Privacy Policy
Version: 2026-10-05.v4. Effective date: 5 October 2026. Operator: ABSOLUTE SERVICES (UEN 53464936W), a sole proprietorship registered in Singapore and owned by LEE KOK WAN. "Hail Pilot" is the name of the product and service operated by ABSOLUTE SERVICES ("Hail Pilot", "we", "us"). Registered address: 60 Paya Lebar Road, #06-28, Paya Lebar Square, Singapore 409051.
This Privacy Policy explains how we handle personal data under the Personal Data Protection Act 2012 (Singapore) ("PDPA") and, for Merchants in Malaysia, how we support their obligations under the Personal Data Protection Act 2010 (Malaysia) ("MY PDPA"). Capitalised terms have the meanings given in the Terms of Service. A separate Notice to Buyers is written for the customers of our Merchants; a Bahasa Malaysia version of this Policy and of the Notice to Buyers will be published before we accept a Merchant established in Malaysia, and the English version governs if they differ.
1. Who we are and how to reach us
1.1 Hail Pilot is operated by the business named above. Our Data Protection Officer can be reached at business@hailpilot.com or at 60 Paya Lebar Road, #06-28, Paya Lebar Square, Singapore 409051; the name of the individual designated is available on request. The Data Protection Officer handles access and correction requests, withdrawal of consent, complaints and questions about this Policy.
1.2 For Malaysia: the person responsible for personal data matters is the same Data Protection Officer, contactable at business@hailpilot.com. The Data Protection Officer is not yet proficient in Bahasa Malaysia. Before we accept a Merchant established in Malaysia we will designate a contact who is proficient in Bahasa Malaysia and English and publish that contact, with a telephone number, here.
1.3 We keep written data-protection policies and practices and a complaints process. Information about them is available on request to the Data Protection Officer.
2. Our three roles
We handle personal data in three different capacities. Which one applies decides who is responsible for what.
2.1 Merchant Users and visitors. For personal data about the people who use our Service on behalf of a Merchant, who contact us, or who visit our website, we are the organisation responsible under the PDPA and, where MY PDPA applies, the data controller.
2.2 Buyer Data in a Merchant's workspace. When a Merchant connects its stores or uploads data, and we process its Buyers' personal data to provide the Service to that Merchant, we act on the Merchant's behalf and for the Merchant's purposes as its Data Intermediary (PDPA) or Data Processor (MY PDPA) under the written Data Processing Agreement. The Merchant is the organisation responsible to its Buyers. Buyers should read the Notice to Buyers and contact their Merchant first.
2.3 Network Signals. When we derive pseudonymised fraud and abuse signals from the data of more than one Merchant, we act as an organisation in our own right, relying on the legitimate interests exception described in section 6. This is the only processing of Buyer-derived data we carry out for our own purposes.
3. Personal data we collect about Merchant Users and visitors
3.1 Account and identity: name, work email address, telephone number if given, business name and registration identifier, role, sign-in credentials (stored as a one-way hash), and, if you sign in with Google, the email address and profile name Google provides.
3.2 Verification and security: a mobile number you give for verification codes, the codes sent, sign-in times, IP address, browser and device information, security-challenge results, and records of actions taken in the account.
3.3 Billing: billing contact details, plan, invoices, and the payment status returned by our payment processor. We never receive, process or store full card numbers, card security codes or magnetic-stripe data; for our own subscription billing we hold no card data at all, and our payment provider holds it.
3.4 Communications: messages you send us, support tickets, and, if you link them, your Telegram chat identifier and messaging preferences.
3.5 Website and application use: page views and events collected without cookies by a privacy-focused analytics service, and the data received by the error-monitoring and any product-analytics scripts described in the Cookie & Tracking Notice, which states which of them run, on which pages, and with what consent.
3.6 Where we get it: from you, from your Merchant, from your sign-in provider, and from our security and payment providers.
3.7 Whether you must supply it: account, verification and billing data are required to open and keep an account; if you do not supply them we cannot provide the Service to you. Telephone number, Telegram identifier and marketing preferences are optional, and you can limit the processing of your data by not supplying them, by changing your account settings, or by exercising the rights in section 11.
4. Buyer Data we process on a Merchant's behalf
4.1 Categories: Buyer names, contact details and addresses; order, delivery, payment-status and dispute records (the card network and the result codes of address and card-verification checks only; we never receive, process or store full card numbers, card security codes or magnetic-stripe data); messages between the Merchant and the Buyer, including, where the Merchant connects WhatsApp or Instagram, the Buyer's WhatsApp phone number, WhatsApp profile name and message delivery status, or Instagram-scoped identifier and Instagram username, and the content of their messages; evidence files such as photographs, screenshots and delivery records, including any personal data they show; and outputs we generate from them such as summaries, drafts and risk signals.
4.2 Sources: the Merchant's connected Platforms, carriers and messaging accounts (including a WhatsApp Business Account or Instagram professional account the Merchant connects through Meta), files the Merchant uploads, and data the Merchant enters.
4.3 What we do not do with Buyer Data: we do not sell it, share it with advertisers, use it to market to Buyers, contact Buyers on our own initiative, or use it to train models shared across Merchants.
4.4 WhatsApp and Instagram. If a Merchant connects a WhatsApp Business Account or an Instagram professional account, messages its Buyers send to that account are delivered to us by Meta so that they appear in the Merchant's workspace, and replies the Merchant sends, or allows us to send automatically on its behalf, are delivered through Meta. We only reply to conversations a Buyer has started. We use data received from Meta only to provide the Service to that Merchant: we do not use it for advertising, and we do not use it to create, train or improve any model other than one used only for that Merchant. These messages are kept, on the Merchant's instruction, without a fixed period while they serve as the Merchant's conversation history and help its AI Features, and are deleted on request, and 90 days after the Merchant's account is closed, as set out in the Retention Schedule. Meta processes these messages in its own systems under its terms with the Merchant.
5. Purposes
5.1 For Merchant Users and visitors: to create and secure accounts; to verify identity and prevent fraud against the Service; to provide the Service and support; to bill and collect Fees; to send account, billing, security and legal notices; to send marketing only where you have consented; to understand and improve the website and Service using data that does not identify you; to comply with law; and to establish, exercise or defend legal claims.
5.2 For Buyer Data, on the Merchant's instructions: to organise evidence for refunds, returns, disputes and chargebacks; to draft communications for the Merchant's review; to detect abuse patterns within the Merchant's own data; to generate summaries and risk signals for the Merchant's human review; to improve the AI Features for that Merchant's own workspace, as described in sections 4.3 and 4.3A of the AI Transparency Notice; and to store, back up and secure that data.
5.3 For Network Signals: to help Merchants recognise repeat abuse across stores, as described in section 6.
5.4 We do not use personal data for a purpose that a reasonable person would not consider appropriate in the circumstances, and we tell you before using it for a new purpose.
6. Network Signals and our legitimate interests
6.1 Network Signals are pseudonymised identifiers produced by keyed hashing of normalised Buyer identifiers, hashes of evidence images, and counts of events such as disputes and refund requests. They contain no names, contact details, addresses or message content.
6.2 Network Signals are personal data in pseudonymised form, because we hold the hashing key and the source data. They are not anonymous data and we do not describe them as such.
6.3 We rely on the legitimate interests exception in the First Schedule to the PDPA for this processing. Our interest, and that of our Merchants, is in detecting and preventing repeat abuse of refund and dispute processes. We have carried out and documented an assessment of the adverse effects on Buyers and the measures that reduce them, and we provide information about it on request to business@hailpilot.com.
6.4 The measures are: the hashing key is stored separately from Buyer Data; a signal is shown to another Merchant only where enough distinct Merchants have contributed that neither a Merchant nor a Buyer can reasonably be identified from it (the number of contributing Merchants required differs by signal type and is set in our internal control standard, available on request); no Merchant learns which other Merchant contributed; signals are information for a person to review and are never used by us to make a decision with legal or similarly significant effect about a Buyer; Merchants may not extract, publish or resell them; and we derive them only from sources whose terms permit it.
6.5 Network Signals are kept indefinitely, including after the Merchant that contributed them closes its account, because detecting repeat abuse is an ongoing purpose. They are not deleted or nullified on request. Because this processing relies on the legitimate interests exception and not on consent, withdrawing consent does not remove them. You may ask us for access to, and correction of, the pseudonymised record we hold about you under section 11.1.
7. Who we share personal data with
7.1 Sub-processors. We use third-party providers to host, store, analyse, communicate and secure data. Each is named in the Sub-processor List with the country where it processes data, the data it receives and its purpose. Each is bound by written terms requiring protection comparable to this Policy and the Data Processing Agreement. We notify Merchants of changes as described in the Sub-processor List.
7.2 Platforms and services you connect. On a Merchant's instruction we send data to, and receive data from, the Merchant's own Platform, carrier, payment-processor and messaging accounts. Those services are governed by the Merchant's agreements with them.
7.3 Professional advisers, insurers and successors. We may share personal data with our advisers and insurers under confidentiality, and with a successor to the Hail Pilot business, who will be bound by this Policy.
7.4 Law. We disclose personal data where the law requires, to comply with a court order or a lawful request from an authority, or to establish, exercise or defend legal claims. Where the law allows, we tell the affected Merchant.
7.5 We do not sell personal data.
8. Where personal data is stored and transferred
8.1 Our production systems run on servers in Singapore, which we operate ourselves. Holding data on them does not transfer it out of Singapore, and the full PDPA obligations apply to it. Backups are stored with providers in the countries named in the Sub-processor List.
8.2 Some Sub-processors process data outside Singapore, in the countries named in the Sub-processor List. Before transferring personal data to a Sub-processor outside Singapore we put in place written terms that require it to protect the data to a standard comparable to the PDPA, and we name the countries concerned so that Merchants can meet their own notification duties. For Merchants in Malaysia, the Data Processing Agreement records the basis on which transfers are made and the register of recipients we provide.
8.3 We do not offer the Service in the European Economic Area or the United Kingdom, and we do not rely on the laws of those places.
9. How long we keep personal data
We keep personal data only as long as it is needed for the purpose it was collected for or for a legal or business requirement. The periods, by data class and by source, are set out in the Retention Schedule, which forms part of this Policy. When the period for Buyer Data ends, we keep the records and replace the personal details in them with keyed tokens, and mask names and contact details written into free text (Retention Schedule 1.3). When a Merchant's account is closed, nothing is deleted except WhatsApp and Instagram messages and media, which are deleted 90 days after closure: at that point the personal details of its other Buyer Data and of its Merchant Users are replaced with keyed tokens, and the result is kept for our analysis and for Network Signals (Retention Schedule 4.1). Those tokens are made with a key we hold and the same detail always gives the same token, so the result is personal data in pseudonymised form, not anonymous data: we keep protecting it under this Policy, and you keep the rights in section 11 over it. Personal data that we have actually deleted, or irreversibly anonymised so that it no longer relates to an identifiable person, counts as deleted.
10. How we protect personal data
We apply the measures described in the Security Statement, including encryption of data in transit and at rest, hashed credentials, access controls and logging, separation between Merchants' data, malware scanning of uploads, and regular backups. No system is perfectly secure; if a Security Incident affects your personal data we act as described in section 12.
11. Your rights
11.1 Singapore. You may ask us for access to the personal data we hold about you and how we have used or disclosed it in the past year, ask us to correct an error or omission, and withdraw consent on reasonable notice. We respond as soon as reasonably possible. If we cannot respond in full within 30 days of receiving your request, we tell you in writing within those 30 days when we will. We may charge a reasonable fee for access, and we will give you a written estimate first; we do not charge for corrections. We may refuse a request where the law allows, for example where it would reveal another person's personal data, and we tell you why.
11.2 Malaysia. Where MY PDPA applies to you, you may ask for access and correction, withdraw consent, require us to stop processing your personal data for direct marketing, and, where technically feasible and the data formats are compatible, ask us to transmit your personal data to another data controller. We respond within the time MY PDPA allows, which is 21 days unless we tell you in writing that we need longer.
11.3 Buyers. If you are a customer of a Merchant, your request should go to that Merchant. If you contact us, we will forward your request to the Merchant within five business days and, unless the law requires us to act, we will not respond in the Merchant's place. Where your request concerns Network Signals, we are the responsible organisation: you may ask us for access to, and correction of, the pseudonymised record we hold about you under section 11.1. We do not delete or nullify Network Signals on request (section 6.5). If you messaged a Merchant on WhatsApp or Instagram and ask us to delete those messages, we act on the request ourselves, as the Data Deletion page describes.
11.4 Withdrawing consent may mean we can no longer provide part of the Service; we tell you the likely consequences before we act on the withdrawal.
11.5 To exercise a right, write to business@hailpilot.com. We may ask you to verify your identity.
11.6 Deleting your data. You may ask us to delete your personal data. A deletion request is carried out as a deletion: the personal details are deleted or blanked in the places the Data Deletion page lists, while the Merchant's order and financial records that referred to you are kept without them. This is different from the tokenisation that happens automatically at the end of a retention period. How to ask, and what happens on each Platform, is set out in our Data Deletion page at /legal/data-deletion.
12. Security Incidents and notification
If we discover a Security Incident affecting personal data, we assess it and, where it concerns Buyer Data, notify the affected Merchant within the time set in the Data Processing Agreement so that the Merchant can meet its own duties. Where we are the responsible organisation and the incident is likely to cause significant harm to you, or is of a significant scale, we notify the Personal Data Protection Commission within the statutory period after assessing it and tell you as soon as practicable, unless the law permits otherwise. For Merchant User data and Network Signals we make that assessment ourselves, within the period the law allows. Where MY PDPA applies and we are the data controller, we notify the Personal Data Protection Commissioner of a personal data breach as soon as practicable and within the period the Commissioner prescribes, and notify affected individuals without unnecessary delay where the breach causes or is likely to cause significant harm.
13. Cookies and tracking
Our use of cookies, local storage and analytics is described in the Cookie & Tracking Notice.
14. Artificial intelligence
We use models from the providers named in the Sub-processor List to summarise evidence, draft replies, classify messages, check images and produce risk signals. When a model processes personal data, only the data needed for that task is sent, the provider's terms exclude training on it (except that where we fine-tune a model used only for one Merchant's workspace, the provider named for that purpose in the Sub-processor List may use the data solely to produce that Merchant's model), and the output is a recommendation for a person to review. On a Merchant's instruction, the AI Features learn from that Merchant's own data, including by fine-tuning a model used only for that Merchant (AI Transparency Notice 4.3). We do not make decisions with legal or similarly significant effect about any person by automated means alone. The AI Transparency Notice describes each feature, the data it uses, its limits, how to report a wrong or harmful output, and how a Buyer can ask for a person to review a decision.
15. Marketing
We send marketing email only to people who have opted in. Every marketing message carries an unsubscribe method and we give effect to an unsubscribe within 10 business days. Account, billing, security and legal notices are not marketing and cannot be unsubscribed from while you hold an account.
16. Children
The Service is for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 18 as a Merchant User.
17. Complaints
Contact the Data Protection Officer first at business@hailpilot.com; we acknowledge complaints within five business days and aim to resolve them within 30 days. If you are not satisfied, you may complain to the Personal Data Protection Commission, Singapore (pdpc.gov.sg) or, for matters under MY PDPA, to the Personal Data Protection Department, Malaysia (pdp.gov.my).
18. Changes
We may update this Policy. Material changes are notified to Merchants in the way and with the notice the Terms of Service require, and listed on the legal changelog page. The version in force is shown at the top of this page.