Privacy Policy
Personal Data Protection Act (PDPA) Compliance Notice
1. Data Controller
Seleckt (“we”, “us”, “our”) is the data controller responsible for the processing of your personal data in accordance with the Personal Data Protection Act (PDPA).
2. Data We Collect
- Account information — name, email address, business name
- Authentication data — hashed passwords, OAuth tokens
- Business data — client records, gallery metadata, contracts, invoices
- Uploaded content — photographs and associated metadata (EXIF data, file names, dimensions)
- Payment data — processed and stored by Stripe; we do not store card numbers
- Usage data — page views, feature usage, error logs
3. Purpose of Processing
- Account creation, authentication, and management
- Service delivery — gallery hosting, photo sharing, client proofing and selection
- Payment processing and invoicing
- Contract generation and e-signature facilitation
- Communication — transactional emails, notifications
- Platform improvement and error monitoring
4. Third-Party Services
We share data with the following third-party processors as necessary to operate:
- Stripe — payment processing
- Resend — transactional email delivery
- Cloudflare R2 — photo storage (Singapore region)
- Sentry — error monitoring
- PostHog — product analytics
5. Cookies & Tracking
We use the following cookies and tracking technologies:
- Session cookies — required for authentication via NextAuth; strictly necessary for the service to function
- PostHog analytics — anonymous product analytics to understand feature usage and improve the platform
- No advertising cookies — we do not use advertising trackers or sell data to advertisers
6. International Data Transfers
Your data may be processed in the following regions:
- Cloudflare R2 (Singapore) — photo storage
- Neon (Singapore) — database hosting
- Stripe (international) — payment processing may involve data transfer to Stripe’s processing centres outside Malaysia
All transfers are conducted with appropriate safeguards and in compliance with applicable data protection laws.
7. Data Retention
We retain your personal data for as long as your account is active or as needed to provide services. Upon account deletion, personal data is removed within 30 days, except where retention is required by law (e.g., financial records).
8. Security Measures
We implement appropriate technical and organisational measures to protect your data:
- All data transmitted over TLS (HTTPS) encryption
- Passwords hashed using bcrypt with appropriate cost factors
- Role-based access controls for multi-user accounts
- Automated error monitoring via Sentry for rapid incident response
9. Your Rights Under PDPA
You have the right to:
- Access — request a copy of your personal data
- Correction — request correction of inaccurate data
- Withdrawal of consent — withdraw consent at any time by deleting your account or contacting us
- Data portability — request export of your data in a structured format
10. Children’s Data
Seleckt is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.
11. Contact
For data protection enquiries, please contact us at privacy@seleckt.app.
See also our Terms of Service.