Version 1.0 - 25 August 2026 (supersedes the in-app Personal Data Protection Policy 1.2)
1. Introduction
COVARAGE PTE. LTD. (UEN 202531227H) ("Covarage", "we", "our", "us") is committed to protecting the Personal Data of our users, customers, employees, partners, and vendors in accordance with the Personal Data Protection Act 2012 ("PDPA") of Singapore. This Policy explains how we collect, use, disclose, store, retain, and protect Personal Data in connection with our insurance document platform, renewal-date records, introductions to licensed insurance intermediaries, concierge services, and policy record-keeping.
2. Definitions
- Personal Data: Data, whether true or not, about an identifiable individual.
- Business Contact Information (BCI): Business email, business phone number, job title or business address. BCI is excluded from PDPA obligations under Section 4(5).
- Data Intermediaries: Vendors or service providers that process data on behalf of Covarage, including cloud and hosting providers.
- User: Any individual interacting with Covarage's website, APIs, mobile applications, concierge services, or insurance operations.
3. Collection of Personal Data
We collect Personal Data when individuals:
- Record the insurance requirements they wish to obtain cover for, or provide renewal details.
- Upload policy documents, employment information, or claim documents.
- Interact with Covarage's apps, web portals, WhatsApp, email, or support channels.
- Communicate with us for account support, document handling or servicing.
- Engage our concierge or medical partners.
- Submit documents such as NRIC, passport, medical reports, or invoices.
- Provide information through employers, brokers, insurers, or landlords.
- We also collect information through cookies and digital analytics tools.
4. Use of Personal Data
- Service Delivery: Operating user accounts, storing uploaded documents, showing the renewal dates a user records, recording the requirements a user provides, passing those details to a licensed insurance intermediary where the user asks to be introduced, where we do so monitoring how promptly that intermediary responds, and storing and forwarding a claim document at the user's request.
- Business Operations: Analytics, product development, fraud detection, and customer support.
- Legal and Regulatory: Responding to lawful requests and fulfilling obligations to authorities and partners.
- Note: We do not sell Personal Data.
5. Disclosure of Personal Data
We disclose Personal Data only where necessary to:
- Licensed insurance intermediaries to whom a user has asked to be introduced, and through them, insurers.
- Concierge partners, clinics, hospitals, and medical networks.
- Cloud service vendors and data intermediaries.
- Legal advisors, auditors, or government agencies.
- A user's own intermediary or insurer, where the user asks us to forward a claim document.
6. Cross-Border Transfers
Covarage's production systems are currently hosted in Singapore. If data is transferred outside Singapore, we ensure PDPA compliance through legally enforceable obligations, data processing agreements, or binding corporate rules.
7. Protection of Personal Data
We implement the following safeguards:
- Administrative: Access governance (role-based access), employee training, and vendor due diligence.
- Technical: access controls, multi-factor authentication for user accounts, and network segmentation.
- Physical: Secure office facilities and controlled disposal of documents.
8. Retention of Personal Data
We retain insurance and claims data for seven (7) years from the end of the policy year or account termination, whichever is later.
9. Data Protection Officer (DPO)
For questions, access requests, or complaints, please contact:
- Email: dpo@covarage.com
- Address: 20 Cecil Street, #22-00 PLUS Building, Singapore 049705