ROi WiFi Online SaaS

Privacy Notice

Version 1.1Effective August 25, 2026

This Privacy Notice explains how personal data is collected, used, stored, disclosed, and protected in connection with the ROi WiFi Online SaaS platform (“ROi WiFi,” “Platform,” “we,” “us,” or “our”).

ROi WiFi processes personal data in accordance with applicable Philippine data-protection requirements, including Republic Act No. 10173, or the Data Privacy Act of 2012, its implementing rules and regulations, and relevant issuances of the National Privacy Commission.

1. Who This Notice Applies To

This Notice applies to personal data processed through:

  • the ROi WiFi public website;
  • tenant registration and administration;
  • tenant and customer portals;
  • WiFi voucher and subscription services;
  • captive-portal authentication;
  • online-payment functions;
  • tenant wallet, earnings, refund, and payout functions;
  • support services;
  • Site Bridge and network integrations; and
  • related ROi WiFi products and modules.

2. Personal Data We May Collect

Account and Business Information

  • name;
  • username;
  • email address;
  • mobile or contact number;
  • business or trade information;
  • tenant name;
  • account role;
  • registration and application information; and
  • account and verification status.

Google Sign-In Identity Information

When a tenant chooses Google Sign-In for registration or password recovery, ROi WiFi requests only the minimum identity information needed to verify the account owner: the Google OpenID subject identifier, verified email address, and basic profile information made available by the OpenID, email, and profile scopes.

ROi WiFi does not request permission to read or send Gmail messages, access Google Contacts or Google Drive, or obtain the tenant's Google password. Google access and refresh tokens are not retained for mailbox access. The stable Google account identifier may be stored with the ROi WiFi user account so future password recovery can verify the same owner.

Network and Device Information

  • MAC address;
  • IP address;
  • access-point MAC or identifier;
  • SSID;
  • site or controller identifier;
  • device association information;
  • browser and device information;
  • network authorization status;
  • connection and session timestamps; and
  • technical logs necessary to operate or secure WiFi access.

Voucher and Subscription Information

  • voucher code and status;
  • subscription username or account identifier;
  • package selected;
  • duration and expiration;
  • speed or access policy;
  • authorized-device records;
  • activation and usage events;
  • renewals and extensions; and
  • refund or cancellation status.

Passwords are stored using appropriate one-way password hashing where the Platform supports password-based accounts.

Payment and Financial Records

  • transaction amount;
  • payment reference;
  • payment status;
  • gateway or processing fee;
  • Platform charges;
  • tenant wallet entries;
  • earnings records;
  • refund records;
  • payout requests;
  • payout destination information;
  • reconciliation records; and
  • receipts and financial audit history.

ROi WiFi does not need to store a customer’s full bank, card, or e-wallet authentication credentials merely to record a payment processed by an authorized third-party payment service.

Support and Security Information

  • support messages;
  • troubleshooting information;
  • administrator actions;
  • login and security events;
  • fraud or abuse indicators;
  • device-management activity; and
  • system audit logs.

3. How We Use Personal Data

Personal data may be processed to:

  • create and administer tenant and user accounts;
  • verify tenant identity through Google Sign-In during registration and password recovery;
  • evaluate tenant applications;
  • provide captive-portal and WiFi authentication;
  • issue, validate, extend, renew, suspend, or expire vouchers and subscriptions;
  • apply device-access restrictions;
  • verify and record payments;
  • maintain tenant wallet and earnings records;
  • process refunds and payout requests;
  • provide receipts and transaction history;
  • detect fraud, abuse, unauthorized access, and security threats;
  • troubleshoot network or account issues;
  • provide customer and tenant support;
  • maintain accounting, reconciliation, and audit records;
  • comply with legal or regulatory obligations;
  • establish, exercise, or defend legal claims; and
  • improve the security, reliability, and functionality of the Platform.

4. Legal Bases for Processing

Depending on the circumstances, ROi WiFi may process personal data because processing is necessary to provide a requested service or perform a contract; the data subject has provided consent where consent is required; processing is necessary to comply with a legal obligation; processing is necessary to protect lawful or legitimate interests, provided such interests do not improperly override the rights of the data subject; or another lawful basis permitted by applicable law applies.

Consent will not be treated as the sole legal basis where another lawful basis properly applies.

5. Cookies, Browser Storage, and Device Storage

ROi WiFi may use cookies, browser storage, IndexedDB, session storage, or similar technologies to maintain sessions, remember authorized-device or voucher information, restore WiFi access states, protect accounts, and operate Platform functionality.

Removing browser data may cause locally stored session or voucher information to be removed from that device but does not necessarily delete server-side transaction, security, accounting, or audit records.

6. Automated Processing

Certain Platform functions operate automatically. Examples include voucher expiration, subscription expiration, package countdowns, payment-status processing, insufficient-balance checks, device-limit enforcement, access authorization, refund restrictions, fraud and security controls, and account or transaction status changes based on defined system rules.

Where applicable law requires human review or additional information regarding automated processing, a request may be submitted through the official ROi WiFi support or privacy channel.

7. Disclosure and Recipients

Personal data may be disclosed only when reasonably necessary to:

  • the tenant responsible for the applicable WiFi service;
  • authorized ROi WiFi administrators and support personnel;
  • hosting, infrastructure, security, or technical service providers;
  • authorized payment or payout service providers;
  • network-controller or integration services necessary to provide WiFi authorization;
  • professional advisers where legally appropriate;
  • government, regulatory, judicial, or law-enforcement authorities when disclosure is lawfully required; or
  • another party with the data subject’s authorization or when otherwise permitted by law.

Service providers are expected to process personal data only for authorized purposes and subject to appropriate privacy and security obligations.

8. Tenant and Platform Roles

Depending on the processing activity, the tenant and ROi WiFi may have separate responsibilities concerning personal data. A tenant may independently determine what customer information it collects for its own WiFi business and may therefore have independent obligations under applicable privacy law.

ROi WiFi is responsible for personal data that it controls for Platform administration, security, payment records, tenant management, and other purposes determined by ROi WiFi.

9. Data Security

ROi WiFi uses reasonable organizational, physical, and technical safeguards appropriate to the nature of the information processed. These may include:

  • access controls;
  • password hashing;
  • encryption of sensitive stored credentials or configuration values;
  • restricted administrator access;
  • HTTPS/TLS where available;
  • security and audit logging;
  • tenant-data isolation;
  • validation of requests and authorization;
  • database and application safeguards; and
  • backup and recovery controls.

No internet-connected system can guarantee absolute security. Security measures are reviewed and may be updated as risks and technologies change.

10. Data Retention

Personal data is retained only for as long as reasonably necessary for the purpose for which it was collected or for legitimate legal, accounting, security, audit, dispute-resolution, or business requirements.

Retention periods may differ by record type. Active account data may be retained while the account remains active; technical session information may be retained for a shorter operational period; transaction, refund, payout, accounting, fraud-prevention, and audit records may be retained longer when necessary for reconciliation, legal obligations, or the establishment or defense of claims; and backup copies may remain temporarily until they are overwritten according to the applicable backup cycle.

Deletion of an account or active transaction object does not necessarily require deletion of records that must lawfully or reasonably be retained.

11. Your Data Privacy Rights

Subject to applicable law, data subjects may exercise rights including the right to:

  • be informed about the processing of personal data;
  • access personal data;
  • object to certain processing;
  • correct or rectify inaccurate personal data;
  • request erasure, blocking, or deletion when legally applicable;
  • obtain data portability when applicable;
  • withdraw consent for processing based on consent;
  • claim damages where permitted by law; and
  • file a complaint with the National Privacy Commission.

Some requests may be limited where continued retention or processing is necessary for a legal obligation, legitimate business purpose, fraud prevention, accounting requirement, contractual obligation, security investigation, or establishment, exercise, or defense of a legal claim.

ROi WiFi may request reasonable proof of identity before processing a privacy-rights request.

12. Children’s Privacy

ROi WiFi is primarily a service platform for tenants and WiFi users and is not designed to intentionally collect more information from minors than is necessary to provide the applicable WiFi service.

Parents, guardians, and tenants responsible for services used by minors should apply appropriate consent, supervision, and privacy safeguards where required by law.

13. Data Breaches and Security Incidents

Where a personal-data breach occurs, ROi WiFi will assess and respond to the incident according to applicable legal requirements and internal security procedures. Affected data subjects and the National Privacy Commission will be notified when notification is required by applicable law.

14. International or Third-Party Processing

Google may process the limited identity information used during Google Sign-In according to Google's own terms and privacy practices. ROi WiFi uses that identity response only for tenant registration, account linking, and password recovery as described in this Notice.

Certain infrastructure or service providers may process information using systems located outside the Philippines. Where applicable, ROi WiFi will use reasonable contractual, organizational, and technical measures to protect personal data transferred to or processed by third parties.

15. Changes to This Privacy Notice

This Privacy Notice may be revised to reflect changes in Platform functionality, service providers, security practices, data-processing activities, or applicable law. The current version and effective date will be published through the Platform. Material changes will be communicated when required or reasonably appropriate.

16. Privacy Questions and Requests

Privacy questions, requests to exercise data-subject rights, requests for access or correction, objections to processing, deletion requests where legally applicable, or concerns regarding the handling of personal data may be submitted through the official ROi WiFi privacy contact channels:

Email: roip.center@gmail.com
Mobile: +63 985 073 2498

ROi WiFi may request reasonable proof of identity before processing a privacy-related request to protect personal information from unauthorized disclosure or modification. A data subject may also lodge a complaint with the National Privacy Commission where appropriate under applicable Philippine law.

Legal: Terms of ServicePrivacy NoticePayment & Payout Terms
ROi WiFi Online SaaS · Privacy Notice · Version 1.1 · Effective August 25, 2026