Privacy policy
What we collect, why we have it, who else sees it, and what you can ask us to do.
Who is responsible
beemate.sg is operated by [OPERATOR NAME], [UEN], [ADDRESS], Singapore, which is the organisation responsible for the personal data described here under the Personal Data Protection Act 2012 (PDPA).
Our Data Protection Officer can be reached through the contact form. As above, the operator is a placeholder until a company is incorporated.
What we collect
This is the complete list, taken from the database rather than from memory.
When you create an account
- your name and email address;
- a password, stored only as a one-way hash — we cannot read it, and neither can anyone who obtains the database;
- if you sign in with Google: the same name and address, your profile picture, and an identifier linking your beemate account to your Google one. We never receive your Google password;
- a handle, generated from your name. It is reserved to you and is not currently shown to other members;
- the date and version of the terms and privacy policy you accepted.
What you choose to add
- a profile photo, if you upload one — public;
- your date of birth — never shown to anyone;
- your phone number — never shown to anyone;
- your notification preferences.
From using the service
- the hives you open or join, and their history including seats you have left;
- messages you send, which the other person in that conversation can read;
- the email address you give for an invite, which the hive owner sees only once they have accepted you;
- notifications generated for you;
- a record of every automated email we send you — the template and the outcome, not the body;
- account events: when the account was created, when its profile changed, when a sign-in method was added, with the IP address and browser where we have them;
- your sessions: a token, expiry, IP address and browser.
What we deliberately do not collect
- Card or bank details. No payment is possible on beemate and no payment information is stored anywhere in the system.
- Identity documents and bank statements. The trust score mentions them, but no upload exists and nothing is held.
- Analytics and advertising data. There are no third-party trackers on this site.
Why we have it
- to create and secure your account, and to let you sign in;
- to show you to other members you deal with — your name, photo and trust score;
- to run hives: seats, requests, and the conversations attached to them;
- to email you about things that happen to your account — a confirmation, a password reset, a message — and to prove afterwards what we sent;
- to compute your trust score, which is derived from the above and never bought in;
- to answer you when you write to us;
- to detect and prevent abuse of the service.
We do not sell personal data, and we do not send marketing email. If that ever changes we will ask first, separately, and the Spam Control Act 2007 and the Do Not Call provisions of the PDPA will apply.
Consent, and taking it back
We rely on your consent, given when you create an account and when you choose to add something optional. You can withdraw it at any time by asking us to close your account.
Withdrawing consent means we can no longer provide the service to you. Some records are kept afterwards where the law requires it, or where they concern somebody else — a conversation, for instance, belongs to two people.
Who else sees it
Other members see only what the service is for: your name, photo, trust score, the hives you are in with them, and the messages you send them.
We use these service providers, each of which necessarily handles some of the data:
- Vercel — hosting and delivery of the site.
- Neon — the database, hosted in Singapore.
- Resend — sending automated email.
- Google — only if you choose to sign in with Google.
- Twilio — configured for phone verification, which is not currently switched on for Singapore numbers.
We may also disclose data where the law requires it, or to establish or defend a legal claim.
Where it is held
The database is hosted in Singapore. The providers above operate internationally, so some data — an email in transit, a request served from a nearby data centre — is processed outside Singapore.
Under section 26 of the PDPA we are required to ensure comparable protection where data leaves Singapore. That is done through the contractual terms of the providers above. The adequacy of those arrangements is one of the things a lawyer should check before this draft becomes final.
How long we keep it
- your account and profile: until you close the account;
- hives, seats and their history: while the hive exists. Deleting a hive deletes its conversations with it;
- the record of emails sent to you, and account events: kept after closure, with your identity detached, so we can answer questions about what happened;
- sessions: until they expire or you sign out;
- messages sent through the contact form: until the matter is closed.
Security
The site is served over HTTPS. Passwords are hashed, never stored in a readable form. Credentials an owner shares with their hive are encrypted before being written to the database and are shown only to that hive's accepted members.
Two things you should know rather than assume. Encryption protects the database, not a compromised server — any system that can show a password to a member also holds the means to read it. And beemate is a preview built by one person: it has not been penetration tested, and it does not yet limit how often sign-in can be attempted.
Your rights
Under the PDPA you may ask us to:
- tell you what we hold about you and how it has been used in the past year;
- correct anything inaccurate — most of it you can edit yourself under Personal details;
- withdraw your consent, which means closing your account.
Write to us through the contact form. We will respond within 30 days, or tell you why we need longer.
You may also complain to the Personal Data Protection Commission of Singapore. We would rather you told us first.
Children
beemate is not for anyone under 16, and the date of birth field refuses one. If we learn that an account belongs to a child we will close it and delete what we hold.
Cookies
beemate sets one cookie: the one that keeps you signed in. It is removed when you sign out or when it expires.
There are no analytics cookies, no advertising cookies, and no third-party trackers, which is why the site does not greet you with a consent banner. Blocking the sign-in cookie in your browser will prevent you from signing in.
Changes
Material changes will be notified to the address on your account, and the version stamp at the top of this page will change with them.