← koop.click
Last updated: 6 July 2026

Privacy Policy

Ko0p ("we", "our", "us") is committed to protecting your personal data in accordance with the Personal Data Protection Act 2012 (PDPA) of Singapore.

This Policy explains what personal data we collect, why we collect it, how we use and protect it, and your rights as a data subject. Tap any section to expand it. By using Ko0p, you consent to the practices described here.

Organisation details
Ko0p (operated by [Company Name to be inserted upon incorporation])
Data Protection Officer: privacy@koop.click
Website: koop.click
1What personal data we collect

From hosts (event organisers)

  • Name and email (from your Ko0p account)
  • PayNow-linked mobile number or UEN (provided by host)
  • Event details created within Ko0p (title, date, location, amount)
  • Group chat links (WhatsApp/Telegram) if provided
  • Cover images uploaded for event rooms

From guests (event participants)

  • Full name (self-declared at RSVP, or from your Ko0p account if you have the app)
  • Singapore mobile number (self-declared at RSVP)
  • Email address (guests without the app — used to deliver your invite link and confirmation)
  • Plus-one guest name (if applicable)
  • Payment status and timestamp
  • Profile photo (app users who set one — shown beside your name in guest lists)
  • Device localStorage data (to remember returning guests on the same device)

Automatically collected

  • IP address and browser/device type (for security and fraud detection)
  • Pages visited and time spent (anonymised usage analytics)
  • Error logs (no personal data stored in logs beyond what is necessary to diagnose errors)
2Why we collect it — purposes
  • Event coordination — to allow hosts to create rooms, invite guests, track RSVPs and payments, and communicate updates.
  • Payment coordination — to display the correct PayNow QR code and reference to guests, and to allow hosts to track who has paid. Ko0p does not process or hold payments.
  • Automated notifications — to send payment reminders (nudges) to guests when payment deadlines approach. Guests are not contacted more than once per day in the 7 days prior to an event.
  • Returning guest experience — to pre-fill your name and details on future RSVPs on the same device. Stored locally on your device only.
  • Security and fraud prevention — to detect and prevent abuse, unauthorised access, and fraudulent activity.
  • Legal compliance — to comply with applicable Singapore law, including responding to lawful requests from regulatory authorities.
3How we share your data

We do not sell your personal data. We share it only in the following circumstances:

  • Within a room — guest names (not phone numbers) are visible to other confirmed guests in the "Who's coming" list. Phone numbers are visible only to the host.
  • Service providers — we use Supabase (database and file storage, servers in Singapore/AWS ap-southeast-1) and Netlify (web hosting). These processors are bound by data processing agreements.
  • SMS / email providers — if you are sent a notification, your phone number or email is passed to our provider solely for that delivery.
  • Legal requirements — we may disclose data to comply with a court order, regulatory requirement, or lawful government request.
4Data retention
  • Payment receipts and refund proofs are retained while a dispute could still be raised, then deleted when no longer needed.
  • Guest email addresses are used only for that event's delivery and are not added to marketing lists without separate consent.
  • Active room data (participants, payments) is retained for 12 months after the event date, then deleted.
  • Host and participation records are kept for as long as needed to operate the service and meet our legal obligations.
  • Notification logs (SMS/email delivery records) are retained for 90 days.
  • Chip-in Jar contributions move directly between guest and host via PayNow, outside Ko0p's systems — Ko0p holds no record of them.
  • You may request deletion of your data at any time (see Section 6). Deletion may not apply to data we are legally required to retain.
5Security
  • All data is transmitted over HTTPS/TLS.
  • Database access is protected by Row Level Security (RLS) — hosts can only access their own rooms and participants.
  • File storage is access-controlled; cover images are public but room data is not.
  • We do not store PayNow credentials, banking details, or card numbers.

In the event of a data breach that is likely to cause significant harm, we will notify affected individuals and the Personal Data Protection Commission (PDPC) within 3 business days, as required under the PDPA Notification Obligation.

6Your rights

Under the PDPA, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Correction — ask us to correct inaccurate or incomplete data.
  • Withdrawal of consent — withdraw consent to our use of your data for any purpose. This may affect your ability to use Ko0p.
  • Data portability — request your data in a machine-readable format.
  • Erasure — request deletion of your personal data, subject to legal retention obligations.

To exercise any right, email privacy@koop.click. We will respond within 10 business days.

7Cookies and local storage

Ko0p uses browser localStorage (not cookies) to remember your RSVP details on the same device. No tracking cookies are used. If we introduce analytics or third-party tools in future, this policy will be updated and your consent obtained.

8Children

Ko0p is not intended for users under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with data, contact us at privacy@koop.click and we will delete it promptly.

9Changes to this policy

We may update this policy from time to time. Material changes will be notified via the email address on your account at least 7 days before taking effect. Continued use of Ko0p after the effective date constitutes acceptance of the updated policy.

10Contact and complaints

For any questions, data requests, or complaints about how we handle your personal data, contact our Data Protection Officer:

Ko0p Data Protection Officer
Email: privacy@koop.click
Response time: within 10 business days

If you are unsatisfied with our response, you may lodge a complaint with the Personal Data Protection Commission (PDPC) at www.pdpc.gov.sg.

This privacy policy was last updated on 6 July 2026.