Privacy Policy

Effective date: April 8, 2026  ·  Issued by: LGU Pandan, Antique — Tourism Office

The Municipality of Pandan, Antique is committed to protecting your personal data in compliance with Republic Act No. 10173 (Data Privacy Act of 2012) and its Implementing Rules and Regulations.

1. Data Controller

The Municipality of Pandan, Antique, through its Tourism Office, is the Data Controller responsible for the personal data collected and processed through toUrist trAck, the official tourism platform of the municipality.

2. Personal Data We Collect

When you register as a tourist, we collect the following information:

Data Required? Purpose
First name & Last nameYesVisitor identification
Email addressYesAccount verification & QR code delivery
Phone numberNoOptional contact detail
Date of birthNoAge-group demographic statistics
SexNoGender demographic statistics
NationalityYesVisitor origin statistics
Type of visitYesLocal / domestic / foreign classification
Purpose of visitNoTourism analytics
Home province / regionNoGeographic origin statistics
Days of stayNoDuration-of-stay statistics
Visit logs (attraction, date/time)AutoGenerated when you scan at an attraction

3. Purpose and Legal Basis for Processing

Your personal data is processed for the following purposes:

  • Tourism monitoring: To track and report visitor arrivals at tourist attractions in Pandan, Antique, as authorized by LGU ordinance and the Department of Tourism (DOT) reporting requirements.
  • Statistical reporting: To generate aggregated, anonymized tourism statistics for LGU planning and policy-making.
  • Visitor identification: To issue a unique QR code that identifies you at attractions without requiring re-registration.
  • Email communication: To send you your QR code and system notifications.

Legal basis: Performance of a task carried out in the exercise of official governmental authority (RA 10173, Sec. 12(e)) and fulfillment of a legitimate purpose of the LGU consistent with its mandate under RA 7160 (Local Government Code).

4. Third-Party Services

This system uses the following third-party services that may process your data:

  • Google reCAPTCHA v2 — Used on the registration form to prevent automated abuse. When you solve the CAPTCHA, your interaction data is sent to Google. See Google's Privacy Policy.
  • Email delivery service — Used to send your verification email and QR code. Emails contain your name and QR code image.

5. Data Retention

Tourist registration records and visit logs are retained for three (3) years from the date of registration, consistent with standard LGU records retention schedules under the National Archives of the Philippines. After this period, records are anonymized or securely deleted unless required for ongoing legal or governmental purposes.

6. Data Sharing and Disclosure

Your personal data is not sold or shared with commercial third parties. Data may be shared only in the following cases:

  • With the Department of Tourism (DOT) in aggregated, statistical form as required by national reporting guidelines.
  • With law enforcement or government authorities when required by law or court order.
  • With authorized LGU personnel (Tourism Officers and Staff) strictly for visitor management purposes.

7. Your Rights as a Data Subject

Under RA 10173, you have the following rights:

  • Right to be informed — You have the right to know how your data is collected and used (this policy fulfills that right).
  • Right to access — You may request a copy of your personal data held by this system.
  • Right to rectification — You may request correction of inaccurate or incomplete data.
  • Right to erasure / blocking — You may request deletion of your data, subject to applicable retention requirements.
  • Right to object — You may object to further processing of your data.
  • Right to lodge a complaint — You may file a complaint with the National Privacy Commission (NPC).

To exercise any of these rights, please contact our Data Protection Officer at dpo@pandanantique.gov.ph.

8. Security Measures

We implement appropriate technical and organizational security measures including encrypted data transmission (HTTPS), hashed credentials, role-based access controls, session management, and activity logging to protect your personal data from unauthorized access, disclosure, or loss.

9. Cookies and Session Data

This system uses session cookies solely for maintaining your login state and form security (CSRF tokens). No tracking or advertising cookies are used. Cookies are deleted when you close your browser session.

10. Changes to This Policy

This Privacy Policy may be updated to reflect changes in law or system functionality. The effective date at the top of this page will be updated accordingly. Continued use of the system after changes constitutes acceptance of the updated policy.