Privacy Policy

Last Updated: June 17, 2026


This Privacy Policy describes how EatWhat ("we", "us", or "our") collects, uses, processes, stores, and protects your personal data when you use our mobile application and digital marketplace platform (collectively, the "Platform").

We operate in strict accordance with the Singapore Personal Data Protection Act 2012 ("PDPA"). By accessing or using the Platform as a Customer, Merchant (Kitchen), or Rider, you explicitly consent to the collection, use, and disclosure of your personal data in accordance with this Privacy Policy.


1. Personal Data We Collect

We collect only the minimum necessary personal data required to securely fulfill your specific operational role on the Platform:

For Customers: Name, email address, mobile contact number, and physical delivery addresses.

For Merchants (Kitchens): Full name, email address, mobile contact number, precise kitchen operation address, ACRA Business Registration details (where applicable), and Workforce Skills Qualifications (WSQ) Food Handling / Food Hygiene Certificates.

For Riders: Full name, email address, mobile contact number, vehicle plate number, photo of the vehicle, and photographic images of the front and back of your NRIC, National ID, or Passport.


2. Real-Time GPS Location Data Tracking

To facilitate hyper-local logistics, the Platform collects real-time geographic location data (latitude and longitude coordinates) from Riders:

Purpose: This data is collected strictly for algorithmic order assignments (matching the closest rider to a kitchen), real-time delivery tracking for customers, operational analysis, and recovery or dispute resolution.

Boundary: GPS tracking occurs only while the Rider app is open and the rider is actively marked "online" or executing a delivery. Tracking ceases entirely the moment the rider logs off or closes the app.


3. Payment Processing & Financial Disclaimers

All financial transactions and payment infrastructure on the Platform are powered directly and exclusively by Stripe Connect via secure Application Programming Interfaces (APIs).

Zero Storage Rule: Our local databases, servers, and scripts never touch, process, or store raw credit card numbers, CVVs, or bank account credentials.

Users manage their financial profiles and payout channels directly within the app via safe Stripe API pipelines. All financial processing is governed by Stripe’s global Privacy Policy.


4. Data Storage, Security, and Cloud Architecture

Primary Database: All user profile data, operational variables, and application parameters are securely stored inside an encrypted Supabase database infrastructure.

Operational Logs: Onboarding expressions of interest and initial registration logs are held securely within Google Sheets under restricted administrative folders on Google Drive.

Telegram Notification Bots: We utilize localized home servers and internal automated scripts to forward system event logs directly into private administrative Telegram channels. These bots are used purely for internal dispatch notifications and operational alerts. No financial details or raw payment records are passed through these notification tunnels.


5. Hard Account Deletion & Permanent Purging Policy

We respect your right to be forgotten under the PDPA. If a user requests a formal account deletion through the Platform:

The Purge Rule: Every piece of personal information tagged to that individual user profile—including personal contact data, account balances, and complete historical transaction or order logs—will be permanently and irreversibly wiped from our live production databases.

Irrevocability: If a user chooses to sign up for eatwhat again in the future, their historical data will be completely unavailable, and they will be treated as an entirely new entity.


6. NRIC & Identification Data Retention Boundaries

For security, verification, and fraud prevention, copies of Rider NRICs/passports are collected during onboarding.

These high-fidelity documents are stored in securely encrypted production buckets with restricted administrative access tokens.

Upon termination, deactivation, or full deletion of a Rider’s account profile, all uploaded copies of NRICs, Passports, and identification documents are permanently and completely destroyed from our storage system.