Privacy Policy

Effective Date: March 18, 2026 · Last Updated: March 18, 2026

Rifftlo Inc. ("Company," "we," "us," or "our") is committed to protecting the privacy of individuals who use the PCRCI Identity application ("App"), website (rifftlo.com), and related services ("Services"). This Privacy Policy describes what data we collect, how we use it, and your rights regarding your information.

This policy is designed to comply with the requirements of the Apple App Store, Google Play Store, the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and applicable data protection laws in our countries of operation.

1. Data Controller

Rifftlo Inc.
Incorporated in Delaware, United States
Email: support@rifftlo.com
Website: rifftlo.com

2. Data We Collect

2.1 Subject Enrollment Data

Data TypeRequiredPurposeHow Stored
Full nameYesIdentity recordEncrypted in Firestore
Estimated birth year / birthdayYesIdentity recordEncrypted in Firestore
Tribe / clan nameOptionalCultural identity contextEncrypted in Firestore
Preferred languageYesCommunication accessibilityEncrypted in Firestore
GPS coordinatesOptionalEnrollment location, fraud detectionEncrypted in Firestore
Facial geometry hashOptionalBiometric deduplication & re-authenticationSHA-256 hash only; raw image immediately discarded
GenderOptionalIdentity recordEncrypted in Firestore

2.2 Agent Data

Data TypePurposeHow Stored
Government ID photo hashAgent verificationSHA-256 hash only
Registered GPS locationFraud geo-fencingEncrypted in Firestore
NFC badge DIDAgent authenticationEncrypted in Firestore
Promo codeAuthorization verificationHashed after validation

2.3 Attestor Data

Data TypePurposeHow Stored
Government ID type & hashAttestor verificationSHA-256 hash only; raw ID never stored
Attestor typeAttestation weightingEncrypted in Firestore
Attestation count & historyFraud detection velocity limitsEncrypted in Firestore

2.4 Automatically Collected Data

2.5 Website Data

When you use rifftlo.com, we collect:

3. Biometric Data Handling

This is a critical privacy safeguard. PCRCI never stores, transmits, or retains raw biometric data. Our process:

  1. A photograph is captured via the device camera during enrollment or verification.
  2. Google ML Kit (running entirely on-device) extracts facial geometry landmarks (eye, nose, mouth positions).
  3. Landmarks are rounded to a 10-pixel grid for tolerance and concatenated.
  4. The concatenated landmarks are hashed using SHA-256.
  5. The original photograph is immediately and permanently discarded. It is never saved to device storage, uploaded to any server, or transmitted over any network.

Only the irreversible SHA-256 hash is stored. It is mathematically impossible to reconstruct a face from this hash. The hash is used solely for deduplication (detecting if two enrollments are the same person) and re-authentication at government kiosks.

4. How We Use Your Data

5. Data Sharing

We share data only in the following circumstances:

We do not sell, rent, or trade personal data to third parties for marketing or advertising purposes.

6. Data Storage and Security

6.1 Storage Architecture

6.2 Security Measures

7. Data Retention

8. Third-Party Data Processors

ServiceProviderData ProcessedProcessing Location
Firebase AuthGoogle LLCEmail, password, auth tokensGlobal
Cloud FirestoreGoogle LLCIdentity records, attestations, activity logsasia-southeast1
Cloud RunGoogle LLCAPI requests, verification queriesasia-southeast1
Cloud StorageGoogle LLCDocument uploads (if applicable)asia-southeast1
Google ML KitGoogle LLCFacial geometry extractionOn-device only — no cloud processing

All third-party processors are bound by their respective data processing agreements. See: Firebase Privacy Information, Google Cloud Privacy.

9. Device Permissions

PermissionPurposeData Handling
CameraFace capture for biometric hashImage processed on-device, hashed (SHA-256), then immediately discarded
Biometric (Fingerprint / Face ID)Agent authenticationProcessed by device OS; never accessed or stored by the App
Location (Fine & Coarse)Fraud geo-fencing (agent within 500m of registered area)Coordinates logged for fraud detection; not shared externally
NFCRead/write DID to NTAG215/216 cardsOnly DID string written to card — no personal data on card
MicrophoneSpeech-to-text for name entryProcessed on-device by Android SpeechRecognizer; audio never recorded or stored
InternetSync local data to FirestoreOnly hashes, scores, and metadata transmitted over TLS

10. Your Rights

Depending on your jurisdiction, you may have the following rights:

To exercise any of these rights, email support@rifftlo.com. We will respond within 30 days.

11. Children's Privacy

The PCRCI application is intended for users aged 18 and older. We do not knowingly collect personal data from children under 13. If we become aware that we have collected data from a child under 13, we will take steps to delete that data promptly. If you believe a child under 13 has provided us with personal data, please contact us at support@rifftlo.com.

12. International Data Transfers

PCRCI operates in the Philippines, Papua New Guinea, Timor-Leste, Solomon Islands, Vanuatu, Fiji, and Indonesia. Data is stored in Google Cloud's asia-southeast1 region (Singapore). Data may be processed in the United States by Rifftlo Inc. for administration and support purposes.

For users in the European Economic Area (EEA), transfers to the United States are conducted under appropriate safeguards including Standard Contractual Clauses as adopted by the European Commission.

13. Cookies and Tracking

The rifftlo.com website does not use cookies for advertising or tracking. We use:

The mobile App does not use cookies or third-party tracking SDKs.

14. Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will:

15. Regulatory Compliance

PCRCI is designed to align with:

16. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated through the App or via email. The "Last Updated" date at the top of this page reflects the most recent revision. Your continued use of the Services after changes are posted constitutes acceptance of the revised policy.

17. Contact Us

For privacy-related inquiries, data requests, or complaints:

Rifftlo Inc.
Email: support@rifftlo.com
Website: rifftlo.com

If you are in the EEA and are unsatisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.