Legal
Privacy
Last updated:
ShiftMalam · UEN 53529156J
Sole proprietorship registered in Singapore
This page explains what happens to personal data when you visit shiftmalam.com or get in touch. It's written to meet Singapore's Personal Data Protection Act 2012 (PDPA), and I've tried to write it in plain English rather than boilerplate.
What this website collects
Nothing. This site has no accounts, no contact forms, no analytics, no advertising cookies, and no tracking pixels. It sets no cookies of its own. I do not know who visits, how many of you there are, or which pages you read.
If that ever changes, this page changes first.
Fonts
This site loads fonts from Google Fonts. That request tells Google your IP address and some browser details, under Google's own privacy policy rather than mine. It's the one third-party request on the site, and I'd like to remove it.
If you email or WhatsApp me
Then I see whatever you choose to send — typically your name, phone number or email address, and a description of your business problem. I use it to reply to you and to discuss and carry out the work. I do not add you to a marketing list, and I don't sell or share it.
WhatsApp is not private between us alone. Messages are carried by WhatsApp (Meta), and the fact that you contacted me, along with your number, is visible to them. If that matters for what you want to discuss, email instead — or ask and I'll suggest something better.
How long I keep it
- Enquiries that don't become projects — kept while we're talking and for up to 24 months after, then deleted. That's so I can pick up a conversation you left, not so I can chase you.
- Project correspondence and records — kept for the length of the engagement, then for as long as I'm required to keep business and accounting records in Singapore, which is five years.
- Anything you ask me to delete sooner — deleted, unless I'm legally required to keep it. See your rights below.
Where your information goes
I'm a one-person operation and I don't have my own data centre, so email and project data are handled by service providers, some of which are outside Singapore. Depending on the project that typically includes hosting and database providers such as Vercel and Supabase, email and font services from Google, and WhatsApp from Meta.
Under the PDPA's transfer limitation obligation I'm required to make sure any personal data sent overseas gets protection comparable to Singapore's. Where I choose the provider, that's what I select for. Where you choose the provider for your own project, I'll tell you plainly what I think of it.
Your rights under the PDPA
You can ask me to:
- Show you what personal data of yours I hold and how I've used it
- Correct anything that's wrong or out of date
- Withdraw your consent to me holding or using it, at any time
Write to the address below and I'll respond as soon as I reasonably can, and in any case within 30 days. If I genuinely can't meet that, I'll tell you when I can. There's no charge for a straightforward request. If I have to refuse part of a request — because it would reveal someone else's personal data, for example — I'll tell you why.
Withdrawing consent may mean I can't keep working on your project. I'll explain the consequences before acting on it, not after.
Data Protection Officer
The PDPA requires every organisation to appoint a Data Protection Officer and publish their contact details. For a one-person business, that person is me.
Reach the DPO at dpo@shiftmalam.com. Use that address for access, correction, withdrawal or complaint requests — it goes to a separate inbox from sales enquiries so nothing time-sensitive gets buried.
If you're not satisfied with how I handle a request, you can escalate to the Personal Data Protection Commission at pdpc.gov.sg.
If something goes wrong
If there's a data breach that's likely to cause you significant harm, or that affects a large enough number of people to be notifiable, I'll notify the Personal Data Protection Commission and tell you directly, as required under the PDPA. I'd rather tell you about a problem than have you find out elsewhere.
Client projects
When I build and run software for a client, the personal data inside that system — their guests, customers, applicants or staff — belongs to the client. They decide what's collected and why. In PDPA terms they are the organisation and I'm acting as a data intermediary processing it on their behalf, which means I'm responsible for protecting it and for not keeping it longer than needed.
The specifics for each project are set out in that project's agreement or NDA, not on this page. If your data sits in a system I built for someone else, your request should go to them — though you're welcome to contact me and I'll point you to the right party.
If you're in Malaysia
I work with businesses in Malaysia as well as Singapore. Where Malaysia's Personal Data Protection Act applies to a project, its requirements — including breach notification timelines and the appointment of a data protection officer contactable by the Malaysian authorities — are handled as part of that engagement. The DPO address above reaches me for Malaysian matters too.
Changes to this page
If this notice changes materially I'll update the date at the top. The version you agreed to at the time of an engagement is the one that governs that engagement.
Governing law
This notice is governed by the laws of Singapore.
Questions
General questions: hello@shiftmalam.com. Anything about your personal data: dpo@shiftmalam.com.