Tabiniki Privacy Policy — DRAFT
Draft for review, not legal advice. Have a Singapore lawyer or your PDPA advisor review it before publishing athttps://tabiniki.com/privacy. Items in [brackets] need your input. BumpCONSENT_VERSIONinapps/mobile/src/lib/consent.tswhenever the published text changes materially, so users are asked to accept again.
Last updated: [date]
Tabiniki ("we", "us") is operated by [legal entity / your name], [address], Singapore. This policy explains what personal data the Tabiniki app collects, why, and the choices you have. It is written to comply with Singapore's Personal Data Protection Act 2012 (PDPA).
What we collect
| Data | Why | Notes |
|---|---|---|
| Email address, display name | Create and secure your account, send account emails (confirmation, password reset) | From email sign-up, or from your Google account if you use Google sign-in |
| Password | Sign in | Stored only as a hash by our authentication provider; we cannot read it |
| Places you mark as explored, with dates and optional notes | Show your progress and personal travel record | |
| Which city introduction pages you have already seen, with the date | Show each introduction once, including after you reinstall or switch phones | |
| Photos you upload for a place | Keep your travel journal | Private to your account. Not shown to other users |
| Settings (e.g. save photos to gallery) | Remember your preferences | |
| Consent record (date, policy version) | Prove you agreed to this policy | |
| Email address on our website's waitlist | Write to you once, when the app opens | Only if you join the waitlist on our website, with your consent (we keep which wording you agreed to, and when). Kept until the app opens or until you ask to be removed. Not linked to an app account |
| Diagnostics and usage analytics | Fix crashes (Sentry); understand whether the app works, e.g. retention (our own analytics_events table — not shared with a third party) | See docs/data-safety-inventory.md for the exact event list |
We do not collect your precise location. Photos are not verified against your location. [Confirm that no location metadata is read; note that photo files may contain EXIF location data that stays inside the file you upload.]
How we use it
To run the app, keep your travel record, secure your account, fix problems, and improve the product. We do not sell your personal data. [If sponsored locations or advertising are added later, this section must be updated first.]
Who processes it for us
- Supabase — authentication and database (hosted in Singapore).
- Cloudflare — photo storage and delivery. [Confirm storage region/jurisdiction.]
- Google — if you choose "Continue with Google".
- Sentry — crash and error reporting.
- [Email provider, e.g. Resend] — sending account emails.
These providers process data only to provide their service to us. Some may store data outside Singapore; where they do, we rely on contractual protections comparable to the PDPA. [Confirm with each provider's data processing terms.]
How long we keep it
Until you delete your account. A waitlist email is kept until the app opens (we write to you once) or until you ask us to remove it, whichever comes first. When you delete your account we remove your profile, explored places, introduction-page records and photo records straight away, and queue your photo files for removal from storage. [State the maximum time for files and backups to be purged, e.g. within 30 days.]
Your choices and rights
- Access / export: in the app, use "Export my data" on the home screen to get a copy of your data.
- Delete: use "Delete my account" on the home screen, or visit
https://tabiniki.com/delete-accountif you no longer have the app installed. This is permanent. - Correction or withdrawal of consent: contact us at [email]. Withdrawing consent means we can no longer provide the service, and you should delete your account.
- Questions or complaints: contact our Data Protection Officer at [name / email]. You may also contact the Personal Data Protection Commission (PDPC) of Singapore.
Children
Tabiniki is not directed at children under [13 / 16]. [Confirm the minimum age and how it is enforced at sign-up.]
Security
Data is encrypted in transit. Access to each user's data is restricted by database rules so that users can only read their own records. No system is perfectly secure; if we become aware of a data breach that is likely to cause you significant harm, we will notify you and the PDPC as the PDPA requires.
Changes
If we change this policy in a material way, we will ask you to review and accept it again in the app.
Contact
[Data Protection Officer name] · [hello@tabiniki.com — set up Cloudflare Email Routing first] · [address]