The short version

  • We collect only what we need to run the service and the website.
  • We don't sell your data. Ever.
  • You can export everything you've given us, in open formats, at any time.
  • You can delete your account and we'll erase your data within 30 days, unless we're legally required to keep something.
  • Your data is encrypted in transit and at rest.

1. Who we are

Boongon ("we", "us", "our") provides an ERP and accounting software-as-a-service platform. For the purposes of the Philippine Data Privacy Act of 2012 ("DPA") and the EU General Data Protection Regulation ("GDPR"), we are the Personal Information Controller for data collected through this website (boongon.com) and the Personal Information Processor for data your organization stores in the Boongon product.

Reach our Data Protection Officer at hello@boongon.com.

2. What we collect

From this website

  • Analytics. We use Google Analytics 4 to see which pages help and which do not. It loads only if you accept cookies, and it sets its own cookie carrying a random identifier for your browser when you do. We enable IP anonymisation and we do not use it for advertising or cross-site tracking. Reject cookies and it is never loaded.
  • Contact form / email. When you write to us, we keep your message and email so we can reply.
  • Account sign-up. Email address, organization name, and the password you choose (stored as a salted hash, never in plain text).
  • Cookies and local storage. Small files for things like your selected language, currency, and theme. These don't leave your device.

Inside the Boongon product

Your transactional and operational data, invoices, journal entries, employee records, etc. We process this on your behalf under the instructions of your organization. Your organization is the Personal Information Controller for this data; we are the Processor.

3. Why we collect it

  • To run the service, process transactions, generate forms, deliver the product.
  • To reply to you, respond to support, sales, and contact-form messages.
  • To improve the product, aggregate, de-identified analytics to understand which pages help and which don't.
  • To meet legal obligations, retain certain records (tax invoices, payroll) for the periods required by law.

4. How long we keep it

  • Website analytics, 14 months.
  • Contact-form messages, 24 months after the last reply, then deleted.
  • Account data, for the life of the account, plus 90 days after closure (so accidental closures can be reversed).
  • Customer transactional data, as long as your organization keeps a Boongon subscription, plus 30 days after termination. Some financial records may be retained longer where required by law.

5. Who we share with

A small number of vendors who help us run Boongon. Each is bound by a Data Processing Agreement and processes data only on our documented instructions. This is everything the product and this website actually load, named rather than described:

  • Supabase, application database, authentication and server-side functions.
  • Cloudflare, website hosting, edge network and secret storage.
  • Resend, transactional and contact-form email delivery.
  • Google Analytics, website analytics, loaded only after you accept cookies.
  • Google Fonts, web font delivery on this website.
  • Crisp, website chat, where enabled.
  • Frankfurter, exchange-rate reference data for the currency switcher.
  • PayMongo, HitPay and PayPal, card and wallet payment processing.

We do not store your full card number; that is handled by the payment processor.

We do not sell, rent, or trade your data to anyone. We do not use your data to train AI models.

6. Where the data lives

The application database runs in a single region. We do not publish which region or the jurisdiction its backups sit in until we are prepared to stand behind those as commitments rather than descriptions — if your procurement needs them in writing, ask us and we will tell you under a data-processing agreement. Some operational vendors (email, analytics) process data in other regions; these transfers are covered by Standard Contractual Clauses or equivalent safeguards.

7. Your rights

Under the Philippine Data Privacy Act and (where applicable) the GDPR, you have the right to:

  • Know what we hold about you, and request a copy.
  • Correct anything that's inaccurate.
  • Ask us to delete your data, unless we're legally required to keep it.
  • Object to or restrict certain processing.
  • Withdraw consent at any time, where consent is the legal basis.
  • Lodge a complaint with the National Privacy Commission (privacy.gov.ph) or your local supervisory authority.

Email hello@boongon.com to exercise any of these rights. We respond within 15 business days.

8. Security

Data is encrypted in transit and at rest. These are standard controls provided by our hosting and database platforms; we deliberately do not quote specific protocol or cipher versions here, because we cannot evidence them from our own configuration. Access to production systems is restricted, logged, and requires multi-factor authentication. We follow the principle of least privilege: only the people who need a specific piece of data to do their job can see it.

Our security page sets out what the product enforces, what our providers operate, and — just as plainly — what is not in place.

If a security incident affects your data, we'll notify you and the National Privacy Commission within 72 hours of confirming the breach.

9. Children

Boongon is a business product, not intended for individuals under 18. We do not knowingly collect personal data from children.

10. Changes to this policy

If we make material changes, we'll notify active account holders by email and update the "Last updated" date at the top. Continued use after a change means you accept the updated policy.

11. Contact

Questions, requests, or complaints: hello@boongon.com.