Privacy Policy
Last updated: 2026-09-10
1. Who We Are
1Plus1Gold ("we", "us", "our") is a gold dealer based in Singapore, licensed by the Ministry of Law (Singapore) under the Precious Stones and Precious Metals (PSPM) Act. Our anti-money-laundering obligations arise under the PSPM Act and are regulated by the Ministry of Law (MinLaw) — not the Monetary Authority of Singapore. Our registered office is in Singapore 437986.
This Privacy Policy explains how we collect, use, disclose, and protect personal data in accordance with the Singapore Personal Data Protection Act 2012 (PDPA).
2. Personal Data We Collect
We collect the following categories of personal data:
- Identity data — full name, date of birth, nationality, NRIC/passport number (for KYC/AML compliance required under the PSPM Act).
- Contact data — mobile phone number, email address, delivery address, postal code.
- Transaction data — orders placed, gold weights, amounts paid, payment references.
- Technical data — IP address, browser type, device information, session logs.
- Communications data — WhatsApp messages and emails sent to or received from our business channels for order coordination and customer support.
- Public social-media interactions — if you comment on, mention, or otherwise publicly interact with our posts on Instagram or LinkedIn, we receive your public username or handle, the platform's own identifier for you, and the text of your comment. This applies whether or not you are a customer of ours.
3. How We Collect Personal Data
- When you register or sign in using one of our supported methods (WhatsApp OTP, email OTP, passkey, Apple, or Google).
- When you complete our Know Your Customer (KYC) verification flow.
- When you place an order, submit a delivery address, or make a payment.
- When you contact us via WhatsApp, email, or through our website contact form.
- When you comment on or publicly interact with our posts on Instagram or LinkedIn. We retrieve these public interactions from the platform so that we can reply to you and understand which of our posts are useful.
- Automatically via cookies and server logs when you browse our website.
4. Purposes of Collection and Use
We use your personal data to:
- Verify your identity and comply with anti-money laundering (AML) and counter-financing of terrorism (CFT) obligations under the PSPM Act.
- Process your gold purchase orders and arrange delivery or self-collection.
- Send order confirmations, receipts, and delivery updates via WhatsApp and email (whichever channels you have on file).
- Send you our periodic market-update newsletter. You may opt out at any time in Account → Notifications or via the unsubscribe link in any newsletter, without affecting the essential service messages above.
- Maintain your account and transaction history.
- Detect and prevent fraud, suspicious activity, or unauthorised access.
- Respond to customer service enquiries.
- Comply with our legal and regulatory obligations, including record-keeping requirements.
5. Disclosure to Third Parties
We disclose personal data only to service providers necessary to operate our business, and only the data each needs for its function:
- Didit — identity verification and KYC/AML screening (European Union). Your identity document, selfie and liveness video are captured by Didit's own verification flow and held by Didit; they do not pass through our systems. We retain only a reference to your verification, its outcome and expiry — never the documents themselves.
- Twilio — WhatsApp one-time-passcodes and order/delivery notifications (your phone number, name, and links to your documents such as receipts).
- Resend — transactional email delivery (your email address, name, and message content — OTPs, receipts, order and delivery updates).
- Stripe — card payment processing; your card details are entered directly with Stripe and are not stored by us.
- HitPay — payment processing (PayNow, card, and other methods), receiving the payment amount and, where applicable, your name and email.
- Lalamove, NinjaVan, and SPX — last-mile delivery of physical gold, receiving your name, phone number, and delivery address.
- Supabase — our database, authentication, and file storage provider.
- Vercel — website hosting and server logs, which include your IP address.
- Anthropic — AI-assisted anti-money-laundering and compliance risk checks, receiving a customer reference, your nationality, the type of identity document you used, and a summary of your orders. It does not receive your name or NRIC/passport number.
- OpenAI — our optional voice assistant, which receives live audio and your gold balance only while you are using it.
- Google — advertising conversion and remarketing measurement (see Section 7). Google does not receive your name, email, or phone number.
- The Ministry of Law (MinLaw), the Suspicious Transaction Reporting Office (STRO), and law enforcement — where required by law or regulatory order.
Instagram (Meta) and LinkedIn. We publish on these platforms and we retrieve the public comments and mentions left on our posts. We do not send them any customer personal data — no name, phone number, email address, order, or identity document. The flow is inbound only. When you comment on one of our posts, the platform is the controller of your account and your comment; what we hold is a copy of that public comment, which we keep for up to 12 months (see Section 6) so that we can reply to you and measure how our posts perform.
We do not sell, rent, or trade your personal data to any third party for marketing purposes.
Overseas transfer. Some of these service providers — and their own sub-processors, backups, and failover systems — may store or process personal data outside Singapore, and the location can vary over time. Wherever personal data is transferred overseas, we require the recipient, under the data-processing terms that govern our use of them, to protect it to a standard comparable to the PDPA.
6. Data Retention
We retain personal data for as long as necessary to fulfil the purposes set out in this policy, and for a minimum of five (5) years after your last transaction to satisfy AML record-keeping obligations under the PSPM Act. KYC documents are retained for the period required by the PSPM Act and MinLaw guidelines.
Some categories have their own shorter windows, which we enforce automatically:
- Public social-media interactions (Section 2) — your handle, the platform's identifier for you, and your comment text are removed 12 months after the interaction. We keep only the de-identified fact that a comment of that type was received on that post and date.
- Website analytics — behavioural analytics records are deleted after 14 months.
7. Cookies
Our website uses essential session cookies required for authentication and security. On our live site we also use Google advertising and conversion-measurement cookies (Google Ads) to measure the effectiveness of our advertising — for example, to record that a purchase was made and its value. These cookies do not receive your name, email, or phone number, and we do not use cookies to build profiles about you for sale to third parties. You may disable non-essential cookies in your browser settings; disabling essential cookies will prevent you from logging in to your account.
8. Security
We implement appropriate technical and organisational measures to protect your personal data, including encrypted data storage, TLS in transit, access controls, and row-level security on our database. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security. If a data breach occurs that is likely to result in significant harm to you, or that affects a significant number of individuals, we will notify the Personal Data Protection Commission within 3 calendar days of assessing it as notifiable, and will notify affected individuals as required by law.
9. Your Rights
Under the PDPA, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate personal data.
- Withdraw consent to non-essential processing (note: withdrawal does not affect processing required by law).
- Data portability — request your data in a commonly used format where technically feasible.
- Delete your account (see Section 10 below).
To exercise any of these rights, please reach us through our Contact page. We will respond within 30 days.
10. Deleting Your Account
You may delete your 1Plus1Gold account at any time, in either of two ways:
- Self-service (preferred) — sign in and go to Account → Security, scroll to the "Delete account" section, and follow the in-app confirmation flow. Deletion takes effect immediately on submission.
- By request — if you cannot access your account, reach us through our Contact page with the subject "Account deletion request" from the WhatsApp number or email address registered on your account. We will action the request within 30 days.
Upon deletion we permanently delete your profile and contact details, your saved delivery addresses, your marketing and notification preferences, and gift messages on cards you own, and we deactivate your personal referral code. Records that necessarily involve another customer — referrals linking you to a person who referred you or whom you referred, and gift messages you sent to another person — are disassociated from your identity rather than deleted, so that the other person's records remain intact. Your identity is anonymised across all remaining records. The following data must, however, be retained even after account deletion in order to comply with our legal obligations:
- Transaction records, KYC documents, and AML screening results — retained for a minimum of five (5) years after your last transaction under the PSPM Act and MinLaw guidelines. Access to these records is restricted to regulatory compliance, audit, and law-enforcement purposes.
- Records required to defend or pursue legal claims — retained for the period prescribed by the Limitation Act or other applicable law.
Deletion of your account ends our active processing of your data for service delivery, marketing, and account-management purposes. It does not affect the lawfulness of any processing carried out before deletion.
If you have an open order, an unresolved dispute, or an outstanding payment with us, we will complete those obligations before processing the deletion.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to registered users via WhatsApp or email (whichever channels you have on file). The "Last updated" date at the top of this page reflects the most recent revision.
The version of this Policy that applies to you is the version in effect on the date you registered your account; an updated version governs from its effective date onward and does not retroactively change what applied before. See section 13 of our Terms of Service for how the version in force is determined and recorded.
12. Contact Us
For any privacy-related queries, access or correction requests, or complaints, please contact our Data Protection Officer:
- Mukesh Ramchand Tejwani, Data Protection Officer
- Email: dataprotection.officer@1plus1gold.com
- Phone: +65 9231 3380
You may also reach us through our Contact page, or direct complaints to the Personal Data Protection Commission (PDPC) at www.pdpc.gov.sg.