Last updated: 02/09/2026
This Privacy Policy explains how Basementgrid Pte Ltd ("Basementgrid", "we", "us", or "our"), a company incorporated in Singapore with its registered address at 7 Temasek Boulevard, #12-07 Suntec Tower One, Singapore 038987, collects, uses, discloses, and protects personal data in connection with the Basementgrid platform (the "Service"), in accordance with Singapore's Personal Data Protection Act 2012 ("PDPA").
This Policy should be read together with our Terms of Service, which governs use of the Service generally. Capitalized terms not defined in this Policy have the meaning given to them in the Terms of Service (for example, "Workspace," "Workspace Owner," "Account," "Content," and "Vendor").
By creating an Account or using the Service, you consent to the collection, use, and disclosure of personal data as described in this Policy, to the extent such consent is required under the PDPA.
1. Who This Policy Applies To
This Policy applies to personal data of all individuals who interact with the Service through a Workspace, regardless of Role — including Administrators, Approvers, Collaborators, Requesters, Vendor Managers, and Vendor Technicians, as those Roles are described in our Terms of Service.
Where a Workspace Owner (typically an MCST or Managing Agent) invites or adds other individuals to its Workspace — for example, an Administrator adding a resident as a Requester, or a Vendor Manager adding a Vendor Technician — that Workspace Owner or Vendor is responsible for ensuring it has the appropriate basis to share that individual's personal data with us for the purposes described in this Policy.
2. Personal Data We Collect
2.1 Workspace Registration Data
When a Workspace is created, the Administrator setting it up provides:
- The Workspace's Unique Entity Number (UEN)
- The estate or building address
- The Workspace's financial year
- The spending threshold amount above which Approver sign-off is required for vendor quotes or work order expenses
2.2 Account and Occupant Data
Once a Workspace is created, Administrators may invite other individuals as Accounts. Depending on their Role, this may include:
- Email address (all Roles, for login and notifications)
- Unit number and unit role — owner or tenant (Requesters)
- Vehicle number and access card details (Requesters, where provided to help Administrators manage estate access)
- Name and company/vendor affiliation (Vendor Managers and Vendor Technicians)
This information is provided to us by the Workspace Owner (via its Administrators) to help that Workspace Owner manage its own occupants, staff, and vendors. We do not independently verify or supplement this data, and we do not use it for any purpose beyond providing the Service to that Workspace.
2.3 Work Order and Operational Content
In the course of using the Service, Accounts may submit or generate: work orders, defect reports, asset and location records, status updates, photos (including GPS-tagged photos uploaded during field work), comments, and vendor quotes. Collectively, this and the data described in Sections 2.1 and 2.2 form part of a Workspace's "Content," as defined in our Terms of Service.
2.4 Financial and Payment-Related Data
Where a Workspace uses paid features or vendor payment tracking, we may hold: invoices and tax invoices, transaction histories, payout logs, vendor UENs (used to generate PayNow QR codes, as described in our Terms of Service), and billing contact details for the Workspace Owner. As explained in our Terms of Service, Basementgrid does not process, hold, or transmit the funds themselves — PayNow payments made using a QR code generated within the Service go directly to the Vendor's own bank account.
2.5 Technical Data
We may automatically collect limited technical data needed to operate the Service, such as login timestamps, device and browser information, and error/diagnostic logs. We do not use cookies. We use Firebase Crashlytics, a third-party crash reporting tool, which logs technical data associated with application crashes (such as device information and crash logs) to help us identify and fix bugs.
3. How We Use Personal Data
We use personal data collected through the Service solely to provide, maintain, and support the Service for the relevant Workspace, including to:
- Create and manage Accounts, and enforce Role-based access as described in our Terms of Service
- Enable Administrators to manage occupants, staff, and Vendors within their Workspace
- Route, track, and display work orders, quotes, and approvals between Roles
- Generate PayNow QR codes for Vendor work orders
- Process billing for paid Subscription Plans
- Provide customer support and respond to enquiries
- Maintain the security, integrity, and proper functioning of the Service
- Comply with our legal obligations, including record-keeping requirements under IRAS
We do not use Workspace Content or personal data for advertising, do not sell personal data, and do not use it to build profiles for any purpose unrelated to providing the Service to the Workspace it belongs to.
3.1 Marketing Communications
By creating an Account, you also agree that we may send marketing and promotional communications to the email address associated with your Account, such as updates about new features, tips for using the Service, and other Basementgrid news. Every marketing email we send includes an unsubscribe link, and you may opt out of receiving further marketing communications at any time by using that link or by contacting us at legal@basementgrid.com. Opting out of marketing communications does not affect our ability to send you transactional or service-related communications (such as billing notices, Payment Receipts, or Account security alerts), which are necessary for us to provide the Service.
4. Legal Basis for Collection and Use
We collect, use, and disclose personal data based on the consent of the individual or the Workspace Owner acting on their behalf, or where permitted or required without consent under the PDPA — for example, where reasonably necessary to provide the Service under a contract, or to comply with a legal obligation such as IRAS record-keeping requirements.
5. Disclosure of Personal Data
5.1 Within a Workspace
Personal data is visible within a Workspace only to the extent permitted by the Role-based access model described in our Terms of Service. For example, occupant personal data such as unit role, vehicle number, and access card details is restricted to Administrator-level Accounts, and a Vendor's roster of Vendor Technicians is private to that Vendor's own Vendor Manager and not exposed to the estate's Administrators.
5.2 Service Providers
We engage third-party service providers to help us operate the Service. This includes Amazon Web Services (AWS), which hosts our database and infrastructure (currently located in the AWS Tokyo, Japan region), and Firebase Crashlytics, which we use for crash reporting as described in Section 2.5. Any such provider is only given access to personal data to the extent necessary to perform its function for us, and is required to protect that data consistently with this Policy and the PDPA.
5.3 No Sale of Personal Data
We do not sell, rent, or trade personal data to third parties.
5.4 Legal Disclosures
We may disclose personal data where required by law, regulation, court order, or governmental authority, or where necessary to establish, exercise, or defend legal claims.
6. Data Retention
We retain personal data and Content for as long as the relevant Workspace remains active, and thereafter in accordance with this section and our Terms of Service.
- On the Free Plan, access to work orders is limited to those created within the past 90 days; older work orders remain stored but are not accessible unless the Workspace upgrades to a paid Subscription Plan (see our Terms of Service, Section 2.3).
- Where a Workspace Owner requests deletion of all Workspace data (see Section 7 below), we will delete Content and personal data within thirty (30) days of confirming a verified request.
- Notwithstanding the above, invoices and tax invoices, transaction histories, payout logs, and merchant/Workspace identification details tied to financial records are retained for a minimum of five (5) years from the date the Workspace is closed, in order to comply with record-keeping requirements of the Inland Revenue Authority of Singapore (IRAS).
7. Your Rights and Choices
7.1 Access and Correction
You may request access to, or correction of, personal data we hold about you by contacting us at legal@basementgrid.com. Where personal data was provided to us by a Workspace Owner (for example, occupant details entered by an Administrator), we may direct your request to that Workspace Owner where appropriate, as they control that data.
7.2 Withdrawing Consent
You may withdraw consent to our collection, use, or disclosure of your personal data at any time by contacting legal@basementgrid.com, subject to legal or contractual restrictions. Withdrawing consent may limit or prevent your ability to use certain features of the Service, or the Service as a whole.
7.3 Deletion
A Workspace Owner may request deletion of all data associated with its Workspace by writing to legal@basementgrid.com. We require proof of identity and authority to act for the Workspace Owner, together with a signed undertaking, before processing such a request. Full details of this process, including the records we are required to retain notwithstanding a deletion request, are set out in our Terms of Service (Section 7.4) and in Section 6 of this Policy.
8. Data Security
We implement reasonable technical and organizational measures designed to protect personal data against unauthorized access, collection, use, disclosure, or similar risks, in accordance with our obligations under the PDPA. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Among these measures, we restrict visibility of work orders and related data within a Workspace according to Role:
- Administrators can view all work orders within their Workspace.
- Collaborators can view only work orders they created or to which they are assigned.
- Requesters can view only work orders they themselves reported.
- The Documents and Amount fields within a work order's Commercials section are visible only to users who otherwise have access to that work order, with the exception of Vendor Technicians, who cannot view the Commercials section at all, regardless of their access to the underlying work order.
9. Overseas Transfer of Personal Data
Our database and infrastructure are hosted with Amazon Web Services (AWS) in the AWS Tokyo, Japan region. This means personal data is stored and processed outside Singapore. We rely on AWS's standard Data Processing Addendum, which contractually binds AWS to data protection commitments, as the legally enforceable safeguard ensuring this transfer meets the standard of protection comparable to the PDPA, as required under Section 26 of the PDPA.
10. Children's Privacy
The Service is intended for use by adults acting on behalf of an MCST, Managing Agent, Vendor, or as a resident/tenant Requester. We do not knowingly collect personal data from children.
11. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will provide reasonable notice (such as by email or in-app notice) before the changes take effect. Continued use of the Service after the updated Policy takes effect constitutes acceptance of the updated Policy.
12. Contact Us
If you have questions, requests, or complaints about this Policy or how we handle personal data, please contact our Data Protection Officer at:
Basementgrid Pte Ltd
7 Temasek Boulevard, #12-07 Suntec Tower One, Singapore 038987
Data Protection Officer: legal@basementgrid.com