RCPinas.com (“RCPinas”, “we”, “us”) is a community
platform for the Philippine RC hobby. This page explains what personal data we collect,
why we collect it, how long we keep it, and the rights you have under the
Philippine Data Privacy Act of 2012 (RA 10173).
1. What we collect
We only collect what we actually need to run the community:
Account & profile
- Required: username, email address, password (stored as a one-way bcrypt hash — we never see your plaintext password).
- Optional: full name, bio, avatar & cover photos, province / city, hobby categories, social links (Facebook / YouTube / Instagram).
Identity verification (Verified badge)
If you choose to apply for a Verified badge via /profile/verify:
- Photo of the front (and back, if applicable) of a government-issued ID you select.
- Three short live selfie frames captured by your browser’s camera, used to confirm a real person submitted the ID.
- Your IP address and browser user agent at the time of submission.
Retention: ID and selfie images are deleted from disk immediately
after a moderator approves or rejects your verification. Only the decision (approved /
rejected, reviewer, timestamp, and rejection reason if any) is kept for audit.
Content you submit
- Posts, comments, reactions, build logs, photos.
- Marketplace listings, including product photos, condition, price, and your stated location.
- RC spot submissions (latitude/longitude, photos, descriptions).
- Hobby shop submissions and partner / sponsor applications.
Automatically collected
- Login attempts (timestamp, IP, success/failure) — for fraud / brute-force protection.
- Last login timestamp and IP, stored on your user record.
- Server access logs maintained by our nginx web server (typically rotated every 14 days).
- Session cookies, CSRF cookies, and (if you tick “Remember me”) a remember-me cookie scoped to RCPinas.com.
2. Why we use it
- Run your account — sign-in, password reset, sessions.
- Show your profile and your contributions to other members.
- Notify you by email about verification, partner / listing decisions, password resets.
- Protect the community — rate limiting, fraud prevention, moderation queues.
- Verify identity for users who choose to apply for the Verified badge.
We do not sell your personal data. We do not run third-party advertising trackers.
3. Who we share it with
- Other members can see information you publish on your profile, posts, listings, and submissions.
- Email delivery uses Hostinger’s SMTP service to send transactional notifications. Hostinger acts as our processor and handles only the email metadata required to deliver mail.
- Hosting — the platform runs on a Hostinger VPS in the Philippines region. Database and uploaded files are stored there.
- Map tiles — spot maps load tiles from OpenStreetMap; their servers see your IP when tiles load.
- Legal requests — we may disclose information when required by Philippine law, valid court order, or to investigate fraud / safety incidents on the platform.
4. How long we keep it
- Active accounts: kept until you delete or we close your account.
- KYC ID / selfie images: deleted immediately after the verification decision.
- Login attempts & rate-limit records: auto-purged after their relevant window (minutes to days).
- Email delivery logs: retained by Hostinger per their policy (typically 30 days).
- Backups: encrypted database snapshots may persist up to 30 days for disaster recovery.
5. Your rights under the Data Privacy Act
You have the right to:
- Be informed about how your data is processed (this page).
- Access the personal data we hold about you.
- Correct inaccurate data — most fields you can edit yourself in your profile.
- Object to processing or request deletion of your account and associated data.
- Data portability — request a copy of your data in a common format.
- File a complaint with the National Privacy Commission (privacy.gov.ph) if you believe we’ve mishandled your data.
To exercise these rights, email us at privacy@rcpinas.com. We respond within 15 working days.
6. Cookies
RCPinas uses only the cookies it needs to run:
rcpinas_session — keeps you signed in for your session (7 days max).
rcp_csrf_cookie — protects forms against cross-site request forgery.
rcp_remember — only set if you tick “Remember me” on sign-in (30 days).
We do not use Google Analytics, Facebook Pixel, or other behavioural advertising trackers.
7. Children
RCPinas is intended for users aged 13 and above. If you are under 13, please do not create an account. If you believe a child under 13 has registered, email us and we will remove the account.
8. Security
We use TLS (HTTPS) for all traffic, bcrypt for password hashing, CSRF protection on every form, server-side rate limiting on auth and submission endpoints, HTTP-only cookies, and `samesite=Lax`. No system is perfectly secure — if you suspect your account has been compromised, change your password and email us immediately.
9. Changes to this policy
If we make material changes, we’ll update the “Last updated” date at the top and, where reasonable, notify you by email or an in-site banner before the changes take effect.
10. Contact
Questions or requests about this policy:
See also: Terms & Conditions.