Legal · PDPA Compliant

Privacy Policy

Effective Date: 20th June 2026

PDPA Compliance: SharedOut is committed to handling your personal data appropriately in accordance with Singapore's Personal Data Protection Act 2012 (PDPA) and other relevant laws and regulations.

I. Preamble and Applicability

Greetings and welcome to SharedOut! (hereinafter referred to as the “SharedOut” or “Platform”). This is the Privacy Policy (“Policy”) that applies to all products and services provided to you by SharedOut (collectively referred to as “the Services”). In the event that a specific product or service provided to you is accompanied by a separate privacy policy or similar legal document, such separate document shall prevail.

The Platform is maintained by Aishin Tech Pte Ltd. (Company Registration No. 201701719W), a private limited company incorporated under the laws of the Republic of Singapore with its registered office address at 21 Merryn Terrace S298427 (“Company”, “we,” “our” or “us”).

To provide the Services to you (“you” and “your”), during your registration, login, browsing, and use of the Platform's services or tools we will, based on this Policy, collect, store, use, process, transmit, disclose, and delete relevant data. This Policy describes:

  • What Personal Data we collect;
  • Why and how it is collected;
  • How it is used, protected, and shared (with third parties if relevant); and
  • How you may exercise your rights concerning your Personal Data.

We place great importance on protecting your personal data and privacy rights. The Platform is committed to handling your personal data appropriately in accordance with Singapore's Personal Data Protection Act 2012 (“PDPA”) and other relevant laws and regulations.

This Policy does not apply to services provided to you by other third parties. The processing and protection of your information by such third parties shall be governed by their respective privacy policies or similar documents. We assume no responsibility for the privacy practices or the collection, use, or disclosure of personal data by any third party. Where the Services involve or integrate third parties (including but not limited to Google Cloud, Firebase and Stripe), the applicable terms and conditions and privacy policies of such third parties shall apply directly between you and the relevant third party.

Before clicking “Agree” and starting to use the Platform's services, please carefully read through this Policy. By clicking to agree or by using the services, you consent to the collection, storage, use, disclosure and other uses and processing of your personal data by us in accordance with this Policy and you are deemed to have understood and accepted all terms of this Policy. In addition to this Policy, we may also, under certain circumstances, inform you of the purposes and scope of our collection, use, and disclosure of your personal data through instant notifications (including pop-up windows, page prompts, etc.) and feature update notes. These instant notifications and feature update notes constitute an integral part of this Policy and hold equal validity.

This Policy applies only to individual users (whether accessing the Platform on their own behalf, or on behalf of other individuals or corporate entities) and not to corporate users.

II. Terms and Definitions

  • Platform Entity/Platform: Refers to the SharedOut Mobile App Platform, including its website, client applications, and all future iterations of service formats.
  • Personal Data: Refers to information, whether factual or not, relating to an identified or identifiable natural person, who can be identified directly or indirectly from that information, or by combining the information with other information the organization possesses or is likely to have access to.
  • Corporate Client Information: Refers to the organizational details, contact information, business contracts, project description, etc., provided when the registered entity is a company, partnership, or institution.
  • Log Information: Includes access time, user ID, dialog ID, dialog content, as well as IP address, browser type, language preference, and access date and time.
  • De-identification: Refers to the process of processing personal data so that it cannot be used to identify a specific natural person without additional information.
  • Anonymization: Refers to the process of processing personal data so that a specific natural person cannot be identified with it, and the data cannot be restored to its original state.
  • Cookie: Refers to the Cookies and similar device identification technologies commonly used on the Internet to collect, identify, and store information about your access and use of the products.

III. Types of Information We Collect

This Platform collects only the minimum data necessary to achieve service objectives, adhering to the principles of legality, legitimacy, and necessity. We will collect information under the following categories:

a) Information Voluntarily Provided by Users

  • Registration Information: Personal data submitted during account registration, such as name, email address, and mobile phone number. For corporate clients, we may process relevant personal data including the position, contact number and other relevant personal data of your legal representative and designated contact person.
  • Real-Name Verification Materials: Personal credentials, ID photos, authorization letters, etc.
  • Information Required for Professional Services: The information you submit will be used to deliver services. Depending on the content of consultation, the personal data of involved parties may include, but not be limited to, names, nationality, place of residence, or other factual bases necessary for the service, as well as any supplementary documents or texts you upload.
  • Feedback Information: When using relevant services, you may provide appropriate ratings for the Services. We will collect your feedback to optimize the service experience.

b) Information Automatically Collected by the Platform

  • Log Information: Access time, IP address, browser type, and operating system.
  • Operational Behavior Data: Client access date and time, server access date and time, clicks, browsing, searches, AI module calling records, and other network information generated during your use of related services.
  • Cookies and Similar Technologies: Used for maintaining authentication status and preference settings.

c) Data Provided by Third Parties

We may obtain data related to you from third parties we collaborate with (e.g., third-party authentication service providers, payment platforms) for the purpose of identity verification, transaction processing, or other service-related functions.

IV. Purposes and Methods of Personal Data Use

We will only use your personal data in compliance with legal requirements and for the following legitimate purposes. We are committed not to use your personal data for any purposes unrelated to those listed below, unless we have obtained your prior consent or as otherwise stipulated by relevant laws.

  • Contractual Obligations — Service Provision and Delivery: To fulfil any contractual obligations that exist between us and you (our Terms of Use); where we provide you with the basic functions or services of the Platform.
  • Registration and Identity Verification: To create and manage your account, verify the authenticity of your identity, and prevent fraudulent registrations or account impersonation.
  • Payment and Settlement: To issue invoices, process payments, make settlements, and manage related fund transfers.
  • Data Analysis and System Optimization: To improve services, optimize system performance, and enhance user experience using anonymized data only within necessary scope.
  • Risk Identification and Platform Governance: To prevent, identify, detect, and investigate fraud or other risky behaviors, and to handle complaints, disputes, and security incidents.
  • Compliance and Regulatory Obligations: To comply with applicable laws, including Customer Due Diligence/Know Your Customer (“CDD”/“KYC”), sanctions screening, Anti-Money Laundering (“AML”), and Combating the Financing of Terrorism (“CFT”).
  • Other Specific Purposes (with consent): Such as marketing communications, product update notifications, or participation in surveys. You may withdraw such consent at any time.

V. Sharing, Transfer, and Disclosure of Personal Data

a) Entrustment

We may entrust the collection, use, disclosure, and/or processing of your personal data to authorized partners so that they may provide certain services or perform certain functions on our behalf for the purposes stated in this Policy. Authorized partners will only have access to the information necessary to perform their functions and must commit through contracts not to use the information for any other purposes.

b) Sharing

Except as set out below, we will never share your Personal Data for any purposes other than those strictly necessary for rendering the Services to you. We may share your personal data: with your explicit consent; as necessary for platform operations and compliance; as necessary for fulfilling an agreement to which you are a party; in compliance with legal obligations; and with partners for jointly provided services.

c) Transfer

To facilitate mergers, acquisitions, business asset transactions, or in connection with bankruptcy, dissolution, winding-up, or liquidation, we may disclose your user information to other organizations or individuals. All international transfers will comply with applicable data protection laws, with safeguards such as Standard Contractual Clauses (“SCCs”) implemented where required.

d) Disclosure

We will only publicly disclose your user information with your explicit consent, or where necessary to protect the personal and property safety of us, our users, or the public in accordance with applicable laws.

VI. Management of Personal Data

You can access and correct your basic information via “Personal Center” → “Account Settings”, or by contacting us using the contact details provided below. You may change or withdraw consent previously granted at any time; however, withdrawal will not affect processing based on previously given consent, and may result in us being unable to continue providing certain services.

For security reasons, you may be required to submit a written request or provide proof of identity. Pursuant to the PDPA, you may also request data portability — to receive your personal data in a structured, commonly used, and machine-readable format (e.g., JSON, CSV), or to transfer it to another organization where applicable and technically feasible.

VII. Protection and Storage of Personal Data

We implement reasonable physical, electronic, and administrative measures — including encryption technologies, access controls, disaster recovery protocols, and data backups — to safeguard user information against unauthorized access, disclosure, use, alteration, damage, or loss. Despite this, we cannot guarantee 100% security due to technological limitations and potential malicious attacks, so we advise you to use complex passwords and keep them confidential.

Our servers are located in Singapore. To provide our services, we may transfer your personal data to other countries where we or our third-party service providers conduct business, ensuring any cross-border transfer complies with the PDPA and that overseas recipients provide comparable protection standards. Generally, we retain your personal data for as long as you use the Platform to achieve the processing purposes described in this Policy, unless a longer retention period is required by applicable laws.

VIII. Protection of Minors' Information

This service is intended solely for users aged 18 or older, or those who have reached the legal age of majority under applicable laws. If you are the guardian of a minor and discover that we have unintentionally collected, used, or disclosed the minor's personal data, you may contact us using the contact information provided below, and we will delete or anonymize the relevant information after the necessary verification procedures.

IX. Advertisements

There may be advertisements of third party products and/or services displayed within this Platform. The Company shall not be responsible for your interactions with such third parties, including their platforms (if any), which are not subject to this Policy.

X. Updates and Modifications to This Policy

We may update this Policy and notify you via SMS or other appropriate means. In the event of significant changes, we will provide more prominent notifications (including SMS, email, in-site pop-ups, or homepage announcements) and, where required by law, obtain your consent. By continuing to use the Platform after an update, you acknowledge that you have fully read and accepted the revised terms.

XI. Dispute Resolution Mechanism and Governing Law

This Policy shall be governed by the laws of Singapore. All disputes shall first be attempted to be mediated internally between the Parties, and referred within seven (7) days to the Singapore Mediation Centre (“SMC”) if internal mediation does not work. If the dispute cannot be resolved by mediation within sixty (60) days of referral, it shall be submitted to the non-exclusive jurisdiction of the Courts of Singapore.

XII. Contact Information and Complaint Channels

If you have any questions or suggestions regarding this Policy or the protection of personal data, you may contact our dedicated Cybersecurity and Personal Data Protection Department:

  • Data Protection Officer (DPO): Matthew Lee
  • Email: support@sharedout.com.sg
  • Customer Service Hotline: +65 8473 8285
  • Address: 21 Merryn Terrace S298427

If you are dissatisfied with our response, particularly if you believe our processing of personal data has infringed upon your lawful rights and interests, you may lodge a complaint or report with the relevant regulatory authorities.