply/ingredient names, units of measurement, unit costs, and pack sizes
  • Bill of materials: recipe components mapping products to their required supplies and quantities

d. Supplier and Client Information

  • Supplier name, type of supply provided, contact person name, contact number, email address, address, and payment terms
  • Client/customer records an outlet chooses to keep for its own billing or accounts receivable purposes, and related contact details

e. Sales, Logbook, and Receivables Data

  • Uploaded images of sales records (tally sheets, handwritten logbooks, screenshots, and point-of-sale outputs)
  • Extracted sales entries: product name, quantity sold, unit price at time of entry, and total sale value
  • Payment method summaries (e.g., cash, card, online payment) and, where recorded, accounts receivable payment instalments (amount, date, method, notes)
  • Log dates, log titles, and user notes associated with each entry
  • Confidence scores and extraction metadata generated during AI processing

f. Inventory, Operating Expense, and Payroll Data

  • Uploaded images of vendor receipts, stock intake records, operating-expense receipts, and payroll or payout records
  • Extracted inventory inflow records: supply name, quantity received, unit cost, and total cost
  • Extracted operating-expense and payroll line items: description or payee, category, and amount — payroll line items may include the names of an outlet's own staff or payees, entered and controlled by the outlet, not by KLARO
  • Records of stock used without a corresponding sale (e.g., spoilage, samples, damage) and their value
  • Calculated supply usage, end-of-day inventory balances, and stock-on-hand figures

g. Fixed Expense Records

  • Expense category names and amounts (in Philippine Peso)
  • Timestamps of each expense entry

h. Subscription and Usage Data

  • Subscription plan tier (Free, Business, Multi-Outlet, or Institution)
  • Subscription status, billing cycle, start and end dates
  • Monthly OCR scan usage count and applicable scan limit

i. Technical and Session Data

  • IP address
  • Browser type, device type, and operating system
  • Session cookie: a browser-session cookie by default, cleared when you close your browser, or a persistent cookie lasting 30 days if you select "Remember Me" at login
  • CSRF token (required for secure form submission)

j. Lead and Contact Form Data

Name, email address, business type, and message body submitted via contact, waitlist, or support forms

k. KLARO Connect (Buyer-Seller Marketplace) Data

  • If you register or take part as a buyer: your account data (as in a. above), the outlets you shortlist, and the product, quantity, frequency, and region details of any quotation request or message you send to an outlet
  • If your outlet is discoverable to buyers: the outlet-level supply information you choose to make visible, and the quotation requests and messages buyers send to you

2. How We Use Your Information

We use the information we collect to operate, secure, and improve the Service. Specific purposes include:

  • Creating and managing your account and outlet profile
  • Processing uploaded images through AI-assisted OCR to extract sales, inventory, expense, payroll, and receivables data
  • Populating your dashboard, financial statements, analytics, and inventory management outputs
  • Calculating inventory levels, supply usage, cost of goods, receivables aging, and other business performance metrics
  • Operating KLARO Connect, including matching buyer demand with outlet supply
  • Managing subscription plans, billing, and usage limits
  • Ensuring platform security, preventing fraud and unauthorized access, and enforcing our Terms and Conditions
  • Responding to support inquiries and communicating platform updates, service notices, or changes to this Policy
  • Complying with applicable legal and regulatory obligations
  • We do not sell your personal data. We do not use it for advertising or unrelated third-party marketing.

Beyond operating the Service for your own outlet, KLARO may also compile aggregated, statistical, or anonymized information — information that does not identify you or your outlet as an individual data subject — for purposes such as internal product improvement, sector- or market-level analysis, supply mapping, benchmarking, and market-access initiatives that support Philippine SMEs generally. Where KLARO intends to use identifiable Personal Data for a purpose beyond providing the Service to you, we will do so only on an appropriate lawful basis under RA 10173 and, where legally required, with appropriate notice, consent, or other safeguards.

3. Third-Party Service Providers and Processing

Certain features of the Service require sharing your data with third-party service providers who help us operate KLARO. We require these providers to maintain appropriate contractual confidentiality, privacy, and security obligations regarding your data.

a. AI-Assisted OCR and Image Processing

When you upload images to the scanning feature, those images are transmitted to third-party AI providers for optical character recognition (OCR) and data extraction. Relevant contextual information, such as your outlet's product and supply catalogue, may also be shared with these providers where reasonably necessary to improve extraction accuracy. We require our AI/OCR providers to handle submitted data under contractual and/or API terms that limit its use to providing the contracted service. We do not represent that every provider guarantees zero data retention, that data never leaves the Philippines, or that no provider ever uses submitted data to improve its own models beyond what its published terms allow. If you have heightened data-handling requirements for particular records, contact us before relying on this feature for them.

b. Authentication via Google

If you choose to register or log in using Google, you will be redirected to Google's authentication service. KLARO requests only your basic profile information (name and email address) and does not request access to your Google Drive, Calendar, Contacts, or other Google services. Google's handling of your data during this flow is governed by Google's own Privacy Policy.

c. Cloud Infrastructure and Storage

The Service, including its database and uploaded media, is hosted on third-party cloud infrastructure located outside the Philippines. Your data may therefore be processed and stored outside the Philippines, subject to the safeguards described in this Policy and required under RA 10173.

d. Internal Notification Services

Submissions made through the contact, waitlist, and support forms (name, email, and message) are forwarded via Telegram to a private internal notification channel accessed solely by KLARO Solutions Inc. staff, so our team can review and respond. This data is also stored in the KLARO database for our business records.

e. Payment Processing

If you subscribe to a paid plan, your payment method information is collected and processed by our payment gateway, as described in KLARO's Charging Terms.

4. Legal Bases for Processing

We process Personal Data on the following lawful bases recognized under RA 10173, depending on the specific processing activity:

  • Consent: where you are asked to and do give specific consent for a processing activity, such as optional communications
  • Contractual necessity: where processing is required to provide the Service you signed up for, such as creating your account, running OCR extraction, and generating your dashboard
  • Legal obligation: where we must process data to comply with Philippine law or a lawful order of a competent authority
  • Legitimate interests: for activities such as maintaining platform security, preventing fraud, and improving the Service, carried out in a way that does not override your fundamental rights

Accepting this Policy at registration is not blanket consent for every possible future use of your data. Where a specific processing activity relies on consent as its legal basis, that consent is obtained separately for that activity and can be withdrawn without affecting processing carried out under another lawful basis.

5. Data Sharing and Disclosure

We do not sell, rent, or trade your personal or business data. We share it only in the following circumstances:

  • Within your outlet: members of your outlet can access shared outlet data (catalogues, logbooks, inventory, expenses) according to their assigned role and permissions
  • KLARO Connect: if you use the buyer-seller marketplace feature, limited outlet or buyer information is shared with the other party as described in Section 1.k
  • Third-party service providers: as described in Section 3, with AI/OCR, cloud infrastructure, authentication, and payment providers under contractual data protection obligations
  • Aggregated or anonymized information: as described in Section 2, for business intelligence, sector analysis, and market-access initiatives
  • Legal requirements: to government authorities, law enforcement, or courts when required by law, valid legal process, or to protect the rights, property, or safety of KLARO, our users, or the public
  • Business transfers: in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction; we will give notice through the Service or by email before this happens where required by law
  • Institutional or enterprise Clients: where you use KLARO under an institutional arrangement, processing of your outlet's data may additionally be governed by a separately executed Data Processing Agreement (DPA) or Master Services Agreement (MSA), which supplements, and does not narrow, the protections in this Policy.

6. Data Retention

We keep Personal Data only for as long as reasonably necessary for the purpose it was collected, our legitimate business and contractual needs, security requirements, or applicable legal and regulatory obligations. Where a fixed retention period has not been separately established for a category below, we apply these criteria to decide when the data is deleted, anonymized, or otherwise disposed of.

  • Account and outlet data: kept for as long as your account or outlet remains on the platform, and for a further period afterward where needed for legal, accounting, security, or dispute-resolution purposes
  • Original uploaded images and extracted operational records (sales, inventory, expenses, payroll): kept as part of your outlet's operating records for as long as the related account or outlet exists
  • Temporary files created locally on our servers during OCR processing: deleted automatically once each processing attempt finishes, whether it succeeds or fails
  • Accounts receivable collection scans: the receipt images used to extract collection payment data are not stored; only the extracted payment records are kept
  • Processing job tracking metadata: purged automatically after 30 days; this does not affect the underlying sales/inventory records or images, which are tracked and retained separately
  • System and security logs, including login-attempt tracking used for account lockout protection: retained for a limited period sufficient for security monitoring, then purged on a rolling basis
  • Contact, waitlist, and support submissions: retained as business records for as long as reasonably necessary to address your inquiry and for our own recordkeeping
  • Billing and payment-method references: retained while your subscription is active, and purged approximately 90 days after cancellation once no outstanding paid obligation remains, consistent with our Charging Terms

Deactivation and deletion work differently from one another. A member's access to an outlet, or a user account, can be deactivated rather than deleted, which suspends access while the underlying records are kept — for example, so a business does not lose its records if a staff member's access is later restored, or while an unresolved billing or legal matter is pending. Separately, an outlet owner can permanently delete a secondary outlet (not an account's sole outlet) from within the Service; doing so permanently removes that outlet's stored records and cannot be undone. Deleting a KLARO user account entirely, or deleting your only outlet, is not currently available as a self-service action — see Section 10 for how to request erasure or blocking of your data.

7. Roles Under the Data Privacy Act: Personal Information Controller and Processor

Depending on the processing activity, KLARO may act in different roles recognized under RA 10173:

  • Where an institutional or business Client submits, uploads, or has its outlet team enter Personal Data about its own staff, customers, or suppliers — for example, payroll line items, client records, or supplier contacts — that Client acts as the Personal Information Controller (PIC) for that data, and KLARO acts as a Personal Information Processor (PIP), processing it according to the Client's instructions and this Policy.
  • For information where KLARO independently determines the purpose and means of processing, such as your own account credentials, subscription and billing records, platform security logs, and aggregated/anonymized analytics, KLARO acts as a PIC.
  • Institutional or enterprise processing may additionally be governed by a separate Data Processing Agreement (DPA), which governs the PIC/PIP relationship for that Client in more detail. This Privacy Policy is KLARO's general privacy notice to individual users and does not replace or limit any DPA in place with an institutional Client.

8. Data Security

We implement reasonable and appropriate organizational, physical, and technical safeguards to protect your data, including:

  • Encrypted transmission of data over HTTPS (TLS)
  • Cryptographic hashing of account passwords
  • HTTPOnly, SameSite session cookies to reduce exposure to client-side script access
  • Cross-site request forgery (CSRF) protection on form submissions
  • Automatic lockout after repeated failed login attempts, and rate limiting on key endpoints to mitigate abuse
  • Role- and permission-based access controls limiting what outlet members can view or edit
  • Private, access-controlled storage for uploaded images and documents
  • No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe your account has been compromised, contact us immediately at info@meetklaro.com.

9. Cookies and Session Management

KLARO uses the following browser cookies, all necessary for the Service to function:

  • Session cookie: keeps you signed in. By default it is a browser-session cookie cleared when you close your browser; if you select "Remember Me" at login, it persists for 30 days instead. This cookie is HTTPOnly and cannot be read by JavaScript.
  • CSRF token cookie: required to secure form submissions and prevent cross-site request forgery attacks.
  • As of the date of this Policy, KLARO does not use third-party advertising, tracking-pixel, or behavioral-analytics cookies. If this changes, we will update this Policy. You may disable cookies in your browser settings, but doing so will prevent you from logging in or using the Service.

10. Your Rights as a Data Subject

Under the Philippine Data Privacy Act of 2012 (RA 10173), you have the following rights over your Personal Data:

  • Right to be Informed: to be notified of how your data is collected, used, and stored
  • Right to Access: to request a copy of the Personal Data we hold about you
  • Right to Rectification: to request correction of inaccurate or incomplete Personal Data
  • Right to Object: to object to the processing of your Personal Data on legitimate grounds
  • Right to Erasure or Blocking: to request the erasure or blocking of your Personal Data
  • Right to Data Portability: to receive your Personal Data in a structured, commonly used format
  • Right to Damages: to be indemnified for damages sustained due to inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorized use of Personal Data
  • Right to File a Complaint: to lodge a complaint with the National Privacy Commission (NPC) at www.privacy.gov.ph

We will evaluate any request to exercise these rights in accordance with RA 10173 and its IRR. We may fulfil a request through deactivation, restriction, or anonymization rather than immediate deletion, or decline or limit it, where retention remains necessary or permitted — for example, for legal or regulatory obligations, the establishment, exercise, or defense of legal claims, security and fraud prevention, legitimate business or accounting records, contractual obligations to you or to an institutional Client, or another lawful purpose recognized under applicable law. Where you ask us to erase or block data that an institutional Client controls as PIC (see Section 7), we will refer your request to that Client and assist as needed.

To exercise any of these rights, contact us at info@meetklaro.com. We will acknowledge and respond within a reasonable time in accordance with RA 10173.

11. Personal Data Breaches

KLARO maintains procedures to identify, investigate, assess, contain, document, mitigate, and remediate suspected or confirmed Personal Data Breaches affecting the Service. Not every security incident rises to the level of a notifiable Personal Data Breach under RA 10173 and NPC regulations. Where a breach meets the applicable legal thresholds, we will notify the NPC and affected data subjects in accordance with NPC requirements, including its 72-hour notification framework. Where KLARO is acting as a Personal Information Processor for an institutional Client (see Section 7), we will notify that Client without undue delay and reasonably assist it in meeting its own notification obligations as the Personal Information Controller.

12. Third-Party Links

The Service may contain links to third-party websites or tools. KLARO is not responsible for the privacy practices, content, or data handling of any third-party sites. We encourage you to review the privacy policies of any external services you access.

13. Children's Privacy

KLARO is intended solely for users who are 18 years of age or older. We do not knowingly collect Personal Data from minors. If we become aware that Personal Data from a minor was collected without appropriate consent, we will take appropriate steps, which may include deactivating the account and erasing, blocking, or otherwise limiting further use of that data, consistent with Section 10 and the retention grounds in Section 6.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or platform features. Where changes are material, we will give notice through the Service, by email to your registered address, or through another reasonable mechanism, before or promptly after the change takes effect. Continued use of the Service after a change takes effect indicates your acceptance of the updated Policy for processing going forward; it is not the sole basis we rely on for processing that legally requires your specific consent. If you do not agree with an updated Policy, you should stop using the Service and may contact us to discuss your options regarding your account.

15. Contact and Data Privacy Inquiries

For all privacy-related inquiries, data subject requests, or concerns regarding this Policy:

Business Name: KLARO Solutions Inc.
Business Address: 50 Esteban Abada St., Loyola Heights, Quezon City, Metro Manila, Philippines 1108
Email: info@meetklaro.com

You also have the right to file a complaint with the National Privacy Commission (NPC) of the Philippines if you believe your privacy rights have been violated: www.privacy.gov.ph