PDPA Compliance
Singapore's Personal Data Protection Act 2012
What is the PDPA?
The Personal Data Protection Act (PDPA) is Singapore's data protection law that governs the collection, use, disclosure, and care of personal data by organisations. It establishes 11 obligations that organisations must follow to protect individuals' personal data.
How Halfway Hungry Complies
Halfway Hungry LLP complies with all 11 PDPA obligations. Here is how we meet each one:
1. Accountability
We have appointed a Data Protection Officer (DPO) and maintain documented data protection policies.
2. Notification
We inform you of what data we collect and why before collecting it, through our Privacy Policy and signup process.
3. Consent
We obtain your explicit consent via a checkbox at signup. You can withdraw consent at any time by deleting your account.
4. Purpose Limitation
Your data is used only for order processing, payments, delivery coordination, and service improvement — nothing else.
5. Accuracy
You can view and update your profile information directly in the app at any time.
6. Protection
We use HTTPS encryption, row-level security, column-level access controls, and service role separation to protect your data.
7. Retention Limitation
We keep data only as long as needed: account data while active, order history for 2 years, photos for 6 months. Deleted accounts are anonymised within 30 days.
8. Transfer Limitation
We disclose all international data transfers (Stripe, Supabase, Vercel, Resend) and ensure comparable protection standards.
9. Access & Correction
You can download all your data as a JSON file or request corrections via our DPO. We respond within 30 days.
10. Data Breach Notification
We will notify the PDPC within 3 days and affected users as soon as practicable in the event of a significant data breach.
11. Data Portability
You can export your personal data in machine-readable JSON format from your Profile page at any time.
Your Rights
As a user, you can:
- Download your data — from your Profile page
- Delete your account — from your Profile page (data anonymised within 30 days)
- Withdraw consent — by deleting your account or contacting our DPO
- Request corrections — update your profile or email our DPO
Data Protection Officer
For any PDPA-related questions or data requests, contact our DPO:
Halfway Hungry LLP
Singapore Management University
81 Victoria Street, Singapore 188065
For the full details of how we handle your data, please read our Privacy Policy. If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commission (PDPC).