Privacy Policy
Last Updated: 12 June 2026 Effective Date: 1 May 2026
This Privacy Policy explains how THE BRAND CANVAS PTE LTD ("we", "us", "our") collects, uses, discloses, and protects personal data in connection with the Revive platform ("Service"), available at https://revive.sg and its associated mobile applications.
By accessing or using the Service, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.
1. About this Policy
This Privacy Policy has been prepared in accordance with the Singapore Personal Data Protection Act 2012 (PDPA), as amended by the Personal Data Protection (Amendment) Act 2020.
It applies to all personal data we collect from users of the Service, including visitors to https://revive.sg and users of the Revive mobile application.
This Policy does not apply to:
- Third-party websites, services, or applications linked to from the Service
- Personal data collected by other organisations from which you obtain products or services
We may update this Privacy Policy from time to time. The most current version will always be available at https://revive.sg/privacy, and we will notify you of material changes via email or a prominent notice within the Service.
2. Personal Data
"Personal Data" means data, whether true or not, about an individual who can be identified from that data, or from that data and other information to which we have or are likely to have access.
This includes but is not limited to:
- Name, email address, phone number, and company name
- Account credentials and profile information
- Device identifiers and technical information
- Communications and content you submit through the Service
"Sensitive Personal Data" such as NRIC numbers, financial account details, or health information is not required by the Service and should not be shared via the platform.
3. Collection of Personal Data
We collect personal data in the following ways:
3.1 Information You Provide Directly
When creating an account:
- Full name
- Email address
- Phone number
- Company or business name
- Job title or role
- Password (stored as a one-way cryptographic hash; we cannot access your plaintext password)
When using the Service:
- Listing information: property, equipment, event, or job details, descriptions, photos, and pricing
- Chat messages sent between users within the platform
- Wishlist items and saved searches
- Support requests, feedback, and correspondence with us
3.2 Information Collected Automatically
When you use the Service, we automatically receive:
- IP address and approximate geolocation
- Browser type, version, and language settings
- Device type and operating system
- Pages visited, features used, time spent, and clickstream data
- Session tokens and authentication information
- Error logs and performance data
3.3 Push Notification Tokens
If you enable push notifications on your mobile device, we collect and store your device's push notification token to deliver real-time notifications about messages, listing activity, and platform updates. You may withdraw consent to push notifications at any time through your device settings or within the app.
3.4 Information from Third Parties
We do not currently obtain personal data from third parties. If this changes, we will update this Privacy Policy and notify you.
4. Purposes for the Collection, Use and Disclosure of Your Personal Data
We collect, use, and disclose your personal data for the following purposes:
| Purpose | Details |
|---|---|
| Account management | Creating, verifying, and maintaining your account |
| Service delivery | Displaying listings, facilitating chat, operating the wishlist, and matching users across property, equipment, event, and job listings |
| Push notifications | Sending alerts about new messages, listing status changes, and platform updates |
| Security and fraud prevention | Detecting and preventing fraudulent activity, abuse, and security incidents |
| Service improvement | Analysing usage patterns to improve features, stability, and user experience |
| Customer support | Responding to your inquiries and resolving disputes |
| Legal compliance | Meeting our obligations under applicable Singapore law |
| Business operations | Internal reporting, auditing, and administrative purposes |
| Marketing (with consent) | Sending promotional messages about the Service — only with your prior explicit consent |
We will not use your personal data for purposes beyond those listed above without obtaining your fresh consent, unless otherwise permitted by the PDPA.
5. Disclosure of Personal Data
We do not sell, rent, or trade your personal data. We may disclose your personal data in the following circumstances:
5.1 Within the Service
- Your public profile information (name, company, role) is visible to other registered users.
- Your listing content is visible to other registered users.
- Chat messages are shared only with the user(s) you communicate with directly.
- Your contact details are not shared automatically; you choose when to exchange them.
5.2 Service Providers (Data Processors)
We engage trusted third-party providers to operate the Service. Each provider is bound by data protection obligations:
| Provider | Purpose | Data Location |
|---|---|---|
| Supabase Inc. | Database, authentication, realtime, file storage | Singapore (ap-southeast-1) |
| Vercel Inc. | Web hosting and content delivery | Singapore (sin1) |
| Apple Push Notification service (APNs) | Push notification delivery | United States |
| Microsoft Azure | In-app message translation (Azure Translator) | Southeast Asia |
Where data is transferred to service providers outside Singapore, we ensure such transfers comply with Section 26 of the PDPA and that recipients provide a standard of protection comparable to the PDPA.
5.3 Legal and Regulatory Disclosures
We may disclose your personal data where required or permitted by law, including:
- Compliance with a Singapore court order, subpoena, or legal process
- Investigation by a Singapore government authority or regulatory body
- Protection of the rights, property, or safety of the Company, our users, or the public
5.4 Business Transfers
In the event of a merger, acquisition, restructuring, or sale of all or part of our business, your personal data may be transferred to the acquirer or successor entity. We will notify you of any such change via email or a prominent notice on the Service before your data is transferred and becomes subject to a different privacy policy.
6. Protection of Personal Data
We implement reasonable technical and organisational security measures to protect your personal data from unauthorised access, disclosure, alteration, and destruction. These include:
- Encryption in transit: All data transmitted between your device and our servers is protected using HTTPS/TLS.
- Encryption at rest: Databases and file storage are encrypted by Supabase.
- Access controls: Row-Level Security (RLS) policies restrict data access to authorised users only.
- Authentication: Passwords are stored as cryptographic hashes; we use secure session tokens.
- Infrastructure security: We rely on enterprise-grade hosting providers (Supabase, Vercel) with SOC 2 compliance.
- Internal access: Access to production data is limited to authorised personnel on a need-to-know basis.
No system is completely secure. You are responsible for keeping your account password confidential and for notifying us immediately if you suspect unauthorised access to your account.
Data Breach Notification: In the event of a data breach that meets the notifiable data breach threshold under the PDPA, we will notify the Personal Data Protection Commission (PDPC) within 3 calendar days and notify affected individuals as soon as practicable.
7. Retention of Personal Data
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law.
| Data Category | Retention Period |
|---|---|
| Active account data (profile, listings, messages) | While your account is active |
| Account data after deletion | Up to 12 months from deletion date (fraud prevention and legal compliance), then deleted or anonymised |
| Chat messages | While both parties maintain active accounts |
| Deleted listings | 30 days in soft-delete state, then permanently deleted |
| Server and access logs | Up to 90 days |
| Backup snapshots | Up to 90 days |
| Push notification tokens | Deleted or deactivated upon account closure or explicit revocation |
Data may be retained for longer periods where required by law (for example, financial records under tax legislation) or for the resolution of active disputes.
8. Cookies
We use cookies and similar tracking technologies to operate and improve the Service. The types of cookies we use are:
| Type | Purpose | Can be disabled? |
|---|---|---|
| Strictly necessary | Session management, authentication, security | No — required for login |
| Functional | Remembering your language and display preferences | Yes, with reduced functionality |
| Analytics | Aggregate, anonymised usage statistics to improve the Service (progressively being introduced) | Yes |
We do not use third-party advertising or retargeting cookies.
How to manage cookies: You can control and delete cookies through your browser settings. Please note that disabling strictly necessary cookies will prevent you from logging in to the Service.
For mobile app users, local storage and device identifiers (including push notification tokens) are used in place of browser cookies.
9. Withdrawal of Consent, Access and Correction of Your Personal Data
9.1 Withdrawal of Consent
You may withdraw your consent to the collection, use, or disclosure of your personal data at any time by contacting our Data Protection Officer at the address in Section 10.
Please note that withdrawal of consent may affect our ability to provide the Service to you. In some cases, withdrawal may require account closure.
Specific withdrawals you may make:
- Withdraw consent to push notifications: via your device settings or the in-app notification settings under Profile → Notifications.
- Withdraw consent to marketing communications: via the unsubscribe link in any marketing email, or by contacting our DPO.
9.2 Access and Correction
Under the PDPA, you have the right to:
Access your personal data: Request a copy of the personal data we hold about you, and information about how it has been used or disclosed in the past 12 months.
Correct your personal data: Request that we correct any inaccurate, incomplete, or misleading personal data we hold about you.
How to submit a request:
Submit your request in writing to our Data Protection Officer (see Section 10). Please provide:
- Your full name and registered email address
- A description of the personal data you wish to access or correct
- For correction requests: the corrected information you wish to update
We will respond to your request within 30 days of receipt. We may charge a reasonable fee for access requests as permitted by the PDPA. If we are unable to fulfil your request (for example, if providing access would reveal personal data of another individual), we will inform you of the reason.
10. Contact Us
For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact our Data Protection Officer:
Data Protection Officer Hanae Ikehata THE BRAND CANVAS PTE LTD
Email: support@revive.sg Website: https://revive.sg
Registered Address: 101 Cecil Street, #10-04 Tong Eng Building Singapore 069533
Mailing Address: 101 Cecil Street, #10-04 Tong Eng Building Singapore 069533
11. Governing Law
This Privacy Policy and any dispute arising from it shall be governed by and construed in accordance with the laws of the Republic of Singapore.
Any claims or disputes relating to your personal data or this Privacy Policy shall be subject to the non-exclusive jurisdiction of the courts of Singapore.