Privacy Policy
Last updated: 27 June 2026
We wrote this policy to be read, not filed away. If something is unclear, please email us — details at the bottom.
1. Who we are
HAH! is a mobile app and website (hah.sg) that helps employers and domestic helpers manage their household together — payroll, groceries, leave planning, and more. It is operated by HAH! HELP AT HOME, a sole proprietorship registered in Singapore (UEN 53526050D), and is subject to Singapore's Personal Data Protection Act 2012 (PDPA).
2. What personal data we collect
We only collect information that the app needs to work. Here is exactly what that is:
Employer account
- Name
- Email address
- Password (we never see it — Firebase stores a secure hash, not the actual password)
- Household name
Helper account
- Name
- Email address
- Password (same — securely hashed by Firebase, not readable by us)
On-device only (not stored on our servers)
- Radio station favourites — saved in your phone's local storage so your bookmarked stations persist between sessions. This data never leaves your device.
- "Remember me" login — if you enable it at sign-in, your email and password are stored encrypted on your device only (Android Keystore / iOS Keychain), protected by your device's screen lock or biometric. They are never uploaded to our servers, and are removed when you turn "Remember me" off or sign out. The biometric check happens entirely on your device — we never see or store any biometric data.
Household data (entered by you or your helper)
- Salary details: monthly base salary, Sunday rate, pay date, exclusion period
- Worked Sunday dates and leave dates
- Generated payslips
- Grocery list items
- Shared noticeboard notes
- Emergency contact names and phone numbers (for the My Helper / My Employer screens)
- Address — the address you optionally add in Settings, shown on the My Helper / My Employer screen so your household contact can reach you
Employment compliance dates (entered by employer)
- Work Permit expiry date, six-monthly medical examination due date, and passport expiry date. These are dates only — no document numbers, FIN, or passport numbers are collected or stored. They are entered by the employer solely for the purpose of generating compliance reminders visible to both the employer and their helper.
Technical data (needed to run the service)
- A push-notification token for your device, so we can send the alerts you've enabled (e.g. pay-day reminders).
- Your language preference, so the app and notifications appear in your chosen language.
- Basic in-app activity used to run features (e.g. unread counts for the shared lists).
Activity and derived data (used for the harmony score)
- Session timestamps — the dates on which you open the app (a daily "check-in"), used as one input to the household harmony score and to show a check-in streak.
- Derived engagement data — a computed harmony score and its sub-signals (see Section 11). This is information inferred from your in-app activity, not information you type in. It is treated as your personal data and is covered by this policy.
What we do NOT collect
- NRIC, FIN, or passport numbers
- Medical records or health information
- Identification documents of any kind
- Biometric data (fingerprints, face scans, etc.)
- Location data
- Device advertising IDs
3. Why we collect it, and our legal basis
| Data | Why we need it |
|---|---|
| Name and email | To create and identify your account, and to link an employer and helper to the same household |
| Password hash | To let you log in securely |
| Salary and payslip data | To calculate pay, generate payslips, and maintain a record for your household |
| Sunday dates | To count worked Sundays accurately in each pay period |
| Grocery items, tasks, notes | To run the shared shopping list, scheduler, and noticeboard between you and your helper |
| Emergency contact details | To display on the My Helper / My Employer screen so either party can reach the other quickly in an emergency |
| Push token, language, activity | To deliver notifications you've enabled and show the app in your language |
We process personal data primarily to provide the services you request, and for purposes reasonably necessary to operate, maintain, secure, and improve the service. Where we rely on your consent — for example, a helper agreeing to this policy at first sign-in — you may withdraw that consent as described in Section 12. We do not use any of your data for advertising, profiling, or marketing of any kind.
4. Who can see your data, and the service providers we use
Within your household only. HAH! is built so that each employer and helper can only see their own household's data. An employer can see their helper's name, salary details, Sunday leave records, and emergency contact details. A helper can see their employer's name and emergency contact details. No one outside your household can access your data through the app.
Our team. As a small sole proprietorship, only the operator has technical access to the backend. We do not have a large team with broad data access.
Service providers we use. We rely on a small number of trusted providers who process data only on our instructions, under their own data-protection terms, and who are not permitted to use your data for their own purposes:
- Google Firebase — Authentication, Firestore Database, Cloud Functions, and Cloud Messaging. This is where your account and household data are stored and processed. (privacy practices)
- Stripe — payment processing for subscriptions, which are purchased on our website (hah.sg). Card details are entered directly with Stripe; we never see or store your full card number. (privacy policy)
- Zoho Mail — sending transactional emails (such as welcome emails and reminders) from support@hah.sg.
- Expo — delivering push notifications you've enabled to your device.
No one else. We do not sell, rent, or share your personal data with any other third party for their own use — ever.
5. Where your data is stored and cross-border transfers
Your data is stored primarily on Google Firebase in the asia-southeast1 region (Singapore). However, certain support, security, backup, or operational functions provided by our service providers may involve processing in other countries. Where this occurs, we take reasonable steps to ensure that transferred personal data receives a standard of protection comparable to that required under Singapore's PDPA.
6. Phone numbers
Phone numbers entered in the My Helper or My Employer screen are displayed on-screen for emergency reference only. They are:
- Never used to call or message you by us or anyone connected to the app
- Never shared with third parties
- Not used for marketing of any kind
- Only visible to the one other person in your household (your employer or your helper)
7. How long we keep your data
| Data type | Kept for |
|---|---|
| All account and household data | As long as your account is open |
| Payslip history | 3 years after account closure — we retain this to help you meet MOM record-keeping requirements if needed |
| Harmony score and its signals | Computed on a rolling 30-day window (older activity drops out automatically); the stored score is deleted as soon as either the employer or the helper closes their account |
| Session timestamps (app-open / check-in dates) | Kept only as long as needed for the rolling 30-day score and the check-in streak, and deleted with your account |
| All other data (grocery items, Sunday dates, emergency contacts, etc.) | Deleted 12 months after account closure |
| Data following a deletion request | Deleted promptly, and no later than 30 days from the date of your request |
The monthly recap figures shown on the home screen (e.g. salary timing, Sundays granted, noticeboard post count) are calculated on the fly from data already listed above — they are not stored as a separate record, so they carry no additional retention period beyond their underlying data.
If you close your account and later want us to delete your payslip history before the 3-year period ends, you can request that too — see Section 12.
8. Security and data-breach notification
Your data is stored on Google Firebase infrastructure in Singapore. Firebase enforces encrypted connections (TLS) for all data in transit. Passwords are never stored in readable form — Firebase Authentication handles credential storage using industry-standard hashing.
Access within the app is controlled by Firestore security rules so that only you and the person you are linked to in the app can read your household's data.
No system is perfectly secure. If we become aware of a data breach that is likely to result in significant harm to affected individuals, or that meets applicable regulatory notification thresholds, we will take reasonable steps to investigate and contain it, and to notify affected individuals and the Personal Data Protection Commission (PDPC) as required by law. If you suspect your account has been compromised, please change your password immediately through the app's Settings screen and contact us at the address below.
9. Cookies, analytics and tracking
We do not use third-party analytics, advertising, or cross-app/cross-site tracking tools (such as Google Analytics, Firebase Analytics, Crashlytics, Meta Pixel, or similar). The app and website use only the technical storage strictly necessary to keep you signed in and to run core features. We do not use tracking or advertising cookies.
10. Automated calculations
The app performs automated calculations based on the information you enter — for example, monthly salary, Sunday pay, and payslip totals. These are tools to assist you and are not a substitute for your own judgement. You remain responsible for reviewing any generated payroll information before relying on or acting on it.
Artificial intelligence. We do not use personal data submitted through the service to train artificial-intelligence models, and we do not sell or share it for that purpose.
11. Harmony score and engagement data
To help a household coordinate, HAH! computes a harmony score for each employer–helper relationship.
What it is. The harmony score is a single number (0–100) that acts as a gentle indicator of how actively the household is using the app together. It is a product feature to aid coordination — it is not an official government, Ministry of Manpower (MOM), or regulatory metric, and it is not an assessment of a person's character or work performance.
What feeds into it. The score is calculated from a rolling 30-day window of ordinary in-app activity:
- how often each person opens the app (the daily check-in),
- noticeboard posting activity,
- grocery list activity,
- how far in advance Sunday leave is planned and confirmed, and
- whether salary is generated on time.
Who can see it. The score and its sub-signals are visible only to the employer, for each of their own helpers. Helpers do not see their own score — the helper home screen deliberately shows no score, streak, or numeric rating. No one outside the household can see it, and it is never shared with MOM, recruitment agencies, or any third party.
Why we can show it. The helper agrees to this at first sign-in (see the in-app consent screen), and the employer acknowledges that the score is a coordination aid only when adding a helper.
How long it is kept. See Section 7 — the score is computed on a rolling 30-day basis and is deleted as soon as either party closes their account.
A note for everyone. Because the score reflects app usage rather than the quality of someone's work, it should never be treated as a performance review or used on its own to make employment decisions. Our Terms of Service set this out as a binding condition of using the app.
12. Your rights under the PDPA
Under Singapore's Personal Data Protection Act, you have the right to:
- Access the personal data we hold about you
- Correct any data that is inaccurate or incomplete
- Withdraw consent for us to use your data (note: this may mean we can no longer provide the service)
- Request deletion of your data
How to delete your account. You can delete your account directly in the app: Settings → Delete my account. You can also email privacy@hah.sg and we will action it for you.
To exercise any of these rights, email our Data Protection Officer (DPO) at privacy@hah.sg. Please include your name and the email address associated with your account so we can locate your data. We will respond within 10 business days. Complex requests may take up to 30 days; we will let you know if that is the case. We do not charge a fee for access or correction requests.
13. Children
HAH! is designed for use by adults. We do not knowingly collect personal data from anyone under the age of 18. If you believe a minor's data has been entered into the app, please contact us so we can delete it.
14. Changes to this policy
If we make changes that affect how we use your data, we will update this page and change the "Last updated" date at the top. For significant changes, we will notify you through the app.
15. Contact and complaints
If you feel that your personal data has been collected, used, or shared in a way that is unfair, not explained here, or that makes you uncomfortable, you have every right to raise it. This applies to everyone — and we especially want helpers to know they are welcome to contact us directly.
Step 1 — Contact us directly. Email our Data Protection Officer at privacy@hah.sg. You can write in English, Tagalog, Bahasa Indonesia, or Burmese and we will do our best to respond. Tell us what happened and what you would like us to do. We will reply within 10 business days.
Step 2 — Contact the PDPC. If you are not satisfied with our response, you can lodge a complaint with Singapore's Personal Data Protection Commission (PDPC) — the government body that enforces the PDPA.
- Website: www.pdpc.gov.sg
- Online complaint form: www.pdpc.gov.sg/complaints
- Helpline: 6377 3131
You do not need a lawyer to make a complaint to the PDPC, and there is no fee.
Other support organisations for domestic helpers in Singapore:
- MOM Helpline: 1800-339-5505
- HOME (Humanitarian Organisation for Migration Economics): +65 6602 1912
- TWC2 (Transient Workers Count Too): +65 6246 8979
