TireNexus Privacy Policy
Effective date: July 27, 2026
This Privacy Policy explains how Robert Bernard Flores, a sole proprietor doing business as "TireNexus" ("TireNexus", "we", "us") collects, uses, stores, and shares personal information in connection with the TireNexus point-of-sale web application at www.tirenexus.co (the "Service"). It forms part of our Terms of Service.
1. Our two roles
TireNexus is a multi-tenant service used by shops ("tenants"). We process personal data in two distinct capacities:
- As a personal information controller for data about you and your staff — account registration data, login records, and communications with us. We decide how and why this data is processed.
- As a personal information processor for data your shop records about its own customers inside the Service — for example customer names, contact numbers, and vehicle plate numbers on sales and service tickets ("Shop Data"). For Shop Data, the shop is the controller: it decides what to record and is responsible for having a lawful basis to do so. We process Shop Data only to provide the Service to that shop.
2. Information we collect
Account and identity data (we are the controller):
- Email address and password (passwords are stored only as secure hashes by our authentication provider; we never see or store plaintext passwords).
- Shop/tenant profile details you provide (shop name, address, contact details, logo).
- Records of your communications with us (e.g., support emails).
Shop Data (the shop is the controller; we are the processor):
- Inventory, pricing, sales transactions, receipts, reports, and settings.
- Customer records the shop creates: names, phone numbers, addresses, vehicle details including plate numbers, and service/purchase history.
Technical and usage data:
- Log data such as IP address, browser/device information, timestamps, and pages or actions used, collected for security, debugging, and abuse prevention.
- Anti-abuse signals from our signup bot-protection provider (see Section 5), where enabled.
- We do not currently use advertising trackers. If we introduce analytics cookies beyond what is strictly necessary for the Service to function, we will update this Policy.
3. How we use personal data (purposes and legal bases)
| Purpose | Data | Legal basis under the DPA |
|---|---|---|
| Creating and operating your account and tenant | Account data | Contract (Terms of Service) |
| Providing POS features to your shop | Shop Data | Contract; processing on behalf of the shop as controller |
| Securing the Service, preventing fraud/abuse | Technical data | Legitimate interests |
| Responding to support requests | Account data, communications | Contract; legitimate interests |
| Service announcements (e.g., changes to terms, downtime, security notices) | Email address | Contract; legal obligation |
| Product improvement and aggregate statistics | De-identified/aggregated data only | Legitimate interests |
| Compliance with law and lawful orders | As required | Legal obligation |
We do not sell personal data, and we do not use Shop Data for advertising or to build profiles across tenants.
4. Multi-tenant isolation
Each tenant's data is logically isolated using per-tenant access controls enforced at the database layer (row-level security). Users can access only the tenant(s) they have been granted membership in. Staff access within your tenant is managed by you.
5. Sub-processors and hosting (including cross-border transfers)
We use reputable infrastructure providers to run the Service. Personal data is processed by:
| Provider | Role | Location of processing |
|---|---|---|
| Supabase (Supabase, Inc.) | Database, authentication, and backend hosting | Singapore (AWS ap-southeast-1 region) |
| Vercel (Vercel Inc.) | Web application hosting and content delivery | Global edge network; primary infrastructure in the United States |
| Cloudflare (Cloudflare, Inc.) — Turnstile | Bot protection on signup, sign-in and password reset (where enabled) | Global network |
Because these providers operate outside the Philippines, your personal data is transferred and stored abroad (primarily in Singapore for database contents). We take steps to ensure such transfers comply with the DPA, including contractual commitments from providers to protect personal data to a comparable standard.
We may update this list as our infrastructure evolves; material changes will be reflected in an updated Policy.
6. Retention
- Account data: kept while your account is active, and for a reasonable period afterwards as needed for security, dispute resolution, or legal compliance.
- Shop Data: kept while your tenant is active. After account/tenant termination, we make reasonable efforts to allow export for thirty (30) days (see Terms of Service), after which the data is scheduled for deletion from live systems, and thereafter from backups in the ordinary rotation cycle.
- Log/technical data: kept for a limited period appropriate to security and troubleshooting purposes, then deleted or de-identified.
7. Security
We implement reasonable organizational, physical, and technical safeguards appropriate to the nature of the data, including:
- encryption of data in transit (HTTPS/TLS) and at rest at our hosting providers;
- password authentication handled by our authentication provider with industry-standard hashing;
- per-tenant row-level security enforced in the database;
- least-privilege access to production systems.
No system is perfectly secure. In the event of a personal data breach affecting sensitive personal information or data that may enable identity fraud, we will notify the National Privacy Commission ("NPC") and affected data subjects within the periods required by the DPA and NPC regulations (generally within 72 hours of knowledge of the breach, where required).
8. Your rights as a data subject
Under the DPA, you have the rights to be informed; to access; to object; to erasure or blocking; to rectification; to data portability; to damages; and to lodge a complaint with the NPC (privacy.gov.ph).
To exercise these rights for account data, contact us at flores.rb17@gmail.com. We will respond within the periods required by law and may need to verify your identity first.
For Shop Data (e.g., you are a customer of a shop that uses TireNexus and want your record corrected or deleted), please contact that shop directly — it is the controller of that data. If a shop instructs us to correct or delete data, we will carry out the instruction. If you contact us directly about Shop Data, we will refer your request to the relevant shop where appropriate.
9. Children
The Service is a business tool intended for users 18 years old and above. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
10. Changes to this Policy
We may update this Policy from time to time. For material changes, we will give notice (for example by email or an in-app notice) before the changes take effect. The "Effective date" above reflects the latest revision.
11. Contact us
For privacy questions, requests, or complaints:
Robert Bernard Flores (sole proprietor, doing business as "TireNexus")
Km. 43 McArthur Highway, Bulihan, Malolos City, Bulacan, Philippines, 3000
Data Protection Officer: Robert Bernard Flores (flores.rb17@gmail.com)
Email: flores.rb17@gmail.com
You may also contact the National Privacy Commission of the Philippines at privacy.gov.ph.