Skip to content
makan rescue

Legal

Privacy policy

Effective 29 July 2026. The data controller is Paaci Pte Ltd, registered at 111 North Bridge Road, #21-01, Peninsula Plaza, Singapore 179098 ("Makan Rescue", "we"). We comply with the Singapore Personal Data Protection Act 2012 (PDPA). This policy explains what we collect through the Makan Rescue apps and website, why, and your rights. We may refine this policy as the service grows; material changes will be announced in the app and on this page.

Makan Rescue is offered only in Singapore. Every participating store is in Singapore and every pickup happens there. We do not target or market the service to people in other countries.

What we collect

  • Account data: name, email address and/or mobile number, and a securely hashed password. For merchants: business name, UEN or GST registration number, store address and contact details.
  • Sign-in with Apple or Google: if you use one, we receive an identifier for your account with that provider and the email address it releases to us (which may be Apple's private relay address). We never receive your password.
  • Verified mobile number: you may verify a Singapore mobile number by SMS one-time code, which protects referral rewards from abuse. The code is sent through Twilio. We store the number encrypted, plus a one-way fingerprint used only to stop the same number being used on two accounts.
  • Order data: bags reserved, amounts paid, pickup status, ratings and reviews.
  • Credit balance: referral rewards and refunds held as Makan Rescue credit, with a record of each amount earned, spent or expired.
  • Location: your device location while using the app, solely to show nearby offers and sort them by distance. We do not track or store a history of your movements. If you save a home, work or other address in the app, we store that address and its coordinates until you remove it or delete your account.
  • Payment data: processed by Stripe Payments Singapore Pte Ltd. Your PayNow or card details never touch our servers; we store only a payment reference, method type and amount.
  • Device data: push notification token, device platform, app version, and standard server logs (IP address, request paths, timestamps) for security and debugging. Because searches carry the coordinates being searched, those coordinates can appear in request logs, which are short-lived.
  • Agreement records: the version of the Terms you accepted, when, and the IP address it was accepted from, kept as evidence of the agreement.
  • Website forms: the partner form collects the business and contact details you submit, and the notify-me form on our home page collects the email address you enter so we can tell you when the service reaches you. If a business arrives through a partner invite link we store the invite code in a cookie; see our cookie policy.
  • Payouts: merchants and referrers provide a PayNow number or bank destination solely so we can pay them. It is stored encrypted and cleared when the account is deleted; see our referral terms.

How we use it

To provide the marketplace: matching you with nearby offers, processing reservations and payments, and generating pickup codes. To send transactional notifications such as order confirmations and pickup reminders, and optional marketing notifications about new nearby bags, which you can switch off in system settings at any time. For merchant sales reporting, fraud prevention, platform security, and legal and accounting obligations, including GST records retained for five years per IRAS requirements.

Who we disclose it to

We use the following service providers, and no others: Stripe (payments and merchant payouts); Twilio (SMS verification codes); Resend (transactional email); Expo, Apple and Google (push notification delivery); Google Maps and OneMap (maps and address search); Neon on Amazon Web Services (database hosting) and Vercel (application hosting); and Plausible (privacy-friendly page counts on the website, loaded only if you accept). We also disclose order details to the merchant you order from, who sees your first name and order but never your contact details, and to authorities where required by law. All processors are bound by contractual data protection obligations.

We do not buy, sell or trade personal data, and we run no third-party advertising or tracking SDKs.

Where your data is held

Our database and application servers are located in Singapore. Some of the providers above operate outside Singapore, so limited data may be processed overseas: for example, verification codes through Twilio, email through Resend, and push notifications through Expo, Apple and Google. Where personal data is transferred out of Singapore we take steps required by section 26 of the PDPA to ensure a comparable standard of protection, principally through the data protection terms in our contracts with those providers.

Maps are rendered by Apple Maps on iPhone and Google Maps on Android and the website, so the map provider on your device receives the map area you are viewing.

Retention

Account data is kept while your account is active. Order and payment records are kept five years for tax and audit purposes, as IRAS requires. Server logs are short-lived and kept only as long as our hosting providers retain them. Verification codes sent by email or SMS are deleted as soon as they are used, and unused ones are deleted within a day of expiring by a daily housekeeping job. Unspent referral credit expires three months after it is earned.

When you delete your account (Profile, then Delete account), we immediately remove your name, email, password, sign-in links, push tokens, saved addresses, verified mobile number and payout details, and record the account as deleted so it can no longer be signed in to. Because the verified-number fingerprint is cleared too, you are free to sign up again later with the same number. Order and payment records remain for the five-year tax retention period described above, and the version and date of the Terms you accepted remain as evidence of the agreement, but they are no longer linked to your contact details.

One exception: if a referral payout to you is still unpaid when you delete your account, we keep the payout destination you gave us until that payment is settled, because it is the only way left to pay you what you are owed. It is cleared once the payout is settled.

Your rights

Under the PDPA you may access, correct, or request deletion of your personal data, and withdraw consent: in the app (Profile, then Delete account) or by writing to our Data Protection Officer at dpo@makanrescue.sg. We respond within 30 days. If unsatisfied, you may complain to the PDPC (pdpc.gov.sg).

Security

Data in transit is TLS encrypted. Passwords are hashed with Argon2. Access to production systems is restricted. No system is perfectly secure; we will notify you and the PDPC of notifiable data breaches as the PDPA requires.

Children

Makan Rescue is not directed at children under 13, and we do not knowingly collect their data.

Contact

Data Protection Officer: dpo@makanrescue.sg
Paaci Pte Ltd, 111 North Bridge Road, #21-01, Peninsula Plaza, Singapore 179098