Privacy Policy anoop August 7, 2025

Privacy Policy

Zhong Yue Pte Ltd (Giggle Jobs) 

Privacy Policy (Singapore) 

Zhong Yue Pte. Ltd. (UEN: 202323760D) trading as Giggle Jobs Version: 2.1 · Effective  date: 14th August 2026 · Last reviewed: 14th August 2026 · Supersedes: version 2.0 dated  27 July 2026 

  1. About this Policy 

Zhong Yue Pte. Ltd. (“Giggle”, “we”, “us”) operates the Giggle Jobs platform: our mobile  application, our website at gigglejobsapp.com, the worker portal, the employer portal and  our related systems (together, the “Platform”), through which hotels, restaurants, caterers  and other hospitality businesses (“Clients” or “Principals”) engage part-time, casual and  full-time hospitality workers (“Workers”). 

This Policy explains how we collect, use, disclose, protect and retain personal data, and the  rights available to you, under the Personal Data Protection Act 2012 (“PDPA”) and its  subsidiary legislation. 

It applies to Workers, jobseekers, Client representatives, website visitors and anyone who  contacts us. It does not apply to how a Client uses your personal data once it has been  provided to that Client for its own purposes — in that respect the Client is independently  responsible under the PDPA and you should consult its privacy policy. 

Our role. For most processing described here, Giggle is the organisation that decides the  purposes of processing. In limited cases — for example, where we host attendance or  rostering records on behalf of a Client and process them only on that Client’s instructions  — we act as a data intermediary under section 4(2) of the PDPA, and the Client is the  responsible organisation. 

  1. Data Protection Officer and how to contact us 

We have appointed a Data Protection Officer (“DPO”) in accordance with section 11(3) of  the PDPA. 

Data Protection  Officer 

Ashik  

Email [email protected] General enquiries [email protected]

Post The Data Protection Officer, Zhong Yue Pte. Ltd., 271 Joo Chiat Place,  Singapore 427952 

In-app Me → Help → Privacy request 

We acknowledge privacy requests within 10 business days and respond substantively  within 30 days, or tell you within that period when we will respond. 

  1. Personal data we collect 

3.1 Data you provide 

Category Examples Why we need it 

Identity Full name, date of birth, gender,  nationality, profile photograph 

Account creation; verifying you  are who you say you are;  

confirming legal age for regulated  work 

Government  identifiers 

NRIC/FIN number, work pass  number, passport details where  applicable 

Verifying your legal right to work  and your identity to the standard  our Clients and the law require  (see clause 4) 

Contact Email, mobile number, address,  emergency contact 

Work profile Skills, certifications (e.g. food  hygiene, first aid), qualifications,  

experience, availability, shift  

preferences, languages, uniform  

sizing 

Student status Institution, enrolment status  where you rely on a student  

category 

Financial Bank account or PayNow details,  payment history, tax reference  

where applicable 

Shift communications; safety and  next-of-kin contact 

Matching you to suitable shifts 

Verifying eligibility for particular  engagements 

Paying you; statutory record keeping 

Engagement  records 

Shifts accepted, declined and  completed, clock-in/clock-out  records, hours, breaks, fees,  cancellations, no-shows 

Performing the contract;  calculating payment; resolving  disputes 

Performance Client ratings and feedback,  incident reports, coaching  

records, complaints 

Communications In-app messages, emails, support  tickets, and where recorded, calls  

(you will be told at the start of a  

recorded call) 

Quality assurance; safety;  matching 

Support; training; evidence in  disputes

Category Examples Why we need it 

Media you choose  to upload 

Photographs, video, voice notes Profile display; verification;  incident evidence 

3.2 Data collected automatically 

Device identifiers, device model and operating system, app version, IP address, browser  type, language, crash and diagnostic logs, in-app activity (pages viewed, features used,  timestamps), and approximate location derived from IP address. 

3.3 Location data 

We collect precise location only in defined circumstances

  • when you clock in or out of a booked shift, to confirm attendance at the venue (a  single geofence check, not a continuous track); 
  • while an in-shift safety feature that you have activated is running; • when you use in-app directions to a venue. 

We do not track your location outside a booked shift window, and we do not track  your location in the background. You can withdraw location permission in your device  settings; if you do, you will need to use an alternative attendance method and some  features will not work. 

3.4 Data from third parties 

We do receive personal data about you from others, namely: 

  • Clients — attendance confirmations, ratings, feedback, incident and complaint  reports; 
  • Identity and background verification providers — verification results (see  clause 4); 
  • Educational institutions — confirmation of student status, where you rely on it  and have consented; 
  • Social login providers (Google, Facebook) — where you register using a social  account, we receive your name, email address, provider account identifier and  profile picture. We do not request or store your contacts or friends list; 
  • Payment providers and banks — payment status, failures and returned transfers; • Referees you nominate — reference information; 
  • Government agencies — where required or permitted by law. 

3.5 Data we ask you not to provide 

Please do not upload information about your race, religion, political views, sexual  orientation, trade union membership, or detailed health information, unless we specifically  ask for it for a stated purpose (for example, an accessibility adjustment, a dietary or  allergy-related requirement, or a fitness-to-work confirmation for a safety-critical role).  We do not use protected characteristics to rank, match or select Workers.

  1. NRIC, FIN and identity documents 

We handle national identification numbers in line with the PDPC’s Advisory Guidelines on  the Personal Data Protection Act for NRIC and Other National Identification Numbers

  • We collect your NRIC/FIN number because it is necessary to verify your identity to  a high degree of fidelity and to confirm your legal entitlement to work in Singapore  — a matter for which we and our Clients bear legal responsibility, including under  the Employment of Foreign Manpower Act 1990. 
  • We may ask you to upload an image of your identity document for a one-off  verification check. Verification images are deleted or irreversibly redacted once  verification is complete or within 30 days, whichever is earlier, unless we are  required to retain them. 
  • Your NRIC/FIN is masked in the Platform interface and is not used as your  account identifier or login. 
  • We disclose your NRIC/FIN to a Client only where the Client is legally required to  record it (for example, for site access control at a licensed or secured premises, or  for its own statutory records) and only to the extent required. 
  • We will not use your NRIC/FIN for marketing, analytics or profiling. 5. Why we use your personal data, and our legal basis 

Under the PDPA we may process personal data with consent, with deemed consent, or  under a statutory exception. The table below maps each purpose to its basis. 

Purpose Basis under the PDPA 

Creating and administering your account;  authentication 

Matching you to shifts; sending shift offers,  confirmations and reminders 

Disclosing a limited profile to a Client so it can  decide whether to accept your offer to work Verifying identity, age and right to work; verifying  certifications and student status 

Recording attendance, hours and breaks;  calculating and making payment 

Consent; deemed consent by  contractual necessity (s. 15) Deemed consent by contractual  necessity (s. 15) 

Consent; deemed consent by  contractual necessity 

Consent; legal obligation; legitimate  interests (First Schedule, Part 3) Deemed consent by contractual  necessity; legal obligation 

Statutory record-keeping, tax and accounting Legal obligation (First Schedule) 

Safety, incident management and emergency  response 

Fraud prevention, investigation of misuse, GPS spoofing and proxy clock-in detection, account  security 

Legitimate interests; vital interests  (First Schedule, Part 1) 

Legitimate interests (First  Schedule, Part 3) 

Handling disputes, complaints and legal claims Legitimate interests; legal  proceedings exception

Purpose Basis under the PDPA 

Support, training and quality assurance (including  reviewing recorded calls) 

Improving and developing the Platform, including  analytics and model development 

Sending marketing about Giggle products, events  and promotions 

Using your image or testimonial in Giggle  marketing 

Deemed consent by contractual  necessity; legitimate interests Business improvement exception (First Schedule, Part 5) 

Express opt-in consent; DNC checked where applicable 

Separate express opt-in consent,  revocable at any time 

Business transfers (merger, acquisition, financing) Business asset transaction exception  (First Schedule, Part 2) 

Where we rely on legitimate interests, we have assessed and documented that the benefit  to Giggle, our Clients, other Workers or the public outweighs any adverse effect on you. A  summary of that assessment is available from the DPO on request. 

  1. Automated processing, matching and ranking 

The Platform uses automated processing to shortlist and rank Workers for shifts. The  signals used are: skills and certifications you have listed, verified experience,  availability, proximity to the venue, past completion and punctuality history,  cancellation and no-show history, and Client ratings. 

  • We do not use race, religion, nationality (except where a legal right-to-work  requirement applies), gender, age (except where a legal minimum applies), marital  or family status, or disability as ranking signals. 
  • Ranking affects the order and frequency in which shifts are offered to you. It does  not by itself remove you from the Platform. 
  • Decisions with a significant effect on you — suspension, removal from the  Platform, withholding of payment, or a finding of misconduct — are not made  solely by automated means. A person reviews them. 
  • You may ask us to explain the main factors affecting your ranking, and you may ask  a person to review an automated outcome, by contacting the DPO. 

We follow the principles of the PDPC/IMDA Model AI Governance Framework, including  maintaining human oversight, documenting our models and testing for unintended bias. 

  1. Who we share personal data with 

Recipient What is shared Why 

Clients / Principals you offer to work for 

Name, profile photo, relevant skills and  certifications, verified right-to-work  status (yes/no), shift history relevant  to that Client, attendance records,  emergency contact for the duration of  the shift 

So they can assess your  offer, admit you to site,  supervise safely and  confirm hours

Recipient What is shared Why 

Identity, right-to work and background  verification providers Payment service  

providers and banks Cloud hosting, IT,  security and  

communications  vendors 

Analytics and crash reporting providers 

Identity data, document images,  NRIC/FIN 

Name, bank/PayNow details, payment  amounts 

Data necessary for hosting, sending  notifications and securing the Platform 

Device and usage data, pseudonymised  where possible 

Verification 

Paying you 

Operating the Platform 

Reliability and  

improvement 

Insurers and brokers Incident details Claims 

Professional advisers (lawyers, accountants,  auditors) 

Educational  

institutions 

Government agencies,  regulators, law  

enforcement and  courts 

Acquirers, investors  and their advisers 

As necessary Advice, audit, claims 

Name and enrolment identifiers Student status  verification, with  

consent 

As required Legal obligation,  investigations,  

proceedings 

As necessary, under confidentiality Business transactions 

Other Workers can see only what you choose to display where the Platform provides a  shared-team feature (for example, first name and profile photo of colleagues on the same  shift). 

We do not sell personal data, and we do not share personal data with advertisers,  advertising networks or data brokers for their own marketing purposes. 

Our vendors are bound by written contracts requiring them to process personal data only  as we instruct, to protect it, and to return or delete it. Where a vendor processes data for its  own separate purposes, it does so as an independent organisation under the PDPA and its  own privacy policy applies. 

  1. Transfers outside Singapore 

Some recipients are located outside Singapore (currently expected to include the United  States, the European Union, Australia, Malaysia and India). Before transferring  personal data overseas we take steps required by section 26 of the PDPA and Part 3 of  the Personal Data Protection Regulations 2021 to ensure the recipient is bound to  provide a standard of protection comparable to the PDPA, by:

  • imposing legally binding contractual obligations on the recipient; • relying on a recipient’s binding corporate rules or a recognised certification (for  example, APEC CBPR/PRP) where applicable; or 
  • relying on your consent, having informed you of the reduced protection, or another  lawful basis under the Regulations. 

A current list of recipient jurisdictions is available from the DPO on request. 

  1. Cookies and similar technologies 

Type Purpose Can you refuse? 

Strictly necessary Login, session security, load  balancing, fraud prevention 

Preference Language, saved filters, display  settings 

Analytics / performance Understanding feature usage,  diagnosing crashes 

No — the Platform will not  function 

Yes 

Yes 

Marketing / measurement  (website only) 

Measuring the effectiveness of  Giggle’s own campaigns 

Yes — off by default; opt in via the cookie banner 

You can manage non-essential cookies through our cookie banner and through your  browser or device settings. Mobile advertising identifiers can be reset or limited in your  device settings. We do not currently respond to browser “Do Not Track” signals, as no  uniform standard exists. 

  1. How long we keep personal data 

We keep personal data only as long as necessary for the purpose for which it was collected,  or as required by law. Our retention schedule is: 

Category Retention period 

Active account data For the life of the account 

Account data after closure  or deactivation 

90 days reactivation window, then deleted or anonymised,  subject to the rows below 

Identity verification images Deleted on completion of verification, or within 30 days 

Right-to-work verification  records (result, not  

images) 

Engagement, attendance  and payment records 

Records relevant to a  dispute, claim, incident or  investigation 

5 years from the last engagement 

5 years from the end of the financial year to which they  relate (Income Tax Act 1947); employment-type records as  required by the Employment Act 1968 and its Regulations Until resolved, then 6 years (Limitation Act 1959) 

Workplace incident and as required by the Workplace Safety and Health Act 2006 

Category Retention period safety records and its Regulations 

Marketing consent and  DNC evidence 

Server, security and access  logs 

For the duration of the consent plus 2 years 12 months 

Recorded calls 6 months, or until a related dispute is resolved 

When retention is no longer required we delete or anonymise the data. Where deletion is  not immediately possible (for example, data in encrypted backups), we isolate it from  further processing until deletion occurs. 

  1. How we protect personal data 

We maintain reasonable security arrangements appropriate to the sensitivity of the data, as  required by section 24 of the PDPA, including: encryption in transit and at rest; role-based  access controls and least-privilege access; multi-factor authentication for administrative  accounts; NRIC masking; audit logging; vendor security due diligence; secure development  practices and periodic testing; staff training and confidentiality obligations; and an incident  response plan. 

No system can be guaranteed to be completely secure. You must keep your login  credentials confidential, use a unique password, enable available security features, and tell  us immediately if you suspect unauthorised access. Sharing your account with another  person is prohibited and may compromise your data as well as breaching our Terms. 

  1. Data breaches 

We assess suspected data breaches promptly and, in any event, within 30 days of  becoming aware of them. Where a breach is notifiable under Part VIB of the PDPA — that  is, where it results in, or is likely to result in, significant harm to affected individuals, or is  of a significant scale (500 or more individuals) — we will: 

  • notify the Personal Data Protection Commission as soon as practicable and in any  case within 3 calendar days of determining that the breach is notifiable; and • notify affected individuals as soon as practicable, unless an exception applies (for  example, where we have taken remedial action that renders significant harm  unlikely, or where technological protection such as encryption makes the data  unintelligible, or where a prescribed law enforcement or regulatory direction  applies). 

Our notification will describe the breach, the data affected, what we have done, and what  you can do. 

  1. Your rights and choices 

Right How it works

Right How it works 

Access You may ask what personal data we hold about you and how it has  been used or disclosed in the past year. We respond within 30 days  

or tell you when we will. We may charge a reasonable fee for access,  

and will give you a written estimate first. 

Correction You may ask us to correct an error or omission. We will correct it  unless we are satisfied on reasonable grounds that correction  

should not be made, and we will send the correction to  

organisations we disclosed the data to in the past year (unless they  

do not need it). 

Withdraw consent You may withdraw consent for any processing that relies on  consent, with reasonable notice. We will tell you the likely  

consequences — for most Workers, withdrawing core consents  

means we can no longer offer shifts, and your account will be  

closed. 

Opt out of  

marketing 

Object to a ranking  outcome / request  human review 

Deactivate or  

delete your account 

Use the unsubscribe link, reply STOP to SMS, change your in-app  preferences, or email the DPO. Service messages about your shifts,  payments, safety and legal terms will continue. 

Contact the DPO (clause 6). 

In the app: Me → Delete Account → Yes. Deactivation hides your  profile; deletion removes your data subject to the retention  schedule in clause 10. 

Limits. We may refuse an access request in the circumstances set out in the Fifth and Sixth  Schedules to the PDPA, including where the data is opinion data kept solely for an  evaluative purpose (for example, an assessment of your suitability for a role), where  disclosure would reveal personal data about another individual, where legal privilege  applies, or where disclosure could reasonably be expected to threaten the safety of another  individual. If we refuse, we will tell you why. 

  1. Marketing, calls and messages 
  • Marketing emails, SMS and push notifications are sent only with your consent, and  you can withdraw it at any time. 
  • Before sending marketing messages, faxes or voice calls to a Singapore telephone  number we check the relevant registers of the Do Not Call Registry under Part 9 of  the PDPA, unless you have given us clear and unambiguous consent in evidential  form or another exemption applies (such as an ongoing relationship for related  messages). 
  • All marketing messages identify Giggle and include a functioning unsubscribe  facility, as required by Part 9 of the PDPA and the Spam Control Act 2007.
  • Operational messages — shift offers, confirmations, cancellations, payment notices,  safety alerts and changes to legal terms — are not marketing and will continue  while your account is open. 
  1. Age 

The Platform is intended for people aged 16 and over, consistent with clause 2.2 of our  Worker Terms & Conditions. Certain hospitality work, including work involving the service  or handling of liquor and work during certain hours, is restricted by law for persons under  18, and we do not offer such Shifts to workers under that age. We do not knowingly collect  personal data from anyone under 16. If you believe a person under 16 has provided us with  personal data, contact the DPO and we will remove it.  

  1. Third-party sites and services 

The Platform may link to third-party websites and services that we do not control. We are  not responsible for their content, security or privacy practices, and this Policy does not  apply to them. Please review their policies before providing personal data. 

Our use of information received from Google APIs adheres to the Google API Services  User Data Policy, including the Limited Use requirements. 

  1. Complaints 

If you are concerned about how we have handled your personal data, contact the DPO first.  We will acknowledge within 10 business days and aim to resolve the matter within 30  days. If you remain dissatisfied you may complain to the Personal Data Protection  Commission (www.pdpc.gov.sg), which may also review certain of our decisions on access  and correction requests under section 48H of the PDPA. 

  1. Changes to this Policy 

We may update this Policy. We will post the updated version with a new version number  and effective date. For changes that materially affect how we use your personal data, we  will give you at least 14 days’ advance notice by email or in-app notification, and where the  change introduces a new purpose requiring consent, we will seek your consent separately. 

  1. Governing law 

This Policy is governed by the laws of the Republic of Singapore. Nothing in it limits your  rights under the PDPA or any other applicable data protection law. Disputes are subject to  the exclusive jurisdiction of the Singapore courts.

Stay In Touch

Get started with our AI-powered staffing solutions for hotels—reliable, hassle-free, and tailored to streamline your workforce.

Stay In Touch

Get started with our AI-powered staffing solutions for hotels—reliable, hassle-free, and tailored to streamline your workforce.