Skip to main content
Gerai information centre

Singapore PDPA Notice

Singapore-specific information about how Gerai collects, uses, discloses, protects, retains, and responds to requests concerning personal data.

Effective
Last updated
Authoritative language
English

1. Scope and organisation

This notice supplements Gerai’s Privacy Policy with information relevant to Singapore’s Personal Data Protection Act 2012 (PDPA). Gerai is a product of World Council for AI PTE. LTD., a Singapore company with UEN 202412852R.

It applies to personal data handled through Gerai’s corporate website, merchant platform, Gerai-powered storefronts, and related communications. Under the PDPA, personal data generally means data about an individual who can be identified from that data alone or with other information to which an organisation has or is likely to have access.

Some business contact information used solely for business purposes may be treated differently under the PDPA. Gerai nevertheless aims to handle corporate contact information responsibly and only for relevant business purposes.

2. Roles and personal data

CategoryExamplesTypical source
Contact and business dataName, work details, organisation, role, enquiry, and correspondenceYou, your organisation, or a person introducing you
Merchant account dataAccount identifiers, contact details, permissions, settings, and access recordsThe merchant and its authorised users
Catalogue and mediaProduct information, files, images, pricing, and availabilityThe merchant
Buyer and order dataContact, delivery, cart, order, payment-status, and fulfilment informationThe buyer, merchant, and licensed payment service
Technical and operational dataIP address, request details, browser or device information, and diagnostic or security eventsGenerated through use of Gerai

3. Purposes

Gerai may collect, use, or disclose personal data for purposes that include:

  • responding to enquiries and discussing merchant onboarding or partnerships;
  • creating, administering, authenticating, and securing merchant access;
  • building and operating storefronts, catalogues, carts, and order workflows;
  • routing buyer order information to the relevant merchant;
  • connecting order records with limited payment references and statuses;
  • supporting fulfilment communications and resolving technical issues;
  • operating, diagnosing, improving, and protecting Gerai;
  • detecting fraud, abuse, unlawful activity, and security threats;
  • complying with law, legal process, and regulatory obligations; and
  • establishing, exercising, or defending legal rights.

If Gerai wishes to use personal data for a materially different purpose that is not already permitted by law or reasonably connected to the original purpose, Gerai will provide any additional notification or seek any consent that the PDPA requires.

5. Disclosure and payments

Personal data may be disclosed, as relevant to the purpose and legal context, to:

  • the merchant from whom a buyer places an order and that merchant’s authorised users;
  • service providers supporting Gerai’s infrastructure, communications, security, diagnostics, or operations;
  • licensed payment services involved in a transaction;
  • professional advisers and legitimate counterparties under appropriate duties;
  • a successor or proposed successor in a legitimate corporate transaction; and
  • public authorities, regulators, courts, or other recipients where disclosure is lawfully required or permitted.

Gerai does not state a fixed public provider list because providers can depend on the merchant engagement and service scope. Procurement teams can request current, relevant information through the Data Processing Addendum page.

6. Overseas processing

Gerai serves Southeast Asia and personal data may be accessed or processed outside Singapore. The countries involved can vary with the service configuration, merchant, payment option, and provider used. This public notice therefore does not claim a universal storage country or provide a fixed country list that may not apply to every engagement.

Where the PDPA’s transfer limitation obligation applies, Gerai will take steps required in the circumstances so that transferred personal data receives a standard of protection comparable to that under the PDPA. Merchants with specific location or transfer requirements should raise them before onboarding so they can be assessed and, where agreed, documented.

7. Accuracy, protection, and retention

Accuracy

Gerai takes reasonable steps to use accurate and complete personal data where it is likely to make a decision affecting an individual or disclose the data to another organisation. Merchants, buyers, and account users should provide accurate information and notify the relevant party when it changes.

Protection

Gerai uses reasonable technical and organisational measures appropriate to the nature and context of the data to protect against unauthorised access, collection, use, disclosure, copying, modification, disposal, or similar risks. We do not publish unverified encryption standards, certification claims, audit claims, or absolute security guarantees.

Retention

Gerai ceases to retain personal data, or removes the means by which it can be associated with an individual, when it is reasonable to conclude that the purpose is no longer served and retention is no longer necessary for legal or business purposes. The relevant period varies according to data type, merchant instructions, account and order status, security needs, disputes, and legal requirements. No universal fixed period is stated where one has not been verified.

8. Access, correction, and withdrawal

Subject to the PDPA’s requirements and exceptions, an individual may ask Gerai for access to personal data in Gerai’s possession or control and information about how it was used or disclosed within the applicable period. An individual may also ask Gerai to correct an error or omission.

Send the request to hello@gerai.shop with a subject such as “PDPA access request”, “PDPA correction request”, or “withdraw consent”. Include enough information to identify the person, account, storefront, order, or enquiry and describe the data concerned. Do not email unnecessary identity documents.

Gerai may ask for proportionate verification before disclosing or changing data. A request may be limited where the PDPA permits or requires that result, including to protect another person, privileged material, confidential commercial information, an investigation, or a legal obligation. If a fee is lawfully chargeable for an access request, Gerai will explain it before proceeding rather than state an invented standard fee here.

For buyer information controlled by a merchant, contact the merchant first. Gerai may refer the request to that merchant or assist it as the organisation responsible for the sales purpose.

9. Marketing and browser storage

Gerai does not use the Services as permission to send unlawful marketing. Where Singapore’s Do Not Call provisions or another marketing rule applies, the sender is responsible for checking and complying with it, identifying itself, and respecting a valid opt-out. Operational messages about an enquiry, account, order, security issue, or service are distinct from promotional messages.

Gerai storefronts use functional localStorage named gerai-cart to retain a buyer’s cart. Gerai uses server-side operational analytics, not browser analytics cookies or advertising cookies. There is no fake cookie-consent control for technologies Gerai does not deploy. See the Cookie and Browser Storage Notice.

10. AI-assisted features

Gerai may use narrow, labelled AI-assisted features for defined commerce tasks. They are fallible and can produce incorrect or incomplete output. Live-shop material is subject to human review, and matters requiring judgement or an exception should be escalated to a person.

Gerai does not describe these features as making significant legal or practical decisions about individuals without human involvement. If an AI-assisted interaction concerns you and appears wrong, identify the interaction when contacting the merchant or Gerai. Read the AI Transparency Notice.

11. Incidents and complaints

Gerai assesses suspected personal-data incidents to understand what happened, contain risk, preserve relevant information, and determine whether notification to the Personal Data Protection Commission or affected individuals is required. This page does not promise a response time beyond what applicable law requires.

Raise a privacy concern with Gerai first so it can be investigated. If you remain dissatisfied, you may contact Singapore’s Personal Data Protection Commission through its official website at pdpc.gov.sg. A merchant-controlled buyer issue may also need to be raised with that merchant.

12. Contact and updates

Gerai’s public data-protection contact is hello@gerai.shop. Use this address for PDPA requests, questions, complaints, and notices. Mail may be addressed to:

World Council for AI PTE. LTD.
Attention: Data Protection
1 Paya Lebar Link, #04-01
Paya Lebar Quarter
Singapore 408533

Gerai may update this notice when the Services, law, or data practices change. The effective and last-updated dates above identify the current public version. Where a change requires additional notification or consent, Gerai will address that requirement in the relevant context.

Legal review notice

This published document explains Gerai’s current approach and intended practices. It does not constitute legal advice to the reader. Gerai recommends obtaining advice from a qualified lawyer about the laws and contractual requirements that apply to your circumstances.

Singapore PDPA Notice | Gerai