Privacy policy
What we collect when you book, why we are allowed to, who else sees it, how long we keep it, and how to have it deleted. Written to meet the Data Privacy Act of 2012 (Republic Act No. 10173).
Who is responsible for your data
Misty Mountain Haven, a campsite in Barangay Kibalabag, Malaybalay City, Bukidnon, is the personal information controller for everything described here. That means we decide what is collected and why, and we answer for it.
CONFIRM(client): the name and email address of the person who handles privacy requests. RA 10173 and the National Privacy Commission both require a named, reachable contact, and "the front desk" is not one. Until it is filled in, requests reach us on the phone number and Facebook page in the footer of this site, and we will answer them.
What we collect, and when
When you book, we collect the name, email address and mobile number you give as the lead guest, the notes or requests you type in, the number of adults, children and infants in your party, your dates, the accommodation and any extras you choose, the amounts, and the full name of each guest travelling with you. Guest names are collected because each guest gets their own gate pass; if you would rather not give them, the booking form will use "Guest 2", "Guest 3" and so on instead.
When you pay by card or e-wallet, you enter your card or wallet details on our payment provider's own hosted page. Those details never reach our systems. What we receive back is whether the payment succeeded, the amount, the method and the provider's reference.
When you pay by GCash transfer, we receive the receipt image you upload and, once a member of staff has checked it, the GCash reference number they record against your booking.
When you arrive, we record the time each guest is checked in and which member of staff did it.
When you use the contact form, we collect the name, email address and message you send. Nothing else on that form is stored.
Automatically, we record your IP address against booking attempts and against attempts to sign in to the staff area. This is used to limit how many attempts one address can make, and for nothing else.
We do not collect sensitive personal information as the Act defines it — no government identification numbers, no health information, no religious, political or other affiliations. Please do not put any of it in the notes field.
Why we collect it, and what allows us to
To take and honour your booking: your name, contact details, party, dates, accommodation, extras and amounts. The lawful basis is section 12(b) of the Act — processing necessary to fulfil a contract with you, and to take the steps you asked for before it. We cannot hold a booking without these, which is why the form requires them.
To send you the emails a booking needs: confirmation, your gate passes, a note before you arrive, and anything about a change or a cancellation. Same basis, section 12(b). These are not marketing and you cannot be a guest without them.
To let you in: the guest names and each guest's gate pass. Same basis.
To answer your message: the contact form. The lawful basis is your consent, section 12(a) — you chose to write to us.
To keep the records the law requires of a business: booking and payment records kept for tax and accounting purposes. The lawful basis is section 12(c), compliance with a legal obligation.
To stop abuse: the IP addresses behind booking attempts and staff sign-in attempts, and the record of every change a member of staff makes to a booking. The lawful basis is section 12(f), our legitimate interest in not having the booking system or the staff area attacked, which does not override your rights because the data is minimal and is used for nothing else.
We do not sell your data, we do not share it for advertising, and we do not profile you or make automated decisions about you.
Who else sees it
Our own staff, to run your stay. Staff accounts are individually named and every change a member of staff makes to a booking is logged with who made it and when.
Our hosting and database provider, which stores the site and the booking records. Our email provider, which delivers your booking emails and only ever receives the address and the message being sent. Our payment provider, which handles card and e-wallet payments on its own pages under its own privacy policy. Each of these is a personal information processor acting on our instructions and nothing more.
Anyone we are legally required to give it to — a court order, a lawful request from a government agency, or the Bureau of Internal Revenue in the ordinary course of keeping records.
Some of these providers store data on servers outside the Philippines. Where they do, we remain accountable for it under the Act, and they are bound by contract to process it only as we instruct.
How long we keep it
Booking records — your details, your stay, your payments — are kept for three years after your check-out date, and then either deleted or stripped of anything that identifies you so that only the anonymous stay figures remain. Three years is the retention period this property has documented for itself; the Act does not set a number, it sets the rule that data is "retained only for as long as necessary".
Receipt images you upload for a GCash payment are deleted once the booking is three years past its check-out date, along with the rest of the booking.
Contact form messages are kept for one year, or longer if the conversation turned into a booking, in which case they follow the booking.
The IP addresses recorded against booking and sign-in attempts are kept for 30 days.
Records we are required to keep for tax or accounting purposes are kept for as long as that law requires, even where it is longer than the periods above. That is the one thing a deletion request cannot reach.
Cookies
The site sets two cookies and neither of them tracks you. One remembers the booking you are part way through filling in, so a refresh or the back button does not lose your dates; it is signed so it cannot be tampered with and it expires on its own. The other keeps a member of staff signed in to the admin area.
There are no advertising cookies, no analytics cookies and no third-party trackers on this site. There is nothing here to opt out of.
Your rights, and how to use them
Under Chapter IV of the Act you have the right to be informed of what we hold and why — which is what this document is for; to access a copy of it; to have anything inaccurate corrected; to object to processing, including withdrawing a consent you gave; to have data blocked or erased where it is incomplete, outdated, unlawfully obtained or no longer needed; to receive an electronic copy in a portable format; and to be indemnified for damage caused by inaccurate, unlawfully obtained or unauthorised use of your data.
To use any of them, write to us using the contact details in the footer of this site, and say which right you are exercising and which booking it concerns. Your booking reference is the fastest way for us to find you. We will answer within 30 days, and if we cannot do what you asked we will tell you why.
To have your data deleted: ask us, and we will delete your booking record, your guest names, your notes and any receipt image you uploaded. Two things survive that request, and it is fairer to say so here than to discover it later — the booking and payment figures we are required to keep for tax and accounting purposes, and the fact that particular dates were occupied. Both are stripped of anything that identifies you.
If you are not satisfied with how we have handled a request, you can complain to the National Privacy Commission at privacy.gov.ph. You do not need to go through us first.
If something goes wrong
If your data is exposed in a way that is likely to put you at real risk, we will notify you and the National Privacy Commission, and we will do it inside the 72 hours the Commission requires.
Changes to this policy
The version string at the foot of this page changes whenever the words do. If a change alters what we collect or why, we will say so on this page rather than quietly reissuing it.
Version: 2026-09-11.privacy-v1