RePace legal
Privacy Policy
- Effective date
- 23 July 2026
- Last updated
- 23 July 2026
1. Who this policy applies to
This policy applies to personal data handled through RePace. RePace is operated by [Legal business name], [UEN, if applicable], with its business contact address at [Business contact address].
For personal-data questions, access or correction requests, withdrawal of consent or complaints, contact our Data Protection Officer at [DPO email address]. For general marketplace support, contact hello@repace.co.
2. Information RePace collects
We collect information you provide when you use RePace and limited technical information required to deliver and protect the service.
- Account information: your email address and display name when you create an account. If you use Google sign-in, we also receive the verified email address, display name and profile image provided by Google. If you use email sign-in, we send a short-lived verification code to confirm you control that email address; RePace does not store an account password.
- Profile and marketplace information: information you choose to publish, such as your biography, general location, listing titles, brand, model, sizes, price, condition, description, status and footwear photographs.
- Communications and activity: messages, offers, reviews, reports, saved listings, saved searches, recently viewed listings, notifications and account preferences created through the service.
- Information shared during a transaction: personal information you voluntarily include in messages or provide directly to another user when arranging a meet-up, collection, delivery or payment. Please share only what is necessary.
- Technical and security information: limited request, device, browser and log information that our hosting and security infrastructure may process to operate, troubleshoot and protect RePace. RePace uses Cloudflare Web Analytics for privacy-first, aggregate traffic measurement and does not use advertising or behavioural profiling.
3. How we collect and use information
We collect information directly from you when you sign in, update your profile, create a listing, upload photos, save a listing or search, send a message, make or receive an offer, write a review, submit a report or contact us.
We use personal data to operate your account and the marketplace; display listings and profiles; enable messages, offers, reviews and notifications; provide support; maintain safety and prevent fraud, abuse and policy breaches; investigate reports; improve reliability; and comply with legal obligations.
When you provide another user’s personal data or include personal data in content, you are responsible for doing so lawfully and only where appropriate.
4. Email and marketing communications
RePace may send an operational email when another user sends you a marketplace message, if email notifications are enabled for your account. We use the email address associated with your account for this purpose.
The current RePace News section does not include an email newsletter subscription form. RePace will update this policy before collecting newsletter subscriptions. If optional marketing communications are introduced, RePace will obtain consent where required and provide a way to withdraw it.
5. Service providers and overseas transfers
RePace currently relies on Google for account sign-in, Cloudflare for application hosting and the database and image storage used to operate RePace, and Resend to send transactional message-notification emails. These providers process information only as needed to provide their services to RePace.
These providers may process information outside Singapore. Where personal data is transferred overseas, RePace will take reasonable steps to ensure that the transfer is made in accordance with applicable law and that the receiving organisation provides a standard of protection comparable to that required under the PDPA, unless an exception applies.
6. Security and retention
We use reasonable administrative, technical and organisational measures designed to protect personal data against unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks. No online service can guarantee absolute security, so please keep account access secure and do not share more personal information than is necessary.
We keep personal data only for as long as it is needed to operate RePace, resolve disputes, enforce policies, meet legal obligations or for other legitimate business purposes. We will stop retaining or dispose of personal data when it is no longer needed, subject to applicable legal requirements.
7. Access, correction, withdrawal and account deletion
You may ask to access or correct personal data that RePace holds about you, subject to applicable law. You may also withdraw consent for uses of personal data where consent is the basis for the use. Withdrawal may mean that we can no longer provide some features or your account.
Account deletion is not currently a self-service feature. To request account deletion, access, correction or withdrawal of consent, contact [DPO email address] from the email address connected to your RePace account. We may need to verify your identity and may retain limited information where necessary for legal, security, fraud-prevention or dispute-resolution purposes.
8. Data breaches and children
If a data incident occurs, RePace will assess it and take steps required by applicable law, including notifying affected individuals and the Personal Data Protection Commission where a breach is notifiable.
RePace is not intended for children under 18. Do not create an account or provide personal data if you are under 18.
9. Changes and contact
We may update this policy as RePace changes or as law requires. The latest version will be posted here with a revised Last updated date.
Questions, requests and concerns about this policy should be sent to [DPO email address].
