AppSavvy Pte. Ltd. (“AppSavvy,” “we,” “us,” or “our”) is committed to protecting the privacy of our clients, prospects, and website visitors. This Privacy Policy explains what personal data we collect, how we use it, when we share it, how we keep it secure, and the rights you have over it.
We comply with the Singapore Personal Data Protection Act 2012 (“PDPA”) and, where applicable to you, the EU and UK General Data Protection Regulations (“GDPR”). This Policy applies to data collected through our website (appsavvy.dev), through our services, and through any communication you have with us.
01Information We Collect
We collect the following categories of information:
- Contact details: name, email address, company name, role, phone number, and billing address you provide when contacting us, booking a call, or engaging our services.
- Project information: details about your business, requirements, deliverables, schedules, and any materials you share with us for the purpose of delivering the engagement.
- Account credentials and access tokens: where you grant us access to systems (Bubble, Supabase, GitHub, hosting providers, etc.) for the purpose of the engagement. We rotate, revoke, and minimise these where practical.
- Communications: emails, call notes, meeting transcripts (where you have consented to recording), and messages exchanged with us via supported channels.
- Website usage data: IP address, browser type, device information, referring page, pages visited, and timestamps, collected via standard web analytics.
- Payment information: handled by Stripe; we do not store full payment card details on our systems. We retain transaction metadata (amount, currency, date, invoice reference) for accounting and tax purposes. See the Stripe Privacy Policy for how Stripe processes your data.
We do not knowingly collect personal data from anyone under 16 years of age.
02How We Use Your Information
We use the information we collect for the purposes of:
- Providing, delivering, and managing the services you have engaged us for.
- Communicating with you about projects, schedules, invoices, and support requests.
- Responding to enquiries and providing information about our services.
- Processing payments and managing billing.
- Complying with legal obligations, including accounting, tax, and statutory reporting in Singapore and other jurisdictions where applicable.
- Improving our services, our website, and our customer experience through analytics on aggregated and de-identified data.
- Protecting our rights, property, or safety, and those of our clients and the public, including detecting and preventing fraud or abuse.
Legal bases (where GDPR applies). We rely on: (a) performance of a contract, for processing required to deliver our services; (b) legitimate interests, for operating, securing, and improving our services and managing client relationships; (c) consent, where required (for example, for marketing emails or non-essential cookies); and (d) legal obligations, for tax, accounting, and statutory compliance.
03Sub-processors and Third Parties
We use a small set of trusted third parties to operate our business. These are bound by confidentiality and data- processing terms and only access the data needed to perform their function. Material sub-processors include:
- Hosting & infrastructure: Vercel, Supabase, Fly.io, Cloudflare.
- Email & communication: Google Workspace, Resend.
- Payments & accounting: Stripe, Xero.
- Project & engineering tools: Linear, GitHub, Trigger.dev.
- AI providers: Anthropic (Claude), OpenAI, OpenRouter. We use enterprise or API configurations that do not train third-party models on customer data.
- Analytics: privacy-preserving web analytics (no cross-site tracking, no advertising identifiers).
We may update this list as our stack evolves. A current list of material sub-processors is available on request.
05Data Security
We implement appropriate technical and organisational measures to safeguard personal data, including: encryption in transit and at rest, role-based access controls, least- privilege credential management, audit logging on production systems, multi-factor authentication on administrative accounts, hardened CI/CD pipelines, secure code review, and regular dependency updates.
No system is perfectly secure. If you believe your data may be at risk, contact us at hello@appsavvy.dev.
06Data Breach Notification
If we become aware of a personal data breach affecting personal data we control or process on your behalf, we will: (a) take immediate steps to contain and remediate the breach; (b) assess the likely impact; (c) notify affected clients without undue delay (and in any event within 72 hours where required); and (d) notify the relevant supervisory authority where required by law.
07Data Retention
We keep personal data only for as long as needed for the purposes for which it was collected, or as required by law. Typical retention periods are:
- Client project records: for the duration of the engagement plus up to seven (7) years for accounting and statutory purposes.
- Invoices & tax records: at least seven (7) years, as required by Singapore tax law.
- Marketing contact records: until you withdraw consent or three (3) years of inactivity, whichever is sooner.
- Website analytics: typically up to twenty-six (26) months in aggregated, de-identified form.
- Access credentials and tokens are revoked at the end of an engagement unless agreed otherwise.
08Your Rights
Depending on your location, you have the following rights in respect of your personal data. We honour the rights granted under the PDPA and GDPR, regardless of your location, where reasonably practicable:
- Access— request a copy of the personal data we hold about you.
- Correction— ask us to correct inaccurate or incomplete data.
- Deletion— ask us to delete your data, subject to our legal and contractual obligations to retain certain records.
- Restriction or objection— ask us to limit or stop processing your data in certain circumstances.
- Portability— receive a copy of data you provided to us in a structured, commonly used, machine-readable format.
- Withdraw consent— where we rely on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Lodge a complaint— with a supervisory authority, such as the Personal Data Protection Commission of Singapore (PDPC) or a relevant EU data protection authority.
To exercise any of these rights, email hello@appsavvy.dev. We will respond within thirty (30) days. We may need to verify your identity before fulfilling the request.
10International Data Transfers
AppSavvy is based in Singapore. Personal data we collect may be stored or processed in Singapore or in other countries where our sub-processors operate (including the United States and the European Union).
Where we transfer personal data out of jurisdictions that impose specific transfer requirements (such as the EU/UK), we rely on appropriate safeguards, including the Standard Contractual Clauses, adequacy decisions, or other recognised mechanisms.
11Third-Party Links
Our website and communications may contain links to third-party websites or services. This Policy does not apply to those websites. We encourage you to review the privacy policies of any third-party site you visit.
12Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, technology, or legal requirements. The “Last updated” date at the top of this Policy indicates when it was last revised. We will notify you of material changes by email or via a prominent notice on our website where appropriate. Continued use of our services after a change indicates your acceptance of the updated Policy.
13Contact Us
For any questions, concerns, or requests regarding this Policy or your personal data, please contact us:
AppSavvy Pte. Ltd.
68 Circular Road, #02-01
Singapore 049422
Email: hello@appsavvy.dev
If you are in the EU/UK and feel we have not addressed your concerns, you have the right to lodge a complaint with your local data protection authority.
Questions?
Email hello@appsavvy.dev and we’ll respond within two business days.
AppSavvy Pte. Ltd.68 Circular Road, #02-01
Singapore 049422