Privacy Policy
Your privacy matters to us. Here's how we handle your data — honestly and transparently.
Last Updated: February 14, 2026
Effective: February 14, 2026
The Short Version
Before the legal details, here's a plain-language summary of how we handle your data:
- We don't sell your data. Period.
- We use AI (Anthropic's Claude) to power event planning and supplier matching. Your event details and preferences are sent to Claude's API to generate plans and recommendations. Anthropic does not use this data to train their models.
- Your data lives on secure cloud infrastructure — specifically Amazon Web Services (AWS) and Cloudflare. We use Bunny.net for video hosting.
- Suppliers and organizers share limited info with each other through bookings — only what's needed to coordinate your event.
- We don't process payments directly yet. Suppliers currently track off-platform payments manually within our system. When we integrate payment processing, we'll update this policy before going live.
- We're a Philippine-based startup in closed beta. We operate under the Philippine Data Privacy Act of 2012. If our scope expands internationally, we'll update this policy accordingly.
- You can request your data or ask us to delete it anytime by emailing privacy@kaganapn.com.
That's the gist. The full details are below.
Information We Collect
Information You Provide Directly
- Account Information
- Name, email address, phone number, and password when you register. Account type (organizer or supplier).
- Organizer Information
- Event details: title, date, location, budget, guest count, theme. AI planning prompts and preferences you enter. Guest lists, RSVP responses, and seating arrangements. Messages sent to suppliers through our booking system.
- Supplier Information
- Business name, description, address, and contact details. Service offerings, pricing, and availability. Portfolio photos (up to 20) and feature video (up to 50MB). Social media URLs (Facebook, Instagram, TikTok). Business categories and service locations. Verification documents (government ID, business registration) if submitted. Payment method details you choose to display (GCash, Maya, bank account info, QR codes). Payment records you log for bookings.
- Communications
- Messages exchanged between organizers and suppliers within bookings. Contact form submissions. Contract comments and booking notes.
Information We Collect Automatically
- Usage Data
- Pages visited, features used, and actions taken on the platform. Timestamps and session duration.
- Device & Technical Data
- Browser type and version, operating system. IP address. Server logs, error reports, and performance data.
- Activity Notifications
- We track key platform events (new signups, bookings created, events published) via internal team notifications on Slack. These contain basic event metadata, not your personal conversations or detailed data.
Information We Do Not Collect
- We do not collect precise GPS location data from your device
- We do not access your contacts, camera, or microphone
- We do not currently process credit card numbers, bank account credentials, or any financial authentication data through our platform
How We Use Your Information
To Deliver Our Core Service
- Create and manage your account
- Generate AI-powered event plans based on your inputs
- Match organizers with compatible suppliers based on location, budget, category, and preferences
- Facilitate the booking workflow between organizers and suppliers
- Enable in-app messaging and booking coordination
- Track payment status on bookings (supplier-recorded)
- Send email notifications for booking updates, event reminders, and account activity
To Improve the Platform
- Analyze usage patterns to identify bugs and improve features
- Monitor AI output quality and accuracy
- Track platform performance and uptime
- Aggregate anonymized data for internal analytics (e.g., popular event categories, booking conversion rates)
To Maintain Security & Compliance
- Prevent fraud, abuse, and unauthorized access
- Enforce our Terms of Service
- Comply with the Philippine Data Privacy Act of 2012
- Respond to legal requests when required by law
AI-Powered Features & Data Processing
AI is central to kaganapn. Here's exactly how it works:
What AI Does on Our Platform
- Event Planning: Generates personalized event plans including budget breakdowns, timelines, and recommendations based on your event details and AI prompts
- Supplier Matching: Scores and ranks suppliers based on compatibility with your event requirements (location, budget, category, preferences)
- Supplier Profiles: Generates enhanced supplier descriptions, specialization summaries, and performance insights from business information
- Prompt Optimization: Refines your event planning inputs for better AI-generated results
AI Provider
We use Anthropic's Claude API (models: Claude Haiku 4.5 and Claude Sonnet 4.5) for all AI features. Anthropic's data usage policy states that API inputs and outputs are not used to train their models.
What Data is Sent to Claude
- Event details: title, date, theme, budget, guest count, location, your AI prompt
- Supplier profiles: business descriptions, categories, services, pricing, location
- No personally identifiable information (names, emails, phone numbers) is intentionally included in AI prompts. However, if you include personal details in free-text fields (like your AI prompt or event description), that text will be processed by Claude.
AI Data Safeguards
- We send only the minimum data needed for each AI task
- AI responses are validated by quality scoring before being shown to you
- We log AI usage for cost tracking and quality monitoring (model used, token count, response quality score)
- Daily AI budgets prevent runaway costs and ensure responsible usage
- If AI processing fails, we fall back to rule-based alternatives — your experience continues without interruption
Your Control Over AI
- AI event planning requires an AI prompt — you control what instructions you give
- You can regenerate or customize AI-generated plans
- You can manually browse and select suppliers without relying on AI recommendations
- Core platform features (bookings, messaging, payments) function independently of AI
Third-Party Services We Use
We believe in being specific about who handles your data:
| Service | What They Do | Data They Access |
|---|---|---|
| Anthropic (Claude AI) | AI event planning, supplier matching, profile generation | Event details, supplier profiles, user prompts |
| Amazon Web Services (AWS SES) | Email delivery | Email addresses, notification content |
| Cloudflare (R2 Storage) | File storage for photos, documents, uploads | Uploaded files (photos, verification docs) |
| Bunny.net (Stream) | Video hosting and CDN for supplier videos | Supplier feature videos |
| Google reCAPTCHA | Bot protection on forms | IP address, browser behavior signals |
| Slack | Internal team notifications for platform activity | Basic event metadata (no personal conversations) |
Anthropic (Claude AI)
Purpose: AI event planning, supplier matching, profile generation
Data: Event details, supplier profiles, user prompts
Amazon Web Services (AWS SES)
Purpose: Email delivery
Data: Email addresses, notification content
Cloudflare (R2 Storage)
Purpose: File storage for photos, documents, uploads
Data: Uploaded files (photos, verification docs)
Bunny.net (Stream)
Purpose: Video hosting and CDN for supplier videos
Data: Supplier feature videos
Google reCAPTCHA
Purpose: Bot protection on forms
Data: IP address, browser behavior signals
Slack
Purpose: Internal team notifications for platform activity
Data: Basic event metadata (no personal conversations)
We do not use any advertising networks, tracking pixels, or third-party analytics platforms that follow you across the web.
Future Addition: We plan to integrate payment processing (e.g., PayMaya, GCash API) for direct transactions. When we do, this section will be updated before launch to disclose the payment processor and what financial data they will access.
Information Sharing
We do not sell, rent, or trade your personal information.
Between Platform Users
- Organizer → Supplier
- When you create a booking, the supplier sees your name, event details, messages, and booking requirements.
- Supplier → Organizer
- Organizers see your business profile, services, pricing, portfolio, reviews, and displayed payment methods.
- Public Profiles
- Supplier profiles, including business name, description, categories, photos, videos, and reviews, are publicly visible in our supplier directory.
- Guest RSVP
- Guests who receive an RSVP link can see event date, time, and location — but not budget or supplier details.
With Service Providers
Only as described in Section 4 above, and only to the extent necessary to provide our services.
For Legal Reasons
We may disclose your information if required by Philippine law, regulation, or court order, or to protect the safety of our users or the public.
Business Transfers
If kaganapn is acquired, merges, or sells assets, your data may transfer as part of that transaction. We will notify you via email and platform notice before any such transfer and before your data becomes subject to a different privacy policy.
Data Security
What We Do
- All data encrypted via SSL/TLS (HTTPS)
- Files stored on Cloudflare R2 with access controls
- Database access restricted, credentials managed through environment variables
- Supplier registration is invite-only
- Secure, HTTP-only session cookies
- Verification documents accessible only to authorized admin users
What We Acknowledge
No system is 100% secure. We're a small team building a startup, and while we follow security best practices, we don't yet have SOC 2 certification or a dedicated security team.
We're transparent about this because we'd rather be honest than make claims we can't back up.
If we discover a data breach that affects your personal information, we will notify you and the Philippine National Privacy Commission as required by law.
Your Privacy Rights
Under the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), you have the following rights:
Right to Be Informed
Know what data we collect, how we use it, and who we share it with. (That's what this policy is for.)
Right to Access
Request a copy of all personal data we hold about you.
Right to Correction
Request correction of inaccurate or outdated information. You can also update most information directly through your profile settings.
Right to Erasure or Blocking
Request deletion of your personal data, subject to legitimate business or legal retention requirements.
Right to Object
Object to processing of your data for purposes beyond what's necessary for our service.
Right to Data Portability
Request your data in a structured, commonly used format.
Right to Damages
Seek compensation if your data is mishandled in violation of the Data Privacy Act.
Right to File a Complaint
Lodge a complaint with the National Privacy Commission (NPC) if you believe your rights have been violated.
How to Exercise Your Rights
Email us at privacy@kaganapn.com with your request. We will:
- Acknowledge your request within 3 business days
- Verify your identity before processing
- Fulfill your request within 30 days (or explain why we need more time)
- Provide the service at no cost for reasonable requests
Data Retention
- Active Accounts
- We retain your data for as long as your account is active.
- Deleted Accounts
-
If you request account deletion, we will:
- Remove your personal profile information within 30 days
- Retain anonymized booking and transaction records as required for business and legal purposes
- Delete uploaded files (photos, documents, videos) within 30 days
- Inactive Accounts
- Accounts with no login activity for 24 months may be flagged for review and potential deletion, with advance email notice.
- AI Data
- AI-generated plans and recommendations are stored as part of your event data and follow the same retention policy. AI score caches expire automatically after 24 hours.
- Backups
- Deleted data may persist in encrypted backups for up to 90 days before being purged.
Beta Program Considerations
kaganapn is currently in closed beta. This means:
- Features may change, and data flows may be adjusted as we develop the platform
- We may collect additional usage feedback and interaction data to improve the product
- Beta participants may be contacted for feedback or usability testing (you can opt out)
- We will notify you of any material changes to how we handle your data during the beta period
If kaganapn discontinues operations, we will:
- Provide at least 30 days' notice via email
- Give you the opportunity to export or request your data
- Securely delete all personal data within 60 days of shutdown
Children's Privacy
kaganapn is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from minors.
If you are a parent or guardian and believe a minor has provided personal information to us, please contact us at privacy@kaganapn.com and we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy as our platform evolves. When we do:
- We will update the "Last Updated" date at the top
- For material changes (new data collection, new third-party providers, payment processing integration), we will notify you via email before the changes take effect
- Continued use of kaganapn after changes take effect constitutes acceptance of the updated policy
Contact Information
Privacy Questions & Data Requests
privacy@kaganapn.com
Response Time
Within 3 business days for acknowledgment; 30 days for fulfillment
General Inquiries
hello@kaganapn.com
Regulatory Authority
National Privacy Commission (NPC) — https://privacy.gov.ph
kaganapn is operated from Cebu, Philippines. This Privacy Policy is governed by Philippine law, specifically the Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations.