BookHomeMassage

Privacy Policy

Governed by Singapore law · Last updated: 25 July 2026

1. Scope

This Privacy Policy explains how the operator of the BookHomeMassage platform, a company incorporated in Singapore whose registered name, UEN and registered address are as published on the Platform's official channels collects, uses, discloses, stores, transfers and protects personal data in connection with the Book Home Massage platform.

It applies to Customers, website visitors and other persons who interact with our Customer App, our website and our support channels. If you are a Therapist (also referred to as a Provider or Partner) or an applicant to become one, the Partner Privacy Policy applies to you instead of this one.

We operate the platform as an intermediary between Customers and independent Providers. We are the only platform entity you contract with, wherever the service is performed, and the subject matter of that contract is platform services — including the collection of the price for a Booking on the selected Provider's behalf. The massage service itself is performed by the independent Provider you select, under a separate contract between you and that Provider, to which we are not a party; we do not supply or perform massage services. That is why the Booking details described in clause 5.1 have to be disclosed to the Provider you select. The apps are made available internationally. Bookings may be made and performed in more than one country, and available payment channels, currencies and local requirements differ by place of service. The governing law and jurisdiction for disputes are set out in the User Agreement.

The English text is the controlling version of this Privacy Policy. Any translation is provided for convenience of reading only, and in the event of inconsistency the English text prevails, except where applicable mandatory law requires otherwise.

In this Privacy Policy, "Provider" means the independent therapist you select when booking; "Booking Request" means a booking in the state of awaiting that Provider's acceptance; "Service Location" means the address you select and submit when booking; and "Support" means our human customer-support channel.

2. Personal Data We Collect

Depending on the features you use, we may collect the following. This list is written to match what the platform actually collects.

2.1 Account and Contact Data

  • mobile number, which is how you register and sign in;
  • one-time verification codes sent to that number;
  • your account password;
  • name and contact phone number you enter for a Booking, which may differ from your account number;
  • profile photo, where you upload one;
  • preferred language;
  • authentication tokens issued to your device;
  • your saved address book entries.

We do not collect a date of birth, an identity document number or an identity document image from Customers. We do not perform identity verification, biometric or liveness checks, or background or sanctions screening on Customers. Any label in the app suggesting that a person is verified is platform display content and is not the result of a check on that person.

2.2 Booking Data

  • the service type, duration, date and time you select, and the identity of the Provider you select;
  • the Service Location, comprising any place or building name, the street address, the unit or house number, the assembled full address line, and the precise latitude and longitude coordinates of the point you selected;
  • a map link generated from those coordinates;
  • the contact name and phone number you provide for the Booking;
  • any free-text note or remark you add to the Booking;
  • order records, order numbers, statuses, amounts, the payment channel selected, and your cancellation, refund and support history for that order.

The coordinates of a Service Location are sent to our servers before you submit or pay for a Booking, because a travel-fee quote is requested for the point you have selected together with the identity of the Provider you have selected.

We do not collect gender for a Booking; the field exists in our systems but the Customer App does not submit it.

2.3 Provider and Applicant Data

Data about Providers and applicants (including the identity documents they submit) is described in the Partner Privacy Policy, not here.

2.4 Chat, Support, Review and Translation Data

  • messages and images you send in an order conversation, together with metadata such as the order identifier, the sender type, the conversation type and timestamps;
  • support conversations, including their contents and any attachments;
  • reviews and ratings you submit;
  • any text you submit for translation using the translate control, and the resulting translation.

2.5 Device, Location and Technical Data

  • device identifiers: the push registration token, operating system, the Android identifier or the iOS identifier for vendor, app version and a brand code;
  • IP address, sign-in records, timestamps, session events and error diagnostics;
  • your device's approximate location, only where you grant the permission, taken as a single reading at the time it is needed;
  • server-side request logs, which may contain the parameters of a request, including addresses, coordinates and message text.

We do not collect your location in the background, we do not track your movement and we do not keep a location history or route trace for Customers. The Customer App requests location only while it is open and in use.

2.6 Payment and Transaction Data

  • the payment channel you select, the payment status, the amount and currency, and the reference our payment provider returns to us;
  • for channels arranged manually, any payment confirmation or transfer reference you send to Support.

Online payments are completed on a page hosted by the payment provider and opened inside the app. We do not receive, hold or store your full card number, card security code or bank credentials.

2.7 Safety, Fraud and Compliance Data

  • account and order behaviour records, including duplicate-account and abuse signals;
  • reports and complaints you make to Support, and our notes on them;
  • account restriction and account closure decisions;
  • records of requests from law enforcement, regulators or courts, and our responses.

We do not maintain watchlist or sanctions screening results, and we do not maintain a log of who viewed a Service Location.

3. Purposes

We collect, use and disclose personal data for purposes that a reasonable person would consider appropriate in the circumstances, including:

  • creating, operating and securing your account, and signing you in by mobile number and verification code;
  • showing you Providers, their published profile content, and an approximate straight-line distance from a reference point derived by our systems;
  • showing your current city, where you allow location access, and setting the initial map position when you choose a Service Location;
  • accepting and recording a Booking directed to the one Provider you select;
  • passing the Booking details, including the Service Location and your contact phone number, to that Provider so that the service can be performed;
  • quoting a travel fee for the point you selected;
  • collecting payment for a Booking on the selected Provider's behalf, through payment providers or through payment details we display, and handling manual cancellation, refund, correction and rescheduling requests through Support;
  • producing order records and order numbers;
  • enabling in-app chat and Support, and translating message and review text where you ask for it;
  • sending you notifications about a Booking, about messages you receive, and about Providers you choose to follow;
  • handling complaints, disputes, safety reports and corrections to order records;
  • investigating fraud, abuse, harassment, sexual misconduct, violence, illegal services, off-platform transactions and breaches of our terms;
  • maintaining the security and integrity of the apps and our services;
  • complying with legal, tax, accounting, regulatory, insurance and law enforcement requirements;
  • improving, debugging and securing the apps;
  • sending service messages, policy updates and operational notices;
  • sending marketing only where permitted by law and consistent with your preferences.

4. Consent and Notification

We notify you of the purposes for which we collect, use or disclose personal data where required by applicable data protection law. By using the Platform, submitting data, making a Booking or enabling app permissions, you consent to our collection, use and disclosure for the notified purposes.

Where applicable data protection law permits collection, use or disclosure on a basis other than your consent (for example deemed consent, contractual necessity, legitimate interests, or a statutory exception), we may rely on that basis where appropriate and documented.

You may withdraw consent by contacting Support or the contacts in clause 15, or by turning off a device permission. Withdrawal may limit or prevent the use of features, including booking, payment, chat, support and safety investigation. The Customer App does not currently provide in-app controls for withdrawing consent to a specific processing activity, for exporting your data, or for deleting your account. Such requests must be made through Support or the contacts in clause 15. Withdrawing consent or turning off a permission does not by itself delete data we have already collected.

5. What Is Shared, With Whom, and When

Because home massage involves private addresses and direct contact between two people, this clause states plainly what leaves our systems and when. Read it before you book.

5.1 Your Service Location and contact phone number are sent to the selected Provider

FROM THE MOMENT A BOOKING REQUEST IS CREATED — THAT IS, BEFORE YOUR SELECTED PROVIDER HAS ACCEPTED IT — THE PLACE OR BUILDING NAME, THE FULL STREET ADDRESS, THE UNIT OR HOUSE NUMBER, THE PRECISE COORDINATES, A MAP LINK AND THE CONTACT NAME AND PHONE NUMBER YOU ENTERED ARE DELIVERED TO THAT PROVIDER'S DEVICE. The Partner App is designed not to display the full address and map until the Provider accepts, and it may show only the place or building name before then, but the underlying data is already on that device. We therefore do not claim that the address is withheld until acceptance.

The mobile number you provide at booking is passed to the Provider without masking or relay. There is no proxy number and no call relay. The Provider can call that number directly using their own telephone service, and a call made that way is outside our systems and is not recorded by us.

Order records containing the full address and coordinates remain available to the selected Provider in the Partner App after the order is completed or cancelled. We do not currently remove, hide or reduce the detail of that data at the end of an order.

Where the Provider uses the navigation control, your coordinates, and on some devices the contact name, are handed to a third-party maps application on the Provider's device, which then handles them under its own terms and privacy policy.

Where a Provider has linked a third-party messaging account to their profile, we may send the order details — including the contact name, contact phone number, address, unit or house number, appointment time and your note — to that Provider through that third-party messaging service.

5.2 Your device location

Where you grant the permission, the Customer App takes a single location reading and uses it to show your current city, to sort Providers by approximate straight-line distance, and to position the map when you choose a Service Location. If you do not grant the permission, the app still works, but the reference point our systems use to sort Providers and to calculate the distances shown to you is then a default point we set, not your location. Distances shown in that case are not distances from you, and the order in which Providers are listed is not an order of proximity to you. We do not look up your location from your network address. We do not collect location in the background, and we do not store a Customer location history.

When you choose a Service Location on the map, the map itself is loaded directly from a third-party maps provider by your device, so your map browsing and the point you select are processed by that provider. Place searches and the conversion of coordinates into an address are relayed by our servers to third-party map providers, which for some languages are located in mainland China.

5.3 Chat, Support, notifications and translation

  • In-app messages are not encrypted end to end. They are processed and retained on our servers in readable form, may be read by our staff, may be recorded in our server logs, and may be forwarded to our support channels.
  • Support conversations are handled through a third-party customer-support platform. A support contact record is created for an order when the order is created, even if you never contact Support.
  • Messages you send to a Provider may be forwarded to that Provider through a third-party messaging service where the Provider has linked such an account, and a reply sent from that service is brought back into the conversation.
  • Push notifications may contain the full text of a message and may be displayed on your device's lock screen. Notifications are delivered through Google Firebase Cloud Messaging and, on Apple devices, the Apple Push Notification service.
  • Where you use the translate control, the text is sent by our servers to a third-party artificial-intelligence service, which may be located outside the country where you are. The translation is cached on our servers and on your device.
  • Deleting a conversation in the app hides it on your device only. Server records are not affected, and the conversation reappears if a new message arrives.
  • Images you send in a conversation are stored in our cloud object storage. That storage is currently configured so that the link to an image does not itself require sign-in. Anyone who obtains the link can open the image. That is a shortcoming in our configuration, not a design choice about how your data should be protected and not a risk we ask you to accept. Protecting that content is our responsibility, and it remains our responsibility whether or not you have read this clause. We are changing the configuration so that image links require authorisation and expire, and we treat that change as work we owe you rather than as an improvement we may choose to make.
  • The Customer App does not provide a message-level report control or a control to block another user. To report a message or a person, contact Support.

5.4 What we do not do

  • we do not sell personal data;
  • we do not use advertising or analytics software development kits in the apps; the apps include a push-notification component only;
  • we do not record audio or video of a service;
  • we do not verify arrival, attendance, the start of a service or its completion by location or by any code, so no such data is generated or held;
  • we do not maintain a log of who viewed your address.

6. Disclosure

We may disclose personal data to:

  • the Provider you select, as described in clause 5.1;
  • payment service providers and the processors they use, including through a payment page they host;
  • cloud hosting and cloud object storage providers;
  • push notification services, namely Google Firebase Cloud Messaging and the Apple Push Notification service;
  • map, place-search, geocoding and routing providers;
  • a third-party customer-support platform used to operate our support conversations;
  • third-party messaging services used to reach Providers and to publish our external contact channels, for example Telegram and LINE;
  • third-party artificial-intelligence services used for translation;
  • our internal operational alerting channel, which runs on a third-party messaging service and may carry order identifiers, amounts, schedule changes and payment alerts;
  • insurers, lawyers, auditors, accountants and professional advisers;
  • affiliates, successors or buyers in a corporate transaction;
  • regulators, law enforcement, courts, government agencies or other persons where required or permitted by law;
  • persons where reasonably necessary to protect life, safety, rights, property, platform integrity or the public interest.

Where you leave the app to use an external contact channel we publish, that channel is operated by a third party and its own terms and privacy policy apply to what you do there. We do not control the data handling of that channel.

7. Cross-Border Transfer

Personal data may be stored or processed outside the country or territory where you are, including by cloud, support, messaging, map, translation, notification and payment providers. Our recipients are located in more than one country.

Before transferring personal data out of a jurisdiction, we take the steps required by applicable data protection law to ensure that the overseas recipient is bound by legally enforceable obligations, or that another recognised safeguard applies, providing a standard of protection comparable to that required of us, unless an exception applies.

We are completing a full record of our processors and transfer destinations. Until it is published, you may ask for the current position using the contacts in clause 15.

8. Retention

We retain personal data only as long as necessary for business or legal purposes, including:

  • account operation;
  • performance and history of orders;
  • safety, fraud, complaint and dispute handling;
  • refund, payment-provider, settlement and tax records;
  • regulatory, audit, insurance and legal claims;
  • enforcement of our agreements and protection of rights.

When personal data is no longer necessary for a legal or business purpose, we delete, anonymise, de-identify or restrict access to it in accordance with our retention rules. We are still setting retention periods for each category; until we publish them, the position is as described below, and you may ask us about a specific category using the contacts in clause 15.

Retention approach:

Data typeWhat the apps showHow long we currently keep it
Service Location, coordinates and contact phone numberIn your order records, and in the selected Provider's order recordsKept with the order record. We do not currently delete it or reduce its detail when the order ends
Chat messagesIn the order conversation. Deleting a conversation hides it on your device onlyKept on our servers, and may also appear in server request logs
Chat imagesIn the order conversationKept in cloud object storage. The link to an image does not currently require sign-in, which we are remediating as stated in clause 5.3
Device location readingsNot shownUsed at the time of the request and not kept as a history
Payment references and amountsIn your order recordsKept for accounting, tax, payment-provider and legal requirements
Device and push registration recordsNot shownKept until superseded. Signing out does not remove them, and the apps do not currently revoke a push token
Unread message countersAs a badge in the appExpire automatically after about thirty days
Support conversationsIn the order conversationKept by us and by our support platform provider for complaint, dispute and legal purposes

9. Accuracy and Correction

Please keep your account, profile, contact and address information accurate. You can edit your profile and your saved addresses in the Customer App, where that function is provided in the version of the app you use.

Other corrections must be requested through Support or the contacts in clause 15. This includes corrections to an order record — for example where an order shows as completed but no service was performed. We may require evidence before correcting a payment, compliance or safety record.

Where we are satisfied that personal data we hold about you is inaccurate or incomplete, we will correct it, and where applicable data protection law requires it we will send the corrected data to the organisations to which we disclosed it. Where we decide not to make a correction, we will tell you why and annotate our records with your requested correction. Correcting an order record is dealt with in the Refund, Cancellation and Safety Policy, which also states when amounts paid are refunded.

10. Access Requests

You may request access to the personal data we hold about you, and information about how it has been used or disclosed, subject to the exceptions in applicable data protection law, to verification of your identity, to any fee permitted by law, and to limits needed to protect other persons, confidential information, legal privilege, investigations, and security and fraud controls.

There is no in-app data access or data download function. Make the request through Support or the contacts in clause 15. We may provide a summary rather than raw internal logs where that is appropriate and permitted by law.

11. Security

We use reasonable administrative, technical and organisational measures to protect personal data, which include:

  • transport encryption for traffic between the apps and our main services;
  • account authentication and access controls;
  • protection of the authentication tokens issued to your device;
  • payment handling through a hosted page so that card data does not reach us;
  • server-side logging that lets us investigate incidents;
  • protected or encrypted storage for sensitive data where appropriate;
  • agreements with the service providers we use;
  • arrangements for responding to security incidents.

NO SYSTEM IS ABSOLUTELY SECURE. Some content is currently reachable by anyone holding a link to it, as clause 5.3 describes. That is a limitation we are remediating, not a standard of protection we are setting, and describing it here does not reduce our obligations or transfer any risk to you. You should also protect your account, your device and your communications.

12. Data Breach

If a data breach occurs, we assess whether it is notifiable under applicable data protection law. Where notification is required, we notify the competent data protection authority as soon as practicable and within any applicable statutory deadline, and we notify affected individuals as soon as practicable.

Where a breach occurs we will act to triage and contain it, preserve evidence, assess the likely harm, notify where notification is required, remediate, and review what happened afterwards.

13. Marketing and Notifications

We send service messages needed for your account, a Booking, safety, payment or policy purposes.

If you choose to follow a Provider, we send you a push notification when that Provider becomes available. This is a promotional notification. Marketing messages are otherwise sent only where permitted by law and consistent with your preferences.

The apps do not currently provide per-category notification settings. To stop notifications about a Provider you follow, unfollow that Provider. To stop all notifications from the app, turn notifications off in your device settings; this will also stop order and message notifications. You may also ask Support to stop marketing messages; we will action that request, which may involve removing a follow relationship on your behalf.

Where local rules on marketing calls or messages apply to us, we comply with them. Service, safety and transactional messages may still be sent where necessary.

14. Children

The Platform is intended for adults. We do not verify the age of Customers: registration requires only a mobile number and a verification code, and we do not collect a date of birth.

You represent and warrant that you have reached the minimum age required by the law of the place where you are, and that you will not book a service for a person who has not. If we become aware that we hold personal data of a person below that age without proper authority, we may restrict or close the account and take steps to delete or restrict the data.

15. Contact and DPO

For privacy requests, complaints or questions, contact us through Support in the app, or:

  • Data Protection Officer: as appointed and published by the Platform.
  • Email: as published in the app and on the Platform's official channels.
  • Address: the Platform's Singapore business address as published on its official channels.

We may verify your identity before processing a request. If you are not satisfied with our response, you may complain to the competent data protection authority for your jurisdiction.

16. Changes

We may update this Privacy Policy. The current version is published on our website and in the app. Material changes will be notified through the app, website, email, SMS, push notification or other reasonable method. Where required, we will seek fresh consent.

17. Obligations and Rights That Cannot Be Excluded

NOTHING IN THIS PRIVACY POLICY EXCLUDES OR LIMITS ANY OBLIGATION OR LIABILITY OF OURS THAT CANNOT BE EXCLUDED OR LIMITED UNDER APPLICABLE LAW, INCLUDING UNDER APPLICABLE DATA PROTECTION LAW AND UNDER ANY CONSUMER PROTECTION OR UNFAIR CONTRACT TERMS LEGISLATION THAT APPLIES TO YOU, AND NOTHING IN IT EXCLUDES OR LIMITS OUR LIABILITY FOR DEATH OR PERSONAL INJURY CAUSED BY OUR OWN NEGLIGENCE OR FOR FRAUD OR FRAUDULENT MISREPRESENTATION.

This Privacy Policy describes how the platform currently works, including where the current position falls short of what we intend, in particular in clauses 5, 8 and 11. Those descriptions are information. They are not a limitation of our obligations, they are not your agreement to a lower standard of protection, and they do not transfer to you any risk arising from our own act or omission. Our duty to protect personal data in our possession or under our control is not discharged by telling you about a shortcoming, and it is not affected by what you choose to send us.

Where the User Agreement limits our liability, that limitation does not apply to any right of action given to you by applicable data protection law in respect of a contravention by us, and does not apply to any obligation under this Privacy Policy that cannot lawfully be limited. Your right to complain to the competent data protection authority is not affected by anything in this Privacy Policy or in any other terms we publish.

18. Country Appendices

Country appendices. Additional terms may apply to services performed in a particular country or territory. Where we publish a country appendix for a place of service, it applies in addition to this Privacy Policy and, for that place only, prevails over any inconsistent term of this Privacy Policy to the extent of the inconsistency. As at the date of this Privacy Policy, the only country appendix in force is the Singapore Appendix.

19. Singapore Appendix

This appendix applies only where you are in Singapore, or where personal data is collected, used or disclosed in Singapore, and only to that extent. It applies in addition to clauses 1 to 17.

Applicable law. The Personal Data Protection Act 2012 applies to our collection, use and disclosure of personal data in Singapore. Where this Privacy Policy refers to applicable data protection law, that means the Act and its subsidiary legislation in respect of such data.

Data Protection Officer. We appoint a Data Protection Officer as required by section 11 of the Act. The contact details are those in clause 15, and are also published on our official channels.

Your rights. You may request access to, and correction of, personal data about you under sections 21 and 22 of the Act, subject to the exceptions in the Act. You may withdraw consent under section 16. Section 14 deemed consent, and the exceptions in the First and Second Schedules, may apply to some of the processing described in clause 3.

Transfer of personal data out of Singapore. Where we transfer personal data out of Singapore, we take the steps required by section 26 of the Act and the Personal Data Protection Regulations 2021, so that the recipient is bound by legally enforceable obligations to provide a standard of protection comparable to the Act, unless an exception in those Regulations applies.

Notifiable data breaches. Where a data breach is notifiable under Part 6A of the Act, we notify the Personal Data Protection Commission as soon as practicable and in any case no later than three calendar days after we determine that the breach is notifiable, and we notify affected individuals as soon as practicable where required.

Marketing messages. Where the Do Not Call provisions in Part 9 of the Act apply, we check the relevant Do Not Call registers before sending a specified message to a Singapore telephone number, unless we have clear and unambiguous consent in evidential form.

Complaints. You may complain to the Personal Data Protection Commission of Singapore.

Rights that cannot be excluded. Nothing in this Privacy Policy, and nothing in the User Agreement or any other terms we publish, excludes, restricts or modifies our obligations under the Act, your right to complain to the Personal Data Protection Commission, or your right of private action under the Act in respect of loss or damage suffered directly as a result of a contravention by us. Clause 17 applies to this appendix.