Privacy policy
Last updated: 2026-04-21
sg-pits ("we", "us") is operated by Maple Education Pte Ltd (UEN: 202349302E), a company incorporated in Singapore. This policy explains what personal data we collect, why, how long we keep it, and the rights you have under the Personal Data Protection Act 2012 (PDPA).
1. What we collect
- Email address — required for magic-link sign-in and reminder delivery.
- Consent records — a timestamped, append-only log of each marketing / service consent you grant or withdraw, along with the IP and user-agent at the time.
- Uploaded documents — tenancy agreements, inventory photos, receipts, correspondence, work-pass screenshots — stored in your personal vault on Cloudflare R2.
- Structured extractions — the fields you confirm from a lease or employment contract (dates, amounts, counterparty names).
- Work-pass records — pass type, issue/expiry dates, and (at your option) the last 4 characters of the FIN. We never store the full FIN.
- Audit logs — append-only records of security-relevant actions (sign-in, consent change, deletion request). Email addresses in audit metadata are stored as SHA-256 hashes so the log survives a PDPA erasure without leaking the plaintext address.
- BYOK API keys — if you save an LLM API key in Account → AI, we encrypt it with AES-GCM before writing to the database.
- Request metadata — IP, user-agent, and timestamps, for rate-limiting and abuse detection.
2. Why we collect it
- To authenticate you (magic-link sign-in).
- To deliver reminders you've opted into: rent due, stamp deadline, work-pass renewal, aircon service, lease renewal window, dispute follow-up.
- To honour your Data Subject Access Requests (export, correction, deletion).
- To provide the tools you use (vault storage, PDF generation, link library).
- To detect and block abuse (rate limits, sign-in flood control).
3. How long we keep it
- Account data — until you request deletion. After a deletion request the account is soft-deleted for 30 days, then hard-deleted by an automated sweep.
- Vault files — default retention is 2 years from upload (matching the typical Singapore private tenancy length). If you have a confirmed lease on file with a later move-out date, retention is extended to180 days after your lease ends so evidence survives the Small Claims dispute window. You can place any file under legal hold to pause deletion while a dispute is live. After the retention date, files are soft-deleted for 30 days (you can recover via a DPO request or by adding a legal hold) and then permanently purged from R2.
- Consent log + audit log — retained for at least 5 years to meet accountability obligations. Email addresses appear only as SHA-256 hashes.
- Magic-link tokens — single-use. Used tokens are retained for audit; unused tokens are cleaned by the daily retention cron. For convenience we no longer auto-expire unused links — however, you should treat a sign-in link in your inbox with the same care as any password, and request a fresh one if you suspect the original message was seen by someone else.
4. Who we share it with
- Cloudflare — Workers, D1, R2, KV. All storage is on Cloudflare's global network; data may transit through Cloudflare data centres outside Singapore.
- Resend — transactional and marketing email delivery.
- Your chosen LLM provider (BYOK only) — if and only if you enable a BYOK LLM config, the text you submit for extraction (e.g. lease text) is sent to the provider you selected (DeepSeek, OpenAI, Qwen, SiliconFlow, or a custom endpoint). Your API key stays in your account, encrypted at rest.
- We do not sell personal data and we do not share it with advertisers.
5. Cross-border transfers
Your data is stored on Cloudflare infrastructure which operates globally. Cloudflare's privacy and subprocessor lists are at cloudflare.com/privacypolicy. We take reasonable steps under PDPA §26 to ensure transfer destinations provide a standard of protection comparable to Singapore's.
6. Your rights
You have the right to:
- Access your data — use "Export my data" in Account for a JSON export, or submit a DPO request.
- Correct your data — edit it in-product, or submit a DPO correction request.
- Delete your account — use "Delete account" in Account. Soft-deleted for 30 days, then hard-deleted by automated sweep.
- Withdraw consent — toggle marketing consent off in Account at any time.
- Complain to us first, then to the PDPC at pdpc.gov.sg if unresolved.
7. Security
- All traffic over HTTPS (TLS 1.3).
- Session cookies are HttpOnly, SameSite=Lax, Secure in production.
- Sessions are stored as SHA-256 hashes; the raw token never hits the database.
- BYOK API keys are encrypted with AES-GCM before storage.
- Audit log is append-only and hash-chained to detect tampering.
8. Contact the DPO
Data Protection Officer — Director, Maple Education Pte Ltd · rubyzhou25@gmail.com. The DPO will acknowledge within 3 business days and respond substantively within 30 days of receipt, per PDPA §21.
We may update this policy. When we make a material change we'll update the version date above and, for logged-in users, show a one-time banner the next time you sign in.