Hello SG

Privacy Policy

Last updated — 10 September 2026

Hello SG ("we", "our") provides news, guides and tools for people living in Singapore. This policy explains what data we collect, why we collect it, and how you control it.

1. Data We Collect

  • AccountEmail and hashed password via Supabase Auth. We never store your plain-text password.
  • Profile preferencesLanguage, selected country/community preference, and theme settings when you set them.
  • Form draftsPassport wizard field values (name, passport number, etc.) saved to your account so you can return later.
  • Salary & fee logsSalary or recruitment-fee entries you create, and data needed to export a PDF report.
  • Comments & reportsText you post on guide/tool pages or place comments, replies, and reports of inappropriate content (login required).
  • PaymentsPayment records (amount, status) and receipt images you upload for manual payment (e.g. KPay/WavePay).
  • Ad measurementImpression and click events for sponsored banners (may be linked to your user id if logged in). Google AdSense may use its own cookies or identifiers.
  • AnalyticsUsage events to improve the product (some anonymous; some tied to your account when logged in).
  • Contact / sponsorshipMessages and contact details you submit through the Contact / sponsorship form.

2. How We Use Your Data

  • Provide guides, tools, saved drafts and reminders.
  • Show community comments and moderate reported content.
  • Show and measure sponsored ads / AdSense so the app can stay free.
  • Respond to support, sponsorship inquiries and deletion requests.
  • Analyse usage patterns to improve the product.

We do not sell your personal data. If you open a sponsored or community-helper link, you leave our site for that third party.

3. Storage & Security

  • Data is stored in Supabase (PostgreSQL) hosted on AWS ap-southeast-1 (Singapore).
  • Payment receipt images are in a private storage bucket — accessible only to admins.
  • Sponsored-ad images and driving-helper photos may be stored in public buckets (uploaded by admins).
  • Traffic uses HTTPS. Supabase Row-Level Security limits access to your own records (admins have separate access for moderation).

4. Third-Party Services

  • Supabase — authentication, database and storage.
  • Google AdSense (when enabled) — ad delivery and measurement.
  • Vercel — hosting the web app.

5. Your Rights

  • AccessView saved drafts and tool data from Account and the relevant tools.
  • DeletionTo delete your account and associated data, use Delete account on the Account page, or email us below.
  • ExportExport your salary record as a PDF where that feature is available.
  • CommentsAdmins may hide or remove comments. You can report inappropriate content.

Contact Us

For privacy questions or account deletion —

hellosgmm@gmail.com