BookHomeMassage

Partner Privacy Policy

Governed by Singapore law · Last updated: 25 July 2026 · The English text is the controlling version.

1. Important Notice

Important notice - the Partner App and our backend systems collect and use personal data for onboarding and account management, for handling Bookings and orders, for location reporting, for communications and notifications, for payouts, for safety, fraud prevention and dispute handling, and for legal compliance and platform security.

Three points are put at the front because they are the most likely to surprise you:

  • LOCATION REPORTING STARTS WHEN YOU SIGN IN AND RUNS AT A FIXED INTERVAL WHILE THE PARTNER APP IS OPEN IN THE FOREGROUND. IT DOES NOT DEPEND ON HAVING AN ORDER, ON THE STATUS OF AN ORDER, OR ON YOUR WORK STATUS. SEE CLAUSE 6.
  • We do not carry out background checks, criminal-record checks, sanctions or watchlist screening, biometric or liveness checks, or licence, qualification or work-right verification. See clause 3.2.
  • When a Booking is directed to you, our systems send the Customer's contact and address data to your device before you accept, including the Customer's mobile number as provided at booking, without masking or relay. See clause 7.

BY APPLYING, CREATING AN ACCOUNT, USING THE PARTNER APP OR ACCEPTING ORDERS, YOU CONSENT TO THE COLLECTION, USE AND DISCLOSURE OF YOUR PERSONAL DATA FOR THE PURPOSES DESCRIBED IN THIS POLICY, SUBJECT TO APPLICABLE DATA PROTECTION LAW. Where we process higher-risk data, we will also seek separate, specific consent or rely on another lawful basis as described below.

Terms used in this Policy. "Provider" (also referred to as Therapist or Partner) means an independent service provider who provides massage services in their own name through the Platform. "Customer" means a person who submits a Booking in the Customer App. "Booking" means a Customer's request for a service type, a start time and a Service Location naming one specific Provider. "Booking Request" means the order object created for that selected Provider and shown only to that Provider. "Service Location" means the address the Customer submits, including place or building name, address line, house or unit number and coordinates. "Support" means our human customer support channels. "Partner App" means the Provider-facing application, and "Customer App" means the Customer-facing application.

The apps are made available internationally. Bookings may be made and performed in more than one country, and available payment channels, currencies and local requirements differ by place of service. Where this Policy describes a feature, it applies where that feature is provided in the app and version you use; the iOS and Android Partner Apps do not offer identical features.

2. Organisation and Data Protection Officer

This Privacy Policy explains how the operator of the BookHomeMassage platform, a company incorporated in Singapore whose registered name, UEN and registered address are as published on the Platform's official channels ("Platform", "we", "us", "our") collects, uses, discloses, stores, transfers and protects personal data relating to Partner applicants, Providers and Partner account users, wherever they are located and wherever the services are performed.

We contract directly with Customers and with Providers as a single contracting entity, wherever the service is performed. Each of those contracts is a contract for our platform service — booking records, accounts, listing, communications, Support and collecting the price of a Booking on the Provider's behalf. The massage service itself is supplied by the Provider to the Customer under a contract between them, to which we are not a party. We are therefore the controlling organisation for the personal data described in this Policy, and each Provider is separately responsible, under applicable data protection law and under the agreements between us, for the Customer personal data that reaches the Provider's own device. We have appointed a Data Protection Officer to answer questions about this Policy and to handle requests under it.

Data Protection Officer: as appointed and published by the Platform. Email: as published in the Partner app and on the Platform's official channels. Address: the Platform's Singapore business address as published on its official channels.

3. Personal Data We Collect

This clause describes the categories of personal data we collect. Where an item is not described here, you should not assume that we collect it.

3.1 Account and Contact Data

  • name, display name, profile photo and other profile media, including photos and videos;
  • mobile number, email address and preferred language;
  • login, authentication, session and account security data;
  • date of birth as self-reported by you, and the age we derive from it.

3.2 Identity and Onboarding Data

  • an identity document number recorded on your Provider record;
  • images of the front and the back of that identity document;
  • any other document you choose to send us through the channel we tell you to use;
  • the onboarding status of your record - pending review, approved, or not approved.

These items are collected through our administrative or offline channels, not through the Partner App. The Partner App neither collects nor displays back your identity document number or your document images, and you cannot edit them yourself.

Where you apply to us for an account, we carry out a manual review of the documents and information you give us before your record is approved for listing to Customers. That review is a human decision whether to approve your record. IT IS CARRIED OUT ON A BEST-EFFORTS BASIS AND IS NOT A GUARANTEE OF ANY OUTCOME. We do not verify the authenticity of any document, the validity of any number, or the accuracy of anything you tell us. We do not collect or check professional licences, certificates, qualifications, training records, insurance documents or their expiry dates. We do not verify your work rights or immigration status. We do not collect selfies, facial images for matching, liveness results or any other biometric data. We do not use any third-party identity-verification, know-your-customer or background-screening service, and we do not carry out adverse-history, criminal-record, sanctions or watchlist screening.

Where a Provider record is created in our systems by an automated synchronisation from a third-party source rather than by an application made to us, no documents are collected from you for that record and no manual review is carried out: the record is approved by that process. Nothing in this Policy is a representation that every Provider record capable of being shown to or booked by a Customer has been read by any person. Where that applies to your record, we may ask you at any time to submit documents for manual review, and this clause then applies to that submission.

Our record of that review consists of the approval status. We do not keep separate reviewer, decision-date or reason fields, so there is no verification file about you for us to produce. Where your record was created by an automated synchronisation as described above, that status was set by that process and not by a person.

Because we do not verify these matters, you remain solely responsible for obtaining and holding all licences, permits, approvals, work rights and registrations required for massage or home-visit services in each place where you perform them, and for the accuracy of everything you tell us. See the Independent Therapist Agreement.

3.3 Profile Data You Provide

  • the service categories and service types you say you offer;
  • years of experience, self-described specialities and introduction text;
  • the city or area in which you say you work;
  • availability, leave and extra-hours entries, where that feature is provided in the app and version you use.

Profile data is self-reported and we do not verify it. Ratings, review counts, positive-feedback rates, badges and labels shown in the apps or on our website are Platform Display Content. Some of them are set by us or generated by our systems and are not derived from Customer feedback. They must not be relied on as a measure of any Provider's quality, conduct or suitability.

A scheduled process may add a review to an order that the Customer has not reviewed within a set period. Such a review is generated by our systems, is not feedback from the Customer, and should not be read as an assessment of the service. Where a review is attached to your record, the personal data in it is processed under this Policy.

3.4 Order and Address Data

  • the Booking Requests directed to you, the orders you accept, and their status history and timestamps;
  • order records and internal order references, and the order number shown in the apps;
  • the Customer personal data described in clause 7, which our systems deliver to your device with each order;
  • the record of who moved an order to a given status - you, Support, or our systems.

A RECORD SHOWN AS "COMPLETED", "SERVICE COMPLETED" OR "AWAITING REVIEW" IS A STATE OF OUR RECORDS. IT IS NOT CONFIRMATION THAT A SERVICE WAS PERFORMED. Completion may be recorded by our systems under a timing rule, or by Support, rather than by you. Our systems do not verify arrival, attendance, start or completion, and there is no arrival check, start code, completion code or Customer confirmation step. If a record about you is wrong, contact Support; we will review the records available to us and may correct the record.

3.5 Location Data

  • the approximate coordinates your device reports under clause 6, and the time of each report;
  • a location value our systems derive in order to decide whether you appear in Customer listings and to calculate the distance displayed to Customers. That value may be your most recent reported coordinates, the coordinates of a Customer's Service Location for an order you have accepted, or a static point set by our administrators;
  • the state of the location permission granted to the app by your operating system.

3.6 Chat, Support and Incident Data

  • the content of messages you send and receive through the Partner App, including text and attachments sent to you by Customers;
  • the order, thread type, sender, time and unread counters associated with each message;
  • support conversations, complaints, safety reports and the records we create when handling them;
  • account measures we apply and the reasons we record for them.

3.7 Device, Notification and Risk Data

  • device identifiers, including the Android device identifier or the iOS vendor identifier, operating system, app version, brand code and distribution channel;
  • the push notification token issued for your device by the push provider, and the list of active devices we keep for your account;
  • IP address, request metadata, app events, logs, crash reports and diagnostics;
  • signals we use to detect duplicate accounts, automated abuse, implausible data and fraud.

3.8 Payout Data

  • the payee name and the payout account identifier you submit when you request a withdrawal;
  • withdrawal requests and their status, and the ledger entries and balances we hold for your account;
  • tax, invoice and accounting records where we are required to keep them.

We do not collect card numbers, card security codes, bank passwords or payment-provider secret keys in the Partner App.

4. Purposes

We collect, use and disclose Provider personal data for the following purposes:

  • creating and operating your account, signing you in, and keeping the account secure;
  • reviewing your application and deciding whether to approve your record for listing;
  • displaying your profile to Customers, and deciding whether you appear in a Customer listing for a given search;
  • delivering to you the Booking Requests that Customers have directed to you, recording your acceptance, your status updates and the closing of orders;
  • giving you the Customer contact and address data needed to attend an order;
  • carrying messages between you, Customers and Support, and translating message text when you ask for a translation;
  • sending you notifications about orders, messages and your account;
  • collecting the price of a Booking on your behalf, accounting for it, handling withdrawal requests, ledgers, adjustments, and tax and accounting records;
  • operating Support and handling corrections, rescheduling, refunds, complaints and disputes, which our staff handle case by case;
  • investigating safety incidents, violence, threats, sexual misconduct, fraud, data misuse, attempts to take transactions off the Platform, and breaches of our agreements and policies;
  • enforcing our agreements and policies, applying account measures, preserving evidence and responding to claims;
  • complying with law and with requests from courts, regulators, police and tax authorities, and dealing with insurers, auditors and professional advisers;
  • protecting Customers, Providers, our staff, the public, and the integrity and security of the Platform;
  • maintaining, debugging, securing and improving the apps and our systems;
  • sending operational notices and policy updates;
  • sending optional product or promotional messages where permitted by law and where you have not opted out.

We do not use your personal data to allocate, dispatch or match Bookings between Providers, because we do not operate any such process. See clause 7.

5. Lawful Basis, Consent and Withdrawal

For most processing we rely on your consent, and on deemed consent for purposes reasonably necessary to provide the Partner service you ask for.

For higher-risk processing we will seek separate, specific consent at the point of collection, or rely on another lawful basis under applicable data protection law, as follows:

  • identity document number and document images - separate consent at the point of collection, for onboarding, record-keeping, safety and legal purposes. No biometric processing is involved;
  • location reporting - the location permission you grant your operating system, together with the notice in clause 6, for listing, distance display, safety and fraud review;
  • Customer personal data delivered to you - necessary in order to perform the Booking that the Customer submitted for you, and handled by you under clause 7;
  • message content, including translation - your use of the messaging and translation functions, together with the notice in clause 8;
  • fraud, risk and integrity checks - the legitimate interests basis, where our assessment shows that the benefit outweighs any adverse effect;
  • safety, legal and regulatory use - deemed consent, legitimate interests or legal obligation, as applicable.

You may withdraw consent by contacting Support or our Data Protection Officer, with reasonable notice. Withdrawal may affect or prevent:

  • approval of your record and your visibility to Customers;
  • receiving Booking Requests and the data needed to attend an order;
  • messaging and notifications;
  • processing of withdrawal requests;
  • safety and fraud review;
  • Support and dispute handling;
  • continued access to the Partner App.

WITHDRAWING CONSENT IS NOT THE SAME AS DELETION. WHERE APPLICABLE LAW PERMITS OR REQUIRES IT, WE MAY CONTINUE TO HOLD AND USE PERSONAL DATA AFTER WITHDRAWAL FOR SAFETY, FRAUD, ACCOUNTING, TAX, LEGAL-DEFENCE AND RECORD-KEEPING PURPOSES.

The Partner App does not provide a withdrawal-of-consent, data-download, data-deletion or account-deletion function. Send any such request to Support or to our Data Protection Officer. See clauses 12 and 13.

Where applicable data protection law permits collection, use or disclosure without consent, or under deemed consent, contractual necessity, legitimate interests or legal obligation, we may rely on those grounds. We keep records of the consents and bases we rely on.

6. Location Reporting

This clause describes how location reporting actually works. Read it before you sign in.

  • Reporting starts when you sign in successfully, and stops when you sign out.
  • While you are signed in and the Partner App is open in the foreground, your device sends approximate coordinates to us at a fixed interval of about every three minutes, together with the time of the report.
  • Reporting does not depend on having an order, on the status of an order, on whether you are on your way to a Service Location, or on your work status. A signed-in Provider who is resting or off duty is still reporting while the app is in the foreground.
  • We do not collect your location in the background. The Partner App has no background-location permission and no background location service. When you send the app to the background, close it, or sign out, reporting stops.
  • We keep only the most recent report. Each report overwrites the previous coordinates and time. We do not build or store a location history or trail, and we cannot produce one.
  • The coordinates are approximate rather than precise. The app asks the operating system for accuracy in the order of a hundred metres, and on Android the value sent may be the last location known to the operating system rather than a fresh fix.
  • Reported coordinates are not used to verify arrival, attendance or performance. Our systems do not compare your location with any Service Location, there is no geofence or arrival check, and order status never advances because of where you are.

We use location data to derive the value described in clause 3.5, which decides whether you appear in a Customer listing for a given search and is used to calculate the approximate distance shown to Customers; to support safety and fraud review; and to respond to complaints, disputes and lawful requests. The distance shown to a Customer is a straight-line approximation and is not an estimate of travel or arrival time. Where the derived value comes from an order you have accepted, the coordinates concerned are the Customer's, not yours; see clause 7.

Notice and controls. Notice before collection is given by your operating system's location permission prompt and, where your platform shows it, by the purpose text displayed with that prompt. ANY "PAUSE SHARING" OR SIMILAR CONTROL SHOWN INSIDE THE PARTNER APP AFFECTS ONLY WHAT THAT SCREEN DISPLAYS. IT DOES NOT STOP LOCATION REPORTING. The in-app data and privacy notice is informational: not opening it, or declining it, does not stop location reporting. The only effective ways to stop reporting are to withdraw the location permission in your device settings, to close or background the app, or to sign out. If you withdraw the permission, we may be unable to show you in Customer listings, and Support may be unable to assist with location-related disputes.

On Android, the Partner App also writes each successful report into the device's own system log. Anything on your device that can read system logs or generate a bug report may be able to read those coordinates. This is a property of your device, not of our servers.

The Partner App does not provide any function to view, correct or delete the location data we hold. Requests of that kind go to Support or to our Data Protection Officer under clause 13.

7. Customer Personal Data You Receive

A Booking is always directed to the single Provider the Customer selects. We do not operate a job pool, we do not allocate, dispatch or match Bookings between Providers, and we do not substitute or reassign a Provider. One Booking Request is created for the Provider the Customer selected, and it is shown only to that Provider.

When a Booking Request is created for you, our systems deliver the order record to your device. That record contains the Customer's personal data from the moment the Booking Request is created, before you accept it. Where the Customer provided them, it includes the Customer's name, the mobile number given at booking, the place or building name, the address line, the house or unit number, the coordinates of the Service Location, a third-party map link to those coordinates, the service type, the booked time and any remarks.

The Customer's mobile number as provided at booking is passed to you without masking or relay. There is no proxy number and no call relay. A call button in the Partner App places an ordinary telephone call from your device to the Customer's own number, and your own number may be shown to the Customer by your telephone network. The Partner App has no platform voice or video calling.

The Partner App hides the address card and map until an order is accepted. That is a display rule in the app only. The underlying data - including the exact coordinates, the address line and the house or unit number - has already been delivered to your device, and some fields are displayed before acceptance, including the place or building name, which may itself be a full address line. Records for completed and cancelled orders continue to contain the same Customer address and contact data.

We do not keep an audit log of which Provider viewed which address. No address-view or address-reveal log exists, and any marking or watermark shown on an address card in the app is not a reliable record of who viewed it.

Two further routes take Customer personal data outside our systems:

  • Navigation. Navigation is handed to a third-party map application or website on your device. When you use it, the Customer's coordinates and any label we pass with them are processed by that third party under its own terms, which we do not control.
  • Linked messaging accounts. Where a third-party messaging account is linked to your Provider record, we may send order details to that account, including the Customer's name, mobile number, address line and house or unit number. Those details are then handled by that messaging provider under its own terms.

The service-area card in your Partner App profile may display the derived location value described in clause 3.5, including its coordinates and a link to a third-party map. Where that value comes from an order you have accepted, the coordinates shown are the Customer's Service Location. Treat that card as Customer personal data.

Your obligations as a recipient. Customer personal data is disclosed to you for the sole purpose of assessing, attending and performing the order concerned, and for dealing with us about it. You must:

  • use it only for that purpose, and only for as long as that purpose requires;
  • keep your device and your account secured, and not let anyone else see or use the order data on your device;
  • not copy, export, photograph, publish, post, sell, share or reuse it for any other purpose, including advertising, direct marketing or building your own client list;
  • not contact the Customer for any purpose unrelated to the order, and not use their contact details to take transactions off the Platform;
  • delete or return it, and stop using it, when we ask you to;
  • tell us promptly through Support if you lose your device, or if Customer personal data you received from us is disclosed, lost or accessed without authorisation.

BREACH OF THIS CLAUSE IS A SERIOUS BREACH OF YOUR AGREEMENTS WITH US. It may lead to account measures, to claims for losses we suffer, and to a report to the police or other competent authority in the place of the incident. Your obligations in the Partner User Agreement and the Independent Therapist Agreement continue to apply, as do your own obligations under applicable data protection law in respect of personal data you hold.

8. Chat, Translation, Support and Notifications

Chat is not private between you and the Customer. Messages are carried by our servers and stored on them in readable form. There is no end-to-end encryption. We can read, retain, review, export and disclose message content, and message content may also be written into our server logs. Do not send anything through chat that you would not want us, Support, an auditor or a court to read, and do not send identity documents, payment credentials or account passwords through it.

  • Conversations are tied to an order. There is no messaging outside an order, and a support thread must be attached to an order. Where you need to raise something that is not attached to an order, use the contact channels we publish in the app, which are operated on third-party platforms; once you leave the app, that third party's own terms and privacy policy apply and we do not control the data you send there.
  • Support threads, where an in-app support thread is provided in the app and version you use, are carried on a third-party customer-support platform. A contact record identifying you is created on that platform when an order involving you is created, whether or not you ever contact Support.
  • IN SOME APP VERSIONS, A MESSAGE YOU SEND FROM AN ORDER CONVERSATION MAY BE DELIVERED TO THE CUSTOMER EVEN WHERE THE SCREEN SUGGESTS THAT YOU ARE WRITING TO SUPPORT. Do not use an order conversation to raise a complaint about a Customer or to send us anything you do not want the Customer to read. Use the contact channels we publish in the app instead.
  • Linked messaging accounts. Where a third-party messaging account is linked to your record, messages addressed to you, including messages from Customers and from Support, may be forwarded to that account, and replies you send there may be brought back into our records.
  • Translation. If you use a translate control, the text concerned is sent to us and then to a third-party artificial-intelligence provider outside the Platform, which returns a translation. The text and the translation are cached by us and on your device. Do not ask for a translation of text containing personal data that you do not want sent to that provider.
  • Deleting a conversation in the app only hides it on your device. It does not delete any message from our systems, and the conversation reappears if a new message arrives. There are no read receipts and no typing indicators. A "sent" or "delivered" marker means only that our server accepted the message; it is not evidence that the recipient received or read it.
  • Messages are fetched by polling at intervals of several seconds. Messages are not instantaneous, and you should not rely on chat for anything urgent or time-critical.
  • We do not run content moderation, keyword filtering or off-platform-transaction detection on messages. What you send is your responsibility.

Notifications. Push notifications are delivered through third-party push infrastructure operated by the mobile platform providers. Notification titles and bodies may contain the full text of a message or the details of an order, and may be displayed on your lock screen and on any device linked to your account with the mobile platform provider. We register your device with the push token and the device data listed in clause 3.7, and we keep a limited number of active device records for each account.

Signing out does not delete the device record or revoke the push token, and the Partner App has no function to de-register a device. The Partner App has no notification preference settings. To stop push notifications, turn them off for the app in your device settings; that also stops order and message notifications. Some notification text is produced by our systems in a fixed language and may not follow the language you have selected in the app.

9. Disclosures

We may disclose Provider personal data to:

  • Customers, to the extent described in clause 10;
  • hosting, database, object storage and content-delivery providers;
  • push notification providers, and the mobile platform providers that operate them;
  • map, geocoding and place-search providers, and the map application installed on your own device;
  • the third-party artificial-intelligence provider we use for translation;
  • the third-party customer-support platform we use for support threads;
  • third-party messaging platforms, where a messaging account is linked to your record or where we publish contact channels on those platforms;
  • payment providers, payout providers and banks, and any account holder we designate to receive payment for a Booking on your behalf;
  • professional advisers, insurers, auditors and accountants;
  • affiliates, and parties to a corporate transaction;
  • courts, regulators, police, tax authorities and other public authorities, where required or permitted by law;
  • persons to whom disclosure is reasonably necessary to protect life, safety, rights, property, evidence, platform integrity or the public interest.

We do not use identity-verification, background-screening, credit-scoring or advertising vendors. The Partner App does not include third-party analytics, advertising or crash-reporting software development kits other than the push provider's own libraries. We do not sell Partner personal data.

Where a vendor processes personal data on our behalf, we engage it under written terms requiring protection and retention limits consistent with applicable data protection law.

10. What Customers and Other People Can See

For each Provider listed in the Customer App, Customers may see:

  • display name, profile photo and other profile media;
  • service categories and self-described profile text;
  • self-reported age;
  • the city or area recorded for the Provider;
  • an approximate distance derived from the location value in clause 3.5;
  • Platform Display Content, including ratings, review counts, positive-feedback rates, badges and labels, which under clause 3.3 must not be relied on as a measure of any Provider.

Any label or badge shown next to your name reflects at most the approval status described in clause 3.2. It is not a statement that we have verified your identity, your licences, your qualifications or your suitability, and it is not a guarantee of safety.

Two things about visibility you should plan around:

  • PROFILE PHOTOS, PROFILE VIDEOS AND UPLOADED IMAGES ARE HELD WITH OUR STORAGE PROVIDER AND SERVED THROUGH LINKS THAT DO NOT REQUIRE SIGN-IN. ANYONE WHO HAS A LINK CAN OPEN THE FILE.
  • Some of our Provider-profile interfaces can be called without signing in, and Provider profiles can also be opened through public share links. TREAT YOUR PROFILE DATA - INCLUDING YOUR DISPLAY NAME, PHOTO, MEDIA, SELF-DESCRIBED TEXT, AREA AND THE APPROXIMATE LOCATION VALUE - AS PUBLICLY VISIBLE, AND DO NOT PUT ANYTHING IN YOUR PROFILE THAT YOU DO NOT WANT PUBLISHED.

The Customer App does not display to Customers your mobile number, your identity document number or document images, your payout details, your home address, your support records or our internal notes about you, and those items are not part of what we make available to Customers. That is a statement about what we display and disclose on purpose. It is not a warranty that our systems or our vendors' systems cannot be accessed without authorisation; see clauses 14 and 15.

11. Cross-Border Transfers

Personal data relating to you may be stored or processed outside the country or territory where you are located, and outside the place where a service is performed, by us and by the recipients listed in clause 9.

Before transferring personal data out of a jurisdiction whose law imposes conditions on such transfers, we will take the steps that law requires to ensure that the overseas recipient is bound by legally enforceable obligations - for example contractual clauses, binding corporate rules or a recognised certification - providing a standard of protection comparable to that law, unless an exception applies. The additional steps that apply under the law of the place of our incorporation are set out in the Singapore Appendix.

Where you ask for a translation, use navigation, link a third-party messaging account, or open a contact channel operated on a third-party platform, data leaves our systems at your instruction and is then processed by that third party, in its own location and under its own terms.

12. Retention

We retain personal data for as long as it is needed for the purposes in clause 4 or for legal purposes, after which we delete, anonymise, de-identify or restrict access to it. Retention periods are as separately stated in writing by us in our retention schedule.

We do not currently operate automatic deletion for the categories below. Signing out, stopping use of the Partner App, or having your record removed from Customer listings does not by itself delete data we hold. There is no account-deletion or data-deletion function in the Partner App. Send deletion requests to Support or to our Data Protection Officer; we will act on them to the extent applicable law requires and our legal obligations permit.

Retention approach:

DataWhat we holdRetention basis
Account and profile dataWhile the account exists, and after it stops being usedAccount operation, support, claims
Identity document number and imagesHeld on your Provider record; not shown in either appOnboarding, compliance, safety, legal defence
Order records, including Customer address and contact dataHeld for all orders, including completed and cancelled ordersService records, disputes, claims, accounting
Location reportOnly the most recent report; each report overwrites the lastListing, distance display, safety, fraud
Chat and support recordsHeld on our systems and on the third-party support platformSafety, complaints, fraud, legal defence
Device, notification and risk dataNot visible to youNotifications, fraud prevention, security
Payout and accounting recordsHeld with our ledgersAccounting, tax, payment providers, legal

On your device: the Android Partner App keeps an encrypted local copy of order data using the operating system keystore, and the iOS Partner App does not keep order data on the device. Both clear their local caches when you sign out. Clearing a local cache does not delete anything from our systems.

13. Access, Correction and Other Requests

You may ask us for access to, or correction of, your personal data. You may also ask us to delete it, or to stop a particular use. There is no in-app facility for any of these requests, and no in-app facility to view, correct or delete the location data we hold. Send requests to Support or to the Data Protection Officer named in clause 2. Requests are handled by our staff, case by case; there is no automated process.

You can edit some profile fields yourself in the Partner App, where that feature is provided in the app and version you use. You cannot see or edit your identity document data.

We may need to verify your identity before acting on a request. We may refuse or limit a request where applicable law permits, including to protect another person, confidential information, legal privilege, an ongoing investigation, or security and fraud controls, and we may refuse to disclose internal risk rules, fraud logic or security methods. We will respond within the time and in the manner required by applicable law, and will tell you the outcome.

14. Protection

We use reasonable administrative, technical and organisational measures, which may include:

  • transport encryption (HTTPS/TLS) for the apps' connections to our servers;
  • authentication, session and token controls;
  • access controls on our administrative systems;
  • encrypted or otherwise protected storage where appropriate, including the encrypted local cache in the Android Partner App;
  • request validation and abuse controls;
  • vendor contracts covering protection and retention;
  • incident response procedures.

NO SYSTEM IS ABSOLUTELY SECURE. WE DO NOT WARRANT THAT PERSONAL DATA HELD BY US OR BY OUR VENDORS CANNOT BE LOST, ALTERED, DISCLOSED OR ACCESSED WITHOUT AUTHORISATION, AND WE DO NOT REPRESENT THAT EVERY TRANSMISSION ON EVERY LEGACY OR THIRD-PARTY PATH IS ENCRYPTED.

We do not represent that message content, order records or address data can be seen only by the parties to an order. Our people, and our vendors' systems, may have access for the purposes in clause 4.

You must protect your account, device and credentials, keep the app updated, use the device security features available to you, and tell us promptly through Support if you suspect unauthorised access to your account or to data you received from us.

15. Data Breach

Where we become aware of a breach affecting personal data, we will assess it and, where applicable data protection law requires notification, notify the competent data protection authority and affected individuals within the time and in the manner that law requires. The specific standard and deadline that apply under the law of the place of our incorporation are in the Singapore Appendix. We will also take reasonable steps to contain the breach and to reduce harm.

You must report to us promptly, through Support, any loss or theft of a device on which Customer personal data is held, any suspected unauthorised access to your account, and any accidental disclosure of Customer personal data you received from us. Where you are the source of a breach, you must cooperate with our investigation, with any notification we are required to make, and with any competent authority.

16. Notifications and Marketing

We may send you operational, account, order, message, safety, payout, policy and legal notices as needed. YOU CANNOT OPT OUT OF THOSE MESSAGES WHILE YOUR ACCOUNT EXISTS.

Optional product or promotional messages are sent only where permitted by applicable law and where you have not opted out. To opt out of promotional messages while continuing to receive the rest, contact Support. As stated in clause 8, the Partner App has no notification preference settings, and turning notifications off in your device settings turns off order and message notifications too.

17. Liability That Cannot Be Excluded

NO DISCLAIMER, LIMITATION OR EXCLUSION IN THIS POLICY APPLIES TO ANY LIABILITY OR OBLIGATION THAT CANNOT BE EXCLUDED OR LIMITED UNDER APPLICABLE LAW, including any consumer protection, unfair contract terms or data protection legislation that applies to you. To the maximum extent permitted by applicable law we rely on every disclaimer and limitation in this Policy; where the law prohibits exclusion or limitation, we do not exclude or limit, and the clause concerned is to be read so that the remainder has the maximum effect the law allows.

Any limitation or cap on our liability is set out in the Partner User Agreement, and applies to claims connected with this Policy to the fullest extent applicable law allows.

This clause does not reduce any other right or protection we have under this Policy, our other agreements with you, or applicable law.

18. Changes to This Policy

We may update this Policy. Material changes will be notified through the app, the website, email, SMS, push notification or another reasonable method. Where applicable law requires it, we will seek fresh consent. Continued use of the Partner App after a change takes effect means you accept the updated Policy.

19. Governing Law, Contracting Party and Language

Contracting party. The Platform is operated by the company identified in clause 2. We contract directly with Customers and with Providers as a single contracting entity, wherever the service is performed. No affiliate, local operator, agent, merchant or Provider is a party to this Policy unless we state otherwise in writing.

Each of those contracts is a contract for the platform service, including collecting the price of a Booking on the Provider's behalf. Having a direct contract with the Customer does not mean that we supply the massage service; that service is supplied by the Provider under a contract between the Provider and the Customer.

Governing law and jurisdiction. This Policy, and any dispute or claim arising out of or in connection with it (including non-contractual disputes or claims), are governed by the law of Singapore. Subject to the paragraph headed "Mandatory local protections", the courts of Singapore have exclusive jurisdiction, and you submit to that jurisdiction and waive any objection to it on the ground of forum. We may, at our sole election, instead refer a dispute to arbitration administered by the Singapore International Arbitration Centre (SIAC), seated in Singapore and conducted in English. We may in addition seek urgent injunctive or protective relief in any competent forum where necessary to protect users, safety, personal data, confidential information, evidence, intellectual property or platform integrity. Nothing in this paragraph limits your right to complain to a data protection or other competent authority.

Mandatory local protections. If you are an individual habitually resident in a country or territory whose law gives you rights or protections that cannot be excluded or restricted by agreement, nothing in this Policy removes those rights or protections, and nothing prevents you from bringing proceedings in a forum that the applicable mandatory law requires. Where such a right or protection conflicts with a term of this Policy, that right or protection prevails for you to the minimum extent necessary and the remainder of the term continues to apply.

Language. The English text is the controlling version of this Policy. Any translation is provided for convenience of reading only, and in the event of inconsistency the English text prevails, except where applicable mandatory law requires otherwise.

20. Country Appendices

Country appendices. Additional terms may apply to services performed in a particular country or territory. Where we publish a country appendix for a place of service, it applies in addition to this Policy and, for that place only, prevails over any inconsistent term of this Policy to the extent of the inconsistency. As at the date of this Policy, the only country appendix in force is the Singapore Appendix. No country appendix limits the governing-law or jurisdiction provisions above.

21. Singapore Appendix

This appendix applies where the Personal Data Protection Act 2012 of Singapore (the "PDPA") applies to our collection, use or disclosure of your personal data. It applies in addition to the clauses above, and prevails over them for that processing to the extent of any inconsistency.

  • Data Protection Officer. We appoint a Data Protection Officer as required by the PDPA. Contact details are in clause 2.
  • Consent and exceptions. We rely on consent, on deemed consent (including deemed consent by contractual necessity and, where its conditions are met, deemed consent by notification), and on the exceptions in the PDPA, including the legitimate interests exception for fraud, safety, security and investigation purposes, and the business improvement and legal or regulatory exceptions where they apply.
  • Cross-border transfers. Before transferring personal data outside Singapore, we will take the steps required by section 26 of the PDPA and the regulations made under it to ensure that the overseas recipient is bound by legally enforceable obligations to provide a standard of protection comparable to the PDPA, unless an exception applies.
  • Data intermediaries. Vendors that process personal data on our behalf are engaged as data intermediaries under written terms addressing protection and retention.
  • Notifiable data breaches. Where a data breach results in, or is likely to result in, significant harm to affected individuals, or is of a significant scale, we will notify the Personal Data Protection Commission as soon as practicable and in any case no later than 3 calendar days after we determine that the breach is a notifiable data breach. Where the breach is likely to result in significant harm to affected individuals, we will also notify those individuals as soon as practicable, unless an exception applies.
  • Access and correction. We will respond to access and correction requests within the time and in the manner required by the PDPA, subject to the exceptions in the PDPA.
  • Retention limitation. The PDPA requires us to cease retaining personal data, or to remove the means by which it can be associated with an individual, once retention no longer serves the purpose for which the data was collected and is no longer necessary for legal or business purposes. Clause 12 describes what we currently hold and how retention periods are set.
  • Your obligations. Where you receive Customer personal data from us under clause 7 in order to perform an order, you must handle it in accordance with clause 7 and with the PDPA obligations that apply to you.
Legal · Privacy · Terms · Home
© 2026 BookHomeMassage · The English text is the controlling version of all terms.