S
SupaChefs

Privacy Policy

SupaChefs Privacy Policy Effective Date: April 17, 2026 Last Updated: April 17, 2026 1. Introduction Welcome to SupaChefs. The SupaChefs platform (“Platform”) is owned and operated by Supa Labs, Inc. (referred

to

as

“we,”

“our,”

or

“us”),

a

corporation

incorporated

under

the

laws

of

the

Republic

of

the

Philippines.

SupaChefs

is

our

community-powered

food

marketplace

application

that

connects

home

chefs

with

customers

seeking

homemade

meals. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when

you

use

the

SupaChefs

mobile

application

and

website

(collectively,

the

“Platform”)



whether

you

are

a

customer

ordering

food

or

a

home

chef

selling

meals. By accessing or using SupaChefs, you acknowledge that you have read and understood this Privacy Policy

and

agree

to

its

terms.

If

you

do

not

agree,

please

do

not

use

our

Platform. 2. Who This Policy Applies To This Privacy Policy applies to all users of the SupaChefs Platform, including but not limited to: • Customers — any person who browses, orders, or purchases meals through the Platform • Home Chefs — any person who register to sell homemade meals through the Platform • Visitors — anyone who accesses the Platform through a website or mobile app without officialy registering 3. What Information We Collect We collect and process personal information in accordance with the principles of transparency, legitimate purpose

and

proportionality

under

the

Data

Privacy

Act

of

2012.

We

only

collect

data

that

is

necessary,

relevant

and

not

excessive

in

relation

to

the

declared

purposes

of

processing. Personal data collected may be classified as: ● Personal information; ● Sensitive Personal Information (e.g. government IDs, financial data, etc.) ● Privileged Information, if applicable. Provision of certain data may be mandatory for account creation and order fulfillment. Failure to provide the

required

data

may

result

in

inability

to

use

certain

features

of

the

Platform.

3.1 Information You Provide to Us When you register or use our Platform, you will be asked to provide the following: • Your full name, email address, and mobile number 1 • Delivery address and location details • Personal photo and bio (for chefs) as your profile information • Food menu listings, descriptions, photos, and pricing (for chefs) • Payment information — for cash-on-delivery orders, we record transaction confirmations. Future payment

methods

(GCash,

Maya,

credit/debit

card)

will

be

processed

through

secure

third-party

payment

providers. • Bank account or e-wallet details for chef payouts • Government-issued ID (for chef identity verification) • Communications you send us through customer support Certain information such as government-issued identification and financial account details are considered Sensitive

Personal

Information

under

applicable

laws

and

are

processed

with

heightened

security

and

confidentiality

safeguards,

and

only

upon

lawful

basis

such

as

consent

or

compliance

with

legal

obligations.

3.2 Information We Collect Automatically When you use our Platform, we automatically collect: • Device information — device type, operating system, unique device identifiers • App usage data — pages visited, features used, time spent, search queries • Log data — IP address, browser type, access times, referring URLs • Location data — general location to show nearby chefs (precise location only with your permission) • Cookies and similar tracking technologies — to remember your preferences and improve your experience 3.3 Information From Third Parties We may receive information about you from: • Google Sign-In, if you choose to log in using your Google account • Third-party delivery partners, when their services are used to fulfill your order (see Section 6.2) • Payment processors when transactions are completed • Analytics providers who help us understand how our Platform is used 4. How We Use Your Information 4.1 To Provide and Operate the Platform • Create and manage your account • Process and fulfill food orders • Connect customers with home chefs in their area • Facilitate order communication between chefs, customers, and delivery partners • Process chef payouts and platform fee deductions 4.2 To Ensure Safety and Trust 2 • Verify the identity of chefs before they go live on the Platform • Investigate complaints, disputes, and reports of misconduct • Monitor for fraud, abuse, and violations of our Terms and Conditions • Comply with food safety obligations and applicable Philippine laws 4.3 To Improve Our Services • Analyze usage patterns to improve app performance and features • Conduct internal research and development • Fix bugs, errors, and technical issues 4.4 To Communicate With You • Send order confirmations, updates, and delivery notifications • Respond to your customer support inquiries • Send you important policy updates or changes to our services • Send promotional messages and marketing communications — only with your consent, and you may

opt

out

at

any

time 4.5 Legal Compliance • Comply with applicable laws including the Philippine Data Privacy Act of 2012 (RA 10173) and the

Internet

Transactions

Act

of

2023

(RA

11967)

and

their

respective

Implementing

Rules

and

Regulations; • National Privacy Council (NPC) Circulars especially on consent, breach notification, and data subject

rights; • Respond to lawful requests from government authorities • Enforce our Terms and Conditions and other legal agreements 5. Legal Basis for Processing Your Data We process your personal data based on one or more of the following lawful criteria under the applicable laws: ● Consent – for optional processing activities such as marketing, location tracking, and profile enhancements.

Consent

may

be

withdrawn

at

any

time.

● Contractual Necessity – where processing is necessary for the performance of a contract (e.g. order

fulfillment,

account

management). ● Legal Obligation – where processing is required to comply with applicable laws, regulations or lawful

orders. ● Legitimate Interest – for fraud prevention, system security, service improvement, and analytics, provided

these

do

not

override

your

fundamental

rights

and

freedoms.

6. How We Share Your Information We do not sell your personal data. We only share your personal information: 3 ● With your consent; ● When necessary to fulfill a transaction; ● When required by law or regulation; ● Under lawful data sharing agreements ensuring adequate safeguards 6.1 Between Chefs and Customers To facilitate orders, we share limited information between parties: • Customers can see a chef’s name, profile photo, bio, food listings, and general location area • Chefs receive a customer’s name, delivery address, and order details to fulfill an order • We do not share full contact numbers directly — all communication is facilitated through the Platform

where

possible 6.2 With Third-Party Delivery Partners SupaChefs may integrate with third-party delivery service providers to offer delivery options for orders. When

a

delivery

partner

is

used

to

fulfill

your

order,

we

may

share

the

following

information

with

them: • Customer name and delivery address • Order details and pickup location (chef’s general area) • Contact information necessary to complete the delivery All third-party service providers, including delivery partners, are required to comply with applicable data privacy

laws

and

are

bound

by

data

processing

or

data

sharing

agreements

to

ensure

that

your

personal

data

is

protected

and

used

only

for

legitimate

purposes. Supa Labs, Inc. exercises reasonable diligence in selecting its partners but remains accountable for ensuring

that

personal

data

shared

is

protected

in

accordance

with

applicable

law.

6.3 With Technology Service Providers We share information with trusted third-party providers who help us operate the Platform, including: • Cloud hosting and data storage providers • Payment processing partners • Analytics and performance monitoring tools • Customer support tools All service providers are contractually bound to handle your data securely and only for the purposes we specify. 6.4 For Legal Reasons We may disclose your information if required to: • Comply with a legal obligation or court order • Protect the rights, property, or safety of Supa Labs, Inc., our users, or the public • Investigate or prevent fraud, security threats, or violations of our policies • Respond to lawful requests from the National Privacy Commission (NPC) or other government authorities 4 6.5 Business Transfers If Supa Labs, Inc. undergoes a merger, acquisition, or sale of assets, your personal information may be transferred

as

part

of

that

transaction.

We

will

notify

you

within

a

reasonable

time

and

before

your

data

is

transferred

and

becomes

subject

to

a

different

privacy

policy. 7. Data Retention We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy

Policy,

or

as

required

by

law. • Active account data — retained for as long as your account remains active • Order history — retained for a minimum of 3 years for tax, accounting, and dispute resolution purposes • Chef verification documents — retained for the duration of the chef’s active status plus 1 year • Communications and support records — retained for 2 years • Deleted accounts — personal data is removed within 30 days of account deletion, except where legal

retention

obligations

apply Further, we determine retention periods based on: ● Nature and sensitivity of the data; ● Purpose of processing; ● Legal and regulatory requirements; and ● Risk of harm from unauthorized use or disclosure. After the applicable retention period, personal data is securely deleted, anonymized or disposed of in a manner

that

prevents

further

processing.

8. Data Security and Breach Notification We implement reasonable and appropriate technical and organizational security measures to protect your personal

information

from

unauthorized

access,

disclosure,

alteration,

or

destruction.

These

include: • Encrypted data transmission (HTTPS/TLS) • Secure cloud storage with access controls • Limited internal access to personal data on a need-to-know basis • Regular review of our data handling practices However, no method of transmission over the internet or electronic storage is 100% secure. In the event of

a

data

breach

that

poses

serious

risk

to

your

rights,

we

will

notify

the

National

Privacy

Commission

(NPC)

and

the

affected

individuals

as

required

by

law. In the event of a personal data breach likely to result in a risk to the rights and freedoms of data subjects, we

shall: ● Notify the National Privacy Commission within 72 hours from knowledge of the breach; ● Notify the affected data subjects without undue delay when required under applicable regulations; and ● Take immediate steps to mitigate and prevent such recurrence. 5 9. Your Rights Under the Philippine Data Privacy Act As a user of SupaChefs, you have the following rights under Republic Act No. 10173 (Data Privacy Act of 2012): • Right to be informed — you have the right to know how your personal data is being collected and used • Right to access — you may request a copy of the personal data we hold about you • Right to correction — you may request correction of inaccurate or outdated information • Right to erasure or blocking — you may request deletion or blocking of your personal data under certain

conditions • Right to object — you may object to the processing of your personal data, particularly for direct marketing • Right to data portability — you may request your data in a structured, commonly used format • Right to damages — you may claim compensation if your data privacy rights have been violated • Right to file a complaint — you may lodge a complaint with the National Privacy Commission (NPC)

at

www.privacy.gov.ph To exercise any of these rights: ● Submit a request via email to our Data Protection Officer through admin@supachefs.com; ● Provide sufficient proof of identity; ● Specify the right you wish to exercise. We will respond within a reasonable period in accordance with applicable regulations. Certain requests may

be

denied

where

legally

justified

(e.g.

retention

required

by

law).

10. Children’s Privacy SupaChefs is not intended for use by individuals under the age of 18. We do not knowingly collect personal

information

from

minors.

If

we

become

aware

that

a

user

under

18

has

provided

us

with

personal

information,

we

will

take

steps

to

delete

that

information

promptly. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at admin@supachefs.com. If processing of minor data becomes necessary in the future, we will ensure verifiable parental consent in accordance

with

applicable

laws

and

regulations.

11. Location Data We use location data to connect customers with nearby home chefs. Specifically: • We request access to your approximate location to display relevant chefs in your area • Precise GPS location is only accessed if you explicitly grant permission through your device settings • You may disable location access at any time through your device settings, though this may limit certain

Platform

features • We do not share your precise location with other users — only general area information is displayed 6 12. Cookies and Tracking Technologies We use cookies and similar technologies to improve your experience on our Platform. These help us: • Remember your login and preferences • Understand how users navigate and use our Platform • Analyze performance and fix issues You may control cookie settings through your browser or device settings. Disabling cookies may affect some

features

of

the

Platform. Where required, we obtain your consent before placing non-essential cookies. You may withdraw consent at

any

time.

13. Third-Party Links and Services Our Platform may contain links to third-party websites or services, including delivery partner platforms. We

are

not

responsible

for

the

privacy

practices

of

those

third

parties.

We

encourage

you

to

review

their

privacy

policies

before

providing

any

personal

information. 14. Cross-Border Data Transfers Supa Labs, Inc. operates primarily in the Philippines. However, some of our service providers (such as cloud

hosting

platforms)

may

store

or

process

your

data

outside

the

Philippines.

Where personal data is transferred outside the Philippines, we ensure that: ● The recipient country has adequate data protection standards; or ● Appropriate safeguards are in place, including contractual obligations requiring compliance with Philippine

data

protection

laws. We remain responsible for ensuring that transferred personal data is protected. 15. Changes to This Privacy Policy We may update this Privacy Policy from time to time. When we make material changes, we will: • Post the updated Privacy Policy on our website and within the app • Update the “Last Updated” date at the top of this document • Notify you through the app or via email for significant changes Your continued use of the Platform after any changes constitutes your acceptance of the updated Privacy Policy. 16. Data Protection Officer In compliance with the Philippine Data Privacy Act, Supa Labs, Inc. has designated a Data Protection Officer

(DPO)

responsible

for

overseeing

our

data

privacy

practices

and

compliance. DPO Contact: • Name: Roxanne Fay Casio, Chief Operating Officer • Email: admin@supachefs.com 7 • Address: Unit 413, Building 12, Urban Deca Homes, Hernan Cortes St., Cebu City Phils 6000 The Data Protection Officer is responsible for: • Monitoring compliance with data privacy laws; • Handling data subject requests and complaints; • Coordinating with the National Privacy Commission. 18. Automated Decision-Making We do not use fully automated decision-making processes that significantly affect users. If such systems are

introduced,

we

will

ensure

transparency

and

provide

users

with

the

right

to

object. 17. Data Minimization and Accuracy We take reasonable steps to ensure that personal data is accurate, complete and up to date. Users are encouraged

to

update

their

information

when

necessary. 18. How to Contact Us If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please

contact

us: • Email: admin@supachefs.com • Website: www.supachefs.com • Address: For complaints related to data privacy, you may also contact the National Privacy Commission: • Website: www.privacy.gov.ph • Email: info@privacy.gov.ph Supa Labs, Inc. (SupaChefs) — Privacy Policy — DRAFT FOR LEGAL REVIEW — Not for public distribution until reviewed

and

approved. 8