Dokumen hukum ini hanya tersedia dalam Bahasa Inggris.

Privacy Policy

Last updated: September 7, 2026 (v2026.09.07)

1. Data Controller

The data controller responsible for your personal data is:

  • GLUESQ Pte. Ltd. (UEN 202548578Z)
  • 22 Sin Ming Lane, #06-76, Midview City, Singapore 573969
  • Email: dpo@gluesq.com

For the purposes of the Singapore Personal Data Protection Act 2012 ("PDPA") and Thailand's Personal Data Protection Act B.E. 2562 ("PDPA-TH"), GLUESQ Pte. Ltd. is the data controller of your personal data.

2. Data We Collect

2.1 Account Information

When you register, we collect:

  • Email address — used for authentication, account recovery, and important service communications;
  • Display name and username — your chosen public identity on the Platform;
  • Profile biography and city — optional information you choose to share publicly;
  • Profile avatar — stored as binary data associated with your account;
  • Authentication identifiers — a unique identifier from your authentication provider (Firebase UID) linked to an internal user ID (UUID).

2.2 Location Data

With your explicit consent, we collect GPS coordinates from your device. Location data is used to:

  • Discover sessions and Local Picks near you (geo-proximity queries);
  • Display your approximate location on session maps;
  • Enable map-based session and promotion discovery; and
  • Provide location-aware search results.

Location data is stored as geographic coordinate points (GEOGRAPHY type with SRID 4326) in our database. You may revoke location permissions at any time through your device settings, though this will limit location-based features.

2.3 User-Generated Content

  • Session details — titles, descriptions, tags, locations, and scheduling information for sessions you create;
  • Chat messages — text messages sent in one-on-one and group conversations, stored as structured payloads;
  • Gift messages — optional messages attached to virtual gifts;
  • Reports and feedback — content you submit when reporting other users or sessions.

Visibilitas Sesi. Ketika Anda membuat sesi, Anda memilih tingkat visibilitasnya:

  • Sesi publik dapat ditemukan di peta bersama oleh pengguna glup terautentikasi mana pun yang tampilan petanya tumpang tindih dengan area sesi Anda, serta berhak muncul dalam penemuan berbasis radius, papan peringkat hadiah, dan umpan aktivitas teman. Nama tampilan, avatar, judul sesi, kategori, lokasi perkiraan, serta waktu mulai/berakhir Anda akan terlihat oleh pengguna tersebut. Hingga tiga nama tampilan peserta yang telah mengonfirmasi kehadiran akan muncul di samping sesi pada peta.
  • Sesi pribadi hanya terlihat oleh Anda, individu yang Anda undang, dan peserta yang telah mengonfirmasi kehadiran. Sesi pribadi dikecualikan dari peta publik, titik akhir penemuan berbasis radius, papan peringkat hadiah, umpan aktivitas teman, dan hasil pencarian. Sesi pribadi juga dikecualikan dari pemberitahuan push kepada pengguna di sekitar.

Kedua mode visibilitas tunduk pada batasan privasi berikut. Seluruh konten sesi dapat diakses oleh: (1) personel moderasi dan tim kepercayaan-dan-keamanan glup yang berwenang, apabila diperlukan untuk menyelidiki laporan berdasarkan Pedoman Komunitas atau Ketentuan Layanan kami; (2) personel teknik glup yang berwenang, apabila diperlukan untuk mendiagnosis insiden produksi yang memengaruhi akun Anda (tunduk pada pencatatan dalam log audit tambah-saja kami); dan (3) aparat penegak hukum atau otoritas pemerintah, apabila kami diwajibkan oleh proses hukum yang sah (subpoena, permintaan berdasarkan Perjanjian Bantuan Hukum Timbal Balik (MLAT), atau perintah Pengadilan Singapura).

Anda dapat mengubah visibilitas sesi kapan saja sebelum sesi dimulai. Mengubah dari pribadi menjadi publik TIDAK mengungkap nama tampilan peserta yang diundang di bawah pengaturan privasi sebelumnya secara retroaktif — hanya peserta yang masih mengonfirmasi kehadiran pada saat perubahan yang akan diungkap. Setelah sesi berakhir, visibilitasnya dikunci pada status yang berlaku saat penutupan.

Mode Tak Terlihat (Go Invisible) merupakan preferensi pengguna terpisah yang menyembunyikan kehadiran langsung Anda (indikator titik hijau, posisi dalam aktivitas teman) tetapi TIDAK menyembunyikan konten yang Anda buat. Sesi yang Anda adakan — baik publik maupun pribadi sebagaimana didefinisikan di atas — akan tetap ditampilkan dengan nama tampilan dan avatar Anda pada peta sesuai mode visibilitas yang Anda pilih saat membuat sesi.

2.4 Transaction and Financial Data

  • Credit balance and transaction history — records of Credits earned, purchased, and spent within the Platform;
  • XP and level data — experience points earned and current user level;
  • Purchase history — records of in-app purchases including platform (iOS/Android), amount, and credits granted;
  • Subscription status — current plan, renewal dates, and subscription identifiers.

We do not store your credit card numbers, bank account details, or full payment credentials. Payment processing is handled entirely by the Apple App Store, Google Play Store, or Stripe.

2.5 Device and Technical Data

  • FCM device tokens — identifiers for delivering push notifications to your specific device(s);
  • Device type — whether you use iOS or Android;
  • IP address — recorded in security event logs for fraud prevention and account protection;
  • Request metadata — correlation IDs and timestamps for operational monitoring and debugging.

2.6 Preferences and Settings

  • Interests — categories of sessions you are interested in;
  • Notification preferences — your choices for push and email notification types;
  • Search radius — your preferred geographic discovery radius;
  • Language preference — your selected locale for the app interface;
  • Safety acknowledgment — whether you have reviewed and acknowledged the safety guide.

2.7 Identity Verification Data (Singpass)

If you choose to verify your identity using Singpass (Singapore's national digital identity), we process the following:

  • Verification hash — a one-way cryptographic hash (HMAC-SHA256) of your Singpass identifier. This hash cannot be reversed to reveal your identity or any personal information.
  • Verification timestamp — when the verification was completed.
  • Verification method — the string "singpass" indicating which provider was used.

What we do NOT store from Singpass: your legal name, NRIC/FIN, date of birth, residential address, email address, or phone number. We request only the minimum "openid" scope — no personal attributes are received from Singpass.

Purpose: to confirm you are a real, unique person and to display a "Verified" badge on your profile. The badge helps other users trust who they are meeting at real-world sessions. One Singpass identity can only be linked to one glup account.

Revocation: you can remove your verification at any time from your Profile settings. This immediately deletes the stored hash and removes your verified badge.

Deletion: if you delete your glup account, all verification data is permanently removed as part of the account erasure process.

Legal basis and retention (PDPA §13 and §25). We process Singpass verification data under Singapore Personal Data Protection Act 2012 §13 (consent) with retention limited by §25 (retention limitation). Upon revocation or account deletion, the verification hash, timestamp, and method are immediately and permanently removed from our database via our automated erasure worker. We retain no backup copies of this data after deletion.

Cross-border transfer (for Thailand residents, PDPA-TH §28). If you are a resident of Thailand and choose to verify your identity with Singpass, your authentication request is processed through GovTech Singapore (the operator of the Singpass service) and our Cloud Functions hosted in Singapore (Firebase region asia-southeast1). This constitutes a transfer of personal data outside Thailand under PDPA-TH §28. The transfer is conducted under the §28(1)(3) basis — necessary for the performance of a contract with the data subject (your glup account verification). We retain no raw Singpass data in either jurisdiction; only the HMAC hash is stored, and it is deleted on revocation or account deletion as described above. Singpass itself is subject to Singapore government data protection standards and is operated by GovTech Singapore, not by glup.

Attribution. Singpass is a service provided by the Government of Singapore and is operated by the Government Technology Agency (GovTech). glup is an independent product of GLUESQ Pte. Ltd. Use of Singpass on glup is an optional user-initiated identity verification feature; it does not constitute an endorsement, sponsorship, partnership, or co-branding arrangement between GLUESQ and the Government of Singapore or GovTech.

2.8 Venue Connect

When you join a Venue Connect room by scanning a venue QR code, your profile information (display name, profile photo, age if enabled, job title, company name, interests, and your "Looking for" text) is shared with other participants in the same venue room. This data is visible only while you are connected to the venue. Disconnecting immediately removes your profile from the venue.

What the venue host can see: your display name and "Looking for" text only. The host cannot see your photo, job title, company, age, or interests.

Data retention: venue presence data (which venue, join and disconnect times) is retained for 30 days and then permanently deleted. Connection and interaction data (likes, interests shown) is retained for 30 days. Chat messages created through Venue Connect are retained per our standard message retention policy.

"Looking for" text: the free-text field you fill in when joining a venue is cleared when you disconnect. It is not retained beyond your active venue session.

Job title and company name: these are optional profile fields. If provided, they are visible on your Venue Connect profile card. You can edit or remove them at any time from your Profile settings.

Contact card exchange: if you and another participant mutually agree to exchange contact cards, the contact details you have chosen to share will be transmitted to the other user. This exchange requires mutual action from both parties and is not initiated automatically.

2.9 Reputation and Specializations

glup allows users to give and receive reputation impressions ("Reps") — short tags describing how someone came across in a real-world interaction (e.g., "Great energy", "Good listener"). We collect:

  • Rep tags received — the tag text, who created it, endorsement count, and creation date;
  • Rep endorsements given — records of which tags you endorsed on other users' profiles;
  • Specializations — free-text skills or certifications you declare on your profile (e.g., "PADI Dive Master", "Grade 8 Pianist"), endorsement counts, and display order.

Visibility: Your top 3 Reps and your Specializations are visible on your profile to other users. You can control Specialization visibility in Privacy Settings. Appearance-related Reps (category: LOOKED) can be hidden via Privacy & Safety settings.

Cost: Creating a Rep costs 999 Sparks. Endorsing a Rep costs 50 Sparks. Endorsing a Specialization is free.

Deletion: All Reps, endorsements, and Specializations are permanently deleted when you delete your account.

2.10 Sparks Virtual Currency

Sparks is a non-transferable, non-redeemable virtual currency used within glup for social interactions. We collect:

  • Balance and lifetime totals — your current Sparks balance and total Sparks ever earned;
  • Tier level — your progression tier (Local, Regular, Connected, Inner Circle, or Black Card) calculated from lifetime Sparks;
  • Purchase history — records of Sparks purchased via Apple App Store or Google Play Store, including platform, amount, and tier;
  • Spending limits — optional daily spending cap you set for yourself;
  • Venue gifts — Sparks gifts sent and received at Venue Connect rooms, including sender, recipient, gift type, and amount. Venue gift leaderboards are visible to other participants in the same room for the duration of the venue session.

Financial note: Sparks have no monetary value outside the Platform. 1 Spark ≈ SGD $0.01 for internal pricing purposes only. The Platform retains 30% of Sparks used in venue gifting. Sparks cannot be withdrawn, transferred to other users, or converted to real currency.

Deletion: All Sparks data (balance, tiers, purchase history, spending limits) is permanently deleted when you delete your account.

Gift Credits: Gift Credits are a separate, earn-only in-app currency that cannot be purchased. We store your Gift Credits balance and lifetime total, which our servers derive solely from your gift-conversion history (they are not set or altered by your device). Gift Credits have no monetary value and cannot be withdrawn, transferred, or converted to real currency. All Gift Credits data is permanently deleted when you delete your account.

2.11 Gamification Data

glup tracks engagement-related data to support gamification features:

  • Streaks — weekly attendance streaks, longest streak, and streak freeze usage;
  • Badges — earned achievement badges (e.g., "First Host", "10 Sessions"), earn dates, and XP awarded;
  • Badge progress — progress counts toward not-yet-earned badges.

Gamification data is visible on your profile (Trophy Case section). It is permanently deleted when you delete your account.

2.12 Screening Questions and Answers

If you are an Active or Business tier subscriber, you may create screening questions ("Intro Questions") that other users answer when they send you a friend request. We collect and process:

  • Questions you create — question text, answer type (free-text or multiple-choice options), importance level, and slot position. Visible to anyone who sends you a friend request.
  • Answers submitted to you — answer text and selected options submitted by other users with their friend requests. Visible only to you (the question creator).
  • Your own answers — if you answer your own questions (for future matching features), these are stored separately and not shared with other users.
  • Reports — if a question is reported, we record the reporter's identity and reason. Reporter identity is never disclosed to the question creator.

Retention: Questions persist while your account is active. Answers attached to accepted friend requests are retained for the lifetime of the friendship. Answers attached to declined or cancelled requests are automatically deleted within 30 days — once a request is declined, the purpose of answer collection is exhausted (Singapore PDPA §25, PDPA-TH §37).

Restricted categories: You must not create questions that solicit information about health or medical conditions, religion or beliefs, sexual orientation, political opinions, criminal history, or biometric data. Such questions violate PDPA-TH §26 (sensitive personal data) and will be automatically removed by our content moderation system.

Deletion: All screening questions, answers, and self-answers are permanently deleted when you delete your account (CASCADE via foreign key on user_id).

Future use: We may use anonymized and aggregated screening question and answer data to improve connection suggestions in the future. If we implement such features, we will update this Privacy Policy before doing so.

2.13 Signal Questionnaire and Common Ground

Signal is an optional questionnaire. You can use the Platform fully without ever opening it, and nothing on your profile changes if you do not. If you choose to answer, we collect and process:

  • Your answers — which statement you answered, the option you chose on the five-point scale, when you answered, and how long you took. Response time is used only to detect answering that is too fast to have involved reading the statement.
  • Derived estimates — from your answers we compute estimates across twenty-three characteristics, each with a margin of error. These are inferences we generate, not statements you made about yourself.
  • Your consent choices — recorded separately for each of the two purposes below, with the time of each change.
  • Common Ground results — when you and another person both opt in and one of you runs a comparison, we store the result so that repeating it does not recompute it.

Two separate purposes, two separate consents. Saving your answers and allowing other people to compare themselves with you are different purposes, and we ask for them separately. You may grant one without the other, and you may withdraw either at any time in the Signal screen. Withdrawing the second stops all future comparisons immediately and deletes stored comparison results.

What other people can see. No one can see your answers. No one can see your estimates, your scores, or any number describing you on your own. A person who has also opted in — and only such a person, never one-sidedly — can see a comparison of the two of you: a broad band rather than a precise figure, a count of the areas where you overlap, and a short description of what you have in common. Comparisons are rate-limited.

What is never shown to anyone. Three of the twenty-three characteristics relate to emotional reactivity. These are excluded from every screen, from Common Ground, and from any description shown to another person. They are never displayed, to you or to anyone else, and cannot be inferred through repeated comparisons.

What Signal is not. It is not a psychological, clinical, or medical assessment, it is not a diagnosis, and it does not predict whether a relationship will succeed. It describes what two people already have in common. We make no claim beyond that.

Reputation tags. Signal may offer you one tag drawn from your own answers. It is added only if you accept it, is labelled on your profile as coming from your answers rather than from another person, and can be removed at any time.

Deletion and reset. You can delete your Signal data at any time without deleting your account. Doing so removes your answers, your estimates, and every stored comparison involving you. All Signal data is also deleted when you delete your account.

3. How We Collect Data

  • Directly from you — when you register, create sessions, send messages, make purchases, or update your profile;
  • Automatically — technical data such as device tokens, IP addresses, and usage patterns collected during your interaction with the Platform;
  • From authentication providers — identity information from Firebase Authentication (Google Sign-In, Apple Sign-In);
  • From device sensors — GPS location data, collected only with your explicit consent;
  • Server-side request logs — may temporarily contain location coordinates included in API requests. These logs are retained for 30 days and are used solely for debugging and performance monitoring.

4. Legal Basis for Processing

We process your personal data on the following legal bases:

Legal BasisProcessing Activities
Performance of contractAccount creation and management, providing core services (session discovery, chat, gifting), processing transactions, subscription management
ConsentLocation data collection, push notifications, marketing communications, optional profile information
Legitimate interestPlatform security and fraud prevention, abuse detection and content moderation, service improvement and analytics, maintaining audit logs
Legal obligationComplying with applicable laws, responding to lawful requests from authorities, maintaining financial records

5. How We Use Your Data

  • Session discovery — matching you with nearby sessions using geo-proximity queries on your location data;
  • Chat delivery — routing messages between users in real time via Supabase Realtime broadcast channels;
  • Push notifications — sending timely alerts about sessions, messages, and promotions using your FCM device tokens;
  • Local Picks — displaying relevant business promotions based on your location and preferences;
  • Hangout area for Nearby notifications — if you turn on Nearby Session notifications, glup stores a single location to work out what counts as “near you”. You choose how we get it: either you set your hangout area yourself, or — only if you separately turn this on — we use the area you were last in while using the app. We never collect your location in the background or when the app is closed, we never build a location history, and we only ever keep one such location at a time, replacing the previous one. We store it in an approximate form — rounded to roughly one kilometre if we derived it from your last use of the app, or roughly 100 metres if you set it yourself — never your exact coordinates. It is used only for these nearby notifications: a new session created near you, and — if you also keep “Nearby picks” turned on — a new pick from a local business. Both use the same notification radius you choose in the app (3, 8, 13 or 18 km); we will never notify you about anything further away than the radius you have selected, and 18 km is the largest available. It is never shared with other users or any third party, including the businesses whose picks you're notified about. We keep it only while Nearby Session notifications are turned on: if you turn the feature off, or delete your account, we delete it. If you later turn Nearby Session notifications on again, we will store a new hangout area at that point, and — because you have already agreed to this use — we will not ask you to consent a second time. You can turn either notification off, or switch back to setting your hangout area yourself, at any time in Profile → Notifications → Session Notifications;
  • Personalization — recommending sessions and content based on your interests and activity history;
  • Safety and moderation — detecting and preventing abuse, enforcing Community Guidelines, and protecting users;
  • Account security — monitoring for unauthorized access, brute-force attacks, and suspicious activity;
  • Service improvement — analyzing aggregate usage patterns to improve Platform features and performance;
  • Service integrity and crash diagnostics — when the app experiences an error, crash, or server-side validation rejection, we collect technical diagnostic information including your user identifier, an approximate viewport area (rounded to approximately 1 km), stack traces, and breadcrumbs describing the immediate user actions preceding the error. This processing is necessary for our legitimate interest in maintaining service reliability, detecting exploit attempts, and fulfilling our PDPA §24 protection obligation. Crash diagnostic records are retained within our own Google Cloud Logging infrastructure in Singapore for no more than thirty (30) days and are purged within the 30-day window upon a Data Access Request for erasure (see Section 10). We do not attach your email, phone number, or IP address to these records. No third-party crash-reporting processor is used.
  • Usage analytics — we record which parts of the app you interact with (for example, opening a session card or panning the map) so we can understand what people actually use and improve it. These events are pseudonymised before they are stored: they carry a one-way identifier derived from your account rather than your name or email. They are processed only within our own Google Cloud project in Singapore, and are automatically deleted after 90 days — that deletion is enforced by the storage itself, not by a job that has to remember to run. They are never sold, and are never used for advertising — the app contains no advertising SDK and does not collect an advertising identifier. You can turn usage analytics off at any time in the app under Profile → Privacy → “Help improve glup”. When it is off, the app stops sending these events and our servers reject any that still arrive, so nothing is recorded. Turning it off does not affect any other feature, and crash diagnostics (described above) are handled separately because we need them to keep the service safe and reliable.
  • Compliance — fulfilling legal obligations, responding to data subject requests, and maintaining required records.

6. Data Sharing and Processors

We do not sell your personal data. We share data only with the following categories of service providers who process data on our behalf:

ProviderPurposeData Shared
Firebase (Google Cloud)Authentication, push notifications (FCM), and the hosting of our own usage analytics and diagnostics (BigQuery and Cloud Logging, in our own project)Email, auth tokens, device tokens, pseudonymised usage events
SupabasePrimary database, real-time messagingAll user data (encrypted at rest and in transit)
Redis CloudCaching, rate limitingCached query responses, rate-limit counters (short-lived)
Google Maps PlatformGeocoding, place searchLocation coordinates, search queries
OpenFreeMap (community-operated, Switzerland-based)Map tile delivery for venue, session and Local Picks map viewsTile-fetch HTTPS requests including the user's IP address and the tile coordinates currently in view. No account information, message content, or persistent user identifiers are transmitted. Switzerland operates under data-protection law recognised as adequate by Singapore PDPC.
GovTech (Singpass)Optional identity verificationHMAC hash of Singpass identifier only (no personal data transmitted to or stored from Singpass)
Apple / GoogleIn-app subscription billing, receipt validation, price-change notificationsTransaction identifiers, subscription status, original_transaction_id (iOS), purchase_token (Android). Payment card details remain with the platform processor and are never transmitted to GLUESQ. See § 6.2 below.
Google (AdMob)Advertising. A single advertisement is shown in the conversation list to members on the free tier. Members on a paid plan are shown no advertisements at all.Your device advertising identifier, IP address, general device information, and your interactions with the advertisement itself (whether it was shown, viewed or tapped). We do not send Google your name, email address, phone number, messages, location, or any other content you create in glup. Whether these signals are used to personalise the advertisements you see is a separate choice you control — see § 11.
StripeWeb subscription billing and gift purchasesTransaction identifiers, subscription status. Stripe handles all payment card details directly. See § 6.2 below.
OpenAIAI-assisted promotion management (GPT Actions) — user-initiated onlyBusiness promotion details and analytics aggregates only (see Section 6.1 below)
AnthropicAI-assisted promotion management (MCP Server) — user-initiated onlyBusiness promotion details and analytics aggregates only (see Section 6.1 below)

We may also disclose personal data when required by law, regulation, or legal process, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

We maintain data processing agreements with all third-party service providers listed above, incorporating standard contractual clauses to ensure your data is handled in accordance with applicable data protection laws.

6.1 AI Integration Providers (BYOAI)

glup offers optional AI-assisted features that allow business users to manage their Local Picks promotions using third-party AI assistants, including OpenAI's ChatGPT (via GPT Actions) and Anthropic's Claude (via the Model Context Protocol, or MCP). These integrations are collectively referred to as "BYOAI" (Bring Your Own AI).

Data shared with AI providers. When you explicitly connect an AI assistant to your glup account, the following business-related data may be transmitted to the AI provider during your interactions:

  • Business name and category;
  • Promotion details — titles, descriptions, prices, discount labels, location, and expiry times;
  • Analytics aggregates — views, saves, and direction-tap counts for your promotions.

Data NOT shared with AI providers. The following categories of personal information are never transmitted to AI providers through these integrations:

  • Email addresses, phone numbers, or account credentials;
  • Location history or GPS tracking data of any user;
  • Chat messages or private communications;
  • Payment information, credit card details, or financial records;
  • Other users' personal data, profiles, or activity.

When data is shared. Data is transmitted to AI providers only when you actively initiate an interaction through a connected AI assistant. No data flows to AI providers in the background or without your direct action. The connection requires an explicit OAuth consent flow, which serves as an additional consent mechanism under the Singapore PDPA. You must authorize the connection before any data is shared.

AI provider data retention. Once data leaves the glup platform and reaches an AI provider, it is subject to that provider's own privacy policy and data retention practices:

  • OpenAI — retains API conversation data for up to thirty (30) days for abuse monitoring, and potentially longer for consumer ChatGPT usage depending on user settings. See OpenAI's Privacy Policy.
  • Anthropic — retains API conversation data for thirty (30) days for safety purposes, and up to five (5) years for consumer usage if model training is enabled by the user. See Anthropic's Privacy Policy.
  • Other MCP-compatible clients — if you connect an AI assistant from another provider via the MCP protocol, that provider's own privacy policy governs their retention and use of data.

Your control. You may disconnect any AI integration at any time through your glup account settings. You may also revoke access by removing the OAuth authorization from the AI provider's side (e.g., revoking the GPT Action in ChatGPT, or disconnecting the MCP server in Claude). Upon disconnection, no further data will be transmitted to that provider. However, data already transmitted is subject to the provider's retention policy as described above.

PDPA compliance. In accordance with the Singapore Personal Data Protection Act 2012, we obtain your consent through the OAuth authorization flow before any data is shared with AI providers. This consent is separate from and in addition to your general consent to these terms. You may withdraw this consent at any time by disconnecting the AI integration, without affecting the lawfulness of data sharing that occurred before withdrawal.

6.2 Subscription Processors (Apple, Google, Stripe)

When you subscribe to Active (S$8/month) or Business (S$24.98/month), GLUESQ Pte. Ltd. shares your transaction identifier and subscription status with the platform processor for billing, receipt validation, and price-change notifications:

Payment card details. We do not collect, process, or store your payment card details (credit card numbers, security codes, billing addresses) at any time. Card details are entered directly into the platform processor (Apple, Google, or Stripe) and remain with the platform processor at all times. GLUESQ Pte. Ltd. receives only the transaction identifier and subscription status from the processor.

Subscription metadata retention. Per the Singapore Companies Act §199(2), we retain subscription transaction metadata (start date, tier, status, transaction hash, processor identifier) for seven (7) years after subscription end for tax-record compliance and PDPA §24 audit purposes. This retention applies even after account deletion. No personal identifying information beyond your account email is retained for this purpose. See Section 8 for the full retention schedule.

Price-change consent. If we increase the price of an active subscription, Apple (via App Store Server Notifications V2), Google (via Real-Time Developer Notifications), or Stripe will each require your explicit consent before continuing your subscription at the new price. If you do not consent, your subscription expires at the end of the current billing period and you may resubscribe at any time. You may also decline by cancelling your subscription per Section 9 of this Policy.

Cross-border transfer. Apple and Google subscription processing occurs in the United States. Stripe processing occurs in the United States and Ireland. We rely on Standard Contractual Clauses (SCCs) for these transfers as permitted under PDPA §26 (Singapore) and PDPA-TH §28 (Thailand). See Section 7 for additional detail on international data transfers.

7. International Data Transfers

Your data is primarily stored and processed in the asia-southeast1 (Singapore) region. Our service providers may process data in other jurisdictions. When data is transferred outside your country of residence, we ensure that appropriate safeguards are in place, including:

  • Standard contractual clauses approved by the relevant data protection authority;
  • Data processing agreements with all third-party processors;
  • Encryption of data in transit (TLS) and at rest.

For users in Thailand, cross-border transfers are conducted in accordance with PDPA-TH §28, with appropriate safeguards in place.

8. Data Retention

We retain your data only for as long as necessary to fulfil the purposes for which it was collected or as required by law:

Data CategoryRetention Period
Account data (profile, email, username)Until account deletion
Signal answers and derived estimatesWhile your account is active, then 90 days — or immediately on Signal reset
Signal data used to calibrate the questionnaireDe-identified and severed from your account, so it is no longer personal data and cannot be traced back to you
Precise GPS location coordinates30 days (rolling)
Chat messagesUntil account deletion or message deletion by user
Session dataUntil account deletion (ended sessions retained for history)
Notifications30 days (automatically purged via scheduled job)
Security event logs90 days (automatically purged via scheduled job)
User presence data5 minutes (automatically expires)
Friend location coordinatesDeleted when you go offline or within 5 days of last update. Permanently deleted on account deletion.
Auth session records30 days (automatically purged via scheduled job)
Reputation tags and endorsementsUntil account deletion
Specializations and endorsementsUntil account deletion
Sparks balance, tiers, and purchase historyUntil account deletion
Subscription transaction records (start date, tier, status, transaction hash, processor identifier)Seven (7) years from subscription end, per Singapore Companies Act §199(2) and PDPA §24 audit obligations. Retained even after account deletion. See § 6.2 above.
Venue gifts30 days (automatically purged via scheduled job)
Venue gift leaderboard7 days (automatically purged via scheduled job)
Streaks and badgesUntil account deletion
Screening questionsUntil account deletion
Screening answers (accepted requests)Until friendship ends or account deletion
Screening answers (declined/cancelled requests)30 days (automatically purged via scheduled job)
OAuth authorization tokens (BYOAI)30 days (refresh tokens), 1 hour (access tokens)
Account lockout records24 hours (automatically purged)
Analytics events (Local Picks)90 days (automatically purged via nightly scheduled job)
Identity verification data (Singpass hash)Until user revokes verification or deletes account
Transaction records7 years (legal/financial compliance requirement)
Redis cache entries30 seconds to 5 minutes (automatically expires)

Upon account deletion, we will erase or anonymize your personal data within thirty (30) days, except where retention is required by law (e.g., financial transaction records).

9. Your Rights

Depending on your jurisdiction, you have the following rights regarding your personal data:

  • Right of access — request a copy of the personal data we hold about you;
  • Right to correction — request correction of inaccurate or incomplete personal data;
  • Right to deletion — request deletion of your personal data (subject to legal retention obligations);
  • Right to data portability — receive your personal data in a structured, commonly used, machine-readable format;
  • Right to withdraw consent — withdraw consent for processing based on consent (e.g., location data) at any time, without affecting the lawfulness of prior processing;
  • Right to restrict processing — request restriction of processing in certain circumstances;
  • Right to object — object to processing based on legitimate interests;
  • Right to lodge a complaint — file a complaint with the relevant data protection authority in your jurisdiction.

Singapore residents: Your rights are protected under the Personal Data Protection Act 2012 (PDPA). You may contact the Personal Data Protection Commission (PDPC) at www.pdpc.gov.sg.

Thailand residents: Your rights are protected under the Personal Data Protection Act B.E. 2562 (PDPA-TH). You may contact the Office of the Personal Data Protection Committee (OPDPC).

10. Data Subject Access Requests (DSAR)

To exercise any of your data rights, please submit a request to:

Please include in your request:

  • Your full name and the email address associated with your glup account;
  • A clear description of the right you wish to exercise;
  • Sufficient information to verify your identity (we may request additional verification).

We will acknowledge your request within five (5) business days and provide a substantive response within thirty (30) days. If we require additional time due to the complexity of the request, we will notify you of the extension (up to an additional thirty days) and the reasons for the delay. There is no fee for exercising your data rights, unless requests are manifestly unfounded or excessive.

11. Cookies and Tracking

The glup website uses only essential, session-based cookies necessary for the proper functioning of the site (e.g., maintaining your session state). We do not use advertising cookies, tracking pixels, or third-party analytics cookies on our website.

The glup mobile application does not use cookies. It uses standard mobile APIs for authentication token storage and device-local preferences. We do not use Google Analytics for Firebase — that SDK is not part of the app. Usage analytics are pseudonymized (each event carries a one-way identifier derived from your account, not your name or email) and are stored only within our own Google Cloud project in Singapore; they are never joined with third-party data. Crash diagnostics are captured within the same infrastructure (no third-party crash-reporting processor is used); error logs, device information, and app state at the time of a crash are retained for 30 days. You can turn usage analytics off at any time in the app under Profile → Privacy → “Help improve glup”; see Section 5 for what this covers.

Advertising. Members on the free tier are shown a single advertisement in the conversation list, delivered by Google AdMob. To request it, the app shares your device advertising identifier and IP address with Google; see the processor table in § 6. We do not share your name, email address, phone number, messages, location, or anything else you create in glup.

Your choices. Two separate controls apply, and they do different things. Whether advertisements are personalised using your advertising identifier is your choice: where the law of your country requires it, you are asked on first launch, and you can change or withdraw that choice at any time under Profile → Privacy → “Ad privacy choices”. Withdrawing consent is as straightforward as giving it, and doing so does not restrict your use of glup. Separately, whether advertisements appear at all is a feature of your plan — members on a paid plan see none.

Your device advertising identifier is controlled by your phone, not by glup. You can reset it, or ask your device to stop apps using it, in your system settings (iOS: Settings → Privacy & Security → Tracking; Android: Settings → Privacy → Ads). We do not use advertising cookies or tracking pixels, and we do not build advertising profiles ourselves.

12. Minimum Age (Adults Only, 21+)

glup is an adult-only Platform. The minimum age to create an account and use any feature of the Platform is twenty-one (21) years, globally, without exception. We do not offer parental or guardian consent pathways, and we do not permit accounts for users under 21 regardless of jurisdiction. See Section 2 of our Terms of Service for the full eligibility rules.

We enforce the 21+ requirement at three independent layers:

  • Client-side validation in the signup form rejects any date of birth that would place the user under 21 at the time of account creation;
  • Server-side validation in our authentication backend re-checks the date of birth on every signup request and returns a 400 AGE_REQUIREMENT_NOT_MET error if the age is below 21, even if the client-side check was bypassed;
  • Database-layer enforcement via a PostgreSQL CHECK constraint that structurally rejects any INSERT or UPDATE that would store a date of birth younger than 21 years old.

We do not knowingly collect personal data from any person under 21. If we become aware that we have collected personal data from a person under 21 — for example, if a user falsifies their date of birth at signup and we subsequently discover the truth — we will take steps to delete such data promptly and terminate the account without notice. If you believe that a person under 21 has provided us with personal data, please contact us at privacy@gluesq.com.

Why 21+? The 21+ global minimum exceeds the age threshold set by every data protection and online safety law that covers our users — Singapore PDPA 2012, Thailand PDPA B.E. 2562 (PDPA-TH, which sets parental consent below 20), Malaysia PDPA 2010, Indonesia UU PDP 2022, Vietnam's data protection rules, the EU GDPR (Article 8 of which permits 13 with parental consent), the UK Online Safety Act 2023, and Australia's Online Safety Amendment (Social Media Minimum Age) Act 2024. Because our minimum is strictly above every jurisdictional threshold, we do not need to collect or store any data from minors, and we do not operate a parental-consent flow.

Declared age range from your device or app store. Where your operating system or app store makes a declared age range available to us — for example through Apple's Declared Age Range API — we may receive and record that age range to corroborate your eligibility. We receive only an age range or age category. We do not receive your date of birth from your app store or operating system. This information is used solely to confirm that you meet our minimum age and to meet our obligations under online safety law. It is never used for advertising, profiling, personalisation, or any form of automated decision-making beyond the age check itself, and it is not shared with any third party.

Assessment of access by children. We have assessed whether glup is likely to be accessed by children and concluded that it is not. The Platform is restricted to adults aged 21 and over by its Terms; that restriction is enforced by our servers before an account can be created; the date of birth supplied at registration cannot subsequently be changed; the Platform contains no features designed for or appealing to children; and we do not market the Platform to minors. We keep this assessment under review and will repeat it whenever we make a significant change to the Platform. App store content ratings are assigned by app store operators under their own criteria and do not alter our minimum age, which is 21 worldwide.

13. Data Security

We implement industry-standard technical and organizational measures to protect your personal data, including:

  • Encryption in transit — all data transmitted between your device and our servers is encrypted using TLS;
  • Encryption at rest — database storage is encrypted at rest;
  • Authentication security — Firebase Authentication with support for multi-factor authentication; brute-force protection via account lockouts and IP blocking;
  • Access controls — role-based access to infrastructure and data; all API requests authenticated via Firebase ID tokens;
  • Rate limiting — global and per-user rate limits to prevent abuse;
  • Audit logging — security events logged with IP addresses and timestamps;
  • Database isolation — SERIALIZABLE transaction isolation for all write operations to ensure data integrity.

While we take reasonable measures to protect your data, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security.

13.2 Data Breach Notification

In the event of a personal data breach that is likely to result in significant harm to affected individuals, we will:

  • Notify the Personal Data Protection Commission (PDPC) of Singapore within three (3) calendar days of becoming aware of the breach, as required by PDPA §26D;
  • Notify the PDPC Thailand within seventy-two (72) hours if Thai users are affected, as required by PDPA-TH §37;
  • Notify affected individuals without undue delay if the breach is likely to result in significant harm to their rights or interests; and
  • Take immediate steps to contain, investigate, and remediate the breach.

14. Automated Decision-Making

We do not engage in fully automated decision-making that produces legal effects or significantly affects you. Our content moderation system may use automated tools to flag potentially violating content, but all enforcement actions (warnings, suspensions, bans) involve human review.

Decisions we automate, and the data used in them. We set this out expressly because Australian law requires a privacy policy to describe automated decision-making, and because it is the honest way to describe what the Platform does. The following are computed automatically:

  • Content moderation screening — text you submit is screened automatically for prohibited content. Data used: the text itself. A positive screen can block a submission; every enforcement action against an account (warning, suspension, ban) involves human review, and you may challenge a decision under section 5A of the Terms.
  • Signal estimates and Common Ground — statistical estimates derived from your questionnaire answers, and a comparison with another user who has also opted in. Data used: your answers. This is a statistical scoring model, not a generative AI system, and it produces no legal or similarly significant effect.
  • Discovery ordering and suggestions — the ordering of sessions, communities and suggested connections. Data used: approximate location, your activity on the Platform, and your stated preferences.
  • Anti-abuse and rate limiting — automated limits on how often an action may be performed. Data used: account identifiers and request timing.

None of these produces a legal effect or a similarly significant effect on you. You may ask us to review any automated outcome that affects you by contacting us using the details in section 17.

The Signal questionnaire (section 2.13) does generate inferences about you automatically. Those inferences affect only what an optional comparison screen displays. They do not affect your access to the Platform, your pricing, your visibility to other users, or any moderation decision, and they are never used to rank or filter you. You can decline the feature entirely or delete the data at any time.

We do not train generative AI models on your personal data. Your profile, messages, photos, location history and Signal answers are not used to train, fine-tune or evaluate any generative AI model, whether ours or a third party's, and are not supplied to any third party for that purpose. The Singapore Personal Data Protection Commission's Advisory Guidelines on the Use of Personal Data in Generative AI Systems (July 2026) require an explicit, AI-specific notification before personal data may be used for such training; if we ever intend to do so, we will seek your consent through a separate, specific notice rather than through an update to this Policy.

This is distinct from the optional AI-assisted business features described elsewhere in this Policy, under which a business user may connect their own ChatGPT or Claude account to manage their own Local Picks promotions. In that arrangement the business user directs their own AI provider, data reaches that provider under the business user's own agreement with it, and we neither control nor train on what is sent. Those features are opt-in, are available only to business accounts, and do not expose another user's personal data.

15. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will provide at least thirty (30) days' advance notice of material changes by:

  • Posting the revised policy on the Platform and our website;
  • Sending a push notification to active users; and/or
  • Emailing you at the address associated with your account.

Your continued use of the Platform after the effective date of the revised policy constitutes your acceptance of the changes.

16. Jurisdiction-Specific Provisions

16.1 Singapore (PDPA)

We comply with the Personal Data Protection Act 2012 of Singapore. We have appointed a Data Protection Officer (DPO) who can be reached at dpo@gluesq.com. We will obtain your consent before collecting, using, or disclosing your personal data, unless an exception under the PDPA applies. You may withdraw consent at any time by contacting our DPO, subject to legal and contractual restrictions.

16.2 Thailand (PDPA-TH)

For users in Thailand, we process your personal data in accordance with the Personal Data Protection Act B.E. 2562 (2019). Where consent is the legal basis, we will obtain explicit consent before collecting sensitive personal data (including precise geolocation). You have the right to withdraw consent, request access, correction, deletion, restriction, and portability of your data, and to lodge a complaint with the Office of the Personal Data Protection Committee.

Cross-border transfers from Thailand. If you use optional features that require processing in Singapore — in particular, the Singpass identity verification described in Section 2.7 — your personal data is transferred from Thailand to Singapore for the duration of that feature request. We rely on PDPA-TH §28(1)(3) as the lawful basis for this transfer (performance of a contract with you, the data subject). Only the minimum data necessary is transferred, and we store no raw Singpass data in either jurisdiction. See Section 2.7 for the specific data elements and retention rules.

16.3 Malaysia (PDPA)

For users in Malaysia, we comply with the Personal Data Protection Act 2010. You have the right to access and correct your personal data, and to withdraw consent for processing. We process personal data only for purposes directly related to the services we provide.

16.4 Indonesia

For users in Indonesia, we comply with applicable data protection regulations, including Government Regulation No. 71 of 2019 on Electronic Systems and Transactions and the Personal Data Protection Law (UU PDP) No. 27 of 2022. You have the right to access, correct, and delete your personal data.

16.5 Where the Platform is available

The Platform is offered in ten territories: Australia, Cambodia, Indonesia, Malaysia, Myanmar, the Philippines, Singapore, Taiwan, Thailand and Vietnam. Singapore is our principal place of business and the location of our primary processing infrastructure. The sections below apply in addition to, and not instead of, the rest of this Policy. Where a right described below is broader than one described elsewhere in this Policy, the broader right applies to you.

16.6 Australia

Advertising (APP 7). We disclose your device advertising identifier to Google so that an advertisement can be shown in your conversation list. To the extent this constitutes direct marketing under Australian Privacy Principle 7, you may opt out of personalised advertising at any time under Profile → Privacy → “Personalised ads”. We draw your attention to that control here because APP 7.3 requires us to. Opting out does not restrict your use of the Platform, and members on a paid plan are shown no advertisements at all.

We are subject to the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) in respect of personal information of individuals in Australia, including under the extraterritorial operation of section 5B.

  • Access and correction (APP 12, APP 13) — you may request access to, and correction of, your personal information. See section 10 for how to make a request.
  • Overseas disclosure (APP 8) — your personal information is stored and processed in Singapore (asia-southeast1) and disclosed to the processors listed in section 6, which operate in Singapore, the United States and other jurisdictions. By using the Platform you acknowledge that once your information is disclosed overseas we may not be accountable under the Privacy Act for that recipient, and you may not be able to seek redress in Australia.
  • Notifiable Data Breaches scheme (Part IIIC) — where a breach is likely to result in serious harm, we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable.
  • Complaints — you may complain to us using the details in section 17, and then to the OAIC at oaic.gov.au.
  • Automated decision-making — see section 14, which describes the decisions we automate and the personal information used in them.

The Platform is available only to adults aged 21 and over (section 12). We do not knowingly provide the Platform to children, and it is not directed at them.

16.7 Taiwan

Advertising (PDPA Arts. 8 and 20). The purpose of collection is to display advertising that funds the free tier; the recipient is Google LLC; the categories disclosed are your device advertising identifier and IP address. Under Article 20 you may refuse the use of your personal data for marketing, and we will stop immediately — switch off “Personalised ads” under Profile → Privacy. Because Taiwan's PDPA applies by nationality, this section applies to you wherever you are located.

We are subject to the Taiwan Personal Data Protection Act (PDPA) in respect of the personal data of Taiwanese nationals. The Taiwan PDPA applies on the basis of the data subject's nationality, so it applies to your data whether you are in Taiwan or elsewhere — including while you are visiting Singapore. Under Articles 3 and 11 you may request to review your data, obtain a copy, supplement or correct it, and demand that we cease collecting, processing or using it, or delete it. Exercising these rights cannot be waived in advance by agreement. Requests may be made using the details in section 17 or through the process in section 10. Taiwan has established the Personal Data Protection Commission as its supervisory authority; you may complain to it or to the relevant sector regulator.

16.8 Vietnam

Advertising (PDPL Law No. 91/2025/QH15). Vietnamese law requires your separate consent before personal data is disclosed to a third party, and provides that silence is not consent. We therefore ask you, at registration, whether Google may use your advertising identifier to personalise advertisements. The question is unticked by default and answering “no” costs you nothing. You may change or withdraw that answer at any time under Profile → Privacy → “Personalised ads”. If you have not given that consent, we do not disclose your advertising identifier to Google for personalisation purposes.

We are subject to the Law on Personal Data Protection (Law No. 91/2025/QH15), in force from 1 January 2026, and Decree No. 356/2025/ND-CP. These replaced Decree No. 13/2023/ND-CP, which ceased to have effect on 1 January 2026. Where we rely on your consent, that consent is given expressly, separately for each purpose, and may be withdrawn at any time without detriment to the lawfulness of processing before withdrawal. You have the rights to be informed, to access, to correct, to withdraw consent, to delete, to restrict, to object, to data portability, and to complain. We will notify the competent authority of a personal data breach within the period prescribed by law.

16.9 Philippines

We are subject to the Data Privacy Act of 2012 (Republic Act No. 10173) in respect of personal information of individuals in the Philippines. You have the rights to be informed, to object, to access, to rectification, to erasure or blocking, to damages, and to data portability. You may lodge a complaint with the National Privacy Commission (privacy.gov.ph). Where a breach is likely to give rise to a real risk of serious harm, we will notify the Commission and affected data subjects within seventy-two (72) hours of knowledge of the breach.

16.10 Cambodia and Myanmar

Neither Cambodia nor Myanmar has, at the date of this Policy, a comprehensive personal data protection statute in force. We nonetheless apply the standard described in this Policy — including the rights in sections 9 and 10 — to users in those territories, and we apply the Singapore PDPA as our baseline. Sectoral laws, including Cambodia's Law on Electronic Commerce and Myanmar's cybersecurity legislation, apply where relevant.

16.11 Other territories and residual rights

If you use the Platform from a territory not listed above, the Singapore PDPA standard set out in this Policy applies to you as a minimum. Nothing in this Policy limits any right you have under a mandatory law of your place of residence that cannot be excluded or limited by agreement. If any part of this Policy conflicts with such a law, that law prevails to the extent of the conflict and the remainder of this Policy continues to apply.

No EU/EEA or United Kingdom offering. The Platform is not offered in, and is not directed to, the European Economic Area or the United Kingdom, and we do not monitor behaviour there. The GDPR and UK GDPR are therefore not engaged. If we make the Platform available in those territories in future, we will update this Policy before doing so.

17. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us: