Legal
Privacy Policy for CheckLah Driver
CheckLah Driver is an Android app for Singapore private-hire drivers, operated by CheckLah ("we", "us"). This policy covers the app (package com.checklah.driver) and this website, checklah.app. It is written to be read: short sections, plain English, and nothing the app doesn't actually do.
The Singapore Personal Data Protection Act 2012 (PDPA) is the frame we operate under. For anything data-related, write to [email protected].
Effective
The short version: we store your account, your settings and the surge reports you choose to send. Your location stays on your phone. No ads, no trackers, no selling of data. Delete everything any time, in the app or by email.
What we collect and store#
When you sign in, the following is stored on our backend (hosted on Supabase):
| Data | Details and purpose |
|---|---|
| Account | Your email address and name, via Google Sign-In or email-and-password signup. Passwords are handled by the authentication provider and stored only as hashes; we never see them. If you sign in with Google, your profile photo URL is also stored. |
| Driver profile | Display name, receipt name and vehicle details, used on the receipts you issue. At signup we also ask an optional "Stay in the loop?" question: whether we may contact you occasionally about driver opportunities and updates. Saying no changes nothing, and you can withdraw consent any time by emailing us. |
| App settings | Preferences synced to your account: hub and alert choices, timing preferences, display options. |
| Push token | A Firebase Cloud Messaging token for each signed-in device, used only to deliver your alert notifications. |
| Surge reports | Only when you tap "report surge": the reported location (latitude and longitude), platform tags, intensity and timestamps. Reports are shown to other signed-in drivers on the surge map without any reporter identity; the reporter field is stripped before anything leaves the server. Reports expire automatically within minutes (extendable by community confirmations). Your confirm-or-dismiss votes are stored against your account and are never exposed to other users either. |
| Stripe link | If you connect Stripe: the link between your CheckLah Driver account and your own Stripe connected account. Card payments are processed entirely by Stripe; card numbers never touch CheckLah servers. A customer email entered for a Stripe receipt goes to Stripe for that receipt. |
| Feedback | If you send in-app feedback: your message plus your account email as the reply-to address, relayed by an email-delivery provider to [email protected]. |
Location stays on your phone#
The app uses your precise location, and, if you grant "Allow all the time", your background location. It is used for two things:
- showing your position on the map, and
- evaluating geofences around pickup hubs, so arrival alerts only fire when they're relevant to where you are.
Geofencing is evaluated on your phone by Google Play services. The app does not transmit your location to our servers and does not store any location history on them. The only location that is ever uploaded is the single point of a surge report you explicitly submit (described above).
Also kept on your device only, never uploaded:
- receipt drafts,
- PayNow QR details,
- cached schedules and preferences.
Third parties we rely on#
- Supabase: backend hosting for our database, authentication, file storage and server functions.
- Google: Firebase Cloud Messaging for push delivery, Google Sign-In, and Play services location and geofencing on your device.
- Stripe: payment processing via Stripe Connect and Tap to Pay. You are a Stripe account holder in your own right, and Stripe's own privacy policy applies to payment data.
- OneMap (Singapore Land Authority): map tiles are fetched directly from your device, so OneMap's servers see your device's IP address, as with any map service.
- An email-delivery provider: relays in-app feedback messages to our inbox, nothing else.
Public data sources (Changi Airport, LTA DataMall, KTMB, cruise and ferry operators, event listings) flow into the app. No user data flows to them.
What we don't do#
- No ads.
- No third-party analytics or tracking SDKs.
- No crash-reporting SDK (as of August 2026).
- No sale or sharing of personal data for advertising.
- This website itself sets no cookies and runs no analytics, so the above stays true end to end.
How long we keep data#
Data is kept while your account exists, and deleted when the account is deleted. Surge reports are shorter-lived regardless: they expire automatically within minutes to hours.
Deleting your account#
Two ways, both free:
- In the app: Profile → Delete account. Deletion is immediate and removes your account and all the data listed above.
- By email: write to [email protected] from your registered email address.
Step-by-step instructions are on the delete account page.
Note: deleting your CheckLah Driver account unlinks Stripe but does not close your own Stripe account (it's yours), and payment records held by Stripe are governed by Stripe's retention obligations.
Your rights#
Under the PDPA you can ask us for access to the personal data we hold about you, ask us to correct it, or withdraw consent (including the optional marketing consent) at any time. Email [email protected] and we'll handle it. If you're in a jurisdiction with similar rights (such as the GDPR's access, rectification, erasure and portability rights), we honour those requests the same way, through the same address.
Changes to this policy#
If our data practices change, we'll update this page and its effective date before the change ships. Material changes will also be flagged in the app.
Contact#
CheckLah, operator of CheckLah Driver.
Data matters: [email protected]