How we handle your personal data under Singapore's PDPA — what we store, how we use it, and the controls you have over it.
Last updated: 9 May 2026
Singapore PDPA-compliant
We follow the Personal Data Protection Act 2012 and notify the PDPC if a notifiable breach occurs.
Limited sharing
We never sell your data. Creators receive only what's needed to fulfil rewards (name, email, shipping address).
You're in control
Download your data anytime via /api/me/export. Email our DPO to access, correct, or delete records we hold.
get that bread (“we”, “us”, “the platform”) is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you use our crowdfunding marketplace at getthatbread.sg.
This policy complies with Singapore's Personal Data Protection Act 2012 (PDPA). By using get that bread, you consent to the data practices described in this policy.
For any privacy-related request or question, contact our Data Protection Officer (see Section 15).
get that bread is a crowdfunding marketplace platform — not a retailer, manufacturer, or direct seller of any goods or services. We provide technology infrastructure that enables independent creators (“Creators”) to raise funds from backers (“Backers”) in exchange for rewards.
Creators are independent third parties.They are not our employees, agents, representatives, or partners. We do not control, direct, or supervise Creators in their conduct, fulfilment of rewards, or handling of personal data. When you interact with a Creator's campaign, you are engaging with that Creator as an independent party, not with us.
This distinction matters for your privacy: once personal data is shared with a Creator for reward fulfilment, that Creator becomes an independent data controller under the PDPA and is solely responsible for how they handle that data. We explain this in detail in Sections 5 and 9.
We collect the following categories of personal data:
We use your personal data to:
We do not sell your personal data. We share data only in the following circumstances:
We share data with the following service providers solely to operate the platform:
When you pledge to a campaign, we may share the following data with the Creator to enable reward fulfilment:
This data is shared on the basis that it is necessary to fulfil the reward you have requested. We share only what is reasonably required for that purpose.
Once personal data has been shared with a Creator for fulfilment purposes, that Creator acts as an independent data controller under the PDPA. This means:
By launching a campaign on get that bread, Creators agree to our Terms of Service, which require them to:
However, we do not guarantee Creator compliance with these obligations. If you believe a Creator has misused your personal data, please contact us at hello@getthatbread.sg — we will take reasonable steps to investigate and, where appropriate, take action against that Creator under our Terms.
We may also disclose your data if required by law, court order, or government or regulatory authority in Singapore.
Some of our service providers process personal data outside Singapore. When we transfer data to them, we do so on the basis that (a) the recipient country provides a standard of protection comparable to Singapore's PDPA, or (b) contractual protections are in place requiring the recipient to provide a comparable level of protection.
We use Sentry's session replay feature to record only the sessions in which an error occurs. We do not record sessions under normal, error-free conditions.
When an error triggers a replay, Sentry captures DOM changes, mouse movement, clicks, navigation, and network request metadata for that session. Form input fields are configured with masking rules in Sentry's replay SDK — the content of input fields is not captured or transmitted. We cannot see what you typed.
Replays are used by our engineering team to reproduce and fix crashes. Recordings are retained by Sentry for 30 days and then deleted.
Creators are required to verify their identity before they can receive payouts. We support two paths and you may choose either:
When you click Allow on the Singpass consent screen, you authorise GovTech to disclose the following MyInfo fields to get that bread for the purpose of payout-eligibility verification:
We request only those five fields and no others. The list of fields requested is governed by the OIDC scopes registered for our Singpass developer account; we cannot request fields outside that registered scope.
From a successful Singpass verification we persist:
txnNo) returned by GovTech. This is our audit trail evidencing that you consented and what you consented to.How the UINFIN is protected: row-level security on the verifications table limits reads to the verified Creator (their own row) and authorised admins; no anonymous or other-user access is permitted. The separate hash column is keyed with a server-side pepper held only on our backend so duplicate-account checks can be done without scanning the raw values.
This data is used strictly for: payout-eligibility verification, anti-fraud (duplicate-account detection), and AML / counter-terrorism financing compliance. It is not used for marketing, not shared with any Backer or other Creator, and not shared with any third party except where legally required (for example, in response to a lawful order from a Singapore regulator or court).
Singpass-derived fields are accessible only to the Creator themselves (via their dashboard) and to platform admins performing compliance review. Access by admins is logged.
You may withdraw consent for our use of your Singpass-derived data at any time by emailing our DPO (Section 16). Withdrawal results in your creator account being closed, because payout eligibility cannot be maintained without verified identity. Records subject to AML retention obligations (see Section 9) will be retained for the legally required period after closure but will not be used for any other purpose.
We collect this data on the basis of your consent (PDPA section 13) given at the Singpass screen, and on the basis that it is necessary for compliance with legal obligations applicable to a payment-related platform operating in Singapore (PDPA First Schedule, Part 3). Where the two bases overlap, the legal-obligation basis governs records we are required by law to retain.
Different categories of data are retained for different periods depending on the legal and operational reason we hold them.
Legal and financial retention obligations override deletion requests for affected records — when you exercise your PDPA rights, we'll confirm which records fall under this.
Creator-held data:Once personal data has been shared with a Creator to fulfil a reward, we have no visibility into or control over that Creator's retention practices. We cannot guarantee that a Creator will delete your data on request. For any data held independently by a Creator, you must contact that Creator directly.
Under Singapore's PDPA, you have the right to:
Self-service download.If you're signed in, you can download a copy of the personal data we hold about you (profile, pledges, creator application, dispute concerns, campaign drafts) at /api/me/export — the response is a structured JSON file you can save locally. Self-service covers the data we hold about you directly; for anything held by Creators or third-party processors, email the DPO below.
Other rights. To request correction, withdrawal of consent, or account deletion (subject to retention obligations for completed transactions and AML records), email our Data Protection Officer at hello@getthatbread.sg. We respond within 30 days as required by the PDPA. We may verify your identity before acting on access or correction requests to protect you against impersonation.
Scope of your rights under this policy: Your PDPA rights under this policy apply only to personal data that we hold and process as data controller. For personal data held by Creators or third-party service providers acting as independent data controllers (see Section 5), you must exercise your rights directly with those parties. We are not able to act as an intermediary for such requests.
We take reasonable technical and organisational measures to protect the personal data we hold, including HTTPS encryption, hashed passwords, and row-level security on our database. Data is encrypted at rest by our infrastructure providers. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
These measures apply to personal data we directly hold and process. We do not control the security practices of Creators or other independent data controllers to whom data may be disclosed in accordance with this policy, and we are not responsible for any security incidents affecting data held by those parties.
Singapore's Personal Data Protection (Notification of Data Breaches) Regulations 2021 require us to assess data breaches against the notifiability thresholds and, where notifiable, notify the Personal Data Protection Commission (PDPC) and affected individuals. We follow the process below.
If you suspect a security incident affecting your account, contact our DPO immediately at hello@getthatbread.sg.
To the fullest extent permitted by law, we are not liable for any loss, damage, or harm arising from the actions of third parties — including Creators, payment processors, or analytics providers — in relation to personal data shared with them in accordance with this policy.
Our liability is limited to personal data that we directly hold and process as data controller. We are not responsible for:
Nothing in this section limits or excludes our liability for our own negligence, fraud, or wilful misconduct, or any liability that cannot be excluded under Singapore law.
get that bread is not intended for users under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has registered on our platform, please contact us immediately.
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on the platform. Your continued use of get that bread after changes take effect constitutes your acceptance of the updated policy.
Our Data Protection Officer can be reached at: hello@getthatbread.sg
This mailbox handles all PDPA rights requests, privacy questions, and any concerns about how we use your data. We respond within a business day for general questions and within 30 days for formal PDPA requests.