Privacy Policy

Last updated: 2026-04-16

1. Who we are

SafetyHub SG is a construction-site safety-management platform operated by TL Advance ("we", "us"). We help main contractors and subcontractors in Singapore manage Permit-To-Work (MOM ePTW), daily checklists, site inspections, toolbox meetings, heat-stress monitoring, and equipment registers.

2. What data we collect

  • Account data: name, email, phone number, organization affiliation, and project role (applicant, verifier, approver, or admin).
  • Work records: permits, daily checklists, inspection findings, toolbox meeting minutes, weekly WBGT readings, and equipment certificates you create in the app.
  • Personnel data: worker names and, where applicable, NRIC or FIN numbers assigned to permits. NRIC and FIN values are encrypted at rest using AES-256.
  • Media: photos you upload for permit attachments, inspections, WBGT thermometer readings, equipment certificates, and water-parade checks, plus digital signatures captured during permit workflow.
  • Location: project postal code (from which we derive the site latitude and longitude for weather estimation) and GPS coordinates you optionally attach to individual permits.
  • Technical: authentication session cookies and standard server logs (IP address, user agent) retained for security and abuse prevention.

3. How we use your data

  • To operate the permit workflow and related safety modules in compliance with Singapore MOM ePTW requirements.
  • To deliver email and in-app notifications about permit actions (submission, verification, approval, closure).
  • To generate PDF reports for permits, WBGT, inspections, and related records.
  • To provide statutory record-keeping required by MOM and workplace-safety regulations.
  • To improve the service: diagnose errors, monitor performance, and guide product decisions. We do not use your data to train machine-learning models.

4. Third parties we share data with

We rely on the following service providers to run the platform. We do not sell your data to anyone.

  • Supabase — database, authentication, and file storage. Data is stored in the Asia-Pacific region.
  • Vercel — application hosting and CDN delivery.
  • Resend — transactional email delivery (permit-state notifications).
  • data.gov.sg — we fetch public weather readings from NEA's Realtime API. We do not transmit any user or project data to data.gov.sg.
  • OneMap Singapore — we send only the project postal code (not personal data) to obtain latitude and longitude.
  • cron-job.org — scheduled triggers for our background jobs. No user data is transmitted.

5. Data retention

Permit, checklist, inspection, and other statutory records are retained for the period required by MOM and the Workplace Safety and Health Act — typically at least five (5) years from the date of the record. Account and profile data are retained while your account is active and for a reasonable period afterwards for audit purposes. Photos and supporting media are retained alongside the parent record. You may request deletion of data that is not required for statutory compliance at any time.

6. Security

  • All data is transmitted over TLS (HTTPS).
  • Database storage is encrypted at rest by our infrastructure provider.
  • NRIC and FIN values are additionally encrypted at the application layer with AES-256 before storage.
  • Access to production data is restricted to a small number of authorized personnel and protected by multi-factor authentication.

7. Your rights under Singapore PDPA

Under the Personal Data Protection Act (PDPA), you may:

  • Request access to the personal data we hold about you.
  • Request correction of personal data that is inaccurate or out of date.
  • Withdraw consent for specific processing activities (understanding that some processing is required for statutory compliance).
  • Request deletion of personal data that is not required for statutory or contractual purposes.

To exercise any of these rights, email us at privacy@safetyhub.live. We will respond within 30 days.

8. Cookies

We use a single first-party cookie to keep you signed in (managed by Supabase Auth). We do not use third-party advertising, tracking, or analytics cookies.

9. Children

SafetyHub SG is a business-to-business service for construction sites and is not directed at persons under the age of 18. We do not knowingly collect data from minors.

10. Changes to this policy

We may update this policy from time to time. When we do, we'll update the "Last updated" date at the top of this page. Material changes will be communicated via email or an in-app notice.

11. Contact

Questions, complaints, or data-access requests: privacy@safetyhub.live