Privacy Policy
Effective date: 11 September 2026
SingBuDong operates the map at https://singbudong.com, which shows Singapore HDB resale transaction prices from public government data. This policy explains what personal data we collect, why we collect it, where it is stored, and the choices you have. It is provided for transparency and is not legal advice.
Browsing prices on the map does not require an account. If you never sign in, we do not collect your email, name, or contact details.
What we collect
- Email address — only if you create an account. You can sign in with a one-time code or sign-in link that we email to you, or with Apple or Google, depending on which options the app you are using offers: the iOS app offers email sign-in and, where the version you have installed provides it, Sign in with Apple, and it does not offer Google sign-in. If you sign in with Apple or Google, that provider gives us the email address of the account you choose. Apple also lets you hide your address; if you do, we receive Apple's private relay address instead of your real one, and that is the only address we can reach you at.
- Name and profile picture link from Google — only if you sign in with Google. When Google signs you in, it passes on the name and the profile picture link of the Google account you choose, and our authentication service stores them with your account. We receive them only because Google includes them when you sign in. They are kept with your account record, we do not display them or use them for any other purpose, and they are deleted when you delete your account.
- Sign-in sessions — while you are signed in, our authentication service keeps a record of each session, including the IP address and browser or device details it was started from, so that it can keep your account secure. The record is removed when you sign out of that session or delete your account.
- Notification (push) subscriptions — if you turn on new-sale alerts for an estate, we store the technical details your device generates so notifications can be delivered: a push endpoint URL and two encryption keys, linked to your account and to the estates you follow.
- Saved estates (favourites) — if you save estates while signed in, the list of estate identifiers is stored with your account. If you are not signed in, favourites stay only in your browser and are never sent to us.
- Posts you write — if you post about an estate while signed in, we store the text you wrote with your account. Posts are public: anyone using the app can read them, shown under a masked form of your email address (for example, “wy***”). Each post also carries a short pseudonymous code derived from your account, so that other people can block you on their own device. The code does not reveal your email address or account identifier, but it lets posts written from the same account be linked to each other. Do not post personal details you do not want to be public.
- Reports you make about a post or its author — if you report someone else's post, or the user who wrote it, as inappropriate, we store which post you reported, that the report came from you, and when it was made. A report about a user is recorded against the post you reported them from. Reporting has no message box, so the record holds nothing you write. We use it to hide a post that several different people report and to review the post and its author.
- Blocks, Terms acceptance and drafts — kept on your device. If you block a user in Talk, the list of people you blocked is stored only in the browser or app on that device and is never sent to us. The note that you accepted the Terms before posting is also stored on the device; each post you send carries the version of the Terms you accepted so that our server can check it, and we do not store it. A Talk post you have started but not sent stays only in that tab or app until you close it.
- Address searches — when you search for a place, the text you type is sent to our server and passed to OneMap (Singapore Land Authority) to find matching addresses. It is not linked to your account. To make repeat searches faster, our hosting provider may keep a search and its results for up to 24 hours.
- Usage events — we record that certain things happened in the app so we can tell how much each feature is used: an estate panel was opened, the comparison table was opened, the share button was tapped, BTO information was opened, or alerts were turned on. Each record holds only five things: which of those actions it was, whether it involved an HDB or a condo listing, whether a share was of a single estate or of a comparison, an anonymous session identifier, and the time. It does not hold your account, your email address, your IP address, which estate you were looking at, or your location.
- About the session identifier — it is a random value created in your browser and kept in session storage, not in a cookie. It disappears when you close the tab, and it is never linked to your account, so events from the same person on different days cannot be connected. Its only purpose is to count a session once instead of many times.
- Anonymous usage statistics — we also use Vercel Web Analytics to count page views and the same actions. This is aggregate and anonymous: no tracking cookies are set, and we do not build advertising profiles. As with any page-view analytics, the address of the page being viewed is part of what is counted, and for a page opened from a shared link that address names the estate the link points to.
- Location — never collected by us. If you tap the locate button on the map, your device's location is used on your device only, to show your position on the map. It is never sent to or stored on our servers.
- Error reports — only while error tracking is enabled in the deployed build (see “Where it is stored”): when the app hits an error, it sends a diagnostic report to our error-tracking provider, Sentry, so that we can fix the fault. A report contains the error message and stack trace, the address of the page you were on, and your browser and operating system version. It does not contain your cookies or request headers, and your IP address is not attached to it or stored with it: the setting that would add them is switched off. It is not linked to your account, and we do not attach your email address or account identifier. Sensitive values that can appear in a web address, such as a sign-in code or an access token, are replaced with “[redacted]” before the report leaves your device. We do not record your screen or your taps.
- Notifications in the mobile apps — the Android and iOS apps deliver notifications through Firebase Cloud Messaging (FCM) instead of web push, and on iOS, FCM hands the notification to Apple's Push Notification service (APNs) for the final delivery. For this we store an installation identifier that the app generates as a random value on first launch, the FCM registration token for that install, and the platform (“android” or “ios”). Once you sign in and turn alerts on, that record is linked to your account and to the estates you have chosen to follow.
What we do not do
- We do not sell or rent your personal data.
- We do not run advertising or cross-site tracking, and the app contains no advertising SDKs.
- We do not ask for your name, phone number, home address, or payment details. The only name the app receives is the one Google passes on if you sign in with Google, as described above.
- We do not track your location. If you tap the locate button, your position is shown on the map by your device only — the coordinates never reach our servers.
How we use it
- To sign you in and sync your favourites and alerts across your devices.
- To send the new-sale notifications you have subscribed to.
- To understand overall usage and keep the service reliable, using the anonymous usage events and analytics described above. We use them to work out proportions — for example, what share of sessions open the comparison table — not to study any individual.
- To diagnose and fix errors and crashes in the app, using the error reports described above.
Where it is stored
Your account email (and, if you sign in with Google, the name and profile picture link Google passes on), favourites, posts, the reports you make, push subscriptions, and the anonymous usage events described above are stored in our database and authentication service, provided by Supabase, hosted in the Singapore (ap-southeast-1) region. The application is hosted on Vercel.
There are two exceptions to the Singapore location above. First, error reports are processed by Sentry on servers outside Singapore, in the United States or the European Union depending on the region of our Sentry project. They contain no account data — see “What we collect” above for exactly what a report holds. Error reports are sent only while error tracking is enabled in the deployed build; when it is not, the app sends no error reports and does not load the error-tracking code at all.
Second, database backups. A backup copy of the database, which includes account data, is made by our scheduled jobs and kept as a private file in our GitHub account, on GitHub's servers outside Singapore; each copy is deleted automatically after 7 days. Before maintenance we may also make a manual backup, which is kept on our administrator's computer and deleted within 7 days. Other service providers listed under “Third parties” may process the data they receive outside Singapore.
Third parties
We share data with the following service providers only as needed to run the service:
- Supabase — database and authentication. Stores your email (and, for Google sign-in, the name and profile picture link Google passes on), favourites, posts and reports, push subscription records, and anonymous usage events, and issues sign-in codes and links.
- Resend — email delivery. Delivers the sign-in emails our authentication service sends, so it processes your email address and the one-time code or link in the message.
- GitHub — runs our scheduled data jobs and keeps the 7-day database backups described above as private files. The jobs' logs are kept for 90 days and can include a shortened form of a device's notification address.
- OneMap (Singapore Land Authority) — receives the text of address searches, as described above, and returns matching places.
- Vercel — application hosting and anonymous usage analytics.
- Google — identity provider, used only if you choose to sign in with Google. The iOS app does not offer Google sign-in.
- Apple — identity provider, used only if you choose Sign in with Apple; it gives us the email address, or the private relay address, of the Apple Account you sign in with. Apple also operates the Push Notification service (APNs) that delivers notifications to iOS devices, and receives the notification we send for that purpose.
- Sentry — error tracking. Receives the error reports described above (error message and stack trace, page address with sensitive values redacted, browser and operating system version), and uses them only to let us diagnose app faults. Reports carry no cookies, request headers, email address, or account identifier, and no IP address is attached to or stored with them — as with any request your browser makes, Sentry's servers see the address a report is sent from.
- The push service used by your browser or device (for example, one operated by your browser or device vendor) — receives the notification we send so that it can be delivered to your device. This is a standard part of web push notifications.
- Google LLC (Firebase Cloud Messaging) — push delivery for the Android and iOS apps. Receives the registration token for your install and the notification we send, and is used only to deliver that notification to your device; for an iOS device it passes the notification on to Apple's Push Notification service, which delivers it.
Map tiles are loaded in your browser from OpenStreetMap. When your browser requests map images, OpenStreetMap receives standard request information such as your IP address, as happens with any website you visit.
Cookies
We use only essential cookies needed to keep you signed in (a session cookie set by our authentication provider, Supabase). We do not use advertising or cross-site tracking cookies, and our analytics are cookieless — the usage events use a session identifier held in session storage inside your browser, which your browser clears when you close the tab. If you never sign in, no authentication cookie is set.
Data source
The property prices we display come from data.gov.sg (HDB resale transaction open data), and location data comes from OneMap (Singapore Land Authority). This is public government data about properties, not about you. SingBuDong is an independent service and is not affiliated with, endorsed by, or connected to HDB, data.gov.sg, or the Government of Singapore.
Your choices
- Sign out at any time from Settings.
- Turn off alerts — remove individual estate alerts, or turn off all alerts on a device, from Settings.
- Remove favourites — delete saved estates at any time.
- Clear local data — the Reset local data button in Settings clears your settings and locally saved estates from this browser.
- Delete your account and data — open the Delete account page below, or use Settings → Account → Delete account in the app.
Deleting your account
You can delete your account and the data linked to it at any time, either from Settings → Account → Delete account in the app, or from the page below without reinstalling the app. Deletion is immediate and permanent — we do not deactivate or freeze accounts instead of deleting them.
Delete your accountDeleting removes your account and its email address, your synced favourites, your posts, the reports you sent about other people's posts, and your new-sale alert subscriptions on every device. If you email us instead, we complete the request within 30 days.
If you signed in with Apple, deleting your account here removes everything we hold. Apple keeps its own record that you used Sign in with Apple for SingBuDong, and only you can remove that: open Settings on your iPhone or iPad, tap your name, tap Sign in with Apple, select the entry for SingBuDong: Property Price Map, then tap Delete. Removing that entry is optional — your account and its data are already deleted either way, and the entry is Apple's own record rather than ours. Apple names each entry in that list after the app or after its developer, so look for the SingBuDong name.
Retention
We keep your account data for as long as your account exists. When you delete your account, your email, favourites, posts, the reports you sent, and push subscriptions are removed immediately from our database. Backup copies that still contain your rows are deleted within 7 days.
Usage events are deleted 90 days after they are recorded, by a scheduled job that runs every day. They are not affected by account deletion because they were never linked to your account in the first place — there is no field in them that identifies you, so there is nothing in them to find or remove. Anonymous analytics held by Vercel are retained in aggregate and cannot be linked back to you. Error reports are retained by Sentry under its own retention schedule and then deleted; they carry no account data, so there is nothing in them to link back to you.
In the Android and iOS apps, turning alerts off removes the estates you were following and delivery stops. The device registration record — the installation identifier, the FCM token and the platform — is kept so that you can turn alerts back on without reinstalling the app. It is deleted when you delete your account. Uninstalling the app erases the installation identifier on your device and invalidates the token — on Android, clearing the app's data does the same — and we delete the record the next time a notification to it is rejected as unregistered.
Children
SingBuDong is not directed at children, and we do not knowingly collect personal data from children.
Changes
We may update this policy. Material changes will be reflected on this page with a new effective date.
Contact
Questions or requests: wygxaa@gmail.com
SingBuDong aims to handle personal data in line with the Personal Data Protection Act (PDPA) of Singapore. This policy is provided for transparency and does not constitute legal advice.