Legal

Privacy Policy

Last updated: 29 July 2026

This Privacy Policy explains what personal data PolyPath collects when you use the app, why we collect it, how we use it, and the rights you have over it. PolyPath is operated as a sole trader based in Singapore and complies with the Singapore Personal Data Protection Act 2012 (PDPA).

1. Who we are

PolyPath ("PolyPath", "we", "us") is a private network for multi-passionate professionals, operated by a sole trader trading under the name "PolyPath" from Singapore. We act as the data controller of the personal data described below. If you have any questions about this policy or want to exercise any of your rights, please contact us through our Support page.

2. What data we collect

Data you give us directly

  • Account details: email address, password (stored hashed), display name.
  • Profile details: bio, skills, interests, goals, and any profile photo you upload.
  • Content you create: discussion posts, replies, direct messages, connection requests, and support tickets.
  • Billing details: name and payment card information you enter into our payment provider (Stripe). We do not see or store your full card number.

Data collected automatically

  • Basic technical data such as IP address, browser type, device type, and pages viewed, used to keep the app secure and working.
  • A small number of essential cookies and similar storage to keep you signed in and remember your preferences. See our Cookie Policy.

Data we do not collect

We do not use third-party analytics, advertising trackers, or marketing pixels.

3. How we use your data

  • To provide the service — creating your account, matching you with peers, delivering messages, and running the discussion channels.
  • To process payments and manage your subscription.
  • To send service and support communications (for example, replies to your support tickets or important account notices).
  • To keep the service safe — preventing fraud, abuse, and breaches of our Acceptable Use Policy.
  • To comply with legal obligations that apply to us in Singapore.

4. Legal bases

Under the PDPA we rely primarily on your consent (given when you sign up and use the app) and on the "legitimate interests" and "contractual necessity" bases recognised in the PDPA — for example, to deliver the paid subscription you have purchased or to keep the platform secure. If the GDPR or UK GDPR applies to you, we rely on the equivalent lawful bases (contract performance, legitimate interests, consent, and legal obligation).

5. Who we share data with

We only share personal data with the service providers we need to run the app:

  • Lovable Cloud (Supabase) — database, authentication, and file storage.
  • Stripe — payment processing and subscription billing.

We do not sell your personal data, and we do not share it with advertisers. We may disclose data if we are legally required to do so, or to protect our rights and the safety of other members.

6. International transfers

Our service providers may process data outside Singapore (including in the United States and the European Union). Where we transfer personal data outside Singapore, we take reasonable steps under the PDPA to ensure it receives a comparable standard of protection.

7. How long we keep data

  • Account and profile data — for as long as your account is active.
  • Messages and posts — until you or we delete them, or you delete your account.
  • Billing records — for as long as required by Singapore tax and accounting law (generally 5 years).
  • Support tickets — up to 3 years after the ticket is closed, so we can help you if you contact us again.

When you delete your account, we remove your personal data and cancel any active subscription, except records we are legally required to keep.

8. Your rights

You can, at any time:

  • Access and update your profile details in the app.
  • Withdraw consent or ask us to correct, restrict, or delete your personal data.
  • Request a copy of the personal data we hold about you.
  • Delete your account from the Account page, which also cancels any active subscription.

To exercise these rights, contact us through the Support page. We will respond within 30 days, as required by the PDPA.

9. Security

We use encrypted connections (HTTPS), managed cloud infrastructure, and row-level security rules so that members can only access their own data. No system is perfectly secure, but we work in good faith to keep your data safe.

10. Children

PolyPath is not intended for anyone under 16. Please do not use the service if you are under this age.

11. Changes to this policy

We may update this policy from time to time. When we do, we will update the "Last updated" date above and, for material changes, notify you in the app.

12. Contact

Questions or complaints? Please use our Support page. You also have the right to lodge a complaint with the Personal Data Protection Commission of Singapore (PDPC).