Find App Privacy Policy
Last updated: 6 May 2026Find Technologies Pte. Ltd. (“Find App”, “we”, “us”, or “our”), incorporated in Singapore, values your privacy. This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you use the Find App mobile application and related services (the “Platform”).
This Policy forms part of, and should be read together with, our Terms & Conditions of Use and Refund Policy. Capitalised terms used in this Policy and not defined here have the meanings given to them in those documents.
By using the Platform, you acknowledge that you have read and understood this Policy and consent to the collection, use, and disclosure of your personal data for the purposes described in this Policy. Where additional consent is required for specific processing activities, we will obtain that consent separately.
1. Personal Data We Collect
We collect the following categories of personal data:
1.1 Information You Provide
- Account Information: name, email address, phone number, password, profile photo, date of birth (for age verification), and (for Merchants) business name, business registration number (e.g., UEN), business address, and authorised contact details.
- User Content: posts, photos, videos, reviews, ratings, tags, and other content you submit to the Platform.
- Communications: messages you send to us through customer support, in-app messaging, or other channels.
- Verification Data: information you provide to verify your account or comply with our policies (for Merchants, this may include identification documents and proof of business).
1.2 Information Collected Automatically
- Device Information: device type, operating system, mobile network, language settings, time zone, and device identifiers (such as Apple IDFA or Google Advertising ID, where you have not opted out at the device level).
- Usage and Behavioural Data: information about how you interact with the Platform, including pages and merchants viewed, searches performed, content liked or shared, time spent on the app, and patterns of use. We use this data to understand your preferences and personalise your experience.
- Precise Location: where you grant us permission through your device's operating system, we collect precise location data from your device's GPS or other location sensors. We use this for proximity-based merchant recommendations, location-tagged check-ins, and verifying you are at a merchant for redemption purposes. You can grant, deny, or revoke location access at any time through your device settings; doing so may limit some features of the Platform.
- Transaction Data: for Users in markets where coupon transactions are available, records of coupon purchases, redemptions, refunds, and Find Coin balances.
1.3 Information from Third Parties
- Payment Service Providers: our payment processors provide us with transaction confirmations, refund and chargeback notifications, and limited cardholder data (such as the last four digits of payment cards, card brand, and expiry). We do not collect or store full payment card details. The specific payment service provider may vary by market and is shown to you at the point of payment.
- Google Places: when you tag a merchant that does not yet have a profile on the Platform, we use the Google Places API to retrieve the merchant's name and address from publicly available information on Google Maps in order to create an unclaimed merchant profile.
- Authentication Providers: if you sign in using a third-party authentication service (such as Apple Sign-In or Google Sign-In), we receive basic profile information from that service in accordance with the permissions you grant.
1.4 What We Do Not Collect
- Full payment card numbers, CVVs, or banking credentials — these are handled directly by our payment service providers;
- Your contacts, calendar, photo library (other than photos you actively upload), or other on-device data without your specific permission.
2. How We Use Personal Data and Basis under PDPA
We use your personal data for the purposes set out below. Each purpose is supported by a basis recognised under the Personal Data Protection Act 2012 of Singapore (“PDPA”). Where we operate in additional markets, the equivalent basis under that market's privacy law applies.
| Purpose | Examples | Basis under PDPA |
|---|---|---|
| Provide the Platform | Account creation, content display, posts, reviews, merchant tagging | Consent (given when you accept this Policy at signup); also necessary for the performance of our service to you |
| Process transactions | Coupon purchases, refunds, payouts to Merchants, Find Coin issuance and use | Necessary for the performance of our service to you |
| Personalisation | Recommend merchants and content based on your usage patterns and preferences | Consent (given when you accept this Policy at signup); you may opt out via account settings at any time |
| Service communications | Transaction confirmations, account security alerts, policy updates, support responses | Necessary for the performance of our service to you |
| Marketing communications | Promotional offers, new merchant announcements, newsletters | Consent (separate opt-in); you may withdraw at any time |
| Fraud prevention and safety | Detect suspicious activity, investigate misuse, enforce our policies, protect Users and Merchants | Legitimate interests exception under the PDPA (Schedule 1); legal obligations |
| Analytics and improvement | Understand how the Platform is used, identify issues, develop new features | Business improvement exception under the PDPA (Schedule 1) |
| Legal and compliance | Comply with laws, regulations, court orders, tax record-keeping, anti-money-laundering checks | Required or authorised by law |
3. Service and Marketing Communications
Service communications are necessary for us to provide the Platform to you and may include transaction confirmations, security alerts, policy notifications, and customer support replies. You will receive these as long as you have an active account.
Marketing communications are optional. We will only send you marketing communications (such as promotional offers and newsletters) where you have opted in via the account settings or signup flow. You can withdraw your consent and opt out of marketing communications at any time through your account settings or by following the unsubscribe instructions in any marketing message. Withdrawing marketing consent does not affect your receipt of service communications.
4. How We Share Personal Data
We share personal data only as set out below. We do not sell your personal data.
4.1 With Merchants
Where you transact with or interact with a Merchant, we share with that Merchant only the information necessary for them to fulfil the transaction, process redemptions, handle refunds, and provide customer support. This may include your User name and the details of your coupon purchase or interaction.
We may also provide Merchants with aggregated, anonymised insights (such as demographic trends, behavioural patterns, or engagement characteristics) about their customers. These insights do not identify individual Users and cannot be used to contact specific individuals.
4.2 With Service Providers
We share personal data with third-party service providers that help us operate the Platform. Our key service providers are:
- Payment processing: we work with third-party licensed payment service providers to process payments for coupon purchases and disbursements to Merchants. Our payment service providers vary by market and operate under their own privacy policies. Each provider handles full payment card data directly and is responsible for that data as a separate organisation under applicable law.
- Amazon Web Services (cloud hosting): provides the cloud infrastructure on which the Platform operates. Personal data is currently hosted on AWS infrastructure in Singapore.
- Google (Places API): provides merchant name and address data when you tag a merchant not yet on the Platform.
In addition to the providers named above, we use other third-party service providers for ancillary functions such as analytics, error monitoring, push notifications, communications, and customer support.
All service providers are bound by contractual obligations to process personal data only as instructed by us, to maintain appropriate security, and to comply with applicable data protection laws.
4.3 With Authorities and for Legal Reasons
We may disclose personal data to regulators, law enforcement, courts, or other authorities where required by law, court order, or legitimate legal process, or where necessary to protect our rights, property, safety, or those of our users.
4.4 Business Transactions
If we are involved in a merger, acquisition, restructuring, or sale of all or substantially all of our assets, personal data may be transferred to the relevant counterparty as part of the transaction. We will provide notice through the Platform or by email where required by law.
4.5 With Your Consent
We may share personal data with other parties where you have given us specific consent to do so.
5. Where We Store and Process Personal Data
Personal data is primarily stored and processed on Amazon Web Services infrastructure located in Singapore. Personal data may also be transferred to other jurisdictions in connection with our use of third-party service providers. Where this occurs, we take appropriate steps to ensure that personal data receives a standard of protection comparable to that required under the PDPA.
As we expand to operate in other markets, we may store or process personal data in additional jurisdictions. Where this occurs:
- We will update this Policy and notify affected users in advance;
- We will comply with the cross-border transfer requirements of any other applicable jurisdictions.
6. How Long We Keep Personal Data
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or for the periods required by law:
| Category | Retention Period |
|---|---|
| Account information | For the duration of your account, plus up to 6 years after closure (aligned with the limitation period for contract claims under the Limitation Act, for legal claim limitation and dispute resolution). |
| Transaction records | Up to 7 years from the transaction date, in accordance with Inland Revenue Authority of Singapore (IRAS) record-keeping requirements and equivalent tax obligations in other markets. |
| User Content (posts, reviews, photos) |
For as long as the content is published on the Platform, plus up to 6 years after deletion or account closure for backup and dispute purposes. Content shared with others or used in marketing materials may be retained longer in accordance with the licence in our Terms of Use. |
| Marketing data and consent records | Until you withdraw your consent, plus up to 1 year after withdrawal for record-keeping purposes. |
| Customer support communications | Up to 2 years from the date of the most recent communication. |
| Fraud, safety, and compliance investigation records | Up to 7 years, or longer if required by law or ongoing legal proceedings. |
| Anonymised analytics data | Indefinitely, as it no longer constitutes personal data. |
Where we no longer require personal data for the purposes for which it was collected and are not required to retain it for legal or business reasons, we will delete or anonymise it.
7. Security
We implement reasonable technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, loss, or destruction. These measures include encryption of data in transit and at rest, access controls, secure authentication, regular security reviews, and contractual safeguards with our service providers.
You also play an important role in protecting your data. Please use a strong password, do not share your account credentials, and notify us promptly if you suspect unauthorised access to your account.
8. Data Breach Notification
In the event of a data breach affecting your personal data, we will:
- Conduct an internal assessment of the breach as soon as we become aware of it;
- Notify the Personal Data Protection Commission (PDPC) of Singapore as soon as practicable, and in any event within 3 calendar days, where the breach is notifiable under the PDPA;
- Notify affected individuals where the breach is likely to result in significant harm, in accordance with PDPA requirements;
- Comply with the breach notification requirements of any other applicable jurisdiction (which may have stricter timelines or requirements);
- Take remediation measures to address the breach and prevent recurrence.
9. Your Rights
Subject to the PDPA and other applicable laws, you have the following rights in relation to your personal data:
- Right of access: you may request access to the personal data we hold about you and information about how it is used.
- Right to correction: you may request that we correct any inaccurate or incomplete personal data.
- Right to withdraw consent: where we rely on your consent for processing, you may withdraw consent at any time. Withdrawal of consent may affect our ability to provide certain features of the Platform.
- Right to deletion: you may request deletion of your account and associated personal data, subject to our retention obligations under Section 6.
- Right to opt out of personalisation: you may opt out of personalised recommendations through your account settings. We will continue to log your activity for service operation, security, and analytics purposes.
- Right to opt out of marketing: you may opt out of marketing communications at any time through your account settings or via the unsubscribe link in any marketing message.
Additional rights may apply in jurisdictions covered in Section 12.
To exercise these rights, contact our Data Protection Officer at the details in Section 13. We will respond to verifiable requests within 30 days, in accordance with the PDPA. We may charge a reasonable fee for access requests, as permitted by law.
10. In-App Tracking Technologies
The Find App mobile application is mobile-only and does not use website cookies. Within the app, we use the following tracking technologies:
- Device identifiers: such as Apple IDFA (iOS) and Google Advertising ID (Android), subject to your operating system permissions. You can reset or limit these identifiers through your device settings.
- Event logging: we log your in-app actions (such as taps, views, and searches) to operate the Platform, provide security, conduct analytics, and personalise your experience.
- Authentication tokens: stored securely on your device to keep you logged in.
If we operate a marketing or information website in the future, we will provide separate disclosure about cookies used on that website.
11. Children
The Platform is intended for users aged 18 and above. We do not knowingly collect personal data from children under 18 without the consent of a parent or legal guardian.
If we discover that we have collected personal data from a user under 18 without appropriate consent, we will close the account and delete the associated personal data, except where retention is required by law.
If you are below 18 and you do not have the consent of your parent or legal guardian, or your parent or legal guardian is not willing to open an account on your behalf, you must cease accessing the Platform.
If you are a parent or guardian and you believe your child has created an account on the Platform without your consent, please contact our Data Protection Officer using the details in Section 13. You may also report a suspected underage account through the in-app reporting function.
12. International Users and Country-Specific Provisions
12.1 General
Find App is operated from Singapore. As we expand into additional markets, we comply with the data protection laws of each jurisdiction in which we operate. The provisions in this Section 12 supplement (and, where applicable, prevail over) the rest of this Policy for users in the named jurisdictions.
This Privacy Policy is also made available in the local language of each market in which we operate.
Nothing in this Policy shall be construed as a waiver or limitation of statutory consumer or data protection rights that cannot be contractually limited under applicable laws.
12.2 Singapore (PDPA)
This Privacy Policy is designed to comply with the Personal Data Protection Act 2012 of Singapore.
- Supervisory authority: Personal Data Protection Commission (PDPC), Singapore.
- Your rights: the rights set out in Section 9 are provided in accordance with the PDPA.
- Complaints: if you are not satisfied with our response to a data protection request, you may lodge a complaint with the PDPC at www.pdpc.gov.sg.
12.3 Malaysia (PDPA 2010)
- Supervisory authority: Personal Data Protection Commissioner, Malaysia.
- Your rights: in addition to the rights set out in Section 9, you may have additional rights under the Malaysian PDPA. Contact our Data Protection Officer at the details in Section 13 to exercise these rights.
- Cross-border transfer: we transfer Malaysian personal data to Singapore for storage and processing.
12.4 Thailand (PDPA 2019)
- Supervisory authority: Personal Data Protection Committee, Thailand.
- Your rights: in addition to the rights set out in Section 9, you may have additional rights under the Thai PDPA. Contact our Data Protection Officer at the details in Section 13 to exercise these rights.
- Cross-border transfer: we transfer Thai personal data to Singapore for storage and processing.
12.5 Indonesia (Personal Data Protection Law 2022)
- Supervisory authority: Personal Data Protection Agency (Lembaga Pelindungan Data Pribadi) of Indonesia.
- Your rights: in addition to the rights set out in Section 9, you have rights under Indonesian PDP Law including objection to automated decision-making and data portability. Contact our Data Protection Officer at the details in Section 13 to exercise these rights.
- Cross-border transfer: we transfer Indonesian personal data to Singapore for storage and processing. The receiving entity is Find Technologies Pte. Ltd. We support this transfer with appropriate safeguards consistent with the PDP Law.
- Breach notification: in the event of a personal data breach affecting Indonesian users, we will notify affected users and the supervisory authority within the timelines required under Indonesian law.
12.6 Vietnam (Decree 13/2023 on Personal Data Protection)
- Supervisory authority: Department of Cybersecurity and High-Tech Crime Prevention, Ministry of Public Security, Vietnam.
- Methods of processing: we may process your personal data by manual or automated methods.
- Your rights: in addition to the rights set out in Section 9, you have rights under Decree 13 including data portability, the right to claim damages, and the right to self-protection.
- Your obligations: under Vietnamese law, you must protect your own personal data, respect and protect the personal data of others, and provide complete and accurate personal data when consenting to its processing.
- Cross-border transfer: we transfer Vietnamese personal data to Singapore for storage and processing. The receiving entity is Find Technologies Pte. Ltd.
12.7 Korea (PIPA — Personal Information Protection Act)
- Supervisory authority: Personal Information Protection Commission (PIPC), Korea.
- Your rights: in addition to the rights set out in Section 9, you have rights under PIPA. Contact our Data Protection Officer at the details in Section 13 to exercise these rights.
- Cross-border transfer: we transfer Korean personal data to Singapore for storage and processing.
12.8 Taiwan (PIPA — Personal Information Protection Act)
- Supervisory authority: the relevant ministry depending on the sector; the National Development Council coordinates personal data protection matters in Taiwan.
- Your rights: in addition to the rights set out in Section 9, you have rights under Taiwanese PIPA. Contact our Data Protection Officer at the details in Section 13 to exercise these rights.
- Cross-border transfer: we transfer Taiwanese personal data to Singapore for storage and processing.
12.9 Japan (APPI — Act on the Protection of Personal Information)
- Supervisory authority: Personal Information Protection Commission (PPC), Japan.
- Your rights: in addition to the rights set out in Section 9, you have rights under APPI.
- Cross-border transfer: we transfer Japanese personal data to Singapore for storage and processing. The receiving entity is Find Technologies Pte. Ltd., located at 24 New Industrial Road, #04-10 In Space, Singapore 536210. Singapore is recognised by the Personal Information Protection Commission of Japan as providing an adequate level of protection for personal information transferred from Japan, pursuant to Article 28 of the APPI.
12.10 Conflict of Laws
Where a user is subject to the laws of more than one of the jurisdictions covered above, we apply the standards required by each applicable law in respect of that user. Where one law imposes a stricter standard than another, the stricter standard applies in respect of the matter governed by that law.
13. Contact Us and Data Protection Officer
If you have questions about this Policy, want to exercise your rights, or wish to raise a concern about our handling of personal data, please contact our Data Protection Officer:
Data Protection Officer: Edmund Ang
Email: Edmund.ang@findapp.asia
Postal address: Find Technologies Pte. Ltd., 24 New Industrial Road, #04-10 In Space, Singapore 536210.
We will acknowledge your request within a reasonable time and respond substantively within 30 days, in accordance with applicable law.
14. Changes to This Policy
Find App may update this Privacy Policy from time to time. The procedure for changes depends on the nature of the change:
- Non-material changes (such as clarifications, formatting, or updates that do not adversely affect your rights or change how we process personal data) will be notified via the Platform or email. Continued use of the Platform after the effective date of the change constitutes acceptance.
- Material changes (such as changes that introduce new categories of personal data, new processing purposes, new third-party recipients, new cross-border transfers, or otherwise materially affect your rights) will be notified to you at least fourteen (14) days in advance via the Platform or email. We will require you to affirmatively accept the updated Policy before continuing to use the Platform. If you do not accept the material changes, you may terminate your account in accordance with the Terms of Use.
15. Order of Precedence
In the event of any conflict or inconsistency between this Privacy Policy and the Terms & Conditions of Use, this Privacy Policy prevails on data protection matters. The Find App Merchant Agreement may contain additional or supplementary data protection provisions for Merchants, which apply alongside this Policy.