Privacy Policy

Your privacy matters to us. Here's how we handle your data — honestly and transparently.

Last Updated: February 14, 2026

Effective: February 14, 2026

The Short Version

Before the legal details, here's a plain-language summary of how we handle your data:

  • We don't sell your data. Period.
  • We use AI (Anthropic's Claude) to power event planning and supplier matching. Your event details and preferences are sent to Claude's API to generate plans and recommendations. Anthropic does not use this data to train their models.
  • Your data lives on secure cloud infrastructure — specifically Amazon Web Services (AWS) and Cloudflare. We use Bunny.net for video hosting.
  • Suppliers and organizers share limited info with each other through bookings — only what's needed to coordinate your event.
  • We don't process payments directly yet. Suppliers currently track off-platform payments manually within our system. When we integrate payment processing, we'll update this policy before going live.
  • We're a Philippine-based startup in closed beta. We operate under the Philippine Data Privacy Act of 2012. If our scope expands internationally, we'll update this policy accordingly.
  • You can request your data or ask us to delete it anytime by emailing privacy@kaganapn.com.

That's the gist. The full details are below.

1.

Information We Collect

Information You Provide Directly

Account Information
Name, email address, phone number, and password when you register. Account type (organizer or supplier).
Organizer Information
Event details: title, date, location, budget, guest count, theme. AI planning prompts and preferences you enter. Guest lists, RSVP responses, and seating arrangements. Messages sent to suppliers through our booking system.
Supplier Information
Business name, description, address, and contact details. Service offerings, pricing, and availability. Portfolio photos (up to 20) and feature video (up to 50MB). Social media URLs (Facebook, Instagram, TikTok). Business categories and service locations. Verification documents (government ID, business registration) if submitted. Payment method details you choose to display (GCash, Maya, bank account info, QR codes). Payment records you log for bookings.
Communications
Messages exchanged between organizers and suppliers within bookings. Contact form submissions. Contract comments and booking notes.

Information We Collect Automatically

Usage Data
Pages visited, features used, and actions taken on the platform. Timestamps and session duration.
Device & Technical Data
Browser type and version, operating system. IP address. Server logs, error reports, and performance data.
Activity Notifications
We track key platform events (new signups, bookings created, events published) via internal team notifications on Slack. These contain basic event metadata, not your personal conversations or detailed data.

Information We Do Not Collect

  • We do not collect precise GPS location data from your device
  • We do not access your contacts, camera, or microphone
  • We do not currently process credit card numbers, bank account credentials, or any financial authentication data through our platform
2.

How We Use Your Information

To Deliver Our Core Service

  • Create and manage your account
  • Generate AI-powered event plans based on your inputs
  • Match organizers with compatible suppliers based on location, budget, category, and preferences
  • Facilitate the booking workflow between organizers and suppliers
  • Enable in-app messaging and booking coordination
  • Track payment status on bookings (supplier-recorded)
  • Send email notifications for booking updates, event reminders, and account activity

To Improve the Platform

  • Analyze usage patterns to identify bugs and improve features
  • Monitor AI output quality and accuracy
  • Track platform performance and uptime
  • Aggregate anonymized data for internal analytics (e.g., popular event categories, booking conversion rates)

To Maintain Security & Compliance

  • Prevent fraud, abuse, and unauthorized access
  • Enforce our Terms of Service
  • Comply with the Philippine Data Privacy Act of 2012
  • Respond to legal requests when required by law
3.

AI-Powered Features & Data Processing

AI is central to kaganapn. Here's exactly how it works:

What AI Does on Our Platform

  • Event Planning: Generates personalized event plans including budget breakdowns, timelines, and recommendations based on your event details and AI prompts
  • Supplier Matching: Scores and ranks suppliers based on compatibility with your event requirements (location, budget, category, preferences)
  • Supplier Profiles: Generates enhanced supplier descriptions, specialization summaries, and performance insights from business information
  • Prompt Optimization: Refines your event planning inputs for better AI-generated results

AI Provider

We use Anthropic's Claude API (models: Claude Haiku 4.5 and Claude Sonnet 4.5) for all AI features. Anthropic's data usage policy states that API inputs and outputs are not used to train their models.

What Data is Sent to Claude

  • Event details: title, date, theme, budget, guest count, location, your AI prompt
  • Supplier profiles: business descriptions, categories, services, pricing, location
  • No personally identifiable information (names, emails, phone numbers) is intentionally included in AI prompts. However, if you include personal details in free-text fields (like your AI prompt or event description), that text will be processed by Claude.

AI Data Safeguards

  • We send only the minimum data needed for each AI task
  • AI responses are validated by quality scoring before being shown to you
  • We log AI usage for cost tracking and quality monitoring (model used, token count, response quality score)
  • Daily AI budgets prevent runaway costs and ensure responsible usage
  • If AI processing fails, we fall back to rule-based alternatives — your experience continues without interruption

Your Control Over AI

  • AI event planning requires an AI prompt — you control what instructions you give
  • You can regenerate or customize AI-generated plans
  • You can manually browse and select suppliers without relying on AI recommendations
  • Core platform features (bookings, messaging, payments) function independently of AI
4.

Third-Party Services We Use

We believe in being specific about who handles your data:

Anthropic (Claude AI)

Purpose: AI event planning, supplier matching, profile generation

Data: Event details, supplier profiles, user prompts

Amazon Web Services (AWS SES)

Purpose: Email delivery

Data: Email addresses, notification content

Cloudflare (R2 Storage)

Purpose: File storage for photos, documents, uploads

Data: Uploaded files (photos, verification docs)

Bunny.net (Stream)

Purpose: Video hosting and CDN for supplier videos

Data: Supplier feature videos

Google reCAPTCHA

Purpose: Bot protection on forms

Data: IP address, browser behavior signals

Slack

Purpose: Internal team notifications for platform activity

Data: Basic event metadata (no personal conversations)

We do not use any advertising networks, tracking pixels, or third-party analytics platforms that follow you across the web.

Future Addition: We plan to integrate payment processing (e.g., PayMaya, GCash API) for direct transactions. When we do, this section will be updated before launch to disclose the payment processor and what financial data they will access.

5.

Information Sharing

We do not sell, rent, or trade your personal information.

Between Platform Users

Organizer → Supplier
When you create a booking, the supplier sees your name, event details, messages, and booking requirements.
Supplier → Organizer
Organizers see your business profile, services, pricing, portfolio, reviews, and displayed payment methods.
Public Profiles
Supplier profiles, including business name, description, categories, photos, videos, and reviews, are publicly visible in our supplier directory.
Guest RSVP
Guests who receive an RSVP link can see event date, time, and location — but not budget or supplier details.

With Service Providers

Only as described in Section 4 above, and only to the extent necessary to provide our services.

For Legal Reasons

We may disclose your information if required by Philippine law, regulation, or court order, or to protect the safety of our users or the public.

Business Transfers

If kaganapn is acquired, merges, or sells assets, your data may transfer as part of that transaction. We will notify you via email and platform notice before any such transfer and before your data becomes subject to a different privacy policy.

6.

Data Security

What We Do

  • All data encrypted via SSL/TLS (HTTPS)
  • Files stored on Cloudflare R2 with access controls
  • Database access restricted, credentials managed through environment variables
  • Supplier registration is invite-only
  • Secure, HTTP-only session cookies
  • Verification documents accessible only to authorized admin users

What We Acknowledge

No system is 100% secure. We're a small team building a startup, and while we follow security best practices, we don't yet have SOC 2 certification or a dedicated security team.

We're transparent about this because we'd rather be honest than make claims we can't back up.

If we discover a data breach that affects your personal information, we will notify you and the Philippine National Privacy Commission as required by law.

7.

Cookies

We keep it simple:

Cookies We Use

Essential Cookies (Required)

Session cookies for login and authentication. CSRF protection tokens. These cannot be disabled if you want to use the platform.

Functional Cookies

Remember your preferences and settings.

Cookies We Don't Use

  • We do not use advertising or marketing cookies
  • We do not use third-party tracking cookies
  • We do not participate in cross-site tracking or retargeting

You can manage cookies through your browser settings. Disabling essential cookies will prevent you from logging in.

8.

Your Privacy Rights

Under the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), you have the following rights:

Right to Be Informed

Know what data we collect, how we use it, and who we share it with. (That's what this policy is for.)

Right to Access

Request a copy of all personal data we hold about you.

Right to Correction

Request correction of inaccurate or outdated information. You can also update most information directly through your profile settings.

Right to Erasure or Blocking

Request deletion of your personal data, subject to legitimate business or legal retention requirements.

Right to Object

Object to processing of your data for purposes beyond what's necessary for our service.

Right to Data Portability

Request your data in a structured, commonly used format.

Right to Damages

Seek compensation if your data is mishandled in violation of the Data Privacy Act.

Right to File a Complaint

Lodge a complaint with the National Privacy Commission (NPC) if you believe your rights have been violated.

How to Exercise Your Rights

Email us at privacy@kaganapn.com with your request. We will:

  • Acknowledge your request within 3 business days
  • Verify your identity before processing
  • Fulfill your request within 30 days (or explain why we need more time)
  • Provide the service at no cost for reasonable requests
9.

Data Retention

Active Accounts
We retain your data for as long as your account is active.
Deleted Accounts
If you request account deletion, we will:
  • Remove your personal profile information within 30 days
  • Retain anonymized booking and transaction records as required for business and legal purposes
  • Delete uploaded files (photos, documents, videos) within 30 days
Inactive Accounts
Accounts with no login activity for 24 months may be flagged for review and potential deletion, with advance email notice.
AI Data
AI-generated plans and recommendations are stored as part of your event data and follow the same retention policy. AI score caches expire automatically after 24 hours.
Backups
Deleted data may persist in encrypted backups for up to 90 days before being purged.
10.

Beta Program Considerations

kaganapn is currently in closed beta. This means:

  • Features may change, and data flows may be adjusted as we develop the platform
  • We may collect additional usage feedback and interaction data to improve the product
  • Beta participants may be contacted for feedback or usability testing (you can opt out)
  • We will notify you of any material changes to how we handle your data during the beta period

If kaganapn discontinues operations, we will:

  • Provide at least 30 days' notice via email
  • Give you the opportunity to export or request your data
  • Securely delete all personal data within 60 days of shutdown
11.

Children's Privacy

kaganapn is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from minors.

If you are a parent or guardian and believe a minor has provided personal information to us, please contact us at privacy@kaganapn.com and we will delete it promptly.

12.

Changes to This Policy

We may update this Privacy Policy as our platform evolves. When we do:

  • We will update the "Last Updated" date at the top
  • For material changes (new data collection, new third-party providers, payment processing integration), we will notify you via email before the changes take effect
  • Continued use of kaganapn after changes take effect constitutes acceptance of the updated policy
13.

Contact Information

Privacy Questions & Data Requests

Email

privacy@kaganapn.com

Response Time

Within 3 business days for acknowledgment; 30 days for fulfillment

General Inquiries

Email

hello@kaganapn.com

Regulatory Authority

National Privacy Commission (NPC) — https://privacy.gov.ph

kaganapn is operated from Cebu, Philippines. This Privacy Policy is governed by Philippine law, specifically the Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations.