Privacy Policy
Zhong Yue Pte Ltd (Giggle Jobs)
Privacy Policy (Singapore)
Zhong Yue Pte. Ltd. (UEN: 202323760D) trading as Giggle Jobs Version: 2.1 · Effective date: 14th August 2026 · Last reviewed: 14th August 2026 · Supersedes: version 2.0 dated 27 July 2026
- About this Policy
Zhong Yue Pte. Ltd. (“Giggle”, “we”, “us”) operates the Giggle Jobs platform: our mobile application, our website at gigglejobsapp.com, the worker portal, the employer portal and our related systems (together, the “Platform”), through which hotels, restaurants, caterers and other hospitality businesses (“Clients” or “Principals”) engage part-time, casual and full-time hospitality workers (“Workers”).
This Policy explains how we collect, use, disclose, protect and retain personal data, and the rights available to you, under the Personal Data Protection Act 2012 (“PDPA”) and its subsidiary legislation.
It applies to Workers, jobseekers, Client representatives, website visitors and anyone who contacts us. It does not apply to how a Client uses your personal data once it has been provided to that Client for its own purposes — in that respect the Client is independently responsible under the PDPA and you should consult its privacy policy.
Our role. For most processing described here, Giggle is the organisation that decides the purposes of processing. In limited cases — for example, where we host attendance or rostering records on behalf of a Client and process them only on that Client’s instructions — we act as a data intermediary under section 4(2) of the PDPA, and the Client is the responsible organisation.
- Data Protection Officer and how to contact us
We have appointed a Data Protection Officer (“DPO”) in accordance with section 11(3) of the PDPA.
Data Protection Officer
Ashik
Email [email protected] General enquiries [email protected]
Post The Data Protection Officer, Zhong Yue Pte. Ltd., 271 Joo Chiat Place, Singapore 427952
In-app Me → Help → Privacy request
We acknowledge privacy requests within 10 business days and respond substantively within 30 days, or tell you within that period when we will respond.
- Personal data we collect
3.1 Data you provide
Category Examples Why we need it
Identity Full name, date of birth, gender, nationality, profile photograph
Account creation; verifying you are who you say you are;
confirming legal age for regulated work
Government identifiers
NRIC/FIN number, work pass number, passport details where applicable
Verifying your legal right to work and your identity to the standard our Clients and the law require (see clause 4)
Contact Email, mobile number, address, emergency contact
Work profile Skills, certifications (e.g. food hygiene, first aid), qualifications,
experience, availability, shift
preferences, languages, uniform
sizing
Student status Institution, enrolment status where you rely on a student
category
Financial Bank account or PayNow details, payment history, tax reference
where applicable
Shift communications; safety and next-of-kin contact
Matching you to suitable shifts
Verifying eligibility for particular engagements
Paying you; statutory record keeping
Engagement records
Shifts accepted, declined and completed, clock-in/clock-out records, hours, breaks, fees, cancellations, no-shows
Performing the contract; calculating payment; resolving disputes
Performance Client ratings and feedback, incident reports, coaching
records, complaints
Communications In-app messages, emails, support tickets, and where recorded, calls
(you will be told at the start of a
recorded call)
Quality assurance; safety; matching
Support; training; evidence in disputes
Category Examples Why we need it
Media you choose to upload
Photographs, video, voice notes Profile display; verification; incident evidence
3.2 Data collected automatically
Device identifiers, device model and operating system, app version, IP address, browser type, language, crash and diagnostic logs, in-app activity (pages viewed, features used, timestamps), and approximate location derived from IP address.
3.3 Location data
We collect precise location only in defined circumstances:
- when you clock in or out of a booked shift, to confirm attendance at the venue (a single geofence check, not a continuous track);
- while an in-shift safety feature that you have activated is running; • when you use in-app directions to a venue.
We do not track your location outside a booked shift window, and we do not track your location in the background. You can withdraw location permission in your device settings; if you do, you will need to use an alternative attendance method and some features will not work.
3.4 Data from third parties
We do receive personal data about you from others, namely:
- Clients — attendance confirmations, ratings, feedback, incident and complaint reports;
- Identity and background verification providers — verification results (see clause 4);
- Educational institutions — confirmation of student status, where you rely on it and have consented;
- Social login providers (Google, Facebook) — where you register using a social account, we receive your name, email address, provider account identifier and profile picture. We do not request or store your contacts or friends list;
- Payment providers and banks — payment status, failures and returned transfers; • Referees you nominate — reference information;
- Government agencies — where required or permitted by law.
3.5 Data we ask you not to provide
Please do not upload information about your race, religion, political views, sexual orientation, trade union membership, or detailed health information, unless we specifically ask for it for a stated purpose (for example, an accessibility adjustment, a dietary or allergy-related requirement, or a fitness-to-work confirmation for a safety-critical role). We do not use protected characteristics to rank, match or select Workers.
- NRIC, FIN and identity documents
We handle national identification numbers in line with the PDPC’s Advisory Guidelines on the Personal Data Protection Act for NRIC and Other National Identification Numbers.
- We collect your NRIC/FIN number because it is necessary to verify your identity to a high degree of fidelity and to confirm your legal entitlement to work in Singapore — a matter for which we and our Clients bear legal responsibility, including under the Employment of Foreign Manpower Act 1990.
- We may ask you to upload an image of your identity document for a one-off verification check. Verification images are deleted or irreversibly redacted once verification is complete or within 30 days, whichever is earlier, unless we are required to retain them.
- Your NRIC/FIN is masked in the Platform interface and is not used as your account identifier or login.
- We disclose your NRIC/FIN to a Client only where the Client is legally required to record it (for example, for site access control at a licensed or secured premises, or for its own statutory records) and only to the extent required.
- We will not use your NRIC/FIN for marketing, analytics or profiling. 5. Why we use your personal data, and our legal basis
Under the PDPA we may process personal data with consent, with deemed consent, or under a statutory exception. The table below maps each purpose to its basis.
Purpose Basis under the PDPA
Creating and administering your account; authentication
Matching you to shifts; sending shift offers, confirmations and reminders
Disclosing a limited profile to a Client so it can decide whether to accept your offer to work Verifying identity, age and right to work; verifying certifications and student status
Recording attendance, hours and breaks; calculating and making payment
Consent; deemed consent by contractual necessity (s. 15) Deemed consent by contractual necessity (s. 15)
Consent; deemed consent by contractual necessity
Consent; legal obligation; legitimate interests (First Schedule, Part 3) Deemed consent by contractual necessity; legal obligation
Statutory record-keeping, tax and accounting Legal obligation (First Schedule)
Safety, incident management and emergency response
Fraud prevention, investigation of misuse, GPS spoofing and proxy clock-in detection, account security
Legitimate interests; vital interests (First Schedule, Part 1)
Legitimate interests (First Schedule, Part 3)
Handling disputes, complaints and legal claims Legitimate interests; legal proceedings exception
Purpose Basis under the PDPA
Support, training and quality assurance (including reviewing recorded calls)
Improving and developing the Platform, including analytics and model development
Sending marketing about Giggle products, events and promotions
Using your image or testimonial in Giggle marketing
Deemed consent by contractual necessity; legitimate interests Business improvement exception (First Schedule, Part 5)
Express opt-in consent; DNC checked where applicable
Separate express opt-in consent, revocable at any time
Business transfers (merger, acquisition, financing) Business asset transaction exception (First Schedule, Part 2)
Where we rely on legitimate interests, we have assessed and documented that the benefit to Giggle, our Clients, other Workers or the public outweighs any adverse effect on you. A summary of that assessment is available from the DPO on request.
- Automated processing, matching and ranking
The Platform uses automated processing to shortlist and rank Workers for shifts. The signals used are: skills and certifications you have listed, verified experience, availability, proximity to the venue, past completion and punctuality history, cancellation and no-show history, and Client ratings.
- We do not use race, religion, nationality (except where a legal right-to-work requirement applies), gender, age (except where a legal minimum applies), marital or family status, or disability as ranking signals.
- Ranking affects the order and frequency in which shifts are offered to you. It does not by itself remove you from the Platform.
- Decisions with a significant effect on you — suspension, removal from the Platform, withholding of payment, or a finding of misconduct — are not made solely by automated means. A person reviews them.
- You may ask us to explain the main factors affecting your ranking, and you may ask a person to review an automated outcome, by contacting the DPO.
We follow the principles of the PDPC/IMDA Model AI Governance Framework, including maintaining human oversight, documenting our models and testing for unintended bias.
- Who we share personal data with
Recipient What is shared Why
Clients / Principals you offer to work for
Name, profile photo, relevant skills and certifications, verified right-to-work status (yes/no), shift history relevant to that Client, attendance records, emergency contact for the duration of the shift
So they can assess your offer, admit you to site, supervise safely and confirm hours
Recipient What is shared Why
Identity, right-to work and background verification providers Payment service
providers and banks Cloud hosting, IT, security and
communications vendors
Analytics and crash reporting providers
Identity data, document images, NRIC/FIN
Name, bank/PayNow details, payment amounts
Data necessary for hosting, sending notifications and securing the Platform
Device and usage data, pseudonymised where possible
Verification
Paying you
Operating the Platform
Reliability and
improvement
Insurers and brokers Incident details Claims
Professional advisers (lawyers, accountants, auditors)
Educational
institutions
Government agencies, regulators, law
enforcement and courts
Acquirers, investors and their advisers
As necessary Advice, audit, claims
Name and enrolment identifiers Student status verification, with
consent
As required Legal obligation, investigations,
proceedings
As necessary, under confidentiality Business transactions
Other Workers can see only what you choose to display where the Platform provides a shared-team feature (for example, first name and profile photo of colleagues on the same shift).
We do not sell personal data, and we do not share personal data with advertisers, advertising networks or data brokers for their own marketing purposes.
Our vendors are bound by written contracts requiring them to process personal data only as we instruct, to protect it, and to return or delete it. Where a vendor processes data for its own separate purposes, it does so as an independent organisation under the PDPA and its own privacy policy applies.
- Transfers outside Singapore
Some recipients are located outside Singapore (currently expected to include the United States, the European Union, Australia, Malaysia and India). Before transferring personal data overseas we take steps required by section 26 of the PDPA and Part 3 of the Personal Data Protection Regulations 2021 to ensure the recipient is bound to provide a standard of protection comparable to the PDPA, by:
- imposing legally binding contractual obligations on the recipient; • relying on a recipient’s binding corporate rules or a recognised certification (for example, APEC CBPR/PRP) where applicable; or
- relying on your consent, having informed you of the reduced protection, or another lawful basis under the Regulations.
A current list of recipient jurisdictions is available from the DPO on request.
- Cookies and similar technologies
Type Purpose Can you refuse?
Strictly necessary Login, session security, load balancing, fraud prevention
Preference Language, saved filters, display settings
Analytics / performance Understanding feature usage, diagnosing crashes
No — the Platform will not function
Yes
Yes
Marketing / measurement (website only)
Measuring the effectiveness of Giggle’s own campaigns
Yes — off by default; opt in via the cookie banner
You can manage non-essential cookies through our cookie banner and through your browser or device settings. Mobile advertising identifiers can be reset or limited in your device settings. We do not currently respond to browser “Do Not Track” signals, as no uniform standard exists.
- How long we keep personal data
We keep personal data only as long as necessary for the purpose for which it was collected, or as required by law. Our retention schedule is:
Category Retention period
Active account data For the life of the account
Account data after closure or deactivation
90 days reactivation window, then deleted or anonymised, subject to the rows below
Identity verification images Deleted on completion of verification, or within 30 days
Right-to-work verification records (result, not
images)
Engagement, attendance and payment records
Records relevant to a dispute, claim, incident or investigation
5 years from the last engagement
5 years from the end of the financial year to which they relate (Income Tax Act 1947); employment-type records as required by the Employment Act 1968 and its Regulations Until resolved, then 6 years (Limitation Act 1959)
Workplace incident and as required by the Workplace Safety and Health Act 2006
Category Retention period safety records and its Regulations
Marketing consent and DNC evidence
Server, security and access logs
For the duration of the consent plus 2 years 12 months
Recorded calls 6 months, or until a related dispute is resolved
When retention is no longer required we delete or anonymise the data. Where deletion is not immediately possible (for example, data in encrypted backups), we isolate it from further processing until deletion occurs.
- How we protect personal data
We maintain reasonable security arrangements appropriate to the sensitivity of the data, as required by section 24 of the PDPA, including: encryption in transit and at rest; role-based access controls and least-privilege access; multi-factor authentication for administrative accounts; NRIC masking; audit logging; vendor security due diligence; secure development practices and periodic testing; staff training and confidentiality obligations; and an incident response plan.
No system can be guaranteed to be completely secure. You must keep your login credentials confidential, use a unique password, enable available security features, and tell us immediately if you suspect unauthorised access. Sharing your account with another person is prohibited and may compromise your data as well as breaching our Terms.
- Data breaches
We assess suspected data breaches promptly and, in any event, within 30 days of becoming aware of them. Where a breach is notifiable under Part VIB of the PDPA — that is, where it results in, or is likely to result in, significant harm to affected individuals, or is of a significant scale (500 or more individuals) — we will:
- notify the Personal Data Protection Commission as soon as practicable and in any case within 3 calendar days of determining that the breach is notifiable; and • notify affected individuals as soon as practicable, unless an exception applies (for example, where we have taken remedial action that renders significant harm unlikely, or where technological protection such as encryption makes the data unintelligible, or where a prescribed law enforcement or regulatory direction applies).
Our notification will describe the breach, the data affected, what we have done, and what you can do.
- Your rights and choices
Right How it works
Right How it works
Access You may ask what personal data we hold about you and how it has been used or disclosed in the past year. We respond within 30 days
or tell you when we will. We may charge a reasonable fee for access,
and will give you a written estimate first.
Correction You may ask us to correct an error or omission. We will correct it unless we are satisfied on reasonable grounds that correction
should not be made, and we will send the correction to
organisations we disclosed the data to in the past year (unless they
do not need it).
Withdraw consent You may withdraw consent for any processing that relies on consent, with reasonable notice. We will tell you the likely
consequences — for most Workers, withdrawing core consents
means we can no longer offer shifts, and your account will be
closed.
Opt out of
marketing
Object to a ranking outcome / request human review
Deactivate or
delete your account
Use the unsubscribe link, reply STOP to SMS, change your in-app preferences, or email the DPO. Service messages about your shifts, payments, safety and legal terms will continue.
Contact the DPO (clause 6).
In the app: Me → Delete Account → Yes. Deactivation hides your profile; deletion removes your data subject to the retention schedule in clause 10.
Limits. We may refuse an access request in the circumstances set out in the Fifth and Sixth Schedules to the PDPA, including where the data is opinion data kept solely for an evaluative purpose (for example, an assessment of your suitability for a role), where disclosure would reveal personal data about another individual, where legal privilege applies, or where disclosure could reasonably be expected to threaten the safety of another individual. If we refuse, we will tell you why.
- Marketing, calls and messages
- Marketing emails, SMS and push notifications are sent only with your consent, and you can withdraw it at any time.
- Before sending marketing messages, faxes or voice calls to a Singapore telephone number we check the relevant registers of the Do Not Call Registry under Part 9 of the PDPA, unless you have given us clear and unambiguous consent in evidential form or another exemption applies (such as an ongoing relationship for related messages).
- All marketing messages identify Giggle and include a functioning unsubscribe facility, as required by Part 9 of the PDPA and the Spam Control Act 2007.
- Operational messages — shift offers, confirmations, cancellations, payment notices, safety alerts and changes to legal terms — are not marketing and will continue while your account is open.
- Age
The Platform is intended for people aged 16 and over, consistent with clause 2.2 of our Worker Terms & Conditions. Certain hospitality work, including work involving the service or handling of liquor and work during certain hours, is restricted by law for persons under 18, and we do not offer such Shifts to workers under that age. We do not knowingly collect personal data from anyone under 16. If you believe a person under 16 has provided us with personal data, contact the DPO and we will remove it.
- Third-party sites and services
The Platform may link to third-party websites and services that we do not control. We are not responsible for their content, security or privacy practices, and this Policy does not apply to them. Please review their policies before providing personal data.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- Complaints
If you are concerned about how we have handled your personal data, contact the DPO first. We will acknowledge within 10 business days and aim to resolve the matter within 30 days. If you remain dissatisfied you may complain to the Personal Data Protection Commission (www.pdpc.gov.sg), which may also review certain of our decisions on access and correction requests under section 48H of the PDPA.
- Changes to this Policy
We may update this Policy. We will post the updated version with a new version number and effective date. For changes that materially affect how we use your personal data, we will give you at least 14 days’ advance notice by email or in-app notification, and where the change introduces a new purpose requiring consent, we will seek your consent separately.
- Governing law
This Policy is governed by the laws of the Republic of Singapore. Nothing in it limits your rights under the PDPA or any other applicable data protection law. Disputes are subject to the exclusive jurisdiction of the Singapore courts.