Privacy Policy
1. Introduction
Sniff (“we”, “us”, or “our”) is a pet services marketplace operated by Joshua Tan (sole proprietor) in Singapore. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, and what rights you have under Singapore’s Personal Data Protection Act 2012 (“PDPA”).
This policy applies to all users of the Sniff mobile application, including pet owners (“customers”) and pet service providers (“shops”). By creating an account, you acknowledge that you have read and understood this Privacy Policy.
We process your data on the following bases:
- Deemed consent by contractual necessity — for data processing that is reasonably necessary to provide the service you have requested (such as your name, email, phone number, booking records, and transactional communications). You cannot withdraw consent for this processing while using the service, as it is necessary to operate your account and fulfil bookings.
- Explicit consent — for optional data processing (such as marketing communications and promotional push notifications). You may withdraw this consent at any time without affecting your ability to use the core service.
- Deemed consent by conduct — for aggregated product analytics, service improvement, and personalisation of your discovery feed. By using the app after being informed of these practices in this policy, you are deemed to have consented to this processing.
If you choose not to provide personal data that is necessary for the service, or if you withdraw consent for us to use it, we may not be able to provide some or all of the service to you.
Sniff is intended for users aged 18 and above. By using the app, you confirm that you are at least 18 years old. We do not knowingly collect personal data from individuals under 18. If we become aware that a user is under 18, we may disable or delete the account and associated personal data, unless we are required or authorised by law to retain it.
Key terms used in this policy:
- “Personal data” means data about an individual who can be identified from that data, as defined in the PDPA.
- “Shops” are pet service providers listed on Sniff.
- “Customers” are pet owners who use Sniff to discover and book pet care services.
- “Active bookings” are bookings with a status of Pending, Confirmed, or Ongoing.
- “Booking snapshot” is an immutable copy of key booking details (customer name, pet details including health information, package, and staff assignment) created at the time of booking.
This Privacy Policy should be read together with our Terms of Service, available in the app under Settings > Legal.
2. What We Collect
We collect information you provide directly, information generated through your use of the app, and limited technical data for diagnostics. Below is a summary of the data we collect, organised by category.
Required vs. optional data: Your name, email address, and phone number are required to create an account. Pet name, species, and breed are required to create a pet profile and make bookings. All other data is optional — if you choose not to provide optional data, you can still use the core service, but some features (such as location-based search) may be unavailable.
Conditionally shared data: If you provide optional data such as an emergency contact or pet health information (allergies, medical conditions), this data will be shared with shops during active bookings for your pet’s safety. You can update or remove this data at any time via your profile.
Account Information
- Name and email address (required for account creation)
- Phone number (Singapore mobile number, required for booking eligibility — verified via SMS one-time password)
- Password (securely hashed — never stored in plain text and not accessible to anyone, including Sniff staff)
- Postal code and street address (optional, used for location-based discovery)
- Profile photo and description (optional — visible to shops when you make bookings, and to other users if they view your reviews)
- Social link (optional — visible on your profile to shops and other authenticated users)
- Emergency contact name and number (optional — if provided, shared with shops during active bookings for your pet’s safety in emergencies)
Phone Verification
When you verify your mobile number, we collect and use records of verification attempts, message delivery status, and related technical information to authenticate your identity, prevent abuse, and troubleshoot delivery issues.
Pet Information
- Pet name, date of birth, gender, weight, and species (required for pet profile and bookings)
- Breed (used for breed-first discovery and search filtering)
- Profile photo and description (optional)
- Allergies and medical conditions (optional but encouraged — shared with shops during active bookings to ensure your pet receives safe and appropriate care. Also included in booking snapshots retained for dispute resolution.)
- Feeding habits (optional — shared with shops during daycare and boarding bookings for your pet’s daily care)
- Last vaccination date and sterilisation status (optional — used by shops to confirm service eligibility and safety protocols)
- Microchip number (optional, for pet identification)
You should provide accurate and up-to-date pet information, especially where the information may affect the safety of your pet or a shop’s ability to provide services.
Shop Information (for service providers)
- Business name, email, phone number, address, and operating hours
- Staff names, titles, photos, and working hours
- Service packages, pricing, and availability
- Business policies, AVS license, and grooming certification
Shop owners are responsible for ensuring they have obtained appropriate consent from their staff members before uploading staff information (names, titles, photos, and working hours) to Sniff. By uploading staff data, shop owners warrant that they have the authority and consent to do so. Sniff processes this information on behalf of the shop for the purpose of displaying the shop’s team to customers.
Staff members who wish to access, correct, or request deletion of their personal data displayed on Sniff may contact our Data Protection Officer at sniff.hq@gmail.com, or ask their shop owner to update the information directly in the app.
Booking Information
- Booking history including dates, times, status, price, and notes
- A booking snapshot — an immutable copy of your name, pet details (including name, species, breed, weight, allergies, and medical conditions), the booked package, and staff assignment, created at the time of booking. This snapshot is retained for booking history, dispute resolution, and business records. It is not updated when you change your current profile.
- Cancellation reasons and attribution
Location Data
- Postal code: when you enter your postal code, we send only the postal code to OneMap (a Singapore government service) to convert it into GPS coordinates for location-based search. The GPS coordinates derived from your postal code are stored on our servers to enable distance-based filtering. Your postal code and street address are not shared with shops.
- Device GPS: if you tap “Use my location”, we request a one-time GPS reading to detect your area. This reading is used on your device only and is not stored on our servers.
- Your location is generalised to a planning area (e.g., “Tampines”) for shop analytics. Only aggregated planning area statistics are visible to shops.
Loyalty & Preferences
- Loyalty points earned, spent, and your current balance
- Saved favourites (shops, packages, and media)
- Notification preferences and app settings
- Push notification token (a device identifier used to deliver booking updates and reminders to your device via Apple Push Notification service or Firebase Cloud Messaging)
Payment Information
- Subscription billing for shops is currently processed by Stripe (or another payment processor we may use in the future). Any replacement payment processor will be subject to equivalent payment-security and data-protection standards. Card details are entered directly into the payment processor’s secure payment form and never touch our servers. Stripe is PCI DSS compliant. We store only payment reference IDs, subscription status, billing cycle dates, and the last four digits of your card for display purposes.
Reviews
- Review text, star rating, and photos you upload
- Shop responses to your reviews
You are responsible for ensuring that your reviews and uploaded photos do not contain personal data of others (such as names, faces, or contact details) without their consent. We may review, moderate, or remove reviews and photos that contain personal data of third parties, that violate our Terms of Service, or that are otherwise inappropriate. If you report content containing your personal data without your consent, we will review and respond within 10 business days. If you believe a review or photo on Sniff contains your personal data without your consent, contact our Data Protection Officer to request its removal.
Analytics & Diagnostics
- Aggregated usage events (e.g., screens viewed, features used, search activity) to help us understand how the app is used and where users encounter issues. These events are identified by an internal user ID only and do not contain your name, email, phone number, or address. Where we provide shops with analytics insights, we use aggregated information and may apply minimum aggregation thresholds or other safeguards to reduce the risk that individuals can be identified.
- Crash and error reports to help us fix bugs and maintain app stability. These reports include technical information such as device model, operating system version, and error context. While we take steps to exclude personal information from these reports, some diagnostic data may contain personal data depending on the nature of the error and the information captured at the time.
On-Device Data
- Your login session is stored securely on your device using encrypted storage. Rate-limiting counters (e.g., sign-in attempts) are stored locally. This data is not sent to our servers.
Data About Other Individuals
If you provide personal data about another individual (such as an emergency contact name and number), you confirm that you have their consent or are otherwise authorised to share their data with us for the stated purpose. Emergency contacts or other individuals whose data appears on Sniff may contact our Data Protection Officer to access, correct, or request removal of their data.
3. How We Use Your Data
We use your personal data for the following purposes:
- To create and manage your account (deemed consent — contractual necessity)
- To facilitate bookings between pet owners and service providers, including scheduling, confirmation, reminders, and status updates (deemed consent — contractual necessity)
- To send transactional communications — booking confirmations, status changes, appointment reminders, and account-related emails (deemed consent — contractual necessity)
- To enable breed-first discovery — matching pet owners with groomers, daycare, and boarding providers based on breed compatibility (deemed consent — contractual necessity)
- To power location-based search — showing shops near your area using your postal code (deemed consent — contractual necessity)
- To personalise your experience — your pet breeds influence which content appears in the discovery feed (deemed consent by conduct)
- To provide shops with aggregated insights — such as how many profile views came from each planning area. Your individual identity is never disclosed to shops through analytics. (deemed consent by conduct)
- To track and manage your loyalty points (deemed consent — contractual necessity)
- To improve our service — aggregated analytics help us identify where users drop off, which features are used, and where the app needs improvement (deemed consent by conduct)
- To maintain security and prevent abuse — we use technical data such as login timestamps and request patterns for rate limiting (preventing excessive login attempts and API abuse), fraud detection (identifying suspicious account activity), and error monitoring (diagnosing and fixing technical issues) (deemed consent — contractual necessity)
- To provide customer support and respond to your queries (deemed consent — contractual necessity)
- To respond to complaints, disputes, and claims relating to bookings or the service (deemed consent — contractual necessity)
- To comply with legal, regulatory, tax, accounting, and record-keeping obligations (required or authorised by law)
- To enforce our Terms of Service and policies (deemed consent — contractual necessity)
- To send marketing communications — only with your explicit opt-in consent, and you can opt out at any time (explicit consent)
- To support a merger, acquisition, restructuring, financing, sale of assets, or similar corporate transaction involving Sniff (as required or authorised by law, or with appropriate notice)
We never sell your personal information to third parties.
4. Who We Share Your Data With
Within Sniff
- During active bookings (Pending, Confirmed, or Ongoing), shops can see your name, phone number, emergency contact (if provided), and your pet’s details including health information. This is necessary for service delivery and your pet’s safety. Shops that receive your personal data through bookings are bound by our Terms of Service, which require them to use your data only for the purposes of the booked service and to keep it confidential.
- After a booking ends, shops can no longer access your phone number, emergency contact, or your current pet profile. They retain the booking snapshot, which includes your name and pet details (including allergies and medical conditions) as they were at the time of booking, for their business records. See Section 6 for retention periods.
- Your reviews and ratings are publicly visible to all users.
- Your street address and postal code are not shared with shops. Only aggregated planning area statistics (e.g., “12 profile views from Tampines”) are visible to shops.
Third-Party Service Providers
We use trusted third-party services to operate Sniff. These providers act as data intermediaries or processors on our behalf. We maintain agreements with these providers that include obligations regarding purpose limitation, data security, retention, and breach notification. These providers are:
- Supabase (Sydney, Australia) — database hosting, user authentication, file storage, and serverless functions. Processes all user account data, booking records, and uploaded files.
- Stripe (global infrastructure) — subscription billing for shops. Card details are handled directly by Stripe and never pass through our servers. Stripe is PCI DSS compliant.
- Sentry (Iowa, USA) — crash and error monitoring. Reports include technical diagnostic information (device model, OS version, error context). While we take steps to exclude personal information, some reports may contain personal data depending on the nature of the error.
- PostHog (Virginia, USA) — aggregated product analytics. Events are identified by an internal user ID only and contain no names, emails, phone numbers, or addresses.
- Expo (USA) — push notification delivery to your device via Apple Push Notification service (APNs) and Firebase Cloud Messaging (FCM)
- OneMap (Singapore) — a Singapore government service. We send your postal code (only) to OneMap to convert it into GPS coordinates for location-based search. While postal codes are public geographic identifiers in Singapore, we treat the association between your postal code and your Sniff account as personal data and protect it accordingly. OneMap’s data handling is governed by Singapore government data policies.
- Twilio (global infrastructure) — SMS delivery for phone number verification
- Resend (USA) — transactional email delivery (booking confirmations, account emails)
This list reflects our current service providers as of the effective date. If we add new service providers that process personal data in materially different ways, or transfer data to new countries, we will update this policy and notify you in accordance with Section 13.
Other Disclosures
- We may disclose your data where required or authorised by law, regulation, court order, government authority, law enforcement request, or legal process.
- We may disclose your data where reasonably necessary to protect the rights, safety, or property of Sniff, our users, pets, shops, or the public; to investigate suspected fraud, abuse, security incidents, or policy violations; to enforce our Terms of Service; or to seek legal advice.
- In the event of a merger, acquisition, restructuring, financing, sale of assets, or similar corporate transaction, your data may be disclosed to or transferred to the relevant parties and their advisers, subject to confidentiality obligations and applicable law. Any such disclosure will be limited to what is reasonably necessary for the transaction. Where required, we will notify you of material changes affecting the handling of your personal data.
5. Where Your Data Is Stored
Our primary database is hosted in Sydney, Australia (Supabase). Analytics services are hosted in the United States (PostHog in Virginia, Sentry in Iowa). Communication services (Expo, Resend) and SMS services (Twilio) are hosted in the United States and globally.
Under PDPA Section 26, we take steps to ensure your personal data receives a comparable standard of protection when transferred overseas. We do this by:
- Using service providers that maintain industry-standard security certifications and data protection commitments (such as SOC 2 compliance, encryption at rest and in transit, and access controls)
- Ensuring our agreements with these providers include obligations to protect your data in accordance with applicable data protection standards
For a summary of each provider’s location and the data they process, see Section 4 (Third-Party Service Providers).
6. How Long We Keep Your Data
We retain your data only as long as necessary for the purposes described in this policy:
- Account data (name, email, phone, address): retained while your account is active. After you delete your account, it is soft-deleted immediately (hidden from all users) and permanently removed after 30 days.
- Pet data: deleted when your account is permanently removed (cascading deletion).
- Booking records: retained while either the customer or shop account is active. Regardless of account status, booking records are permanently deleted or anonymised no later than 7 years from the date of the booking. This period covers Singapore’s standard limitation periods for contractual claims and tax record-keeping requirements.
- Booking snapshots (containing your name and pet details at booking time): retained as part of the booking record. If you delete your account, the booking snapshot on the other party’s records is retained for their business records and dispute resolution, subject to the same 7-year maximum retention period from the date of the booking.
- Reviews: after account deletion, your name is removed from your reviews, but the review text, rating, and any photos remain visible. If a review still identifies you or another individual after anonymisation, you or the identified person may request its removal by contacting our Data Protection Officer. Before deleting your account, you may delete individual reviews in the app if you wish to remove them entirely. After your account is deleted, you may still contact our Data Protection Officer at sniff.hq@gmail.com to request removal of specific reviews.
- Analytics raw logs: automatically deleted after 90 days. Aggregated summaries (containing no personal information) are retained indefinitely.
- Error and diagnostic reports: retained for up to 90 days for error investigation and service stability, after which they are automatically deleted. Where error reports may contain personal data, access is restricted to authorised personnel for debugging purposes only.
- Payment records: we retain payment reference IDs, subscription status, billing cycle dates, and the last four digits of your card for the duration of your account and as required by applicable tax and accounting laws (currently 5 years under IRAS requirements). Full card details are never stored on our servers.
- Authentication audit logs (login events, verification attempts): retained while your account is active and during the 30-day deletion grace period for security and fraud prevention purposes. These logs are permanently deleted when your account is permanently removed, unless retention is required for an ongoing investigation or legal proceeding.
7. Your Rights
Under Singapore’s Personal Data Protection Act 2012, you have the following rights:
Access
You may request a copy of the personal data we hold about you, as well as information about how your data has been used or disclosed within the past 12 months, by contacting our Data Protection Officer. We will respond within 30 days, subject to applicable exceptions under the PDPA.
Access requests should be submitted in writing (email is acceptable). We may need to verify your identity before processing your request. We may charge a reasonable fee for access requests where permitted by the PDPA, and we may decline requests that are frivolous, repetitive, or where exceptions under the PDPA apply. In such cases, we will explain the reason for our decision.
Correction
You can update most of your personal data directly in the app (profile, pet details, address, phone number). For data you cannot edit yourself, contact our Data Protection Officer. Where we have disclosed corrected data to other organisations within the past 12 months, we will send the corrected data to those organisations unless it is not necessary for legal or business purposes. Note that booking snapshots are immutable records that reflect data at the time of booking and are not updated when you correct your current profile. If you believe a booking snapshot contains inaccurate information, you may contact our Data Protection Officer. Where correction of a historical snapshot is not appropriate (as it is a transaction record), we may annotate the record to note the correction you have requested.
Withdrawal of Consent
You may withdraw your consent for optional processing (such as marketing communications and promotional push notifications) at any time without affecting your ability to use the core service.
For processing that is necessary to provide the service (such as your name, email, booking records, and transactional communications), withdrawing consent means we can no longer provide the service to you. If you wish to withdraw consent for all processing, you may delete your account via Settings > Delete Account.
To withdraw consent for any specific purpose, contact our Data Protection Officer or use the controls available in the app. We will process your request within 10 business days and inform you of any consequences. When we process your consent withdrawal, we will also instruct our relevant service providers to cease processing your data for the withdrawn purpose where applicable.
For convenience, you can also withdraw consent directly in the app:
- Marketing communications: toggle off in Settings > Notifications, or use the unsubscribe link in any marketing email
- Push notifications: toggle off in Settings > Notifications, or through your device’s notification settings
- All data processing: delete your account via Settings > Delete Account
Account Deletion
- You can delete your account at any time from Settings > Delete Account. The process requires confirmation to prevent accidental deletion.
- If you have active bookings (Pending, Confirmed, or Ongoing), we will ask you to complete or cancel them before processing your deletion request. If you cannot resolve active bookings, contact us at sniff.hq@gmail.com and we will process your deletion manually.
After you request deletion, your account is immediately hidden from all other users. Most of your personal data is permanently removed from our systems after 30 days, except for the following:
- Reviews you posted (with your identity removed — see Section 6)
- Booking snapshots on the other party’s records (see Section 6)
- Payment records required by law (see Section 6)
- Aggregated analytics data that contains no personal information
Complaints
If you have concerns about how we handle your data, you may submit a complaint to our Data Protection Officer by email at sniff.hq@gmail.com. Please include your name, a description of your concern, and any relevant details. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days.
If you are not satisfied with our response, you may lodge a complaint with Singapore’s Personal Data Protection Commission (PDPC) at www.pdpc.gov.sg.
8. Security
We take the protection of your personal data seriously and implement appropriate technical and organisational measures:
- All data transmitted between your device and our servers is encrypted using HTTPS/TLS
- Our database is encrypted at rest
- Access controls ensure that users can only access data they are authorised to view — customers see their own data, while shops see booking-related customer data only during active bookings, as described in Section 4
- Passwords are securely hashed and never stored in plain text
- Your login session is stored in encrypted device storage
- All user input is validated before being processed
- Rate limiting protects against abuse of authentication and API endpoints
- Administrative access to our systems is restricted and protected by multi-factor authentication
- We monitor for known security vulnerabilities in our software dependencies
No security measures are completely infallible. While we strive to protect your data, we cannot guarantee absolute security.
9. Data Breach Response
When we have reason to believe a data breach may have occurred, we will promptly assess the breach to determine its nature, scope, and whether it is notifiable under the PDPA.
In the event of a data breach that is likely to result in significant harm to affected individuals, or that affects a significant number of individuals, we will:
- Notify Singapore’s Personal Data Protection Commission (PDPC) no later than 3 calendar days after determining that the breach is notifiable, as required by the PDPA
- Notify affected individuals as soon as practicable, with details of the nature of the breach, what data was affected, the steps we are taking to address it, and steps you may take to protect yourself
Where notification to individuals is not required or is prohibited by law, we will comply with the applicable requirements.
If you believe your personal data on Sniff has been compromised, please notify us immediately at sniff.hq@gmail.com so that we can investigate.
10. Accuracy
We make reasonable efforts to ensure that personal data in our possession is accurate and complete where it is likely to be used to make a decision that affects you or is likely to be disclosed to another organisation. You should keep your account, pet, and contact information accurate and up to date. Shops should ensure that staff and business information uploaded to Sniff is accurate and kept current.
11. On-Device Storage
Sniff is a native mobile application and does not use cookies. We store a small amount of data locally on your device:
- Your authentication session token is stored in encrypted device storage to keep you signed in between app launches
- Rate-limiting counters (e.g., sign-in attempt limits, SMS verification cooldowns) are stored in local storage to prevent excessive requests
This data remains on your device and is not transmitted to our servers. It is cleared when you sign out or uninstall the app.
12. Marketing Communications
Email Marketing
We may send you marketing emails such as newsletters, promotions, and feature announcements. Email marketing is always opt-in — we will never send you marketing emails unless you have explicitly enabled them in your notification settings.
To opt out of marketing emails: go to Settings > Notifications > Marketing Emails, or use the unsubscribe link in any marketing email.
Push Notifications
We send push notifications in two categories:
- Transactional (booking confirmations, status updates, appointment reminders): these are tied to your use of the service and are sent when push notifications are enabled. Disabling transactional notifications may mean you miss important booking updates.
- Marketing (promotions, new features, recommendations): these require separate opt-in and can be disabled independently in Settings > Notifications.
You can disable all push notifications at any time via Settings > Notifications or through your device’s notification settings.
SMS and Phone Marketing
We comply with Singapore’s Do Not Call (DNC) Registry provisions. If we send marketing messages via SMS, fax, or voice call to Singapore telephone numbers, we will:
- Check the DNC Registry before sending
- Clearly identify Sniff as the sender
- Provide our contact information in the message
- Honour any request to stop receiving marketing messages
We will not send marketing messages to numbers registered on the DNC Registry without your clear and unambiguous consent. We will not require you to consent to marketing messages as a condition of using Sniff.
Transactional Communications
Transactional communications (booking confirmations, status updates, appointment reminders, and account security emails) are not marketing and are sent as part of the service. While you can disable push notifications through your device settings, doing so may mean you miss important booking updates. We do not currently provide alternative delivery channels (such as SMS or email) for booking status notifications.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you via email or an in-app notification with at least 30 days’ notice before the changes take effect. The updated policy will be available in the app with a revised effective date.
Where we introduce material new purposes for data collection or processing that require consent under the PDPA, we will obtain your consent before collecting, using, or disclosing your personal data for those new purposes.
Your continued use of Sniff after being notified of non-material changes constitutes your acceptance of the updated policy.
This policy was last updated on July 20th 2026.
14. Contact Us
If you have questions about this Privacy Policy, wish to exercise your data rights, or want to make a complaint, please contact our Data Protection Officer:
- Joshua Tan
- Email: sniff.hq@gmail.com
- Phone: 9052 6122
- Address: 71 Oxley Rise #01-07 Singapore 238698
If you are not satisfied with our response, you may contact Singapore’s Personal Data Protection Commission (PDPC) at www.pdpc.gov.sg.