PRIVACY POLICY

Basementgrid

Last updated: 02/09/2026

This Privacy Policy explains how Basementgrid Pte Ltd ("Basementgrid", "we", "us", or "our"), a company incorporated in Singapore with its registered address at 7 Temasek Boulevard, #12-07 Suntec Tower One, Singapore 038987, collects, uses, discloses, and protects personal data in connection with the Basementgrid platform (the "Service"), in accordance with Singapore's Personal Data Protection Act 2012 ("PDPA").

This Policy should be read together with our Terms of Service, which governs use of the Service generally. Capitalized terms not defined in this Policy have the meaning given to them in the Terms of Service (for example, "Workspace," "Workspace Owner," "Account," "Content," and "Vendor").

By creating an Account or using the Service, you consent to the collection, use, and disclosure of personal data as described in this Policy, to the extent such consent is required under the PDPA.

1. Who This Policy Applies To

This Policy applies to personal data of all individuals who interact with the Service through a Workspace, regardless of Role — including Administrators, Approvers, Collaborators, Requesters, Vendor Managers, and Vendor Technicians, as those Roles are described in our Terms of Service.

Where a Workspace Owner (typically an MCST or Managing Agent) invites or adds other individuals to its Workspace — for example, an Administrator adding a resident as a Requester, or a Vendor Manager adding a Vendor Technician — that Workspace Owner or Vendor is responsible for ensuring it has the appropriate basis to share that individual's personal data with us for the purposes described in this Policy.

2. Personal Data We Collect

2.1 Workspace Registration Data

When a Workspace is created, the Administrator setting it up provides:

2.2 Account and Occupant Data

Once a Workspace is created, Administrators may invite other individuals as Accounts. Depending on their Role, this may include:

This information is provided to us by the Workspace Owner (via its Administrators) to help that Workspace Owner manage its own occupants, staff, and vendors. We do not independently verify or supplement this data, and we do not use it for any purpose beyond providing the Service to that Workspace.

2.3 Work Order and Operational Content

In the course of using the Service, Accounts may submit or generate: work orders, defect reports, asset and location records, status updates, photos (including GPS-tagged photos uploaded during field work), comments, and vendor quotes. Collectively, this and the data described in Sections 2.1 and 2.2 form part of a Workspace's "Content," as defined in our Terms of Service.

2.4 Financial and Payment-Related Data

Where a Workspace uses paid features or vendor payment tracking, we may hold: invoices and tax invoices, transaction histories, payout logs, vendor UENs (used to generate PayNow QR codes, as described in our Terms of Service), and billing contact details for the Workspace Owner. As explained in our Terms of Service, Basementgrid does not process, hold, or transmit the funds themselves — PayNow payments made using a QR code generated within the Service go directly to the Vendor's own bank account.

2.5 Technical Data

We may automatically collect limited technical data needed to operate the Service, such as login timestamps, device and browser information, and error/diagnostic logs. We do not use cookies. We use Firebase Crashlytics, a third-party crash reporting tool, which logs technical data associated with application crashes (such as device information and crash logs) to help us identify and fix bugs.

3. How We Use Personal Data

We use personal data collected through the Service solely to provide, maintain, and support the Service for the relevant Workspace, including to:

We do not use Workspace Content or personal data for advertising, do not sell personal data, and do not use it to build profiles for any purpose unrelated to providing the Service to the Workspace it belongs to.

3.1 Marketing Communications

By creating an Account, you also agree that we may send marketing and promotional communications to the email address associated with your Account, such as updates about new features, tips for using the Service, and other Basementgrid news. Every marketing email we send includes an unsubscribe link, and you may opt out of receiving further marketing communications at any time by using that link or by contacting us at legal@basementgrid.com. Opting out of marketing communications does not affect our ability to send you transactional or service-related communications (such as billing notices, Payment Receipts, or Account security alerts), which are necessary for us to provide the Service.

4. Legal Basis for Collection and Use

We collect, use, and disclose personal data based on the consent of the individual or the Workspace Owner acting on their behalf, or where permitted or required without consent under the PDPA — for example, where reasonably necessary to provide the Service under a contract, or to comply with a legal obligation such as IRAS record-keeping requirements.

5. Disclosure of Personal Data

5.1 Within a Workspace

Personal data is visible within a Workspace only to the extent permitted by the Role-based access model described in our Terms of Service. For example, occupant personal data such as unit role, vehicle number, and access card details is restricted to Administrator-level Accounts, and a Vendor's roster of Vendor Technicians is private to that Vendor's own Vendor Manager and not exposed to the estate's Administrators.

5.2 Service Providers

We engage third-party service providers to help us operate the Service. This includes Amazon Web Services (AWS), which hosts our database and infrastructure (currently located in the AWS Tokyo, Japan region), and Firebase Crashlytics, which we use for crash reporting as described in Section 2.5. Any such provider is only given access to personal data to the extent necessary to perform its function for us, and is required to protect that data consistently with this Policy and the PDPA.

5.3 No Sale of Personal Data

We do not sell, rent, or trade personal data to third parties.

5.4 Legal Disclosures

We may disclose personal data where required by law, regulation, court order, or governmental authority, or where necessary to establish, exercise, or defend legal claims.

6. Data Retention

We retain personal data and Content for as long as the relevant Workspace remains active, and thereafter in accordance with this section and our Terms of Service.

7. Your Rights and Choices

7.1 Access and Correction

You may request access to, or correction of, personal data we hold about you by contacting us at legal@basementgrid.com. Where personal data was provided to us by a Workspace Owner (for example, occupant details entered by an Administrator), we may direct your request to that Workspace Owner where appropriate, as they control that data.

7.2 Withdrawing Consent

You may withdraw consent to our collection, use, or disclosure of your personal data at any time by contacting legal@basementgrid.com, subject to legal or contractual restrictions. Withdrawing consent may limit or prevent your ability to use certain features of the Service, or the Service as a whole.

7.3 Deletion

A Workspace Owner may request deletion of all data associated with its Workspace by writing to legal@basementgrid.com. We require proof of identity and authority to act for the Workspace Owner, together with a signed undertaking, before processing such a request. Full details of this process, including the records we are required to retain notwithstanding a deletion request, are set out in our Terms of Service (Section 7.4) and in Section 6 of this Policy.

8. Data Security

We implement reasonable technical and organizational measures designed to protect personal data against unauthorized access, collection, use, disclosure, or similar risks, in accordance with our obligations under the PDPA. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Among these measures, we restrict visibility of work orders and related data within a Workspace according to Role:

9. Overseas Transfer of Personal Data

Our database and infrastructure are hosted with Amazon Web Services (AWS) in the AWS Tokyo, Japan region. This means personal data is stored and processed outside Singapore. We rely on AWS's standard Data Processing Addendum, which contractually binds AWS to data protection commitments, as the legally enforceable safeguard ensuring this transfer meets the standard of protection comparable to the PDPA, as required under Section 26 of the PDPA.

10. Children's Privacy

The Service is intended for use by adults acting on behalf of an MCST, Managing Agent, Vendor, or as a resident/tenant Requester. We do not knowingly collect personal data from children.

11. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will provide reasonable notice (such as by email or in-app notice) before the changes take effect. Continued use of the Service after the updated Policy takes effect constitutes acceptance of the updated Policy.

12. Contact Us

If you have questions, requests, or complaints about this Policy or how we handle personal data, please contact our Data Protection Officer at:

Basementgrid Pte Ltd
7 Temasek Boulevard, #12-07 Suntec Tower One, Singapore 038987
Data Protection Officer: legal@basementgrid.com