Last updated 24 Sep 2026
Privacy Policy
Lunas helps businesses send invoices and collect deposits. This policy explains what personal data we handle, why, where it's kept and what you can ask us to do with it, in line with Singapore's Personal Data Protection Act 2012 (PDPA). We don't sell personal data, and we don't use it for advertising.
1.Who we are
Lunas is operated by [Company name] (UEN [UEN]), Singapore (“we”, “us”). Our Data Protection Officer can be reached at hey@bindery.run.
2.Two kinds of data
- Account data: about you as a user of Lunas (your name, email, business details). For this data we are the organisation responsible under the PDPA, and this policy applies.
- Your customers' data: the names, contact details, orders and payments you record in Lunas. Here your business is the organisation responsible, and we act as your data intermediary: we process it only to run the service for you, as set out in our Data Processing Agreement. If you're one of those customers, please contact the business that invoiced you; we'll help them respond.
3.What we collect
| Data | Examples | From |
|---|---|---|
| Account | Name, email, password (stored only as a one-way hash), sign-in sessions | You, at sign-up |
| Business details | Business name, UEN, address, GST number, PayNow UEN or mobile, bank details you choose to print, logo | You, in setup and Settings |
| Customer records | Your customers' names, phone numbers, email and postal addresses, notes, orders, invoices, payments | You, or a spreadsheet you import |
| Customer activity | When a pay link was opened, when deposit terms were accepted (time and date) | Your customers' use of pay links |
| Billing | Subscription plan and status; card details are handled by Stripe, never by us | Stripe |
| Technical | IP address (for rate limiting and security), browser type, error reports without personal details | Your device |
| Notifications | If you turn them on: a push address for your device, provided by your browser's push service | Your device |
We don't ask for NRIC numbers, and you shouldn't record them in the service.
4.How we use it
- To provide the service: create invoices and receipts, PayNow QR codes, pay links, reminder emails and notifications, and keep your records.
- To keep it secure: verify email addresses, prevent abuse (sign-in limits), investigate errors.
- To bill your subscription and honour the founding price and guarantee.
- To talk to you about your account, changes to the service or this policy. Marketing emails only with your consent, with a way to opt out in each one.
- To meet legal obligations (for example, tax records).
We use your customers' data only to run the service for you, never for our own marketing or anyone else's.
5.Where it's stored and who helps us
Your data is stored in Singapore. These service providers process it for us, under contracts that require them to protect it:
| Provider | What for | Where |
|---|---|---|
| Supabase | Database: all account, business and customer records, logos and invoice PDFs | Singapore (ap-southeast-1) |
| Vercel | Runs the app | Singapore (sin1) |
| Resend | Delivers emails (invoices, receipts, reminders, sign-in emails) | [Confirm region before launch] |
| Stripe | Subscription billing and card payments to us | Stripe's global infrastructure |
| Apple, Google, Mozilla push services | Deliver notifications to your devices (contents are encrypted end to end) | Their infrastructure |
Where a provider processes data outside Singapore, we require protection comparable to the PDPA, as the PDPA's transfer rules require. [Lawyer to confirm transfer clauses for each provider.]
6.How long we keep it
- Account, business and customer records: while your account is open. Invoices and payments can't be edited or deleted during that time (only voided), so your records stay trustworthy.
- When you close your account, we delete your business and everything in it, including customer records, within 30 days, except what the law requires us to keep.
- Copies of invoice PDFs are regenerated as needed; cached copies are removed after 30 days.
- Pay links expire (links in emails after 60 days) and can be revoked sooner.
- Backups follow our database provider's retention. [Confirm backup and point-in-time-restore periods on the database plan before launch.]
7.How we protect it
- Each business's data is separated by the database itself (row-level security): even a mistake in the app can't show one business another's records.
- The app connects with a restricted database role, not an administrator account.
- Passwords are stored only as salted one-way hashes. Sign-in attempts are rate-limited, and email addresses are verified.
- Pay links use long random codes, are stored only as hashes, expire, can be revoked, and are hidden from search engines.
- All traffic is encrypted (HTTPS, with strict transport security), and the app sends strict security headers.
- The installable app never stores your business data on the device; it only keeps the app's own files for faster loading.
No system is perfectly secure. If a data breach affects you, we'll tell you, and where required the PDPC, as the PDPA requires.
8.Your choices and rights
- Access and correction: see and edit your details in Settings, or ask us for a copy of the personal data we hold about you.
- Export: download all your records as CSV files at any time, including after you stop paying.
- Withdraw consent / delete: close your account and we'll delete your data as described above. Withdrawing consent may mean we can't provide the service.
- Notifications: turn push notifications on or off per device in Settings.
Email hey@bindery.run. We reply within 30 days. You can also contact the Personal Data Protection Commission (PDPC).
10.If you're in the United States
Draft, to be reviewed by a US lawyer.
- Your account and your clients' details are stored in Singapore (see section 5), not in the US.
- We don't sell personal information or share it for advertising.
- Emails we send for you (invoices, reminders, receipts) are transactional messages about a purchase your client made with you. We don't send marketing email on your behalf. Any marketing email from us to you says who it's from, includes our postal address and has a one-click unsubscribe (CAN-SPAM).
- We send no text messages. The “Text” button opens your own phone's messages app; the message is sent from your number, by you.
11.Changes and contact
If we change this policy in a way that matters, we'll tell account holders by email before it takes effect. Questions: hey@bindery.run.