Legal Information
PDPA Policy
ShopNJoy Group Personal Data Privacy Policy (PDPP). How we collect, use, disclose, and protect personal information. Ver. 1 | May 2026
This Personal Data Privacy Policy (thereafter called “this policy”) explains how ShopNJoy Group (thereafter called “The company”) collects, uses, discloses, and protects personal information when individuals interact with our websites, applications, products, services, internet, email and intranet.
1. Introduction
Such data includes but is not limited to officers, employees, customers, suppliers, merchants, shoppers, stakeholders, etc. We are committed to safeguarding personal information in accordance with applicable data protection laws in Singapore.
2. Scope
This Policy applies to all personal information processed by the company in which the individual resides or the data is processed.
For the purposes of the Personal Data Protection Act 2012 (No. 26 of 2012), you consent to the processing of all or any personal data in manual, electronic or any other form by ShopNJoy and/or any agent or third party nominated by ShopNJoy and bound by a duty of confidentiality. Processing includes the transfer of data to any country.
3. Information We Collect
We may collect the following categories of personal information:
- Identity Information: name, date of birth, identification numbers
- Contact Information: email address, phone number, mailing address
- Account Information: login credentials, preferences, profile details
- Payment Information: billing details, transaction records, credit card & bank account numbers
- Usage Data: IP address, device information, browser type, pages visited
- Cookies & Tracking Data: analytics, session data, preferences
- Communications: messages, enquiries, feedback, emails, chatbot, online chat via MS Teams, Google Workspace, WhatsApp & other applications
- Any information voluntarily provided by the individual
4. How We Use Personal Information
We may use personal information for the following purposes:
- Providing, operating, and improving our products and services
- Processing orders, payments, and transactions
- Responding to enquiries and providing customer support
- Personalising user experience
- Displaying on website or applications including data, logo, photos, website link, customized QR code and social media
- Sending administrative or service-related communications
- Processing HR, admin, accounts, payrolls, operating matters
- Conducting analytics, research, and service optimisation
- Detecting and preventing fraud or security incidents
- Complying with legal and regulatory obligations
- Any purpose for which consent has been provided
5. Legal Bases for Processing
Where required by applicable laws, we process personal information based on:
- Consent
- Performance of a contract
- Legitimate interests
- Compliance with legal obligations
- Protection of vital interests
- Public interest (where applicable, e.g. website)
6. Sharing of Personal Information
We may share personal information relating to you only for the relevant purposes described in this Policy, or to protect the interests of our customers. Sharing is based on the consent you have provided at the point of collection, or where otherwise permitted or required under applicable law.
Personal data is disclosed to the recipients below only to the extent necessary for the stated purposes. In some cases, we encrypt, anonymise, or aggregate the information before sharing it.
- Service providers and vendors (e.g. logistics, IT, marketing) — for service delivery, operations, and support
- Business partners and affiliates — for joint promotions, co-branded services, referrals, or in the event of a business asset transaction (e.g. merger or acquisition)
- Payment processors (e.g. HR & accounting systems, banks, payment gateways, credit bureaus, debt collection agencies) — for processing transactions, payroll, financial reporting, and fraud or credit risk monitoring
- Professional advisors (e.g. auditors, legal counsel) — for legal compliance, auditing, risk management, and defending or enforcing our rights
- Relevant regulators, statutory boards, authorities, or law enforcement agencies — where required or permitted by applicable laws, rules, guidelines, or regulations
- Any other party — where the individual has provided specific consent, or where disclosure is necessary to prevent a threat to life or health
- External system & service providers (e.g. Microsoft, AI tools, cloud platforms) — for platform operations, data hosting, analytics, and technology services
We will ensure that all organisations or entities we share personal data with (whether located locally or overseas) observe strict confidentiality and data protection obligations in accordance with applicable Personal Data laws. Where personal data is transferred overseas, we will take steps to ensure it receives a standard of protection at least comparable to that provided under Singapore’s Personal Data Protection Act.
7. Social Media and Communication
Our reputation relies on responsible social media use and effective communication practices. Guidelines include:
- Respecting confidentiality and refraining from sharing sensitive company information on personal social media accounts.
- Maintaining professionalism in online communications that may be associated with ShopNJoy.
- Understanding the potential impact of personal online activities on our brand reputation and fostering positive interactions.
8. International Data Transfers
We may transfer personal information to countries outside the individual’s jurisdiction. Where required, we implement safeguards such as:
- Standard contractual clauses
- Data transfer agreements
- Adequacy decisions
- Other legally recognised mechanisms
9. Data Storage
We may store personal information from time to time including physically or electronically and all employees should handle and store such data carefully as per this policy.
- Use designated storage systems both local and overseas, drives or secure cloud platforms approved by IT department.
- Avoid creating duplicate or conflicting copies of files with personal data.
- Files containing sensitive or confidential information must be stored only in restricted areas with appropriate permissions.
- All portable storage devices (e.g. USB drives, external hard disks) must be encrypted before use. Cloud storage accounts must use strong authentication methods to protect data.
- All file transfers containing personal data must be encrypted and password protected. The password must be communicated to the recipient via a separate channel (e.g. a separate email, SMS, or phone call) and must never be included in the same message as the encrypted file.
10. Data Retention and Disposal
We retain personal information only for as long as necessary to fulfil the purposes described in this Policy or as required by law. Outdated or unnecessary data is securely deleted, anonymised, or archived.
11. Data Security
We implement administrative, technical, and physical safeguards to protect personal information, including:
- Access controls
- Encryption and secure storage
- Employee training
- Regular audits and monitoring
- Incident response procedures
For more details, please refer to Cybersecurity Policy (CP).
12. Individual Rights
Depending on applicable laws, individuals may have the right to:
- Access their personal information
- Correct inaccurate or incomplete information
- Delete personal information
- Restrict or object to processing
- Withdraw consent
- Request data portability
- Lodge a complaint with a supervisory authority
Such requests should be submitted to respective officers or in-charge to take immediate actions.
13. Cookies and Tracking Technologies
We may use cookies, web beacons, analytics tools, and similar technologies to enhance user experience. Users may manage cookie preferences through their browser settings.
14. Third-Party Links
Our products, services, website and applications may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties.
15. Do Not Call
ShopNJoy will not send any messages to any telephone number that is generated or obtained through the use of address-harvesting software, or to use directory attacks or similar automated means to send indiscriminately.
Due to the nature of business, our products and services may require us to contact stakeholders such as customers, merchants, and companies from time to time by phone, text, emails, etc. If stakeholders request that they no longer want to be contacted via any form of channels, our employees must stop all direct communication with professional courtesy and respect their wishes as well as update / delete personal data in our systems.
16. Data Protection Officer (DPO)
Our DPO oversees our company’s data protection responsibilities and ensure compliance with the Data Protection and Cybersecurity requirements. For questions, requests, or concerns regarding this Privacy Policy, please contact:
17. Updates to This Policy
By following the above mentioned measures, we reduce the risk of data breaches, protect sensitive information and ensure compliance with regulatory obligations.
We may update this Privacy Policy periodically. The latest version will be posted on the company’s intranet.