Starter legal document
Privacy Policy
Review before commercial launch: Confirm actual vendors, retention periods, contact details and Singapore PDPA obligations with a qualified professional.
Information collected
SINGO may collect account details, merchant profile information, deal claims, redemption records, limited security logs and technical request data needed to operate and protect the service.
How information is used
Information is used to authenticate users, deliver claims, verify merchant redemptions, administer listings, prevent abuse, troubleshoot errors and improve the service.
Passwords and sessions
Passwords are stored as one-way hashes. Session tokens are stored in HttpOnly cookies and only hashed session tokens are stored in the database.
Service providers
Production deployment may use hosting, PostgreSQL and optional AI providers. The final policy must identify the providers actually chosen and the data each receives.
Retention and rights
Define operational retention periods and processes for access, correction and deletion requests before launch. Security logs should be retained only as long as reasonably necessary.