Chilli Club

Privacy Policy

Effective 2026-08-15 · Governed by Singapore's Personal Data Protection Act 2012 (PDPA)

Chilli Club ("we", "us") operates chilliclub.org as a community platform for members to organize and join weekend activities. This policy explains what personal data we collect, why, and how you can control it.

What we collect

We collect your information in two clearly separate tiers:

Community profile (Tier 1)

Name, email or phone number, avatar, a short bio, interest tags, and an optional emergency contact. This is what runs the platform — signing in, showing your name to other members, and letting event organizers reach you in an emergency.

Society registration support (Tier 2, optional)

Legal full name, NRIC/FIN, nationality, residential address, postal code, and occupation. We only ask for this if you choose to fill it in, and only after you separately tick a dedicated consent box explaining this purpose.

Why we collect it

Tier 1 data operates the community platform: authentication, event participation, seat management, and matching you with activities you're interested in.

Tier 2 data is used only to prepare Chilli Club's formal registration filing with Singapore authorities (expected to be the Registry of Societies). We do not use it for marketing, profiling, or any purpose beyond that filing, and we do not share it with any third party except as required to complete the registration itself.

How long we keep it

Tier 2 data is retained only for as long as you remain a member and the registration process is active. You can withdraw your registration consent at any time from your profile page, which deletes the Tier 2 fields immediately.

Your rights

Under the PDPA, you can at any time:

  • Withdraw consent for Tier 2 (registration) data from your profile page.
  • Request a copy of the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your account and associated data.

To exercise any of these, email privacy@chilliclub.org. Our designated Data Protection Officer can be reached at the same address.

How we protect it

Tier 2 fields are encrypted at rest and only accessible to you and administrators preparing the registration filing. Access to the underlying database is restricted, and we never log Tier 2 field values.