Privacy Policy

What we collect, what we don't, and what's yours.

Version 1.0Effective August 15, 2026Last published August 15, 2026

Your privacy matters to Been There.

Overview

Your privacy matters to Been There. Been There is operated by No.3 ("Been There," "No.3," "we," "us," or "our"). This Privacy Policy explains what personal data we collect, why we process it, how it may be used or disclosed, how long it may be retained, and the choices and rights available to you. We aim to follow the principles of transparency, legitimate purpose, and proportionality under the Philippine Data Privacy Act of 2012 and applicable rules and regulations.

1. Our Privacy Philosophy

Been There is built around personal experiences. Some experiences may be sensitive. For that reason, our approach is simple: Collect what we need. Protect what you share. Don't ask for information we don't need. Been There is designed for pseudonymous participation. You do not need to publicly use your real name. However, pseudonymity does not mean that no information about you is processed behind the scenes.

2. Who Controls Your Personal Data

For purposes of applicable Philippine data-protection law, the personal information controller for Been There is: No.3 / Been There Contact: [INSERT PRIVACY EMAIL] Business address: [INSERT BUSINESS/REGISTERED ADDRESS IF APPLICABLE] Data Protection Officer / Privacy Contact: [INSERT WHEN APPLICABLE]

3. Information We Collect

Depending on how you use Been There, we may process the following categories of information. Account Information This may include: • email address; • authentication information; • account identifier; • nickname; • avatar; • account creation date; • account status; and • preferences. Passwords should be handled through our authentication provider and should not be available to Been There in readable form. Content You Choose to Share This may include: • stories; • replies; • journey updates; • reactions; • categories; • tags; • feedback; • reports; and • other content you voluntarily submit. Because Been There is about lived experiences, content you voluntarily share may reveal information that could be considered personal or sensitive. Please avoid including unnecessary identifying information. Community and Moderation Information We may process information such as: • reports submitted; • reports involving your content; • moderation actions; • warnings; • restrictions; • suspensions; • safety flags; • audit records; and • evidence reasonably necessary to investigate misuse. Feedback Information When you submit feedback, we may process: • your feedback; • category; • page or feature involved; • optional screenshots; • account identifier, if logged in; • device/browser information; and • timestamp. Screenshots may unintentionally contain personal information. Review them before submitting. Technical and Usage Information We may collect limited technical information necessary to operate, secure, understand, and improve Been There, such as: • device type; • browser type; • operating system; • IP address or network information where processed by our infrastructure; • timestamps; • session information; • pages or features used; • errors; • security events; and • general usage events. We aim to avoid collecting technical information that is unnecessary for operating or improving the service.

4. Information We Ask You Not to Share

Please avoid posting: • full legal names where unnecessary; • phone numbers; • personal email addresses; • home addresses; • passwords; • government identification numbers; • financial account numbers; • medical record numbers; or • private identifying information about another person. Our systems may detect or block some forms of personal information before publication. Detection is not perfect. You are still responsible for reviewing what you share.

5. Why We Process Information

We may process information where necessary to: Provide Been There Including: • create and maintain accounts; • publish stories; • display replies; • record reactions; • maintain journeys; • deliver notifications; • operate search and discovery; and • provide requested features. Protect the Community Including: • detect spam; • investigate reports; • enforce Community Guidelines; • prevent fraud; • prevent abuse; • restrict malicious accounts; • detect security incidents; and • maintain moderation records. Improve Been There Including: • understand how features are used; • identify technical problems; • evaluate product performance; • analyze aggregated community activity; and • improve user experience. Communicate With You Including: • account-related messages; • security notifications; • replies or activity notifications; • important service updates; • responses to feedback; and • policy updates. Marketing communications, if introduced, should use an appropriate separate choice or lawful basis. Meet Legal Obligations We may process or preserve information where reasonably necessary to comply with applicable law, lawful orders, legal processes, regulatory requirements, establish or defend legal claims, or protect legal rights.

6. Legal Basis for Processing

Depending on the processing activity, we may rely on: • your consent; • processing necessary to provide the service you requested or perform our agreement with you; • legitimate interests consistent with applicable law, such as security, fraud prevention, moderation, and service improvement; • compliance with legal obligations; or • another lawful basis available under applicable law. Where processing specifically requires consent, you may have the right to withdraw that consent, subject to applicable law and processing that remains permitted on another lawful basis.

7. Public Content

Stories, replies, journey updates, reactions, nicknames, and other community activity may be visible to other users or, depending on the feature, visitors who are not logged in. Do not assume that content posted publicly within Been There is private. Although we design the service to reduce unnecessary identity exposure, another person may copy, screenshot, quote, or otherwise record content they can view. We cannot completely control what another user does outside Been There.

8. Automated Safety Processing

Been There may use automated systems to identify: • obvious personal information; • spam; • suspicious behavior; • prohibited links; • potential abuse; or • content that may require safety review. These systems may flag or block content. Automated detection may be imperfect. Where appropriate, moderation decisions may involve human review. We do not intend to use automated processing as the sole basis for decisions that significantly affect your legal rights without appropriate safeguards where required by law.

9. Who May Receive Your Information

We do not sell your personal data. Information may be accessible to or processed by: Other Users Public or community-facing information is displayed according to the functionality of Been There. Authorized No.3 Personnel Authorized administrators may access information where necessary for: • moderation; • security; • support; • privacy requests; • troubleshooting; or • operation of the service. Access should be limited according to role and need. Service Providers We may use third parties to provide infrastructure such as: • cloud hosting; • databases; • authentication; • storage; • email delivery; • security; • analytics; and • technical services. These providers may process information on our behalf as necessary to provide their services. We will seek to use appropriate safeguards when engaging service providers that process personal data. Legal or Regulatory Recipients We may disclose information where required or permitted by applicable law, lawful court order, subpoena, regulatory requirement, or valid legal process. We may also disclose information where reasonably necessary to protect users, prevent serious harm, investigate fraud or abuse, or protect the rights and security of Been There, subject to applicable law.

10. International Processing

Some service providers may operate infrastructure outside the Philippines. As a result, personal data may be processed or stored in another jurisdiction. Where applicable, we will take reasonable steps to ensure that cross-border processing is handled with appropriate contractual, organizational, and technical safeguards consistent with applicable data-protection requirements.

11. How Long We Keep Information

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, subject to legal, security, moderation, backup, and dispute-resolution requirements. General principles include: Active Accounts Account information is generally retained while the account remains active. User Content Content is generally retained while published or until it is deleted by the user or removed according to platform rules. Removed Content Content removed for moderation or safety reasons may be retained in restricted form for up to 90 days, unless a longer period is reasonably necessary for an investigation, legal requirement, fraud prevention, safety issue, or dispute. Moderation and Security Records Certain records may be retained longer where reasonably necessary to prevent repeated abuse, protect the platform, establish or defend legal claims, or comply with legal obligations. Backups Deleted information may remain temporarily in secure backups until those backups cycle out according to our backup-retention practices. We will not retain personal data indefinitely without a legitimate purpose.

12. Security

We use reasonable organizational and technical safeguards designed to protect personal data. These may include: • access controls; • database authorization; • row-level security; • restricted administrative privileges; • private storage; • signed access to protected files; • authentication controls; • moderation audit logs; and • monitoring for suspicious activity. No online service can guarantee absolute security. If you believe your account or information has been compromised, contact us promptly.

13. Your Rights

Under applicable Philippine data-protection law, you may have rights including: • the right to be informed; • the right to access personal data processed about you; • the right to object to certain processing; • the right to rectify or correct inaccurate data; • the right to erasure or blocking where applicable; • the right to data portability in applicable circumstances; • the right to file a complaint with the National Privacy Commission; and • rights relating to damages or indemnification where provided by law. You may learn more about these rights from the National Privacy Commission.

14. Accessing and Exporting Your Data

Been There provides a Download My Data feature where available. You may also contact us if you need assistance exercising an applicable data-subject right. We may need to verify your identity before fulfilling certain requests to prevent unauthorized disclosure or deletion.

15. Correcting Your Information

Certain account information may be corrected through your account settings. For other corrections, contact us through the Privacy or Feedback channel.

16. Deleting Your Account

You can request account deletion through: Settings → Privacy & Account → Delete My Account Before deletion, Been There will explain what will be removed and what may need to be retained. Depending on the circumstances: • profile information may be deleted or anonymized; • authentication access will be revoked; • user content may be removed or anonymized according to applicable product rules; • security/moderation records may be retained where reasonably necessary and lawful; and • backups may retain information temporarily until normal deletion cycles complete.

17. Objection and Withdrawal of Consent

Where processing relies on consent, you may withdraw that consent where applicable. You may also have the right to object to certain processing. Withdrawal or objection may affect our ability to provide functionality that depends on the relevant information. Some processing may continue where another lawful basis applies.

18. Children

Been There's initial beta is intended for users aged 18 and above. We do not knowingly allow children below 18 to create accounts during this phase. If we learn that an ineligible child has provided personal data through an account, we may remove the account and associated information as appropriate.

19. Data Breaches

If a personal-data breach occurs, we will assess it and take appropriate containment, investigation, remediation, documentation, and notification measures as required by applicable law.

20. Changes to This Policy

We may update this Privacy Policy as Been There changes. Published versions will display an effective date and version number. If a material change requires renewed acknowledgement or consent, we may notify you and request appropriate action before continuing relevant processing. Previous versions may be retained for compliance purposes.

21. Complaints

If you believe your personal data has been handled improperly, please contact us first so we can investigate. You may also have the right to lodge a complaint with the National Privacy Commission of the Philippines.

22. Contact Us

For privacy questions, requests, objections, or concerns: Been There Privacy Contact: John Del Rosario Email: armyofcaco@gmail.com We will make reasonable efforts to respond to legitimate privacy requests within applicable legal requirements.