Legal

Privacy and PDPA policy

This notice explains how Bezro Luxe Drive handles personal data for Singapore chauffeur bookings under the PDPA. The English version governs.

The English version of this page is the governing text under Singapore law. The translation is provided for convenience.

Last updated 22 September 2026 · Singapore

1. Who we are

The organisation responsible for personal data on this website is BEZRO LUXE DRIVE PTE. LTD. (UEN 202243920N), trading as Bezro Luxe Drive. The registered office is 7030 Ang Mo Kio Avenue 5, #08-61, Northstar @ AMK, Singapore 569880. “We”, “us” and “the organisation” mean that company. A named Data Protection Officer will be listed once appointed.

This notice should be read with our Terms and Conditions and Cancellation and Refund Policy.

2. What this notice covers

It covers personal data of guests who request a quote, book, manage a trip, write to us, or use WhatsApp; corporate bookers and approvers; and, at a high level, chauffeurs, partners and job applicants who give us data to work with us. Employee and contractor files may also be handled under internal HR notices.

“Personal data” means data about an identifiable individual, as defined in the PDPA. It includes data you give us about other passengers. If you book for someone else, you warrant that you are authorised to provide their data and to accept this notice on their behalf.

3. What personal data we collect

Depending on the form you use, we may collect:

  • Identity and contact: full name, mobile number, email, company name, billing name and address, cost centre and purchase-order references.
  • Journey data: pickup and drop-off addresses or place names, extra stops, date and time, trip type, passenger and luggage counts, child/booster/infant seats, mobility-assistance flags, special requests, event name, and passenger name if different from the booker.
  • Airport data: flight number, terminal, and flight status we look up or you tell us (scheduled, delayed, landed, cancelled, diverted).
  • Corporate and MICE files: itineraries, hotel and venue lists, coordinator names and numbers, and documents you upload with a quotation request.
  • Chauffeur onboarding files: optional photos or PDFs of a PDVL, motor insurance and vehicle marking, uploaded from the chauffeur portal. Images are compressed and photo-location metadata is stripped. We do not ask for NRIC on this upload.
  • Payment data: method chosen (card, PayNow, Apple Pay, Google Pay, or invoice), amount, status and our payment-intent reference. We do not store full card numbers on this server. When a live gateway is connected, the gateway processes the card.
  • Operations data: booking reference, messages, complaints, incidents, additional charges (waiting, parking, tolls), cancellation records, portal login session cookies for admin, chauffeur, partner and corporate accounts, and the chauffeur vehicle’s GPS while a trip is active.
  • Technical data: IP address and basic request logs our host may keep for security, plus cookies described in section 9.

We do not routinely collect NRIC, FIN or passport numbers from passengers. PDPC guidance is that NRIC should not be collected unless the law requires it or it is necessary to accurately establish identity. Cross-border jobs, if later offered, may require travel-document checks at the checkpoint — those remain the passenger’s documents, not a copy we keep unless the law requires it.

Chauffeurs and partners may be asked for licence, insurance, inspection and bank details needed to pay them and to meet Land Transport Authority rules. Owner-drivers, freelance and company chauffeurs, and fleet partners, can optionally upload those files after sign-in; they are also accepted offline. That is collected on onboarding, not on the public booking form.

4. How we collect it

We collect personal data when you:

  • complete the booking wizard, quote form, contact form or manage-booking lookup;
  • email, telephone or WhatsApp us;
  • open a chauffeur, partner or corporate portal, including optional document upload on the chauffeur portal;
  • are named as a passenger or coordinator by someone else who books;
  • are assigned as a chauffeur or partner on a job.

We may also receive flight status from a flight-data provider when you give us a flight number, and payment status from a payment provider when a gateway is live. Checkout is currently a demonstration until a live gateway is connected.

5. Why we use it

We use personal data only for purposes you would reasonably expect, or that we notify, including to:

  • quote, confirm, amend, dispatch and complete chauffeur journeys;
  • assign a vehicle and chauffeur and share pickup details with them;
  • monitor inbound flights so airport arrivals can move with the aircraft;
  • take payment, issue invoices and process refunds under the cancellation policy;
  • show a live car position to the guest and operations during an active trip;
  • send transactional messages (confirmation, chauffeur assignment, delays, receipts) by email, SMS or WhatsApp;
  • handle complaints, lost property, incidents, insurance and chargebacks;
  • meet accounting, tax, audit and lawful requests from authorities;
  • improve routing, fleet mix and the booking flow, using aggregated or de-identified data where we can;
  • measure how the public website is used, through Google Analytics;
  • send marketing only where section 11 allows.

Mobility-assistance and child-seat notes are used only to staff and equip the journey, not for unrelated profiling.

6. Consent and when we do not need fresh consent

Ticking acceptance at checkout, submitting a quote or contact form, or continuing a conversation after we point you to this notice is consent to the purposes above that are needed to respond.

Under the PDPA we may also use or disclose personal data without fresh consent where an exception applies — in particular where it is necessary to conclude or perform a contract with you (or that you request), where it is required or authorised by law, or for investigations and legal proceedings. We rely on those exceptions for dispatch, payment, cancellation, insurance and mandatory records.

You may withdraw consent for optional uses (such as marketing) at any time. Withdrawal does not affect a booking already in progress. If you withdraw consent that we need to perform the trip, we may have to cancel under the Cancellation and Refund Policy.

7. Who we share it with

We do not sell personal data. We disclose it only as needed to:

  • the assigned chauffeur, owner-driver or licensed transport partner, limited to what they need for that job;
  • operations and finance staff;
  • payment, PayNow, Apple Pay or Google Pay providers, when connected;
  • flight-status providers, when connected;
  • Google LLC, if Google Analytics is enabled, for page-view measurement;
  • our website host, email/SMS vendors, and professional advisers (accountants, insurers, lawyers);
  • authorities, courts or insurers where required by Singapore law or to establish, exercise or defend legal rights.

If you message us on WhatsApp, Meta Platforms processes that chat under WhatsApp’s terms. Do not send NRIC images or card numbers over chat.

8. Transfers outside Singapore

We intend to keep booking records on systems operated for us in Singapore. Some vendors (for example a global payment gateway, email provider, WhatsApp, or Google Analytics) may process data outside Singapore, including in the United States.

Before we use a vendor that stores personal data outside Singapore, we will take steps required under the PDPA so the data is protected to a standard comparable to the PDPA, and we will name material vendors here. WhatsApp and Google Analytics, when enabled, are those overseas processors.

9. Cookies and similar technology

We use cookies that are necessary to run the site:

  • session cookies so you stay signed in to admin, chauffeur, partner or corporate portals;
  • cookies the framework needs to load pages securely;
  • the language cookie so a chosen English, Chinese or Indonesian view stays selected.

When Google Analytics is switched on, Google sets its own measurement cookies (typically _ga and _ga_*) so we can see which public pages are used. We do not use advertising pixels or remarketing audiences. You can block analytics cookies in your browser; the site and booking flow still work. Essential cookies may stop login if you block those as well.

10. Cameras, location and in-vehicle systems

Some private-hire vehicles in Singapore carry inward- or outward-facing cameras for safety and dispute handling. If a vehicle on your job is fitted with cameras, recordings are used only for safety, training, insurance and complaints, and are retained no longer than needed for those purposes (and any legal hold).

Dispatch holds pickup and drop-off coordinates from the location catalogue. While a job is active, the chauffeur app may send the vehicle’s GPS (latitude, longitude, heading and a timestamp) so the guest can see the car on Manage Booking and operations can see it on dispatch. We track the car, not the passenger’s phone. Sharing stops and the last ping is deleted when the trip is completed, cancelled or marked no-show. Live coordinates are not written into confirmation emails, SMS or calendar files.

We do not sell location data.

11. Marketing and the Do Not Call Registry

Messages about a booking you already made (confirmation, chauffeur details, delay, receipt, refund) are transactional. They are not marketing and are not treated as telemarketing under the Do Not Call (DNC) provisions.

We will not send promotional SMS, voice calls or faxes unless you have given clear consent or another DNC exception applies, and we will check the DNC Registry where the PDPA requires it. Email marketing, if we start it, will include an unsubscribe. WhatsApp promotions will only be sent if you opt in.

12. How we protect data

We apply security that is reasonable for a small transport operator: access to booking records is limited to people who need it, portal sessions use cookies, and payment card PAN is not stored on this server. Hosting, backups and staff access will be documented with the DPO once appointed.

No method of transmission over the internet is completely secure. Do not send full card numbers or NRIC images by email or WhatsApp.

13. How long we keep it

We keep personal data only as long as needed for the purposes above, then delete or anonymise it. Typical periods, unless a longer legal hold applies:

  • Enquiries and unused quotes: up to 24 months after the last meaningful contact.
  • Bookings, invoices, refunds and ledgers: at least five years after the relevant year of assessment, which is the usual IRAS record period, and longer if a dispute or insurance claim is open.
  • Live vehicle pings: deleted when the trip completes, is cancelled, or is marked no-show.
  • CCTV or in-car video: a short operational window unless needed for an incident.
  • Lost-property records: in line with the 30-day holding practice in the terms, then disposed of.
  • Marketing opt-in lists: until you unsubscribe, plus a short suppression record so we do not message you again by mistake.

14. Your rights under the PDPA

Subject to the exceptions in the PDPA, you may:

  • ask whether we hold personal data about you and request access;
  • request correction of inaccurate data;
  • withdraw consent for optional processing;
  • ask how we have used or disclosed your data in the year before the request (as the Act allows).

Send requests through Contact and mark the message “PDPA request”. We may need to verify the booking email or a similar identifier. We will respond within the period the PDPA requires (generally 30 days), or tell you if we need more time. A reasonable access fee may be charged where the Act allows. We may refuse a request where an exception applies (for example opinion data, or data that would reveal another person).

Managing a trip at /manage uses the reference and booking email; that is an operational lookup, not a formal access request.

15. Children

We do not knowingly open payment accounts for children. Child passenger first names, ages or seat needs are collected only to provide the correct restraint and to carry out the journey with a responsible adult, as described in the terms.

16. Data breaches

If we assess that a data breach is notifiable under the PDPA (significant harm to affected individuals, or a significant scale), we will notify the Personal Data Protection Commission and affected individuals as required, unless an exception applies. Please report suspected misuse of a booking reference or portal login through Contact immediately.

17. Third-party sites

Links to WhatsApp, maps, airlines or hotels are those parties’ services. Their privacy notices apply once you leave our site. We are not responsible for their practices.

18. Changes to this notice

We may update this page when our vendors, hosting or purposes change. The date at the top is the current version. Material changes will be posted here before they apply to new collections. A booking already confirmed is handled under the notice in force when that contract was formed, unless the law requires otherwise or we notify you.

19. How to contact us and the PDPC

For access, correction, withdrawal or complaints, use Contact and mark the message as a PDPA matter. The DPO’s name and direct email will be added here once appointed. The published company telephone is a general enquiries line, not a dedicated DPO line.

If we cannot resolve your concern, you may contact the Personal Data Protection Commission (PDPC) at pdpc.gov.sg. This notice is an operating template, not a substitute for appointing a DPO or for Singapore legal advice.