Privacy policy
What Latchwork collects, why, how long it is kept, and who can see it — under Singapore's Personal Data Protection Act.
Last updated 9 September 2026
Who this is about
GX TECH PTE. LTD. (UEN 202503838W), trading as Latchwork, is the organisation responsible for the personal data described here. We are a Singapore company and we operate under the Personal Data Protection Act 2012.
This policy covers two different relationships, and it is worth knowing which one you are in. If you have enquired with us or bought from us, we decide what happens to your data and this policy governs it in full. If you use a locker on a site that bought a system from us, the site normally decides what is collected and why, and we handle it on their instructions — their own privacy notice applies alongside this one. Where Latchwork funds and operates the lockers itself under the managed model, we decide, and this policy applies directly to you.
What we collect, and what happens to it
Everything below is data the platform actually holds. If a row does not apply to your installation — a keyed locker bank collects none of it — then none of it is collected.
Enquiry details
- What it is
- Name, email address, company or organisation, project location, and whatever you write in the enquiry itself.
- Why we have it
- To answer your enquiry, prepare a quotation and keep a record of what was quoted.
- On what basis
- Your consent, given by sending the enquiry.
- How long we keep it
- Up to 3 years from the last contact, then deleted. Where an enquiry becomes an order, it is kept with the order record.
Customer and contract records
- What it is
- Contact details for the people we deal with at a customer, site addresses, orders, drawings, invoices and correspondence.
- Why we have it
- To perform the contract, meet warranty and service obligations, and satisfy Singapore accounting and tax record-keeping requirements.
- On what basis
- Performance of a contract, and legal obligation.
- How long we keep it
- At least 5 years from the end of the financial year the transaction falls in, as Singapore tax law requires.
Locker user accounts
- What it is
- The identifier the site chooses to use — typically a name and a mobile number or email address — plus membership or tenancy status where the site supplies it, and the compartment assigned.
- Why we have it
- To assign a compartment, let the right person open it, and end access when the membership or tenancy does.
- On what basis
- Performance of a contract with the user, or the instructions of the site operating the bank.
- How long we keep it
- For as long as the account is active, then 12 months, then deleted.
Access records
- What it is
- Which compartment was opened, by which account, at what time, and by which method — app, QR, PIN or card.
- Why we have it
- To resolve disputes about missing property, to answer a site's own audit questions, and to detect misuse of a bank.
- On what basis
- Legitimate interests in the security of the lockers and their contents, and the site's own obligations.
- How long we keep it
- 24 months, then deleted automatically. Records under active dispute are retained until the dispute closes.
Payment records
- What it is
- Amount, date, status, and the last four digits and brand of the card. Latchwork never receives or stores full card numbers.
- Why we have it
- To take locker fees, issue receipts, handle refunds and produce revenue statements for host sites.
- On what basis
- Performance of a contract, and legal obligation for accounting records.
- How long we keep it
- At least 5 years, as Singapore tax law requires.
Website usage
- What it is
- Standard server and edge logs — IP address, user agent, pages requested, timestamps.
- Why we have it
- To keep the site available, diagnose faults and defend against abuse.
- On what basis
- Legitimate interests in operating and securing the site.
- How long we keep it
- Short-lived, typically under 30 days at the hosting provider.
Who else sees it
We do not sell personal data, and we do not share it for anyone else's marketing. It reaches three kinds of third party and no others:
- Our payment provider. Card payments are processed by Stripe. Card details are entered into Stripe's own systems and are never held by Latchwork — we see the amount, the status, and the last four digits.
- Our infrastructure providers. The platform and this website run on commercial cloud hosting. Providers hold data on our instructions under contract and do not use it for their own purposes.
- The site operating your lockers. Where a club, condominium, school or employer runs the bank, their administrators can see the assignments and access records for their own site. They cannot see any other site.
We may also disclose personal data where the law requires it, or where it is necessary to investigate a theft or a safety incident involving the lockers.
Where it is held
Platform data is held on cloud infrastructure, and some of our providers operate outside Singapore. Where personal data is transferred overseas we take steps to ensure it receives a standard of protection comparable to the PDPA, as section 26 requires — in practice, contractual protections with providers that are themselves subject to comparable regimes. If you need the specifics for a tender or a data protection impact assessment, ask and we will give you the current list of providers and locations for your installation.
How it is protected
- Traffic between locker controllers, the platform and your browser is encrypted in transit.
- Administrator access is granted per person and scoped to a single site, so a site administrator cannot see another customer's data.
- Access to production systems inside Latchwork is limited to the people who need it to run the service.
- Full card numbers are never held by us — they go directly to our payment provider.
- Access records are retained on a fixed clock and deleted automatically at the end of it, rather than kept indefinitely because nobody chose a period.
No system is perfect. If we become aware of a data breach that is likely to result in significant harm, we will notify the Personal Data Protection Commission and the people affected, as the PDPA requires.
Your rights
Ask what we hold about you
Under the PDPA you may request access to the personal data we hold about you and information about how it has been used or disclosed in the past year. We respond within 30 days, or tell you when we can if it will take longer.
Have it corrected
If something we hold is wrong, tell us and we will correct it and pass the correction to anyone we shared it with.
Withdraw consent
You may withdraw consent to our use of your personal data at any time. We will tell you what that means in practice — withdrawing consent for a locker account, for example, ends the ability to open the compartment.
Ask us to delete it
We delete personal data when the purpose it was collected for has ended and no legal retention period requires us to keep it. Where a retention period applies, we will say which one and when it expires.
If you use a locker on a site run by someone else, send the request to us and we will pass it to the site where they are the ones who decide — and tell you that we have.
Cookies and analytics
This website sets no advertising or tracking cookies. Your browser may store a small amount of data locally to remember things like a filter you selected; that stays in your browser and is never sent to us. Standard server logs are described in the table above.
Contact our data protection officer
Questions, access requests, corrections and complaints all go to the same place, and a person reads them:
Email us → info@latchwork.com.sg
GX TECH PTE. LTD. (UEN 202503838W), trading as Latchwork, Singapore, island-wide.
If you are not satisfied with our response you may raise the matter with the Personal Data Protection Commission of Singapore.
Changes to this policy
When the platform changes what it collects or how long it keeps it, this page changes in the same release and the date at the top moves. Where a change materially affects locker users on a managed site, we notify them rather than relying on them re-reading this page.
See also our terms of use.