On this page
This Privacy Policy covers personal data handled through the Operator App for Merchant Users under Singapore’s Personal Data Protection Act 2012 (PDPA). Read it together with the Terms of Use.
About this Policy
This Privacy Policy explains how Mezzofy collects, uses, discloses and protects the personal data of Merchant Users of the Operator App, in accordance with the Personal Data Protection Act 2012 of Singapore (the “PDPA”). It applies to the App only; it does not cover a Merchant’s own handling of its customers’ data, or separate Mezzofy consumer products.
Personal data we collect
We collect the following categories of personal data about Merchant Users:
- Identity & account data — your name, work email or username, the Merchant you belong to, and your assigned role or permissions;
- Device & technical data — device identifier, device model, operating system, App version, IP address and log data;
- Usage data — the Redemption and Distribution actions you perform, timestamps, and error reports;
- Location data — approximate location only where enabled for a specific redemption or anti-fraud purpose.
To scan Coupons, the App may request access to your device camera or NFC. Scanned Coupon codes are processed to complete a transaction; the App does not store photographs from the camera.
How we collect it
We collect personal data: directly from you when you sign in and use the App; automatically as you use the App (for example device and usage data); and from your Merchant, which provisions your account and defines your access.
Why we use your data
We use personal data to:
- provide, operate and maintain the App;
- authenticate you and secure your account;
- process Coupon Redemption and Distribution and keep accurate records;
- detect, prevent and investigate fraud, misuse and security incidents;
- provide support and respond to requests;
- improve the App and understand how it is used, using aggregated or de-identified data where possible; and
- comply with legal and regulatory obligations.
Consent & legal basis under the PDPA
We collect, use and disclose personal data with your consent, on the basis of deemed consent where you voluntarily provide data for an evident purpose, or where the PDPA otherwise permits — including the legitimate interests and business improvement exceptions. Because the App is a workplace tool, some processing is necessary for your Merchant to manage its operations and for us to provide the service.
Who we share it with
We may disclose personal data to:
- your Merchant, which is entitled to see the activity of its Merchant Users;
- service providers and sub-processors that host and support the platform (such as cloud infrastructure providers), under confidentiality and data-protection obligations;
- authorities or advisers where required by law, regulation or legal process, or to protect our rights and safety.
We do not sell personal data.
Data visible to your Merchant
The App is used on behalf of your Merchant. Your Merchant can see the Redemption and Distribution activity carried out under your account, along with your account and role details, so it can manage its coupon operations. Your Merchant’s own use of that information is governed by the Merchant’s privacy practices, not this Policy.
International transfers
Personal data may be processed and stored on servers located outside Singapore, including through cloud providers in other jurisdictions. Where we transfer personal data outside Singapore, we take reasonable steps to ensure it is protected to a standard comparable to the PDPA, through contractual and technical safeguards.
How long we keep it
We retain personal data for as long as your account is active and as needed to provide the App. We keep transaction and audit records for the period required for legitimate business, fraud-prevention, accounting and legal purposes, after which data is deleted or anonymised.
How we protect it
We use reasonable administrative, technical and physical safeguards to protect personal data, including encryption of data in transit, access controls, and monitoring. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your data and to respond to incidents appropriately.
Your rights under the PDPA
Subject to the PDPA, you may request access to the personal data we hold about you, request correction of inaccurate data, and withdraw a consent you have given (which may affect your ability to use the App). Some requests are best directed to your Merchant, which controls your account. To make a request to Mezzofy, contact us using the details in Section 15. We will respond within the time required by law.
Local storage on your device
The App stores limited information on your device, such as your session, language preference and settings, so it can function and remember your choices. This local data stays on your device and is cleared when you sign out or remove the App. The App does not use advertising trackers.
Business use only
The App is intended for business use by Merchant Users and is not directed at consumers or children. We do not knowingly collect personal data from anyone under 18 through the App. If you believe a person under 18 has been given access in error, please contact your Merchant.
Changes to this Policy
We may update this Privacy Policy from time to time. When we make material changes we will update the effective date shown on this page and, where appropriate, notify you in the App or through your Merchant. Please review this page periodically.
Data Protection Officer, governing law & contact
This Policy is governed by the laws of the Republic of Singapore and the PDPA. The App is published by Mezzofy (Singapore) Pte Ltd.
To contact our Data Protection Officer or ask about this Policy or your personal data, email support@mezzofy.com.