Skip to main content
Last Updated: December 27, 2025

Privacy Policy

Patakaran sa Pagkapribado

Your privacy is important to us. This policy explains how Homesure Health Plan collects, uses, and protects your personal information in compliance with the Philippine Data Privacy Act (RA 10173).

1. Introduction

Welcome to Homesure Health Plan, a health insurance management platform operated in the Philippines and underwritten by Philcare Inc.

This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you use our website and services. We are committed to protecting your privacy in accordance with:

  • Republic Act No. 10173 - Data Privacy Act of 2012 (Philippines)
  • Implementing Rules and Regulations of the Data Privacy Act
  • National Privacy Commission (NPC) issuances and advisories
  • General Data Protection Regulation (GDPR) principles where applicable

By using our services, you consent to the collection and use of your information as described in this policy.

2. Data Controller Information

Data Controller

Homesure Health Plan

Underwriter

Philcare Inc.

Data Protection Officer

emm@claim135.net

Support Contact

Homesureph@gmail.com

3. Data We Collect

Personal Information

Data TypeExamplesPurpose
IdentityFull name, birthdate, gender, civil statusMember identification and eligibility
ContactEmail address, phone number, home addressCommunication and policy delivery
EmploymentOccupation, employer nameRisk assessment and underwriting
Government IDsUploaded ID documentsIdentity verification

Health Information

Data TypeExamplesPurpose
Medical HistoryPre-existing conditions, previous illnessesCoverage determination and PEC evaluation
Family HealthDependent medical informationFamily plan processing
Previous HMOPrior coverage details, card expirationContinuity of coverage assessment

Financial Information

Data TypeExamplesPurpose
Payment ReferencesTransaction IDs, payment confirmationsPayment tracking and reconciliation
Invoice DataBilling amounts, payment historyAccount management

Technical Data

Data TypeExamplesPurpose
Device InfoIP address, browser type, device typeSecurity and fraud prevention
Usage DataPages visited, session durationService improvement

Important Note

We do NOT store credit card numbers, bank account details, or CVV codes. All payment processing is handled securely by DragonPay, our PCI-DSS compliant payment processor.

4. Purpose of Data Collection

1

Insurance Application Processing

To evaluate and process your health insurance application

2

Coverage Administration

To manage your health plan, claims, and benefits

3

Payment Processing

To generate invoices and process premium payments

4

Communication

To send important updates about your coverage

5

Legal Compliance

To comply with insurance regulations and Philippine laws

6

Service Improvement

To enhance our platform and customer experience

7

Fraud Prevention

To protect against fraudulent activities

6. Data Sharing and Third Parties

We share your personal data only with trusted third parties necessary to provide our services:

Third PartyTypePurposeLocation
Philcare Inc.Insurance UnderwriterPolicy underwriting and claims processingPhilippines
Supabase Inc.Cloud DatabaseSecure data storage and authenticationSingapore (AWS)
DragonPay Corp.Payment ProcessorPayment processing and verificationPhilippines
Resend Inc.Email ServiceTransactional email deliveryUSA
Vercel Inc.Web HostingWebsite hosting and deliveryGlobal CDN

We DO NOT:

  • Sell your personal data to any third party
  • Share your data for third-party marketing purposes
  • Transfer data to unapproved processors

7. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:

Data TypeRetention PeriodLegal Basis
Active Member DataDuration of membership + 7 yearsInsurance regulations
Inactive Applications2 yearsBusiness necessity
Payment Records10 yearsTax regulations
Communication Logs3 yearsService records
Technical Logs90 daysSecurity purposes

8. Your Rights Under Philippine DPA

As a data subject under the Philippine Data Privacy Act, you have the following rights:

Right to Be Informed

Know what personal data we collect and how we use it

Right to Access

Request a copy of your personal data we hold

Right to Rectification

Request correction of inaccurate or incomplete data

Right to Erasure

Request deletion of your personal data (with limitations)

Right to Object

Object to certain types of data processing

Right to Data Portability

Receive your data in a portable, machine-readable format

Right to Damages

Seek compensation for privacy violations

How to Exercise Your Rights

Email: emm@claim135.net
Response time: Within 30 days

Limitations: We may retain data required by law (insurance records). Active coverage data cannot be erased without policy cancellation.

9. Security Measures

We implement comprehensive security measures to protect your personal data:

Encryption in Transit

All data transmitted via HTTPS/TLS 1.3

Encryption at Rest

Database encryption via Supabase with AES-256

Access Control

Role-based access control (member, agent, admin)

Row-Level Security

Database policies restrict data access per user

Audit Logging

All data access and changes are logged

PII Redaction

Sensitive data automatically redacted from logs

Security Headers

8 industry-standard HTTP security headers

Regular Audits

Periodic security assessments and penetration testing

10. Cookies and Tracking

Essential Cookies (Required)

CookiePurposeDuration
sb-*Supabase authenticationSession
Session IDUser authenticationSession

We DO NOT use:

  • Third-party advertising cookies
  • Cross-site tracking technologies
  • Social media tracking pixels

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes:

  • We will notify you via email at least 30 days before the changes take effect
  • We will update the "Last Updated" date at the top of this policy
  • Continued use of our services after changes constitutes acceptance

12. Contact Us

For General Support

13. Filing Complaints with NPC

If you believe your privacy rights have been violated and we have not adequately addressed your concerns, you have the right to file a complaint with the National Privacy Commission:

National Privacy Commission (NPC)

3rd Floor, Core G, GSIS Headquarters Building

Financial Center, Roxas Boulevard, Pasay City, Philippines

(02) 8234-2228
complaints@privacy.gov.ph