Legal
Privacy Policy
How we handle personal data under Singapore’s Personal Data Protection Act.
Draft — not yet in force. Every highlighted field must be completed by the business, and this policy needs a lawyer’s review before it is relied on. It is built from the PDPC’s Advisory Guidelines on Key Concepts in the PDPA (17 May 2022), but it is not legal advice.
1. Who we are
The One Printing is the printing storefront operated by [OWNER: registered entity name] (UEN [OWNER: UEN — confirm from BizFile before publishing]) (“we”, “us”). We are the organisation responsible for the personal data described in this policy.
This policy explains how we collect, use, disclose and care for personal data in accordance with the Personal Data Protection Act 2012 of Singapore (the “PDPA”).
2. Our Data Protection Officer
Section 11(3) of the PDPA requires us to designate at least one individual responsible for ensuring we comply with the Act. Our Data Protection Officer is:
[OWNER: DPO name or role title]
[OWNER: DPO email address]
[OWNER: postal address for written requests]
You may contact our Data Protection Officer about anything in this policy, to access or correct your personal data, or to withdraw consent.
3. What personal data we collect
We collect only what we need to print and deliver your order:
- Account details — your name, email address and password (stored only as a cryptographic hash, never in readable form).
- Contact and delivery details — delivery address and phone number, so your order reaches you.
- Artwork you upload — the files you send us to print. These may contain personal data if you choose to include it, for example on a name card.
- Order history — what you ordered, its specification, and its status.
- Points balance and transactions — your points balance and the record of points earned and redeemed, linked to your Rainmaker account.
- Technical data — aggregate, cookieless page analytics provided by Cloudflare, which does not identify you individually, and security logs kept to protect the service.
We do not collect payment card numbers. Where an order requires a cash payment, it is made by PayNow directly to the payment provider — we never see or store your banking credentials.
4. Why we collect it, and your consent
We collect, use and disclose personal data for these purposes, and no others without telling you first:
- creating and administering your account;
- producing, checking and delivering your printed order;
- processing points redemptions and any cash balance payable on an order;
- sending you messages about a specific order — proof approval, dispatch, delivery;
- meeting our legal and tax obligations, including issuing tax invoices and keeping accounting records;
- preventing fraud and abuse, and keeping the service secure.
You may withdraw your consent to any of these at any time by contacting our Data Protection Officer. We will tell you the likely consequences before we act on a withdrawal — for example, we cannot complete an order in production if you withdraw consent to use your delivery address. Withdrawing consent does not affect anything we are required by law to keep.
5. Who we share it with
We share personal data only where it is needed to fulfil your order or to run the service:
- Production partners. Some items are produced by trade printing partners. They receive only what is needed to produce the job.
- Delivery partners. They receive your name, address and phone number so they can deliver.
- Service providers. Hosting, network security and messaging providers who process data on our instructions.
- The Rainmaker points ledger, to read your balance and record redemptions.
- Authorities, where we are required by law to disclose.
We do not sell personal data, and we do not share it for third-party advertising.
6. Accessing and correcting your data
You may ask us what personal data we hold about you and how we have used it in the past year, and you may ask us to correct anything that is wrong. Write to our Data Protection Officer.
We will respond as soon as reasonably possible. If we cannot respond within 30 days we will tell you when we will. We may charge a reasonable fee for an access request and will tell you the amount before we proceed. In a small number of cases the PDPA permits or requires us to refuse a request; if that happens we will tell you why.
7. Keeping it accurate and protected
We take reasonable steps to keep personal data accurate and complete where we use it to make a decision affecting you or pass it to someone else.
We protect personal data with access controls, encryption in transit, hashed passwords, and restricted administrative access. No system is perfectly secure, but we treat these as minimums rather than aspirations.
8. How long we keep it
We stop keeping personal data once it no longer serves the purpose it was collected for and there is no legal or business reason to retain it.
[OWNER DECISION: state retention periods. Note that Singapore tax law requires accounting records — including tax invoices — to be kept for five years, so order and invoice records cannot be deleted on request. Uploaded artwork is a separate decision: how long after delivery should print files be held for reorders?]
9. Transfers outside Singapore
Some of our service providers process data outside Singapore. Where that happens we take steps to ensure the recipient protects the data to a standard comparable to the PDPA.
[OWNER: confirm which providers process data overseas and in which countries, then name them here.]
10. If something goes wrong
If a data breach occurs that is likely to result in significant harm to you, or is of a significant scale, we will notify the Personal Data Protection Commission and affected individuals as the PDPA requires.
11. Changes to this policy
We may update this policy. The date below shows when it last changed. If a change materially affects how we use your personal data, we will tell you.
Last updated: [OWNER: date this policy takes effect]