Simpli lets you scan a QR code at a restaurant table, order and pay from your browser. This notice explains what personal data we collect when you do that, why, and the choices you have. It is written for Singapore's Personal Data Protection Act (PDPA).
What we collect
- Ordering without an account (the default): your order items, table number and payment status. We do not know your name. Payment details (card number, PayNow account) go directly to our payment processor, Stripe. We never see or store your full card number.
- If you create a free account: your email address, the name you choose to display, and your order history across Simpli restaurants, so you can see past orders, earn visit badges and receive any welcome gift a restaurant offers.
- If you set dietary preferences: these are treated as sensitive data. They are collected only with your consent, used only to label menu items for you, and you can turn them off or delete them at any time.
- If you opt in to restaurant emails: your consent choice per restaurant. This is off by default and every email includes one-click unsubscribe.
How we use it
- To take your order, process payment and show the kitchen what to prepare.
- To show the restaurant its own sales and item popularity (never your card details).
- To run your account features: order history, badges, reviews and welcome gifts.
- To keep the platform safe: fraud prevention, security logging and legally required records.
We do not sell personal data. Restaurants see the orders placed at their own venue; they do not see your activity at other restaurants.
Your rights
- Access and portability: signed-in diners can download all their data from their profile at any time.
- Correction: you can edit your display name and preferences in the app.
- Withdrawal: you can unsubscribe from marketing, disable dietary preferences, or ask us to delete your account by contacting us below.
Retention and protection
Order and payment records are kept as required by Singapore tax and accounting law. Account data is kept while your account is active. Data is stored with access controls and encryption in transit; sensitive actions are audit-logged. If a data breach is likely to cause significant harm, we will notify the PDPC and affected users within the timelines the PDPA requires.
Contact
Simpli's data protection contact: privacy@simpli.sg. We reply to access, correction and deletion requests within 30 days.