Privacy Policy
Last updated: May 4, 2026
Welcome to Pasado. We respect your privacy and are committed to protecting your personal data. Pasado is operated by Seed Within Digital Inc., a corporation incorporated in Ontario, Canada.
Our mission is simple: tulungan kang pumasa. This Privacy Policy explains how we collect, use, share, and protect your information when you use our app or website.
1. Who This Policy Applies To
This Privacy Policy applies to:
- Pasado mobile apps on iOS (Apple App Store) and Android (Google Play Store)
- Web app at pasadoapp.com
- Waitlist and signup pages
- All related services operated by Seed Within Digital Inc.
By using Pasado, you agree to the practices described in this policy.
2. Information We Collect
2.1 Pre-Launch Waitlist Signup
When you join our waitlist, we collect:
- Full name
- Email address
- Phone number
- Nursing school attended
- Learner type (first-time taker or retaker)
- IP address (for security and analytics)
- Timestamp of signup
2.2 During Account Use (Post-Launch)
Account Data:
- Email address
- Hashed password (we never store passwords in plain text)
- Google or Apple SSO authentication tokens (if you use single sign-on)
Subscription and Payment Data:
- Subscription status (active, paused, canceled)
- Payment history (transaction dates, amounts)
- We do NOT store credit card numbers. All payments are processed by Stripe (web), Apple App Store (iOS), or Google Play Store (Android), each with their own privacy practices.
Learning and Usage Data:
- Questions answered (correct/incorrect)
- Time spent on questions and topics
- Identified weak areas
- Study patterns and session frequency
- Spaced repetition progress
User-Generated Content:
- Personal notes
- Bookmarks
These are private to your account and never shared with other users.
Technical Data:
- Login timestamps
- Device type and operating system version
- Session metadata
- App version
Optional Profile Data:
- Target exam date
- Current preparation status
- Other voluntary profile information
2.3 What We Do NOT Collect
We do not collect:
- Credit card numbers (processed exclusively by Stripe, Apple, or Google)
- Government-issued ID numbers
- GPS or precise location data
- Health information beyond what you voluntarily share
- Biometric data
3. How We Use Your Data
We use your data to:
- Provide and improve the Pasado app and services
- Personalize your study experience and recommendations
- Track your progress and identify weak areas via algorithmic analysis (see Section 9)
- Manage subscriptions and process billing
- Send service-related notifications (account alerts, important updates)
- Send optional marketing communications (only with your explicit opt-in consent)
- Improve app performance, security, and stability
- Comply with legal obligations
- Detect and prevent fraud or abuse
4. Notifications and Communications
4.1 Push Notifications
Pasado may send push notifications, including:
- Study reminders
- Streak notifications
- Content updates
- Account alerts (security, billing, subscription changes)
Push notifications are off by default. You will be asked for permission before any push notifications are sent. You can control or disable notifications anytime in your device settings.
4.2 Marketing Emails
Marketing emails (tips, promotions, product news):
- Require your explicit opt-in consent
- Always include an unsubscribe link
- Are sent in compliance with Canadian Anti-Spam Legislation (CASL) and Philippine Data Privacy Act (PDPA)
You can withdraw consent at any time without affecting your account or service.
4.3 Transactional Emails
We will always send essential transactional emails (payment receipts, password resets, account security alerts) regardless of marketing consent — these are necessary for service delivery.
5. Third-Party Service Providers
We share data with trusted providers who help us operate Pasado. Each operates under their own privacy policies, which we encourage you to review:
| Provider | Purpose |
|---|---|
| Supabase | Database hosting and authentication |
| Resend | Transactional email delivery |
| Stripe | Web payment processing |
| RevenueCat | Mobile subscription management |
| Hostinger | Web infrastructure (landing page, current backend) |
| Apple App Store | iOS app distribution and subscription billing |
| Google Play Store | Android app distribution and subscription billing |
| ElevenLabs | Backend voiceover generation (no user data sent) |
Planned future integrations (will update this policy when activated):
- PayMongo (Philippine payment processor)
- Analytics tools (Google Analytics or similar) — currently NOT integrated
We do NOT sell your personal data to anyone.
6. Cross-Border Data Transfers
Pasado uses cloud infrastructure that may store and process your data outside the Philippines:
- Primary database and authentication (account data, learning progress, subscription records) is hosted in Canada (Montreal, AWS ca-central-1) via Supabase. This places primary user data in the same jurisdiction as Seed Within Digital Inc. and within Canada's federal privacy framework (PIPEDA). Canada has been recognized by the European Commission as providing an adequate level of personal data protection under GDPR Article 45.
- Transactional email delivery (account, billing, security notifications) operates primarily from the United States via Resend.
- Web payment processing operates from the United States and Ireland via Stripe.
- Mobile subscription management operates from the United States via RevenueCat.
- Mobile app distribution and billing is handled by Apple App Store and Google Play Store in their respective global regions.
By creating an account or using Pasado, you provide informed consent to this cross-border transfer in accordance with:
- Philippine Data Privacy Act of 2012 (RA 10173), Section 21
- Canadian PIPEDA cross-border transfer requirements
- GDPR Standard Contractual Clauses (for EU users)
We require all third-party providers handling your data to maintain appropriate security and privacy standards comparable to those described in this policy.
7. Data Retention
Active accounts: Data is retained while your account is active and for the duration of your subscription.
Account deletion: Upon account deletion (whether self-initiated in-app or by email request), your personal data is deleted or anonymized within 30 days.
Exceptions to deletion:
- Financial records may be retained for up to 7 years for tax and legal compliance
- Anonymized aggregate data may be retained indefinitely for analytics
- Data subject to legal hold or active dispute resolution
8. Your Rights
Depending on your jurisdiction, you may have the following rights:
Under Philippine Data Privacy Act (RA 10173):
- Right to be informed about data collection
- Right to access your data
- Right to object to processing
- Right to correct inaccurate data
- Right to data portability
- Right to file a complaint with the National Privacy Commission
Under Canadian PIPEDA:
- Right to access your personal information
- Right to challenge accuracy
- Right to know how your data is used and disclosed
Under GDPR (EU users):
- Right to access (Article 15)
- Right to rectification (Article 16)
- Right to erasure (Article 17)
- Right to restrict processing (Article 18)
- Right to data portability (Article 20)
- Right to object (Article 21)
- Right not to be subject to automated decision-making (Article 22) — see Section 9
Under CCPA (California users):
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt out of sale (we don't sell data)
- Right to non-discrimination
How to Exercise Your Rights
To exercise any of these rights, contact us at hello@pasadoapp.com with:
- Your full name and registered email
- Specific right you wish to exercise
- Verification of identity (we may request additional information to confirm your identity before processing)
We will respond within 30 days of receiving a valid request, in accordance with applicable law.
9. Automated Decision-Making
Pasado uses algorithmic logic to:
- Identify your weak areas based on quiz performance
- Recommend questions via spaced repetition algorithms
- Adjust difficulty and topic distribution
These automated processes do not produce legal effects or significantly affect you in a legal sense. They are designed solely to improve your study experience.
Under GDPR Article 22, EU users have the right to request human review of automated decisions. To request review, contact hello@pasadoapp.com.
10. Account Deletion
You can delete your account at any time:
- In-app: Go to Account Settings → Delete Account (available on iOS, Android, and web)
- Email request: Send a deletion request to hello@pasadoapp.com if you cannot access your account
Upon deletion:
- Your personal data is removed or anonymized within 30 days
- Some records may be retained as described in Section 7
- Active subscriptions will be canceled
11. Cookies and Tracking
Pasado uses:
- Session cookies for authentication and security (essential, cannot be disabled)
- Preference cookies to remember your settings
Pasado does NOT currently use marketing or advertising cookies.
We may add analytics cookies in the future. When we do, we will update this Privacy Policy and notify users in advance.
12. Data Security
We implement reasonable technical and organizational measures to protect your data:
- Encryption in transit: TLS 1.2+ for all data transmission
- Encryption at rest: Database encryption via Supabase infrastructure
- Secure authentication: Hashed passwords, optional SSO via Apple/Google, session tokens
- Access controls: Role-based access for internal team members
- Audit logging: System events logged for security review
- Regular security reviews: Periodic assessment of our infrastructure
While we use industry-standard security practices, no system is 100% secure. We cannot guarantee absolute security of data transmitted over the internet.
13. Data Breach Notification
In the event of a personal data breach, we will:
- Notify affected users without undue delay
- Notify the Philippine National Privacy Commission within 72 hours where required
- Notify other applicable regulators within required timeframes (e.g., GDPR Article 33)
- Provide information on the nature of the breach, likely consequences, and measures taken
14. Children's Privacy
Pasado is intended for adults preparing for the Philippine Nurse Licensure Examination. Minimum age to create an account: 18 years old.
We do not knowingly collect personal information from anyone under 18. If we discover that a minor has created an account, we will promptly delete the account and any associated data.
If you believe a minor has provided us with personal information, contact hello@pasadoapp.com immediately.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Notify you via email at least 30 days before changes take effect
- Display an in-app notice
- Update the "Last updated" date at the top of this policy
Your continued use of Pasado after changes take effect constitutes acceptance of the updated policy.
16. International Users
If you access Pasado from outside the Philippines or Canada, your data may be transferred to and processed in countries with different data protection laws than your jurisdiction. By using Pasado, you consent to this transfer.
17. Contact Us
For privacy inquiries, requests to exercise your rights, or any questions about this policy:
Email: hello@pasadoapp.com
Company: Seed Within Digital Inc.
Jurisdiction: Ontario, Canada
For Filipino users, you may also contact the Philippine National Privacy Commission at https://privacy.gov.ph if you believe your data privacy rights have been violated.