Privacy Policy
Effective date: March 19, 2026 | Last updated: March 19, 2026
1. Introduction
Welcome to ReStrip. ReStrip (“we”, “us”, or “our”) is operated by Bek Joon Hao (“the Operator”), an individual based in Singapore. We operate the website restrip.app and any related mobile or desktop applications (collectively, the “Service”).
This Privacy Policy explains how we collect, use, disclose, and protect your personal data in accordance with Singapore’s Personal Data Protection Act 2012 (No. 26 of 2012) (“PDPA”), as amended, and any regulations or advisory guidelines issued by the Personal Data Protection Commission (“PDPC”).
By using our Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please discontinue use of the Service.
2. Definitions
- Personal Data means data, whether true or not, about an individual who can be identified from that data, or from that data and other information to which we have or are likely to have access.
- Processing means any operation performed on personal data, including collection, use, disclosure, storage, transfer, or deletion.
- Data Protection Officer (DPO) means the individual designated by ReStrip to oversee data protection compliance.
3. Personal Data We Collect
We collect personal data that you voluntarily provide to us and data that is automatically generated when you use the Service.
3.1 Data you provide
- Account information: name, email address, and password (managed via Clerk Authentication).
- Photo strips and images: photo booth strips you upload or that are delivered to you through the Service.
- Communications: messages or queries you send to us by email or through any support channel.
3.2 Data collected automatically
- Device and usage data: IP address, browser type, operating system, and pages visited, collected via Cloudflare and Vercel analytics.
- Cookies and similar technologies: session identifiers and preference cookies. See Section 10 for details.
- Log data: server logs generated when our RunPod inference service processes your uploaded images.
4. Why We Collect Your Personal Data
We collect and use personal data only for the purposes described below, which we consider necessary to provide the Service or which you have consented to:
- Account creation and management: to register your account, authenticate your identity, and maintain your profile.
- Service delivery: to receive, process, and deliver photo strip memories to you via email (powered by Resend) and through the in-app scrapbook editor.
- Image processing: to run our photo strip detection and cropping pipeline on images you upload.
- Customer support: to respond to your inquiries and resolve issues.
- Service improvement: to analyse aggregated usage patterns and improve the performance and features of the Service. This analysis uses anonymised or aggregated data wherever possible.
- Security and fraud prevention: to detect, investigate, and prevent fraudulent transactions, abuse, and other illegal activities.
- Legal compliance: to comply with applicable laws, regulations, and legal processes in Singapore.
We will not use your personal data for any purpose not listed above without first notifying you and, where required, obtaining your consent.
5. Disclosure of Personal Data to Third Parties
We share personal data only to the extent necessary to operate the Service. Our current third-party service providers include:
- Clerk (US): identity and authentication management.
- Supabase (US): database hosting and storage (PostgreSQL).
- Vercel (US): web hosting and edge network.
- Cloudflare (US): content delivery network and DDoS protection.
- RunPod (US): serverless GPU compute for image processing.
- Resend (US): transactional email delivery.
Each of these providers acts as a data processor on our behalf. We have assessed or will assess each provider to ensure they maintain appropriate data protection standards comparable to those required under the PDPA, including through contractual safeguards.
We do not sell, rent, or trade your personal data to any third party for their own marketing purposes.
We may disclose personal data if required to do so by law, court order, or a government authority in Singapore, or if we reasonably believe disclosure is necessary to protect the rights, property, or safety of ReStrip, our users, or the public.
6. Transfer of Personal Data Outside Singapore
As our service providers are located outside Singapore (primarily in the United States), your personal data will be transferred to, stored in, and processed in countries outside Singapore. When we transfer personal data internationally, we take steps to ensure that the recipient provides a standard of protection comparable to that under the PDPA. These steps may include:
- Entering into binding contractual arrangements with the recipient that require them to maintain adequate data protection standards;
- Ensuring the recipient is subject to laws or regulations that provide comparable protection to the PDPA; or
- Obtaining your consent to the transfer.
7. Retention of Personal Data
We retain personal data only for as long as it is necessary to fulfil the purposes for which it was collected, or as required by applicable law. Our general retention periods are:
- Account data: for the duration of your account.
- Photo strips and uploaded images: as specified in the Service settings or until you delete them. If no explicit retention preference is set, images are retained for an indefinite time after delivery.
When personal data is no longer required, we will delete or anonymise it securely.
8. Protection of Personal Data
We implement reasonable technical and organisational security measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:
- AES-256-GCM encryption for sensitive data at rest.
- Row-Level Security (RLS) on our Supabase/PostgreSQL database, ensuring users can only access their own data.
- HTTPS/TLS encryption for all data in transit.
- Access controls limiting personal data access to authorised personnel only.
- Regular review of our security practices.
While we take reasonable steps to protect your personal data, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.
9. Your Rights Under the PDPA
Subject to certain exceptions under the PDPA, you have the following rights in respect of your personal data held by us:
9.1 Right of Access
You may request access to the personal data we hold about you and information about how it has been used or disclosed in the past year. We will respond to your request within 30 calendar days of receipt, or notify you if more time is required.
9.2 Right of Correction
If you believe that any personal data we hold about you is inaccurate, incomplete, or misleading, you may request that we correct it. We will correct the data as soon as practicable.
9.3 Withdrawal of Consent
Where you have given consent to our processing of your personal data (for example, for marketing communications), you may withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal. Please note that withdrawing consent for certain purposes may affect our ability to provide the Service to you.
To exercise any of the above rights, please contact our DPO at the details in Section 12. We may need to verify your identity before processing your request.
10. Cookies and Tracking Technologies
We use cookies and similar technologies on restrip.app. Cookies are small text files stored on your device that help us provide and improve the Service.
10.1 Types of cookies we use
- Strictly necessary cookies: required for the Service to function (e.g. authentication session cookies). These cannot be turned off.
- Analytics cookies: help us understand how users interact with the Service. We use aggregated, anonymised data for this purpose.
- Preference cookies: remember your settings and preferences.
11. Children’s Personal Data
The Service is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13 without verified parental consent. If we become aware that we have inadvertently collected personal data from a child under 13 without appropriate consent, we will take steps to delete that data promptly.
Users aged 13 to 17 may use the Service, but we encourage parents and guardians to be involved in their use of the Service. In accordance with the PDPC’s Children’s Personal Data Guidelines, we take additional care to present information in a clear and age-appropriate manner for young users.
12. Data Breach Notification
In the event of a data breach involving your personal data that is likely to result in significant harm to you or is of a significant scale, we will:
- Notify the PDPC as soon as practicable, and in any case within 3 calendar days of assessing that the breach is notifiable, in accordance with the PDPA’s Mandatory Data Breach Notification requirement.
- Notify affected individuals as soon as practicable where the breach is likely to result in significant harm to them.
We maintain internal incident response procedures to detect, assess, and respond to data breaches.
13. Contact Our Data Protection Officer
If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or wish to make a complaint about how we have handled your personal data, please contact our DPO:
- Operated by: Bek Joon Hao
- Email: privacy@restrip.app
We will acknowledge your request within 5 business days and respond substantively within 30 calendar days. If you are not satisfied with our response, you may lodge a complaint with the PDPC at www.pdpc.gov.sg.
14. Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make material changes, we will notify you by:
- Posting the updated Privacy Policy on restrip.app with a revised effective date; and
- Sending you an email notification if the change materially affects your rights or how we process your personal data.
Your continued use of the Service after the effective date of any update constitutes your acceptance of the revised Privacy Policy. We encourage you to review this page periodically.
ReStrip · restrip.app · privacy@restrip.app