X Multiply Private Limited · UEN 202622174G · Last updated 19 August 2026
X Multiply Private Limited ("X Multiply", "we", "us") is a management consultancy registered in Singapore under UEN 202622174G. We provide advisory services to food and beverage businesses, and we operate software that helps our clients collect their own daily operational reporting.
This policy explains how we handle personal data, and is issued in accordance with Singapore's Personal Data Protection Act 2012 (PDPA). It covers two distinct things:
This website does not run analytics, advertising trackers, or third-party scripts, and does not set cookies for tracking purposes.
The contact form on this site does not transmit anything to us directly. Submitting it opens your own email application with a pre-filled message, which you then choose to send or discard. We therefore receive your name, email address, and message only if you decide to send that email — at which point we hold it as ordinary business correspondence.
Our web host may keep standard server logs, such as IP addresses and requested pages, for security and reliability purposes.
For clients who engage us to operate daily sales reporting, our system handles the following, all of it relating to that client's own employees:
| Category | What it is | Where it comes from |
|---|---|---|
| Contact details | Name, mobile number, job title of the store in-charge | Supplied by the employer |
| Message content | WhatsApp replies, selections and form answers | Sent by the employee |
| Photographs | Images of point-of-sale closing receipts | Sent by the employee |
| Business figures | Daily sales totals and related operational data | Read from the receipts, or entered |
| Delivery records | Whether a message was sent, delivered or read | The messaging provider |
Receipt photographs are operational documents rather than personal records, but they may incidentally contain a staff identifier printed by the till. We treat them as personal data for that reason.
We do not knowingly collect data about members of the public through this service, and it is not used to contact consumers.
When we operate the reporting service, the employing business decides what data is collected and why. Under the PDPA we act as a data intermediary, processing that data on their instructions and on their behalf.
This means that if you are an employee of one of our client businesses, your employer is the organisation responsible for your personal data. Requests about your data are best directed to them; if you contact us instead, we will refer you to them and assist as required.
For our own business records — our staff, our suppliers, and people who write to us — we are the responsible organisation.
We use personal data only to deliver the service our client has engaged us for, specifically to:
We do not send marketing or promotional messages, we do not sell or rent personal data, and we do not use it to build advertising profiles.
We use a small number of established service providers to run the system. Each receives only what it needs, and each is bound to use it solely to provide their service to us:
| Provider | What it does | What it sees |
|---|---|---|
| Messaging provider (Twilio, and/or Meta Platforms for WhatsApp) | Delivers and receives WhatsApp messages | Mobile numbers and message content |
| Text-recognition provider (OpenAI, Google Cloud Vision, or Microsoft Azure, depending on configuration) | Reads figures from receipt photographs | Receipt images |
| Cloud hosting and database (Railway) | Runs the application and stores its data | All service data, at rest |
| Object storage | Stores uploaded receipt images | Receipt images |
| Google (sign-in) | Authenticates our own staff into the administration tools | Staff email address and name |
We may also disclose personal data where we are required to do so by law, by a court, or by a regulator, or where necessary to establish or defend a legal claim.
Our service providers operate infrastructure outside Singapore, so personal data may be transferred to and stored in other countries. Where we transfer personal data overseas, we take reasonable steps to ensure it receives a standard of protection comparable to that required under the PDPA, including through the contractual terms we accept with those providers.
We keep personal data only for as long as it serves the purpose it was collected for, or as long as we are required to keep it by law or by our agreement with the client.
| What | How long |
|---|---|
| Receipt photographs | Not retained. Images are retrieved from the messaging provider, read, and discarded. We do not store them. |
| Message content | 12 months, after which the stored message body and sender number are permanently cleared |
| Delivery and audit records | 3 years, after which they are deleted |
| Generated report documents | 12 months, after which the document is deleted |
| Staff contact records | Removed within 30 days of a client engagement ending |
When data is no longer needed, we delete it or render it anonymous.
We apply security measures appropriate to the sensitivity of the data, including:
No system can be guaranteed completely secure. If a data breach occurs that is likely to result in significant harm, we will notify the affected organisation and the Personal Data Protection Commission as required under the PDPA.
Under the PDPA you may, subject to certain exceptions:
Withdrawing consent may mean we can no longer provide part or all of a service to you. If you are an employee of a client business, please raise these requests with your employer in the first instance, as described in section 4.
For any question about this policy, or to make a request under section 10, contact our Data Protection Officer:
Data Protection Officer
X Multiply Private Limited
hello@xmultiplysg.space
We aim to acknowledge requests within 5 business days and to respond substantively within 30 days. If we cannot respond within 30 days, we will tell you when to expect our response.
We may update this policy from time to time. The revised version takes effect when published on this page, and the date at the top will change. Where a change is significant, we will take reasonable steps to notify affected clients directly.