Simpli Diner Privacy Policy

Last updated: 30 July 2026

This Privacy Policy explains how Simpli Private Limited ("Simpli", "we", "us", "our"), a company incorporated in Singapore, handles your personal data when you use the Simpli diner experience: scanning a table QR code, browsing a menu, placing and paying for an order, and any Simpli account or profile you create. It is written to meet Singapore's Personal Data Protection Act 2012 (PDPA), which is the law that governs how we handle your data.

Simpli is at an early (pilot) stage. This policy describes what we actually do today, and we have tried to be honest about what is and is not built. Where a right is exercised by writing to us rather than by a button in the app, we say so plainly.

Simpli helps you order and pay, and it never gives medical advice. Any dietary or health information is used only to label or flag menu items for you, not to diagnose or treat any condition.


1. Who we are and how to contact us

Simpli Private Limited is the company responsible for the Simpli diner service in Singapore.

For any privacy question, request, or complaint, contact our Data Protection Officer (DPO):

You can reach the DPO about anything in this policy, including seeing a copy of your data, correcting it, withdrawing consent, or asking us to delete your account.

Who is responsible for which data (the controller split)

Two organisations may be responsible for your data, and it helps to know which:


2. What we collect, and why

We only collect what we need to let you order and pay, to run and secure your account, and (with your separate consent) to build your dining profile. Here is the full picture.

2.1 Ordering as a guest (no account, no app)

If you just scan a table QR code and order in your browser, you can do so without giving us any name, email, or phone number. To make guest checkout work we create a temporary guest session that stores only which restaurant and table you are at, a secured (hashed) session token, and an expiry time. We do not require real personal details to order as a guest.

2.2 Your account (if you create or sign in to one)

If you create a Simpli account, sign in, or turn a guest session into a profile, we collect and store:

We offer three ways to sign in: email and password, a one-time code sent to your email, or Google. If you use the email-code method, we store the login code in secured (hashed) form only, and it can be used once before it expires.

We use this data to sign you in, keep your account secure, and power your portable dining identity.

2.3 Your orders

When you place and pay for an order, we record the order and its items, the quantities, the prices and totals, GST and any service charge, the payment and fulfilment status, and the restaurant and table. We also capture the meal period and day of week of the order so that, in future, we can make dining discovery more relevant to you. If you add a free-text note to an item (for example a special request), that note is stored with the order.

We use this to fulfil your order, show you your order history and receipts, and (see section 2.6) build the record of your dining behaviour.

2.4 Dietary and health information (sensitive, and only if you choose to give it)

You can optionally tell us about dietary needs and health preferences. This is sensitive personal data and we treat it with extra care. It comes in two separate places:

This information is used only to label or flag menu items and to alert the kitchen. It is not medical advice and not a medical diagnosis, and it is not treated as US-regulated health information (Simpli has no US healthcare use). We will say an item "may not fit your selected preferences", never that it is "unsafe for your condition".

2.5 Payments (we never see or store your card number)

Payments are processed by Stripe. Your card details are entered directly into Stripe's secure fields. Simpli never receives or stores your full card number, security code (CVV), or expiry date. On a completed payment, the only card-related detail we keep is the card network name (for example "visa" or "mastercard"), together with Stripe references, the payment method type (card, PayNow, or wallet), the amount, and the status.

Because of how Simpli is set up (Stripe Connect direct charges), your payment is made to the restaurant's own Stripe account, the restaurant is the seller of record, and Simpli never holds your funds. Simpli only collects a small platform fee. If you save a payment method, the saved-card details (brand, last four digits, expiry) are fetched live from Stripe when you view them and are not stored by us.

2.6 Your dining behaviour and social activity

As you use Simpli, we build a record of your dining behaviour, which is the heart of the service. This can include:

We use this to power your dining identity, your history, the social features, and popularity signals shown to other diners. Popularity and quality signals are computed only from real completed orders. We do not let any restaurant pay to change where it ranks.

2.7 Device and notification data

If you use the Simpli mobile app and enable notifications, we store a push notification token, a device identifier, the platform, and the app version so we can send you order-status updates. We also keep a record of the notifications we send you.

2.8 Table bookings (where offered)

If you book a table, we collect the contact name, contact phone number, party size, any note you add, and the booking time, plus deposit details where a deposit applies. This feature is being introduced and may not be available everywhere yet.

2.9 Security and audit records

For money-related and security-sensitive actions, we keep an audit record that can include your IP address and browser or device information (user agent), along with a request identifier and a masked summary of the action (identifiers, amounts, and status only, never card data or secrets). This is kept for accountability and to investigate problems. It is limited to sensitive actions and is not a general tracking log of everything you do.

2.10 Marketing consent

If you opt in to marketing, we record your consent per channel (email, and in future WhatsApp or SMS), when you granted it, and when you withdrew it. Marketing is off by default and is never bundled into creating an account: nothing is recorded unless you actively opt in. Only email marketing is live today. Every change is logged.

2.11 Insights we derive from your behaviour

Simpli may build a derived "taste profile" from your order history to help improve dining discovery in the future. This is an inferred profile, not something you enter. Today this capability is early and is turned off from the diner experience by default: it is not driving a live personalised recommender that you see. If and when we switch on personalised recommendations, we will do so consistently with this policy.


3. When we ask for consent

Service messages you need (order confirmations, receipts, payment status) are not marketing and are sent as part of running your order.


4. Who we share your data with

We do not sell your personal data. We share it only with the following, and only as needed to run the service.

We may also disclose data where the law requires it, to protect our rights or safety, or as part of a business transfer, in each case consistent with the PDPA.


5. Sending data outside Singapore

Our servers and primary database run in Fly.io's Singapore region. However, several of the providers above (Stripe, Resend, Google, Zoho, Slack, and our media storage provider Tigris) process data outside Singapore. The PDPA allows this as long as the data continues to receive a comparable standard of protection, which we rely on through each provider's standard data-processing terms. We can provide our current list of providers and their locations on request to the DPO.


6. How long we keep your data

We keep personal data only as long as we need it for the purposes above or as the law requires.

We should be honest here: we do not yet run an automatic scheduled deletion process. Deleting or anonymising data on request is currently done by our team as an administrator action. If you want your data deleted, contact the DPO (see section 7).


7. Your rights under the PDPA, and how to use them

Under the PDPA you have the right to access the personal data we hold about you, to correct it, and to withdraw consent. Here is exactly how each works today, including where it is self-serve and where you need to email us.

| Your request | How it works today | |---|---| | See or get a copy of your data | Email the DPO at privacy@simpli.sg and we will provide a copy. There is no self-serve "download my data" button in the app yet. The copy we produce covers your profile, orders, reviews, dish ratings, marketing-consent history, and dietary/health profile. If you want other categories we hold (for example visit history, follows, notifications, or bookings), ask and we will include them. | | Correct your data | Self-serve in the app: you can edit your display name, bio, avatar, and your dietary/health profile yourself. | | Withdraw or change marketing consent | Self-serve: use the marketing toggle in your account settings, or the unsubscribe link in any marketing email. | | Withdraw dietary/health-data consent | Self-serve: set your guidance mode to off, or clear your dietary/health profile in the app. | | Remove a review | Self-serve: you can delete a review you posted. | | Remove a saved payment method | Self-serve: you can delete a saved card, which removes it at Stripe. | | Delete your account (erasure) | Email the DPO at privacy@simpli.sg. Account deletion is not a self-serve button today; we handle it as an administrator action so that legally required order and tax records are dealt with correctly. |

We will respond to requests within the timeframe required by the PDPA. We may need to verify your identity first, and we may keep certain records where the law requires us to.

If you are not satisfied with how we handle your request, you may contact the Personal Data Protection Commission (PDPC) in Singapore.


8. How we protect your data

We use industry-standard measures to protect your data, including encryption in transit, provider-managed encryption at rest, hashed passwords and login codes, restricted access, rate limiting, and audit logging of sensitive actions. No system is perfectly secure, but we work to protect your data and to respond quickly if something goes wrong. In line with the PDPA, we will notify the PDPC, and affected individuals where required, if a notifiable data breach occurs.

To be clear about what we do not claim: Simpli is at pilot stage and does not hold SOC 2, ISO 27001, or HIPAA certification. Our compliance baseline is Singapore's PDPA. Because Stripe handles card data, Simpli's payment setup is PCI DSS SAQ-A, meaning we do not store raw card numbers.


9. Cookies and similar technologies

We use only the storage needed to make the service work, such as keeping you signed in and remembering your cart and language. We do not run third-party advertising trackers, and the IP and device information we keep is limited to the security and audit records described in section 2.9. If we add any analytics in the future, we will update this policy.


10. Children

Simpli is intended for adults ordering and paying at restaurants. It is not directed at children, and we do not knowingly collect personal data from children. If you believe a child has given us personal data, contact the DPO and we will address it.


11. Changes to this policy

We may update this policy as the service develops or as the law changes. When we do, we will change the "Last updated" date at the top. For material changes we will take reasonable steps to let you know.


12. Contact

For any question or request about your personal data, contact our Data Protection Officer:

Simpli Private Limited, Singapore.

Privacy Policy: Simpli | Simpli