← Back to Home

Privacy Policy

Last updated: 6 June 2026

1. Introduction

ServiceSync SG Pte Ltd ("ServiceSync", "we", "us", or "our") is committed to protecting your personal data in accordance with the Personal Data Protection Act 2012 ("PDPA") of Singapore.

This Privacy Policy explains what personal data we collect, how we use and protect it, and your rights as a data subject. It applies to the ServiceSync website, the ServiceSync iOS and Android apps, and related services (together, the "Services").

2. Data We Collect

We collect the following categories of personal data:

  • Account data: Name, email address, phone number, password (hashed)
  • Business data: ACRA UEN, trade category, service areas, PayNow key
  • Client & booking data: The customer names, phone numbers, email addresses, service addresses, job descriptions and private notes that you (the business owner) enter to run your business
  • Payment data: Subscription billing details processed by Stripe (name, email, card metadata — we never store full card numbers), and invoice amounts, payment status, PayNow reference numbers and digital signatures
  • Technical data: IP address, browser type, device information, access logs
  • Usage & analytics data: Pages and features used, in-app actions, approximate session activity and crash/error diagnostics (see Section 5)
  • Contact data:If you choose to import contacts, we access names and phone numbers from your device's contact list or uploaded .vcf files. This data is only used to create client records in your account.
  • Location data:We use your device's location (with your permission) to estimate travel times, power turn-by-turn navigation to your jobs, and provide address autocomplete via OneMap SG. Location is used only while you are using these features and is not tracked in the background.
  • Push notification data: If you enable notifications, we store the device push token needed to deliver them
  • Review data:If a customer rates a completed job, we collect the name they provide, a star rating, and an optional comment. Reviews are displayed publicly on the technician's profile page.

3. How We Use Your Data

We use your personal data for the following purposes:

  • To create and manage your account
  • To facilitate bookings between customers and service providers
  • To process payments, subscriptions and issue invoices
  • To send transactional notifications (booking confirmations, payment receipts)
  • To verify business registration via ACRA
  • To understand product usage, fix bugs, monitor reliability and improve the Services (analytics and crash reporting)
  • To provide optional AI-assisted features you choose to use (see Section 6)
  • To comply with legal obligations

4. Legal Basis (PDPA Consent)

By creating an account, you consent to the collection, use, and disclosure of your personal data as described in this Policy. You may withdraw consent at any time by deleting your account, though this may affect your ability to use the Services.

5. Analytics, Cookies & Session Recording

We use a small number of trusted tools to keep the Services working and to improve them:

  • PostHog (product analytics): Records which pages and features are used and high-level in-app events. PostHog may also capture anonymised session recordings of how the interface is used. All text inputs are masked by default and passwords are never captured, so the content you type is not recorded.
  • Sentry (crash & error monitoring): Captures technical error and performance diagnostics so we can fix problems. Authentication tokens and cookies are stripped before transmission.
  • Cookies: We use strictly necessary cookies for authentication and session management. We do not use third-party advertising cookies. No cookie consent is required for strictly necessary cookies under the PDPA, but we provide transparency here.

6. AI-Assisted Features

Some optional features use artificial intelligence to help you draft text and summarise figures (for example, drafting a quote, categorising an expense, drafting a customer message, or summarising your GST figures). These features are off by default and are only available on paid plans.

AI requests are processed through the Vercel AI Gateway and the underlying model provider (Anthropic). We send only the minimum needed for the feature — typically text you have entered and, in some cases, a customer's name where you are drafting a message to that customer. We do not send your full client lists to the AI provider, and AI output is always shown to you for review before it is used. Our AI providers do not use your data to train their models.

7. Data Sharing & Processors

We do not sell your personal data. We share data only with the following categories of recipients:

  • Service providers: Customer contact details are shared with the technician assigned to a booking
  • Payment processors: Stripe (subscription billing) and PayNow (processed through DBS/OCBC/UOB banking rails)
  • Infrastructure partners: Supabase (database hosting) and Vercel (application hosting) — data stored in Singapore or APAC regions
  • Analytics & monitoring: PostHog (product analytics and masked session recording) and Sentry (error monitoring)
  • AI processing: Vercel AI Gateway and Anthropic, for the optional AI features described in Section 6
  • Maps & geocoding: OneMap SG (onemap.gov.sg) for address lookups. No personal data is sent — only the search query text.
  • Legal authorities: When required by Singapore law or court order

Each processor is engaged under contractual terms requiring them to protect your data and use it only to provide their service to us.

8. Data Retention

We retain your personal data for as long as your account is active. After account deletion:

  • Personal profile data is deleted within 30 days
  • Invoice and payment records are retained for 5 years as required by the Income Tax Act and GST regulations
  • Anonymised usage data may be retained indefinitely for analytics

9. Data Security

We implement industry-standard security measures including: encryption in transit (TLS 1.3), encryption at rest (AES-256), Row Level Security (RLS) policies on all database tables, secure cookie-based authentication, and Content Security Policy headers. Access to production systems is restricted to authorised personnel only.

10. Your Rights Under PDPA

You have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Update or correct inaccurate personal data via your Profile page
  • Withdrawal of consent / deletion: Delete your account and associated data at any time (see Section 11)
  • Data portability: Request your data in a machine-readable format

To exercise the access or portability rights, contact our Data Protection Officer at dpo@servicesync.sg.

11. Account Deletion

You can permanently delete your account and personal data directly from within the Services — no email request is required:

  • Mobile app: Profile → Delete account
  • Web: Dashboard → Settings → Delete account

Deletion removes your profile and all associated clients, bookings, invoices, quotes, schedule entries and services. Records we are legally required to keep (such as tax and GST invoices) are retained for the periods described in Section 8 and then deleted. You may also email dpo@servicesync.sg to request deletion.

12. Mobile App Permissions

The mobile app requests the following device permissions, each only when needed and only for the stated purpose. You can decline or revoke any of them in your device settings; the related feature will simply be unavailable.

  • Photos: to attach job photos and upload a business logo
  • Location (while in use): for navigation to jobs and address autocomplete
  • Contacts: to let you add clients from your phonebook
  • Notifications: to deliver booking and payment reminders

13. Children's Privacy

ServiceSync is a business tool intended solely for users aged 18 and over. We do not knowingly collect personal data from children. If you believe a minor has provided us with personal data, please contact us and we will delete it.

14. International Transfers

Your data is primarily stored and processed in Singapore. Where data is processed outside Singapore (e.g., by infrastructure, analytics or AI partners), we ensure adequate protection through contractual safeguards compliant with the PDPA Transfer Limitation Obligation.

15. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified via email or in-app notification at least 14 days before taking effect.

16. Contact & DPO

For privacy-related inquiries or complaints, contact our Data Protection Officer:

Email: dpo@servicesync.sg

If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commission (PDPC) at www.pdpc.gov.sg.