Privacy Policy
Last updated: 24 September 2026
We wrote this policy to be read, not filed away. If something is unclear, please email us — details at the bottom.
1. Who we are
HAH! is a mobile app and website (hah.sg) that helps employers and domestic helpers manage their household together — payroll, groceries, leave planning, and more. It is operated by HAH! HELP AT HOME, a sole proprietorship registered in Singapore (UEN 53526050D), and is subject to Singapore's Personal Data Protection Act 2012 (PDPA).
2. What personal data we collect
We only collect information that the app needs to work. Here is exactly what that is:
Employer account
- Name
- Email address
- Password (we never see it — Firebase stores a secure hash, not the actual password)
- Household name
Helper account
- Name
- Email address
- Password (same — securely hashed by Firebase, not readable by us)
On-device only (not stored on our servers)
- Radio station favourites — saved in your phone's local storage so your bookmarked stations persist between sessions. This data never leaves your device.
- "Remember me" login — if you enable it at sign-in, your email and password are stored encrypted on your device only (Android Keystore / iOS Keychain), protected by your device's screen lock or biometric. They are never uploaded to our servers, and are removed when you turn "Remember me" off or sign out. The biometric check happens entirely on your device — we never see or store any biometric data.
- Photos you share in Chat — kept on your phone and on the phone of the person you sent them to. To get a photo from one phone to the other, it passes through our servers only until the other person's app collects it, and is then deleted from our servers. A photo that is not collected within 7 days is deleted anyway. Before a photo leaves your phone, the app removes the hidden information cameras add to photos, including the location where it was taken.
Household data (entered by you or your helper)
- Salary details: monthly base salary, Sunday rate, pay date, exclusion period
- Worked Sunday dates and leave dates
- Generated payslips
- Grocery list items
- Chat messages (text). Photos in Chat are kept on your phones, not by us — see "On-device only" above.
- Emergency contact names and phone numbers (for the My Helper / My Employer screens)
- Address — the address you optionally add in Settings, shown on the My Helper / My Employer screen so your household contact can reach you
Employment compliance dates (entered by employer)
- Work Permit expiry date, six-monthly medical examination due date, and passport expiry date. These are dates only — no document numbers, FIN, or passport numbers are collected or stored. They are entered by the employer solely for the purpose of generating compliance reminders visible to both the employer and their helper.
Technical data (needed to run the service)
- A push-notification token for your device, so we can send the alerts you've enabled (e.g. pay-day reminders).
- Your language preference, so the app and notifications appear in your chosen language.
- Basic in-app activity used to run features (e.g. unread counts for the shared lists).
- How you found us — if you reach our website through an advertisement or a shared link, we record what that link says about where it came from (for example the advertising platform and the campaign name) and the website that referred you, if any. We keep this with your account so we can tell which of our efforts actually reach people. It is not used to build a profile of you, it is not combined with data from other companies, and it is never sent back to the advertising platform. We do not use advertising cookies or tracking pixels on our website.
Reports
- If you report a message in Chat, we receive a copy of that message, and of its photo if it has one, together with who reported it, who sent it, and when. We use this only to review the report. See Section 7 for how long it is kept.
Activity and derived data (used for the harmony score)
- Session timestamps — the dates on which you open the app (a daily "check-in"), used as one input to the household harmony score and to show a check-in streak.
- Derived engagement data — a computed harmony score and its sub-signals (see Section 11). This is information inferred from your in-app activity, not information you type in. It is treated as your personal data and is covered by this policy.
What we do NOT collect
- NRIC, FIN, or passport numbers
- Medical records or health information
- Identification documents of any kind
- Biometric data (fingerprints, face scans, etc.)
- Location data
- Device advertising IDs
3. Why we collect it, and our legal basis
| Data | Why we need it |
|---|---|
| Name and email | To create and identify your account, and to link an employer and helper to the same household |
| Password hash | To let you log in securely |
| Salary and payslip data | To calculate pay, generate payslips, and maintain a record for your household |
| Sunday dates | To count worked Sundays accurately in each pay period |
| Grocery items, tasks, notes | To run the shared shopping list, scheduler, and noticeboard between you and your helper |
| Emergency contact details | To display on the My Helper / My Employer screen so either party can reach the other quickly in an emergency |
| Push token, language, activity | To deliver notifications you've enabled and show the app in your language |
| How you found us | To measure which of our own advertisements and shared links actually bring people to HAH! |
| Photos in Chat (while in transit) | To deliver a photo from one household member's phone to the other's |
| Reports | To review reported messages and photos, and to act on misuse, including mistreatment |
We process personal data primarily to provide the services you request, and for purposes reasonably necessary to operate, maintain, secure, and improve the service. Where we rely on your consent — for example, a helper agreeing to this policy at first sign-in — you may withdraw that consent as described in Section 12. We do not advertise to you, build profiles about you, or share or sell your data to advertisers or data brokers. The one marketing-related thing we do is count how people arrived (Section 2, "How you found us"), so we can tell which of our own efforts are working — that measurement stays entirely with us and never leaves for an advertising platform.
4. Who can see your data, and the service providers we use
Within your household only. HAH! is built so that each employer and helper can only see their own household's data. An employer can see their helper's name, salary details, Sunday leave records, and emergency contact details. A helper can see their employer's name and emergency contact details. No one outside your household can access your data through the app.
Photos in Chat. While a photo is on its way, only the person who sent it and the person it was sent to can open it. We do not look at photos in Chat. The one exception is a photo someone chooses to report to us: we look at it only to deal with that report.
Our team. As a small sole proprietorship, only the operator has technical access to the backend. We do not have a large team with broad data access.
Service providers we use. We rely on a small number of trusted providers who process data only on our instructions, under their own data-protection terms, and who are not permitted to use your data for their own purposes:
- Google Firebase — Authentication, Firestore Database, Cloud Storage, Cloud Functions, and Cloud Messaging. This is where your account and household data are stored and processed. (privacy practices)
- Stripe — payment processing for subscriptions purchased on our website (hah.sg), which is also how Android users subscribe. Card details are entered directly with Stripe; we never see or store your full card number. (privacy policy)
- RevenueCat — manages subscriptions bought in the app on iPhone or iPad. It receives your HAH! account ID — a random identifier, not your name or email address — and your purchase and subscription status, so we can confirm your access. (privacy policy)
- Zoho Mail — sending transactional emails (such as welcome emails and reminders) from support@hah.sg.
- Expo — delivering push notifications you've enabled to your device.
Services that act under their own terms. Two services are not our providers in the sense above: they deal with you directly, under their own privacy policies rather than our instructions.
- Apple — if you subscribe in the app on iPhone or iPad, Apple takes the payment through the App Store. We never receive your card or Apple account details; we are told only whether your subscription is active. (Apple privacy policy)
- Radio Browser and radio stations (My Radio, helpers only) — My Radio lists stations from the open Radio Browser directory (radio-browser.info), and each station streams from its own broadcaster's server. When you open My Radio or play a station, your device connects to them directly, so they receive your device's IP address and the station you chose. We do not send them your name, email, or any account information, and your favourite stations stay on your device (see Section 2). If you do not use My Radio, these connections are never made.
If an agency introduced you to HAH!. Some employment agencies share HAH! with the households they place a helper with, using their own link or code. If you arrived that way, we record which agency it was. We tell that agency only counts — how many households joined through them, and how many are still using HAH! — never your name, your email, your household's data, or whether any particular person signed up. You can remove the agency from your household at any time in Settings, and nothing about you is sent to them either way.
No one else. Apart from the services named above, we do not share your personal data with any third party — and we never sell or rent it, to anyone, ever.
5. Where your data is stored and cross-border transfers
Your data is stored primarily on Google Firebase in the asia-southeast1 region (Singapore). However, certain support, security, backup, or operational functions provided by our service providers may involve processing in other countries. Where this occurs, we take reasonable steps to ensure that transferred personal data receives a standard of protection comparable to that required under Singapore's PDPA.
Two services named in Section 4 operate outside Singapore. If you subscribe in the app on iPhone or iPad, RevenueCat, a US-based provider, processes your account ID and subscription status. If a helper uses My Radio, their device connects directly to radio stations, which may be hosted in any country.
6. Phone numbers
Phone numbers entered in the My Helper or My Employer screen are displayed on-screen for emergency reference only. They are:
- Never used to call or message you by us or anyone connected to the app
- Never shared with third parties
- Not used for marketing of any kind
- Only visible to the one other person in your household (your employer or your helper)
7. How long we keep your data
| Data type | Kept for |
|---|---|
| All account and household data | As long as your account is open |
| Payslip history | 3 years after account closure — we retain this to help you meet MOM record-keeping requirements if needed |
| Billing records held by Stripe (invoices and payment history) | 5 years, as Singapore tax law requires us to keep business accounting records. When you delete your account we delete your Stripe customer profile — your name, email address and saved payment method — but the underlying invoices remain for this period. If you never subscribed, there is nothing to keep. |
| Harmony score and its signals | Computed on a rolling 30-day window (older activity drops out automatically); the stored score is deleted as soon as either the employer or the helper closes their account |
| Session timestamps (app-open / check-in dates) | Kept only as long as needed for the rolling 30-day score and the check-in streak, and deleted with your account |
| All other data (grocery items, Sunday dates, emergency contacts, etc.) | Deleted 12 months after account closure |
| Data following a deletion request | Deleted promptly, and no later than 30 days from the date of your request |
| Photos in Chat, on our servers | Only until the other person's app collects the photo, then deleted. Never kept longer than 7 days. |
| Photos in Chat, on your phones | Until you delete the message, remove the app, or change phones. We cannot recover them for you. |
| Reported messages and photos | Deleted when we close the report, and no later than 30 days after it was made |
Deleting a Chat message. When you delete one of your own messages, it is removed for everyone, and any photo in it is deleted from our servers straight away. The other person's app is told to delete its copy of the photo too, including the next time they open the app if their phone was off. We keep a small record that the photo was deleted (not the photo itself) for up to one year for this purpose. We cannot guarantee a copy is gone if the other person saved it elsewhere, for example by taking a screenshot.
The monthly recap figures shown on the home screen (e.g. salary timing, Sundays granted, noticeboard post count) are calculated on the fly from data already listed above — they are not stored as a separate record, so they carry no additional retention period beyond their underlying data.
If you close your account and later want us to delete your payslip history before the 3-year period ends, you can request that too — see Section 12.
8. Security and data-breach notification
Your data is stored on Google Firebase infrastructure in Singapore. Firebase enforces encrypted connections (TLS) for all data in transit. Photos in Chat are encrypted in transit and on our servers, as all data is. They are not end-to-end encrypted: while a photo is waiting to be collected, it could technically be opened by our systems, which is why we delete it as soon as it has been delivered. Passwords are never stored in readable form — Firebase Authentication handles credential storage using industry-standard hashing.
Access within the app is controlled by Firestore security rules so that only you and the person you are linked to in the app can read your household's data.
No system is perfectly secure. If we become aware of a data breach that is likely to result in significant harm to affected individuals, or that meets applicable regulatory notification thresholds, we will take reasonable steps to investigate and contain it, and to notify affected individuals and the Personal Data Protection Commission (PDPC) as required by law. If you suspect your account has been compromised, please change your password immediately through the app's Settings screen and contact us at the address below.
9. Cookies, analytics and tracking
We do not use third-party analytics, advertising, or cross-app/cross-site tracking tools (such as Google Analytics, Firebase Analytics, Crashlytics, Meta Pixel, or similar). The app and website use only the technical storage strictly necessary to keep you signed in and to run core features. We do not use tracking or advertising cookies.
10. Automated calculations
The app performs automated calculations based on the information you enter — for example, monthly salary, Sunday pay, and payslip totals. These are tools to assist you and are not a substitute for your own judgement. You remain responsible for reviewing any generated payroll information before relying on or acting on it.
Artificial intelligence. We do not use personal data submitted through the service to train artificial-intelligence models, and we do not sell or share it for that purpose.
11. Harmony score and engagement data
To help a household coordinate, HAH! computes a harmony score for each employer–helper relationship.
What it is. The harmony score is a single number (0–100) that acts as a gentle indicator of how actively the household is using the app together. It is a product feature to aid coordination — it is not an official government, Ministry of Manpower (MOM), or regulatory metric, and it is not an assessment of a person's character or work performance.
What feeds into it. The score is calculated from a rolling 30-day window of ordinary in-app activity:
- how often each person opens the app (the daily check-in),
- noticeboard posting activity,
- grocery list activity,
- how far in advance Sunday leave is planned and confirmed, and
- whether salary is generated on time.
These signals are combined into the single score. The score updates automatically as activity changes.
Who can see it. The score and its sub-signals are visible only to the employer, for each of their own helpers. Helpers do not see their own score — the helper home screen deliberately shows no score, streak, or numeric rating. No one outside the household can see it, and it is never shared with MOM, recruitment agencies, or any third party.
Why we can show it. The helper agrees to this at first sign-in (see the in-app consent screen), and the employer acknowledges that the score is a coordination aid only when adding a helper.
How long it is kept. See Section 7 — the score is computed on a rolling 30-day basis and is deleted as soon as either party closes their account.
A note for everyone. Because the score reflects app usage rather than the quality of someone's work, it should never be treated as a performance review or used on its own to make employment decisions. Our Terms of Service set this out as a binding condition of using the app.
12. Your rights under the PDPA
Under Singapore's Personal Data Protection Act, you have the right to:
- Access the personal data we hold about you
- Correct any data that is inaccurate or incomplete
- Withdraw consent for us to use your data (note: this may mean we can no longer provide the service)
- Request deletion of your data
Because photos in Chat are kept on your phones rather than by us, an access or deletion request covers only what is still on our servers: photos not yet collected, and reports. To delete a photo from your household's phones, delete the message in Chat.
How to delete your account. You can delete your account directly in the app: Settings → Delete my account. You can also email privacy@hah.sg and we will action it for you.
To exercise any of these rights, email our Data Protection Officer (DPO) at privacy@hah.sg. Please include your name and the email address associated with your account so we can locate your data. We will respond within 10 business days. Complex requests may take up to 30 days; we will let you know if that is the case. We do not charge a fee for access or correction requests.
13. Children
HAH! is designed for use by adults. We do not knowingly collect personal data from anyone under the age of 18. If you believe a minor's data has been entered into the app, please contact us so we can delete it.
14. Changes to this policy
If we make changes that affect how we use your data, we will update this page and change the "Last updated" date at the top. For significant changes, we will notify you through the app.
15. Contact and complaints
If you feel that your personal data has been collected, used, or shared in a way that is unfair, not explained here, or that makes you uncomfortable, you have every right to raise it. This applies to everyone — and we especially want helpers to know they are welcome to contact us directly.
Step 1 — Contact us directly. Email our Data Protection Officer at privacy@hah.sg. You can write in English, Tagalog, Bahasa Indonesia, or Burmese and we will do our best to respond. Tell us what happened and what you would like us to do. We will reply within 10 business days.
Step 2 — Contact the PDPC. If you are not satisfied with our response, you can lodge a complaint with Singapore's Personal Data Protection Commission (PDPC) — the government body that enforces the PDPA.
- Website: www.pdpc.gov.sg
- Online complaint form: www.pdpc.gov.sg/complaints
- Helpline: 6377 3131
You do not need a lawyer to make a complaint to the PDPC, and there is no fee.
Other support organisations for domestic helpers in Singapore:
- MOM Helpline: 1800-339-5505
- HOME (Humanitarian Organisation for Migration Economics): +65 6602 1912
- TWC2 (Transient Workers Count Too): +65 6246 8979
This policy is written in plain English and is intended to be the complete and authoritative description of how HAH! handles your personal data. If there is any conflict between this document and any other communication, this document applies.
