Introduction & Scope
This Data Protection Policy explains how Aspact Pte Ltd collects, uses, discloses and protects personal data in connection with OneHub+ — our smart condominium operations platform — including this marketing website, the OneHub+ mobile apps (resident, security and manager experiences), and the property management portal operated on behalf of MCSTs and managing agents.
This policy is issued under the Singapore Personal Data Protection Act 2012 (No. 26 of 2012) (“PDPA”). By using our services, you acknowledge that you have read this policy. We may update it from time to time; the current version is always published on this page.
Who We Are
Aspact Pte Ltd is the data controller for personal data processed through the OneHub+ platform, except where your MCST or managing agent remains responsible for resident records they provide to us.
Product name: OneHub+ (formerly marketed as OneHub). Data Protection Officer: Mr Richie Choo, Aspact Pte Ltd, 17 Mandai Estate, #06-02B Hwa Yew Industrial Building, Singapore 729934.
Personal Data
“Personal data” means data, whether true or not, about an individual who can be identified from that data or from that data and other information to which we have or are likely to have access.
Examples include: name, residential unit, email address, mobile number, vehicle registration number, visitor details, access and carpark records, device identifiers, push notification tokens, photographs or CCTV stills linked to an incident, and audit logs tied to a user account.
Who This Policy Applies To
- Website visitors who browse onehubplus.com or submit a contact/demo form.
- Residents, subsidiary proprietors and tenants using the OneHub+ resident app.
- Security officers, managers and MCST committee members using operational or read-only accounts.
- Authorised staff of managing agents who administer estates on the platform.
How We Collect Personal Data
We collect personal data in the following ways:
- From your MCST or managing agent when you register as an owner, tenant or carpark applicant.
- When you create or use a OneHub+ account, invite visitors, book facilities or submit forms in the app.
- When security staff register walk-in visitors, scan licence plates (OCR) or process carpark entries.
- When you submit the OneHub+ website contact form (name, company, email, phone, property name, message).
- Automatically through system logs, security audit trails, ANPR/CCTV integrations configured by your estate, and push notification services.
- When you optionally pick a contact from your device address book to pre-fill a visitor invitation: we use only the selected name and phone for that invitation form session; we do not upload your address book, store contacts on our servers, or persist contact data locally beyond the current form.
- When security staff clock in or verify attendance: GPS coordinates and reverse-geocoded address to record on-site presence.
- When you grant camera or photo library access: profile pictures and image uploads (residents); patrol, incident, attendance selfies and licence-plate / barcode camera preview (security).
- Device push tokens (FCM/APNs) to deliver notices and operational messages.
- Local device storage for app functionality (e.g. login session token, language, theme, form-type cache); this is not a transfer to third parties except as otherwise stated.
Accuracy
You should ensure personal data you provide is complete, accurate and up to date. Incomplete data may prevent us from delivering notifications, access control or carpark services.
Purposes for Collection, Use and Disclosure
- Estate and facilities management, including bookings and announcements.
- Safety and security of the premises, visitor verification and gate access.
- Carpark management, enforcement alerts and ANPR/OCR matching.
- Notifying residents of visitors via SMS, push notifications or WhatsApp where enabled.
- MCST announcements, emergency alerts and operational broadcasts.
- AI-assisted operational insights such as alert prioritisation and management summaries (using aggregated or pseudonymised data where appropriate).
- Two-factor authentication, fraud prevention and audit compliance.
- Responding to demo requests and sales enquiries from the website.
- Improving reliability, support and product development.
- Crash reporting and stability diagnostics via Firebase Crashlytics (account id, condominium context and role metadata only; no phone or email in crash custom keys).
- Processing facility booking payments through Stripe as payment processor (Aspact does not store full card numbers).
Disclosure of Personal Data
We do not sell personal data. We may disclose personal data to:
- Your MCST, managing agent and authorised on-site personnel for estate operations.
- Cloud hosting, messaging (SMS/WhatsApp/push), email and integration partners that help us run OneHub+ under contract.
- Government ministries, regulators, statutory bodies or law enforcement when required by applicable law.
- Professional advisers under confidentiality obligations.
Display of mobile numbers
Mobile numbers retrieved from resident records are not shown in full on resident-facing screens when viewing another individual’s number; they are masked (e.g. “XXXX4567”) unless full display is strictly necessary for the stated purpose.
Authorised operational roles — including security officers and managers / managing-agent staff acting for the MCST — may view full mobile numbers where necessary for visitor verification, carpark or SMS operational logs, resident management and booking coordination.
Cross-Border Transfer
Our primary application and business data are hosted on Amazon Web Services in the Singapore region. OneHub+ is operated primarily for Singapore condominium estates.
Some service providers — including Google Firebase (Crashlytics, Cloud Messaging and related services) and Stripe — may process personal data outside Singapore, depending on their infrastructure, product regions and your account configuration.
Where personal data is transferred outside Singapore, we require contractual safeguards, vendor security commitments and protection standards comparable to those under the PDPA. Specific overseas processing locations remain subject to each processor’s configuration and may be refined after operational confirmation.
Retention & Disposal
We retain operational personal data — including visitor records, security clock-in and patrol media, SMS operational logs, and facility booking payment metadata (not full card numbers) — for up to 36 months by default, unless a longer period is required by law or the estate's legitimate needs. When no longer required, we delete or anonymise the data. Automated purge jobs will be rolled out to enforce this policy.
Crash and diagnostic data processed via Firebase Crashlytics is retained according to our product configuration and Firebase controls, with a target retention not exceeding 36 months where we control retention settings.
Local device convenience data (such as session tokens and login hints) is cleared when you log out of the app, as described in the collection section.
Your Rights
Under the PDPA you may request access to, correction of, or withdrawal of consent for use of your personal data, subject to legal exceptions.
Resident personal data originally provided by a third party (e.g. your MCST managing agent) should generally be directed to that organisation, which may lodge requests with Aspact on your behalf.
For platform-specific requests, contact us using the details in the Contact section below.
Third-Party Services
- Push notification services (e.g. Apple Push Notification service, Firebase Cloud Messaging).
- Firebase Crashlytics for crash reporting and stability diagnostics (stack traces, device/app version metadata, and account identifiers such as user id, condominium context and role; no phone numbers or email addresses in crash custom keys).
- Stripe for facility booking payments: cardholder data is collected and processed by Stripe as payment processor when you use the in-app payment sheet; Aspact does not store full card numbers. See Stripe’s privacy policy and applicable data processing terms.
- Google ML Kit for on-device text recognition (OCR) and barcode scanning in security workflows (e.g. licence plates, visitor documents, QR/barcode verification). Recognition runs primarily on the device; extracted results are sent to OneHub+ servers for access control and carpark matching.
- WhatsApp or SMS gateways where enabled by your estate.
- Email delivery for notifications and contact form routing.
- Cloud infrastructure and backup providers, including Amazon Web Services hosted in the Singapore region for primary application data.
- Hardware and software integrations (gate barriers, intercom, ANPR/CCTV) configured by your property — governed also by your estate’s rules.
Security Measures
We implement administrative, technical and physical safeguards including role-based access control, encryption in transit, two-factor authentication options and per-condo data isolation. For an overview of security capabilities, visit the Security & Compliance page on this website.
Updates to This Policy
We may revise this Data Protection Policy to reflect legal, technical or business changes. Material updates will be published on this page with a revised “Last updated” date. Continued use of OneHub+ after changes constitutes acceptance of the updated policy, subject to your rights under the PDPA.
Contact & Withdrawal of Consent
MCST resident data originally collected via your managing agent: please contact your MCST Managing Agent to query, correct or withdraw consent; they may forward requests to Aspact.
OneHub+ platform data controlled by Aspact: Aspact Pte Ltd, 17 Mandai Estate, #06-02B Hwa Yew Industrial Building, Singapore 729934. Attention: Mr Richie Choo, Data Protection Officer.
Governing Law
This policy is governed by the laws of Singapore. More information: https://www.pdpc.gov.sg/legislation-and-guidelines
