PDPA Compliance

Singapore's Personal Data Protection Act 2012

What is the PDPA?

The Personal Data Protection Act (PDPA) is Singapore's data protection law that governs the collection, use, disclosure, and care of personal data by organisations. It establishes 11 obligations that organisations must follow to protect individuals' personal data.

How Halfway Hungry Complies

Halfway Hungry LLP complies with all 11 PDPA obligations. Here is how we meet each one:

1. Accountability

We have appointed a Data Protection Officer (DPO) and maintain documented data protection policies.

2. Notification

We inform you of what data we collect and why before collecting it, through our Privacy Policy and signup process.

3. Consent

We obtain your explicit consent via a checkbox at signup. You can withdraw consent at any time by deleting your account.

4. Purpose Limitation

Your data is used only for order processing, payments, delivery coordination, and service improvement — nothing else.

5. Accuracy

You can view and update your profile information directly in the app at any time.

6. Protection

We use HTTPS encryption, row-level security, column-level access controls, and service role separation to protect your data.

7. Retention Limitation

We keep data only as long as needed: account data while active, order history for 2 years, photos for 6 months. Deleted accounts are anonymised within 30 days.

8. Transfer Limitation

We disclose all international data transfers (Stripe, Supabase, Vercel, Resend) and ensure comparable protection standards.

9. Access & Correction

You can download all your data as a JSON file or request corrections via our DPO. We respond within 30 days.

10. Data Breach Notification

We will notify the PDPC within 3 days and affected users as soon as practicable in the event of a significant data breach.

11. Data Portability

You can export your personal data in machine-readable JSON format from your Profile page at any time.

Your Rights

As a user, you can:

  • Download your data — from your Profile page
  • Delete your account — from your Profile page (data anonymised within 30 days)
  • Withdraw consent — by deleting your account or contacting our DPO
  • Request corrections — update your profile or email our DPO

Data Protection Officer

For any PDPA-related questions or data requests, contact our DPO:

halfwayhungryadmin@gmail.com

Halfway Hungry LLP
Singapore Management University
81 Victoria Street, Singapore 188065

For the full details of how we handle your data, please read our Privacy Policy. If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commission (PDPC).