Lpeso PRIVACY POLICY

Platform: Android

Operated by Singularity Financing Inc.

Policy Version: 1.0

Effective Date: August 20, 2026

Last Revised: August 20, 2026


1. About This Policy

This Privacy Policy explains how Singularity Financing Inc. processes personal information when you apply for, receive, manage, or repay a loan through the Lpeso Android application. In this Policy, the Lpeso Android application is the App, and a loan applied for or obtained through the App is a Loan. This Policy also covers account administration, identity verification, fraud prevention, customer support, complaints, and related legal and regulatory duties.

In this Policy, we, us, and our mean Singularity Financing Inc. You and your mean an applicant, borrower, or other person who uses Lpeso.

We act as the Personal Information Controller for the processing described in this Policy. Some service providers process personal information for us under our instructions. Other recipients, such as the Credit Information Corporation (CIC) or a payment provider acting under its own legal duties, may act as separate controllers for their own processing.

Reading or acknowledging this Policy does not provide every consent that may be needed. Where we rely on consent, we request it separately for the relevant processing. Sensitive Personal Information, qualifying financial transaction data from Short Message Service (SMS) messages, limited App checks, optional approximate foreground location, and marketing each have separate controls where applicable.


2. Company and Contact Information

  • Legal name: Singularity Financing Inc.
  • App and online lending platform: Lpeso, Android
  • Securities and Exchange Commission (SEC) Company Registration No.: 2021060015436-59
  • SEC Certificate of Authority No.: 1326
  • Registered office: The Penthouse, Marajo Tower, 26th Street cor. 4th Avenue, Bonifacio Global City, Taguig City, Metro Manila 1634, Philippines
  • Data Protection Officer (DPO): dpo@lpeso.ph
  • Customer service and complaints: cs@lpeso.ph

3. Rules That Apply

We process personal information under the Data Privacy Act of 2012, its Implementing Rules and Regulations, and applicable National Privacy Commission (NPC) issuances. Our lending operations are also subject, as applicable, to the Financing Company Act, the Truth in Lending Act, the Credit Information System Act, the Anti-Money Laundering Act (AMLA), the Financial Products and Services Consumer Protection Act (FCPA) and its implementing rules, and other Philippine laws.

Our current SEC regulatory references include:

  1. SEC Memorandum Circular No. 20, Series of 2026, including its requirements on data privacy, automation, profiling, disclosures, credit information, and collection conduct;
  2. SEC Memorandum Circular No. 14, Series of 2025, where the loan is within its scope;
  3. SEC Memorandum Circular No. 5, Series of 2023, to the extent applicable and as amended or modified by SEC Memorandum Circular No. 20, Series of 2026; and
  4. the substantive collection rules in SEC Memorandum Circular No. 18, Series of 2019, as amended or modified by SEC Memorandum Circular No. 20, Series of 2026 and later applicable issuances.

We also apply applicable Google Play requirements for personal-loan Apps, user data, sensitive device access, and limited checks for other Apps.


4. Information We Do Not Obtain From Your Device

Lpeso does not obtain or use the following device data:

  • your Contacts or address book;
  • your Call Logs or call history;
  • broad access to your photo or media library;
  • precise location or background location;
  • emergency contacts;
  • calendar data;
  • clipboard contents;
  • browsing history;
  • messages from third-party messaging applications; or
  • a complete inventory of Apps installed on your device.

We do not use device contacts, reference persons, or similar third-party data to contact another person for collection or to treat that person as a guarantor, surety, co-maker, or person liable for your loan unless that person separately and expressly agreed in writing to assume that legal obligation.


5. Data Processing Details

Each category below uses the same fields so you can review how we handle it. More than one lawful basis may apply when the same information is used for different purposes. We document the basis for each activity and do not treat consent as the basis when contract performance, legal obligation, or another lawful basis applies.

5.1 Account and Contact Data

Data: Name, mobile number, email address, residential address, account identifier, and authentication records.

Source: You, and records created when you register or authenticate.

Purpose: Create and secure your account; send one-time codes and service notices; communicate about an application, Loan, support request, or complaint.

Legal basis: Steps at your request before a contract; contract performance; legal obligation; legitimate interest in account security.

Recipients: Communications providers; hosting and security providers; customer support providers; authorities when legally required.

Retention: For the account relationship and afterward only as needed for legal, contractual, security, complaint, or claims requirements.

User control: Correct your details; manage communication settings; request access, correction, erasure, or blocking where applicable.

5.2 Identity and Profile Data

Data: Date of birth, nationality, marital status, educational attainment, number of dependents, housing status, employment, employer details, and self-reported income.

Source: You.

Purpose: Assess eligibility; verify application details; perform responsible lending and credit assessment; comply with customer due diligence duties.

Legal basis: Steps before contract and contract performance; legal obligation; consent where the Data Privacy Act requires consent for Sensitive Personal Information.

Recipients: Know Your Customer (KYC) and document verification providers; fraud and compliance providers; CIC where applicable; authorities when legally required.

Retention: According to the purpose and applicable legal retention duties, including the periods in Section 11.

User control: Review and correct your information; withdraw consent where consent applies; request manual or alternative verification when available.

5.3 Government-Issued Identification (ID) Data

Data: The selected document image, ID number, issuing authority, and validity information.

Source: You, through a user-initiated Camera capture or system file or image selection.

Purpose: Verify identity and document authenticity; prevent impersonation and fraud; satisfy customer due diligence and recordkeeping duties.

Legal basis: Legal obligation; steps before contract; contract performance; separate consent where required for Sensitive Personal Information.

Recipients: KYC and document authentication providers; compliance and security providers; authorities when legally required.

Retention: For required identity and compliance records and afterward only for applicable legal, audit, complaint, or claims periods.

User control: Choose the available capture or file selection method; exercise data subject rights; withdraw consent where consent applies, subject to another valid basis.

5.4 Selfie, Liveness, and Biometric Data

Data: Selfie, facial image, liveness result, and biometric or similarity result if the KYC flow uses them.

Source: You, through a user-initiated Camera session; KYC or biometric provider.

Purpose: Confirm that the applicant is present; compare the applicant with the submitted ID; prevent impersonation and account takeover.

Legal basis: Separate consent where required for Sensitive Personal Information; legal obligation or another basis where Philippine law permits.

Recipients: KYC, liveness, and biometric verification providers; security and fraud providers.

Retention: Only for the verification, audit, legal, and fraud-prevention periods that apply to the implemented process. A provider may not retain it for an unrelated purpose.

User control: Receive a separate notice and consent control where consent applies; request an available manual or alternative KYC route; withdraw consent subject to lawful continuing processing.

5.5 Loan and Transaction Data

Data: Requested and approved amounts, loan purpose, disclosures, agreements, repayment schedule, disbursement, payments, balance, arrears, servicing, and collection records.

Source: You; Lpeso transaction systems; banks, e-wallets, payment providers, and lawful collection providers.

Purpose: Evaluate, document, disburse, service, collect, reconcile, and close the Loan; provide required disclosures and account records.

Legal basis: Steps before contract; contract performance; legal obligation; legitimate interest in establishing, exercising, or defending legal claims.

Recipients: Banks, e-wallets, and payment providers; lawful collection providers and counsel; CIC; authorities, courts, and law enforcement when legally required.

Retention: For the Loan lifecycle and the legal, accounting, tax, regulatory, complaint, and claims periods in Section 11.

User control: Access account and transaction records; correct errors; dispute payments, balances, or credit information; request deletion subject to lawful retention.

5.6 Bank or E-Wallet Details

Data: Account name, provider, masked or full account identifier where needed, and transfer reference.

Source: You; bank, e-wallet, or payment provider.

Purpose: Verify ownership where required; disburse funds; receive and reconcile payments; investigate failed or disputed transactions.

Legal basis: Contract performance; steps before contract; legal obligation; legitimate interest in fraud prevention and reconciliation.

Recipients: Banks, e-wallets, payment gateways, and reconciliation providers; authorities when legally required.

Retention: For transaction processing and applicable accounting, AMLA, tax, complaint, and claims periods.

User control: Choose from available payment methods; correct account details; dispute a transaction.

5.7 Credit Information

Data: Lpeso repayment history and credit data obtained from or submitted to the Credit Information Corporation and other lawful credit sources.

Source: Lpeso; CIC; lawful credit bureaus or credit reference sources.

Purpose: Assess creditworthiness and affordability; support responsible lending; submit and correct credit data as required by law; manage credit risk.

Legal basis: Legal obligation under the Credit Information System Act and applicable rules; steps before contract; contract performance; legitimate interest in responsible credit risk management.

Recipients: CIC and its lawful participants; approved credit providers; authorities when legally required.

Retention: According to credit reporting, contract, regulatory, complaint, and claims requirements.

User control: Request access and correction; dispute incomplete, inaccurate, or misleading credit information; request human review of a decision.

5.8 Qualifying Financial SMS Transaction Fields

Data: The minimum sender and message data is processed briefly on your device only to determine whether a message is a qualifying financial transaction message. Non-matching content is not uploaded to Lpeso servers and is not retained. For a qualifying message, only the financial-institution sender, transaction type, amount, date and time, reference, status, and masked account indicator needed for the disclosed purpose are uploaded or retained.

Source: Your device, only after Lpeso presents a separate prominent in-App disclosure, you provide separate consent, and you grant the Android SMS permission. Messages are checked only when identified as coming from a recognized bank, e-wallet provider, payment gateway, or other financial institution.

Purpose: Qualifying financial transaction fields may be used only to verify financial transactions, reported income or cash flow, disbursements, repayments, repayment capacity, transaction fraud, or another disclosed financial verification step. They may assist automated credit assessment and, for a new application, may affect eligibility and the proposed loan amount or credit limit. They are not used for advertising and are not sold.

Legal basis: Separate consent for access, checking, uploading, and use of qualifying fields. Legal obligation and legitimate interest in demonstrating compliance and security support retention of consent evidence and legally required audit records after consent is withdrawn.

Recipients: Lpeso personnel with a need to know; approved security, fraud, or financial verification processors; authorities only when legally required. Only qualifying financial transaction fields are sent to Lpeso or these processors.

Retention: Only qualifying financial-institution transaction fields are retained for the relevant disclosed financial verification, fraud, legal, or audit purpose. Consent evidence and legally required audit records may be retained after withdrawal under legal obligation and legitimate interest in demonstrating compliance and security. Non-matching content remains on the device only for the brief classification step, is not uploaded to Lpeso servers, and is not retained.

User control: You may decline, revoke the Android SMS permission, or withdraw the related processing consent through the available in-App control or by contacting the DPO. Refusing or withdrawing this access is not a breach or default and does not change an already confirmed Loan. If the financial check is still needed for a new application, you may provide transaction evidence manually or use another lawful verification method where available. Withdrawal does not affect processing already performed lawfully.

5.9 Limited App Checks

Data: A yes or no result showing whether one of a limited number of pre-identified Apps linked to known fraud, unauthorized remote control, or a compromised device is present. Lpeso does not obtain the complete list of Apps on your device and does not read another App's content, internal data, communications, or usage history.

Source: Your device, after a separate in-App disclosure and consent, by checking only the specific Apps and purpose described before consent. This check does not use an Android device permission prompt.

Purpose: Fraud prevention, security, and device-integrity checks only. The result is not used for ordinary credit scoring, credit-limit setting, advertising, marketing profiling, analytics monetization, or sale. A result that indicates possible fraud or device risk may cause the application to be referred for human review or an alternative verification step.

Legal basis: Separate consent for checking and use. Legal obligation and legitimate interest in demonstrating compliance and security support retention of consent evidence and legally required audit records after consent is withdrawn.

Recipients: Lpeso personnel with a need to know; approved fraud and security processors; authorities only when legally required.

Retention: Only the necessary yes or no result, a record of which disclosed check was applied, consent evidence, and legally required audit records are retained for the relevant fraud, security, legal, or audit purpose. Consent evidence and legally required audit records may be retained after withdrawal under legal obligation and legitimate interest in demonstrating compliance and security. No complete installed-App list is retained.

User control: You may decline or withdraw consent through the available in-App control or by contacting the DPO. Refusing or withdrawing consent is not a breach or default and does not change an already confirmed Loan. If the check remains necessary for a new application, you may use an available manual or alternative fraud or device-security verification method. Withdrawal does not affect processing already performed lawfully.

5.10 Optional Approximate Foreground Location

Data: Approximate location while the App is in use. No precise or background location record is created.

Source: Your device while the App is in use, after you grant coarse location access.

Purpose: Check whether an application appears to originate in an expected service area; detect unusual geographic or fraud patterns.

Legal basis: Separate consent for optional device location access; legitimate interest in fraud prevention where allowed.

Recipients: Fraud and security processors; authorities when legally required.

Retention: Only for the fraud, security, audit, or legal period applicable to the location result. We do not retain precise or background location.

User control: Decline or revoke coarse location access; use an available alternative verification route.

5.11 Device, Network, and Security Data

Data: Device model, operating system, language, network type, Internet Protocol (IP) address received by our server, an identifier used to distinguish this Lpeso installation, checks showing whether the App and device appear genuine, signs that device software may have been altered, signs that the App is running in a simulated device environment, and signs of suspicious automated input.

Source: Your device; Android and related platform services; Lpeso servers.

Purpose: Maintain compatibility and service security; prevent account takeover, device manipulation, automated abuse, and fraud; diagnose security events.

Legal basis: Contract performance; legitimate interest in service and account security; legal obligation where applicable.

Recipients: Hosting, infrastructure, security, fraud, and diagnostics providers; authorities when legally required.

Retention: For the account or security event and afterward only for applicable fraud, audit, legal, complaint, or claims periods.

User control: Manage or reset an identifier where Android provides that control; object where applicable; request access or deletion subject to lawful retention.

5.12 App Usage and Diagnostics

Data: Screens viewed, actions taken, timestamps, application flow status, crash data, and performance information.

Source: Your use of Lpeso; App and diagnostics systems.

Purpose: Operate the service; troubleshoot errors; maintain performance and security; improve the App using aggregated or de-identified analysis where appropriate.

Legal basis: Contract performance; legitimate interest in a reliable and secure service.

Recipients: Hosting, diagnostics, security, and technical support providers.

Retention: For the period needed to troubleshoot, secure, and improve the service, subject to shorter operational schedules and legal needs.

User control: Use device or App settings where available; object to processing where applicable; request access or deletion subject to lawful retention.

5.13 Support, Complaint, and Rights-Request Records

Data: Messages, attachments you choose to provide, investigation notes, and resolution records.

Source: You; customer service; DPO; service providers; regulators where a matter is escalated.

Purpose: Respond to inquiries; investigate and resolve complaints; handle data subject requests; demonstrate regulatory compliance.

Legal basis: Contract performance; legal obligation; legitimate interest in resolving disputes and establishing or defending claims.

Recipients: Customer support and communications providers; DPO and authorized staff; SEC, NPC, courts, counsel, and other authorities where appropriate.

Retention: For the period required by applicable FCPA, SEC, NPC, complaint-handling, and claims rules.

User control: Access and correct your submissions; add relevant information; escalate to the SEC or NPC; request restriction or deletion where allowed.

5.14 Marketing Preferences and Interactions

Data: Your marketing opt-in or opt-out, delivery status, and interaction with a marketing message.

Source: Your separate choice; delivery records.

Purpose: Send and measure marketing communications that you chose to receive.

Legal basis: Separate consent.

Recipients: Communications delivery providers and approved marketing processors acting under our instructions.

Retention: Until withdrawal, plus the minimum suppression and consent record needed to honor and prove your choice.

User control: Opt in separately; opt out at any time without affecting service messages or your Loan.


6. Camera, Selected Files, and Location Controls

6.1 Camera and KYC

The Camera is used only during a user-initiated capture of a government ID, selfie, or liveness step presented in the KYC flow. It is not used for background capture. The screen explains what will be captured and why before capture begins.

6.2 Selected Images or Files

Where an upload option is available, Lpeso uses Android's file or image selection screen so you select the specific item to provide. This selection does not give Lpeso broad access to your photo or media library.

6.3 Approximate Foreground Location

Coarse location is optional and may be accessed only while you use the relevant Lpeso feature in the foreground. Lpeso does not request or collect precise location or background location. If you decline, we may use another available verification or fraud check.


7. Purposes and Lawful Bases

We use personal information only for disclosed, legitimate purposes. The main lawful bases are:

  1. Steps before a contract and contract performance. This covers processing needed to receive and evaluate your application at your request, create and secure your account, present loan terms, disburse and service an accepted Loan, receive payments, and provide support.
  2. Legal obligation. This covers customer due diligence, AMLA recordkeeping and reporting, CIC submission and correction, consumer disclosures, complaint handling, tax and accounting duties, regulatory reporting, lawful orders, and other requirements that apply to financing companies.
  3. Legitimate interest. This covers proportionate processing needed to prevent fraud and account takeover, protect systems, diagnose errors, manage credit and operational risk, and establish, exercise, or defend legal claims. We assess necessity and the effect on your rights before relying on this basis.
  4. Consent. We use separate consent when required, including for consent-based processing of Sensitive Personal Information, qualifying Financial SMS, limited App checks, optional coarse location access, and marketing. You may withdraw consent without affecting processing already performed lawfully. Consent evidence and legally required audit records for Financial SMS and limited App checks may remain under legal obligation and legitimate interest in demonstrating compliance and security. Another documented lawful basis may continue to apply to other specific records or purposes after withdrawal.

We do not make access to an existing confirmed Loan conditional on optional Financial SMS, limited App checks, optional location, or marketing consent. Before approving a new application, we may still require a lawful identity, affordability, transaction, fraud, security, or device check and provide a manual or alternative route where available.


8. Automated Processing, Credit Scoring, and Profiling

Lpeso may use automated tools to assist with identity verification, fraud screening, credit assessment, loan eligibility, credit-limit setting, servicing, and security. Ordinary credit assessment and credit-limit setting may consider application data, verified identity data, Lpeso repayment history, CIC or other lawful credit data, and transaction records. Any automated processing of Financial SMS or limited App check results remains subject to the specific data, purpose, consent, and use limits in Sections 5.8 and 5.9.

We do not use Contacts, Call Logs, personal or non-financial SMS, precise or background location, or a complete installed-App list in credit scoring.

Automated processing can affect whether a new application is approved, referred for further checks, found eligible, or assigned a credit limit within applicable product and legal limits. We maintain human oversight appropriate to the decision and applicable law.

You may ask for meaningful information about the categories of information and main factors used, request human review, provide additional information, express your point of view, and contest a decision. Contact cs@lpeso.ph or dpo@lpeso.ph and include the relevant application or Loan reference when available. We may protect security controls, fraud-detection methods, trade secrets, and another person's rights while still giving the information required by law.


9. When We Disclose Personal Information

We do not sell, rent, or trade personal information. We do not allow a processor to use personal information for its own advertising or to sell it.

9.1 Controller Disclosures

We may disclose necessary personal information to a recipient that acts under its own legal authority or purpose:

  • the Credit Information Corporation, for required credit data submission, access, correction, and dispute handling;
  • the Securities and Exchange Commission, Anti-Money Laundering Council, National Privacy Commission, Bureau of Internal Revenue, and other competent regulators or government authorities;
  • courts, tribunals, law enforcement bodies, and other persons acting under a valid legal process;
  • banks, e-wallet providers, payment gateways, and other payment providers when they independently process a disbursement or repayment under financial laws;
  • lawful collection providers, assignees, and external counsel to service or enforce a Loan, resolve a dispute, or establish, exercise, or defend legal claims, subject to fair collection and privacy rules; and
  • a prospective or completed corporate transaction recipient in a merger, acquisition, financing, reorganization, asset transfer, loan portfolio transfer, securitization, or assignment, subject to confidentiality, due diligence limits, applicable notices, and continuing legal protections.

9.2 Processor Sharing

We may appoint service providers to process personal information only for our documented purposes and instructions. Processor categories may include:

  • identity verification, document authentication, biometric matching, and liveness providers;
  • cloud hosting, storage, database, infrastructure, backup, and security providers;
  • fraud prevention, device integrity, risk, sanctions, and compliance providers;
  • banks, e-wallets, payment gateways, disbursement, repayment, and reconciliation providers when acting for us;
  • customer support, complaint management, and rights-request tools;
  • SMS, email, push notification, voice, and other communications delivery providers;
  • App performance, crash diagnostics, and technical support providers; and
  • lawful collection service providers and counsel when they process information on our instructions.

We require processors to apply confidentiality, access, security, retention, deletion, incident, audit, and subprocessing controls appropriate to their role and applicable law. A current processor register is maintained internally and can be requested from the DPO, subject to security and contractual limitations.


10. International Processing

A processor may handle personal information outside the Philippines. Before an international transfer, we assess the purpose, data, recipient, destination, and safeguards required by the Data Privacy Act and applicable NPC rules. We use appropriate contractual, organizational, and technical safeguards and require the recipient to protect the information for the disclosed purpose. We do not claim that all information remains in a particular country unless the implemented data flow has been verified.


11. Retention and Disposal

We retain personal information only for the period needed for the disclosed purpose and for applicable legal, regulatory, contractual, tax, accounting, complaint, security, audit, and claims requirements. The retention period depends on the category, the status of an application or Loan, and whether a dispute, investigation, legal hold, or regulatory direction applies.

The following rules guide our retention schedule:

  1. Customer identification, account, and transaction records covered by the Anti-Money Laundering Act are retained for at least five (5) years from the applicable statutory trigger, including the end of the business relationship or completion of the relevant transaction, as required by law.
  2. Contract, transaction, tax, accounting, and legal-claims records may be retained for up to ten (10) years when the applicable law, limitation period, audit need, or defense of a claim requires it.
  3. Complaint and dispute records are retained for the period required by applicable FCPA, SEC, NPC, and complaint-handling rules and for any related claim or investigation.
  4. CIC data and submission records are retained and corrected according to the Credit Information System Act, CIC rules, and applicable dispute obligations.
  5. For Financial SMS, non-matching content is processed briefly on the device only for classification. It is not uploaded to Lpeso servers and is not retained. We retain only qualifying financial-institution transaction fields for the relevant disclosed financial purpose. Consent evidence and legally required audit records may remain after withdrawal under legal obligation and legitimate interest in demonstrating compliance and security.
  6. For limited App checks, we retain only the necessary yes or no result, a record of which disclosed check was applied, consent evidence, and legally required audit records for the relevant fraud, security, legal, or audit purpose. Consent evidence and legally required audit records may remain after withdrawal under legal obligation and legitimate interest in demonstrating compliance and security. We do not retain a complete list of Apps installed on your device.
  7. Marketing data is processed until you withdraw consent, after which we may keep the minimum suppression and consent record needed to honor and demonstrate your choice.

When retention is no longer permitted or necessary, we securely delete, destroy, or anonymize the information under our approved disposal process. Backup copies and records under a legal hold are handled under documented schedules and access restrictions.


12. Security and Personal Data Breaches

We apply reasonable and appropriate organizational, physical, and technical safeguards based on the nature of the information, processing risks, available technology, and legal requirements. These safeguards include appropriate access controls, confidentiality duties, personnel training, change and incident management, vendor oversight, secure development and operations practices, and measures to protect information in storage and transmission.

No system can eliminate every security risk. We review safeguards and address identified weaknesses according to risk. If a Personal Data Breach occurs, we investigate, contain, document, and notify the National Privacy Commission and affected people when and within the period required by applicable law.


13. Your Data Subject Rights

Subject to the Data Privacy Act and lawful limitations, you may exercise the following rights:

  • be informed about the processing of your personal information;
  • request access to personal information and processing details;
  • correct inaccurate or incomplete information;
  • object to processing based on legitimate interest, direct marketing, automated processing, or profiling where the right applies;
  • withdraw consent for processing based on consent;
  • request erasure, blocking, or restriction where the legal conditions are met;
  • obtain data portability where applicable;
  • request human review and contest an automated decision;
  • seek damages where provided by law; and
  • file a complaint with the National Privacy Commission or another competent authority.

You may submit a request even if you have an outstanding or active Loan. We do not require full repayment before accepting and evaluating an account deletion, erasure, blocking, objection, or other rights request. An outstanding Loan may limit what we can delete because we may still need information to perform the contract, apply payments, communicate with you, collect lawfully, comply with AMLA, CIC, SEC, tax, and accounting duties, resolve complaints, or establish, exercise, or defend claims.

We will process the parts of your request that can be fulfilled and explain any lawful limitation. You may be asked for information reasonably needed to verify your identity and protect your account. We respond within the period required by applicable law.

Send requests to dpo@lpeso.ph. You may also contact cs@lpeso.ph for an account or Loan concern.

13.1 Credit Information Rights

For credit information, you may request access, dispute inaccurate, incomplete, or misleading data, seek correction through the applicable CIC process, and receive notices required by the Credit Information System Act and CIC rules. Information about CIC processes is available from the Credit Information Corporation through its official channels.

13.2 Permission and Consent Controls

You can manage Android permissions through your device settings. Revoking a permission stops future access through that permission but does not by itself erase information already processed lawfully. Consent withdrawal controls are separate from Android permission settings. Use both controls where applicable, or contact the DPO for assistance.


14. Service and Marketing Communications

We may send account, security, application, Loan, payment, collection, complaint, and legal notices through the contact channels you provided. We process these service communications under contract, legal obligation, or another applicable lawful basis. Opting out of marketing does not stop necessary service or legal communications.

Marketing requires a separate, freely given opt-in. You can withdraw that consent through the available preference control, an unsubscribe method in the communication, or a request to the DPO. Financial SMS and limited App checks are never used for advertising.


15. Third-Party Services

Lpeso may link to or interact with a bank, e-wallet, government service, or another third-party service. This Policy covers our processing. A third party's own privacy notice applies when it independently determines how it processes your information. Review that notice before providing information directly to the third party.


16. Changes to This Policy

We may update this Policy to reflect changes in law, regulation, App functions, data flows, providers, or security practices. We will update the version and Last Revised date. We will give notice of a material change through an appropriate channel. If a change requires a new consent, we will request that consent before starting the consent-based processing. Continued use of Lpeso does not replace a consent required by law.

Prior versions may be requested from the DPO.


17. Questions and Complaints

For a privacy question, data subject request, or complaint, contact:

Data Protection Officer

Singularity Financing Inc.

Email: dpo@lpeso.ph

Registered office: The Penthouse, Marajo Tower, 26th Street cor. 4th Avenue, Bonifacio Global City, Taguig City, Metro Manila 1634, Philippines

For general customer service or a Loan complaint, email cs@lpeso.ph.

You may also file a complaint through the current official channels of the National Privacy Commission or the Securities and Exchange Commission. Contacting us first is not a waiver of your right to contact a regulator or seek another lawful remedy.


18. Acknowledgment and Separate Consents

By acknowledging this Policy, you confirm only that the Policy was made available to you and that you had an opportunity to read it. Your acknowledgment is not a bundled consent to every processing activity.

Where consent is the lawful basis, Lpeso presents a separate notice and affirmative control for the relevant processing. The following choices are separate from each other and from confirmation of a Loan:

  1. consent-based processing of Sensitive Personal Information, including biometric or liveness data where applicable;
  2. qualifying Financial SMS processing;
  3. limited App checks;
  4. optional coarse foreground location access; and
  5. marketing communications.

Refusing or withdrawing an optional choice is not a breach or default. Processing needed under contract, legal obligation, legitimate interest, or another lawful basis is not converted into consent-based processing by your acknowledgment of this Policy.


End of Lpeso Privacy Policy.