Privacy Policy
How HostSG collects, uses, and protects your personal data in compliance with the Singapore Personal Data Protection Act (PDPA).
Contents
1. Information We Collect
When you use HostSG, we collect the following categories of personal data:
- Account Information: Full name, email address, phone number, profile photo, and preferred language.
- Identity Verification Data: Singpass MyInfo data (for Singapore-based hosts), government-issued ID details, and biometric liveness scan results.
- Booking & Transaction Data: Tour selections, booking dates, milestone escrow payment records, and payout history.
- Location Data: GPS coordinates during active tours (for guide-traveler meetup verification and safety tracking).
- Communications: In-app messages between travelers and hosts, support inquiries, and feedback/reviews.
- Device & Usage Data: Device type, operating system, IP address, browser information, and app usage analytics.
2. How We Use Your Information
We process your personal data for the following purposes:
- Facilitating bookings and milestone escrow transactions between travelers and verified hosts.
- Verifying host identity through Singpass MyInfo and biometric liveness checks.
- Providing real-time GPS tracking during active tours for safety and accountability.
- Processing milestone-based payments and issuing digital receipts.
- Sending booking confirmations, reminders, and service notifications.
- Improving our platform through aggregated, anonymized analytics.
- Complying with legal obligations under Singapore law and MAS regulations.
3. Singpass & MyInfo Integration
For host verification in Singapore, HostSG integrates with the government's Singpass MyInfo service. This integration allows us to:
- Verify a host's legal identity, residency status, and age directly from government databases.
- Retrieve verified personal particulars with the host's explicit consent.
- Perform pre-tour biometric liveness scans to confirm the registered host is present.
MyInfo data is transmitted via encrypted government APIs and is never stored on third-party servers. All biometric data is processed in real-time and discarded immediately after verification.
4. Data Sharing & Third Parties
We do not sell your personal data. We may share limited information with:
- Payment Processors: Secure PCI-DSS compliant processors to facilitate escrow transactions.
- Government Authorities: When required by law, court order, or regulatory investigation.
- Cloud Infrastructure Providers: AES-256 encrypted storage with SOC 2 Type II certified hosting partners.
- Analytics Partners: Anonymized, aggregated data only — never personal identifiers.
5. Escrow Transaction Data
All milestone escrow payment data is handled with bank-grade security:
- Payment records are encrypted at rest (AES-256) and in transit (TLS 1.3).
- Milestone release approvals are logged with immutable audit trails.
- Refund and dispute records are retained for regulatory compliance for a minimum of 7 years.
6. Data Security & Encryption
We implement enterprise-grade security measures to protect your data:
- AES-256 encryption for all data at rest.
- TLS 1.3 encryption for all data in transit.
- Multi-factor authentication for administrative access.
- Regular penetration testing and vulnerability assessments.
- SOC 2 Type II compliant infrastructure.
7. Data Retention
We retain your personal data only as long as necessary:
- Active accounts: Data is retained while your account remains active.
- Closed accounts: Core account data is deleted within 90 days, except where retention is legally required.
- Financial records: Escrow transaction data is retained for 7 years per MAS regulatory requirements.
- Biometric data: Processed in real-time and discarded immediately after liveness verification.
8. Your Rights Under PDPA
Under the Singapore Personal Data Protection Act, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Withdrawal of Consent: Withdraw consent for data processing (this may affect service availability).
- Data Portability: Request transfer of your data in a structured, commonly-used format.
To exercise these rights, contact our Data Protection Officer at the details below.
9. Cookies & Tracking
HostSG uses essential cookies to maintain session state and security tokens. We use analytics cookies (with your consent) to understand usage patterns and improve our service. You can manage cookie preferences in your browser settings.
10. Contact Us
Data Protection Officer
HostSG Pte. Ltd.
Email: privacy@hostsg.com
Address: 1 Raffles Place, #20-61, Tower 2, Singapore 048616
For complaints, you may also contact the Personal Data Protection Commission (PDPC) at www.pdpc.gov.sg.