Legal
Privacy Policy
Quick summary
This section is a plain-English summary. The full legally binding terms are below. If anything in the summary conflicts with the detailed sections, the detailed sections govern.
| The short answer to… | …in plain English |
|---|---|
| Who runs Mixly? | Mixly is operated by Mixly Pte. Ltd., a private limited company incorporated in Singapore (UEN 202627688W). |
| How old do I have to be? | 16 or over. Mixly is not for under-16s and we do not knowingly collect their data. |
| What data do you collect? | Your name, email, profile photo, real-time location (only when you allow it), your in-app activity, your attendance and reliability record, and, if you use cost-sharing, what you owe or are owed and who you paid. |
| Do you sell my data? | No. We never sell your personal data. Ever. We may share anonymised, aggregated insights that cannot identify you (Section 7.6). |
| Do you track me for ads? | No. We use no advertising identifiers and do not track you across other companies’ apps or websites. |
| Who handles payments? | Nobody. There are no payments in this version of the app. Mixly does not process, hold or move money. We calculate who owes what; you pay each other directly, outside the app. We never see your bank account or card. |
| Can other people see my details? | Players in a game see your name, photo and reliability badge. If you host a shared-cost game they also see each person's share, and the PayNow number you added if you chose to add one. We never ask for a card, a bank account or a QR code. |
| Can I delete it all? | Yes. Settings > Account > Delete Account. We delete within 30 days, except records the law requires us to keep. |
| Where is it stored? | Mostly Singapore. Some providers process data outside Singapore, in the United States and Germany, under PDPA-compliant safeguards. The full list is in Section 7.2. |
| How do I reach you? | Email privacy@mixly.sg for any data or privacy question. We respond within 30 days as required by the PDPA. |
1. Who we are
Mixly is a social sports application that helps users in Singapore find, join and host casual pickup games.
Operator: Mixly is operated by Mixly Pte. Ltd. (the “Company”, “we”, “us”, “our”), a private company limited by shares incorporated in the Republic of Singapore.
- Unique Entity Number (UEN): 202627688W
- Registered office: 4 Binjai Hill, Singapore 589921
- Data Protection Officer (DPO): privacy@mixly.sg
- Support: support@mixly.sg
- Website: https://mixly.sg
Reference: This Privacy Policy is governed by the Personal Data Protection Act 2012 of Singapore (“PDPA”) and is designed to comply with the PDPA obligations, including Consent, Notification, Purpose Limitation, Access and Correction, Accuracy, Protection, Retention Limitation, Transfer Limitation, Accountability, Data Breach Notification and Data Portability.
2. Scope of this policy
This Privacy Policy applies to all personal data collected, used or disclosed through:
- The Mixly mobile application
- The Mixly website at mixly.sg
- Any related communications between you and Mixly (including emails to support@mixly.sg or privacy@mixly.sg)
Intended for Singapore. Mixly is intended for users located in Singapore. It is not directed at, or marketed to, individuals in other jurisdictions. If you access Mixly from outside Singapore, you do so on your own initiative and are responsible for compliance with your local laws.
When you create an account, you are asked to read and expressly agree to this Privacy Policy and our Terms of Service before your account is created. By creating an account or using Mixly, you confirm that you have read, understood and consented to the collection, use and disclosure of your personal data as described in this Policy.
3. Personal data we collect
We collect only the personal data reasonably necessary to provide the Mixly service. This satisfies the Purpose Limitation Obligation under Section 18 of the PDPA.
3.1 Account information
- Full name, for profile identification and game communications
- Email address, for account creation and service notifications
- Password, stored only in encrypted (hashed) form, and only where you sign up by email
- Profile photo, displayed on your profile and to other players in games you join
- Sports you play and your self-declared skill level in each
- A record that you accepted our Terms of Service and this Privacy Policy, with the date and the version you accepted
A note on “Sign in with Apple” and hidden email addresses. Apple lets you hide your real email address when you sign in. If you choose to do that, Apple gives us a private relay address ending in @privaterelay.appleid.com instead of your real one, and forwards our messages to you. In that case the relay address is what we hold and use. We never receive your real email address, and Apple sits between us. You can stop the forwarding at any time in your Apple ID settings, but if you do, we will no longer be able to reach you by email.
3.2 Location data
- Precise location, used only while the app is in active use, to show you nearby games and venues
- We do not collect or store your location in the background, or while the app is closed
- Location access requires your explicit permission (express consent under the PDPA) and can be revoked at any time in your device settings
- We use location only in the moment to show you nearby games. We do not build or store a history of where you have been
- The app works without location. If you decline, you can enter or pick a location manually
- When you search for an address, or move the pin on the map, that text or coordinate is sent to our address-search provider so that it can be resolved into a location (see Section 7.2)
3.3 Activity data
- Games you create, join, leave, waitlist for, or express interest in
- In-app interactions, filters and preferences
- Users you have blocked, so that we can keep their content hidden from you
- Reports you have submitted, and reports submitted about you (see Section 3.8)
- Searches. We record only the number of results returned, never the text you type
- Aggregated participation statistics
3.4 Attendance and reliability data
Because Mixly depends on people turning up, we keep a simple record of reliability:
- Whether you attended, cancelled, or did not turn up to a game you joined, and when you cancelled
- Thumbs up given to you by teammates after a game you both played
- Your resulting reliability badge
This is personal data about you, and it is visible to other users. Your reliability badge is shown on your profile and to everyone on the roster of any game you join. It is calculated from recorded facts only. There is no rating, review or star voting by other users. Whether a shared cost was paid has no effect on it. How the record is worked out is set out in our Terms of Service, and your right to ask us to correct it is in Section 12.2 below.
3.5 Technical and diagnostic data
- Device type, operating system and app version
- IP address, used by our backend to estimate your general region for fraud prevention and service localisation. Our analytics and error-reporting providers do not retain your IP address (see Section 7.2)
- Crash, error and performance logs, pseudonymous: linked only to a random account identifier, with your email and name stripped before transmission. They are not anonymous, because we can connect that identifier back to your account
- Pseudonymous identifier, a random ID (your Firebase user ID) used to link your activity and crash reports across sessions for analytics and debugging. It is not your name or email, but because it can be connected back to your account we treat it as personal data
- Device identifiers. We may use device-level identifiers together with your IP address to detect duplicate or secondary accounts, identify users attempting to evade a block or suspension, and enforce our Terms of Service
- Device push token. If you enable notifications, a token that lets us deliver them to your device. You can revoke it at any time by turning off notifications in your device settings
3.6 Communications
- The content of messages you send to support@mixly.sg or privacy@mixly.sg
- In-app chat messages you send to other players in a game. We do not routinely read them, but we may review them in response to a report or where required by law
3.7 Cost-sharing data
Mixly does not process payments. There is no payment feature in this version of the app. We never receive, hold or move money, and we never see your card details or your bank account. Money moves directly between players and hosts, outside Mixly. What we hold is a record of what the app calculated and what each person told us.
Where a host sets a cost for a game, we collect and hold:
- If you are a host: the total cost of the court that you entered, and — only if you choose to add one — a PayNow identifier, typically your mobile number or a UEN, so your players know where to send their share. It is optional. If you ask us to remember it, we store it on your own account, readable only by you, and copy it into a game when you post one. We collect no card number, bank account number or payment QR code, and there is no field for any of them anywhere in the app
- If you are a player: the amount the app calculated you owe and the game it relates to
- For both: whether you marked yourself as having paid, whether the host confirmed receiving it, and the timestamps of those actions
These records show what each person stated, not what a bank did. Mixly has no visibility of any bank account and does not verify that any payment was actually made.
A PayNow identifier you add is shown to that game's players. If you host a shared-cost game and choose to enter one, it is displayed to the players who have joined that game, so they can pay you. It is never on the public game listing, and someone browsing without joining cannot see it. If you would rather not show it, leave the field empty and arrange payment with your players directly.
If you are 16 or 17, note that adding a PayNow number means your mobile number is visible to everyone who joins that game, which may include adults you have not met. We encourage you to speak to a parent or guardian first. You can host shared-cost games without adding one.
3.8 Safety and incident reports
Because Mixly connects people for in-person games, safety matters to us. If you report another user, a game or a chat message, for example for harassment, a safety concern, a no-show, or a breach of our rules, or if another user reports you, we collect the details of the report, including what is submitted and the relevant account, game and message information. We use this to investigate and keep the community safe (see Sections 5 and 7.4). Reports are delivered to our support address through an external email provider (see Section 7.2).
4. App permissions
Mixly requests the following device permissions. You can grant or revoke each one individually in your device settings at any time:
- Location: to show you nearby games. Your device asks you once, while you are setting up your account, and again only if you use a feature that needs it. Declining is fine: the app works without location and you can enter or pick a place yourself.
- Camera: only if you choose to take a photo for your profile.
- Photo library: only if you choose to upload an existing photo as your profile picture.
- Notifications: to alert you about games you have joined or hosted, roster changes, and cost-sharing updates.
Revoking a permission may limit certain features, but will not prevent you from using Mixly.
5. How we use your personal data
Under the Purpose Limitation Obligation (Section 18, PDPA), we use your personal data only for the following purposes:
- To create, maintain and secure your Mixly account
- To show you games and venues near your location
- To allow you to create, join, host and manage games
- To send you operational notifications about games you have joined or hosted
- To enforce our Terms of Service, including issuing warnings, tracking compliance periods, and detecting attempts to evade enforcement
- To calculate each player’s share of a shared cost and display who owes what to whom
- To record and display attendance, no-shows and reliability, so that hosts and players can judge who to play with
- To respond to your support and privacy enquiries
- To understand product usage and improve the platform, fix bugs and enhance security
- To prevent fraud, abuse or breaches of our Terms of Service
- To review safety reports, investigate incidents, and take action to protect users and the community
- To comply with applicable Singapore law and lawful requests by Singapore authorities
We will not use your personal data for any purpose materially different from those listed above without first notifying you and, where required, obtaining fresh consent in accordance with the PDPA.
6. Legal basis for collection, use and disclosure
Under the PDPA, we rely on the following legal bases:
- Express consent: you provide consent when you create an account, accept this Privacy Policy, and grant device permissions.
- Deemed consent by contractual necessity: we may process your data where reasonably necessary to perform our contract with you, for example, displaying your name to other players in a game you join, or showing each player their share of a game's cost and how to pay the host.
- Legitimate interests exception (First Schedule, Part 3, PDPA): where the benefit of processing outweighs any adverse effect on you, for example fraud prevention, platform security, product analytics, and maintaining a reliability record so that users can make informed decisions about who they play with.
- Legal obligation: where we are required to process your data to comply with Singapore law or a lawful request by a Singapore government authority.
7. Sharing with third parties
We do not sell, rent, trade or otherwise commercialise your personal data. We share personal data only in the limited circumstances described below. For anonymised, non-identifying insights, see Section 7.6.
7.1 Service providers
We share data with third-party service providers who help us operate the platform. We require all such providers to handle your data to a standard at least as strong as required under the PDPA.
7.2 Specific service providers
As of the Effective Date, the following service providers may process your personal data through the Mixly app:
- Firebase (Google LLC): backend services only: authentication, database, storage and cloud functions. Firebase receives your email, user ID and IP address as part of normal backend operation. Privacy policy: policies.google.com/privacy
- PostHog: product analytics. Collects in-app usage events (such as screens viewed and games joined or created) linked to your pseudonymous user ID. It does not receive your email, does not store your IP address (it derives an approximate country, then discards the IP), and collects no device or advertising identifier. Privacy policy: posthog.com/privacy
- Sentry: crash and error reporting. Collects the error message, stack trace, and device and app version, linked to your pseudonymous user ID. It does not receive your email or IP address. Privacy policy: sentry.io/privacy
- Komoot GmbH (“Photon”): address search. When you type a venue address, or move the pin on the map, that text or those coordinates are sent to Photon to convert between an address and a map location. Photon receives no account identifier, no name and no email. It is operated from Germany. Privacy policy: komoot.com/privacy
- CARTO: map imagery. The map you see in the app is assembled from image tiles served by CARTO. Requesting them transmits your IP address and the area of the map you are viewing. No account identifier, name or email is sent. Privacy policy: carto.com/privacy
- Resend: email delivery. Where you submit a safety or incident report, we email it to our support address for review. Resend delivers that message and processes what it contains, including the details of the report and the accounts involved. Privacy policy: resend.com/legal/privacy-policy
- Apple Inc.: “Sign in with Apple” authentication. Where you choose to hide your email, Apple operates the private relay described in Section 3.1. Privacy policy: apple.com/legal/privacy
- Google LLC: “Google Sign-In” authentication. Privacy policy: policies.google.com/privacy
No payment processor. Because Mixly does not process payments, no payment processor receives your data and no card, bank or identity-verification data is collected by anyone on our behalf.
No advertising tracking. Mixly does not use advertising identifiers and does not track you across other companies’ apps or websites for advertising.
7.3 Other Mixly users
Some information is visible to other users. This is unavoidable in a service that connects people to play sport together, and it is limited to the following:
- Your name and profile photo are visible to other players in games you join or host
- Your sports and self-declared skill level are visible on your profile
- Your reliability badge is visible on your profile and to everyone on the roster of any game you join
- Your game activity is visible to other players in that game
- If you are a host: the participants of your game are visible to you, along with their attendance and, for shared-cost games, what each owes and whether they have marked themselves as paid
- If you host a shared-cost game: the total cost you entered, each player's equal share, and any PayNow identifier you chose to add, are shown to the players who joined that game and to nobody else
- Your private chat messages are visible only to the other participants of that game’s chat
- Making a game public does not change who can see the roster. Public games are discoverable by any Mixly user, but only the sport, venue, time, skill level and number of slots left are shown. Names, photos and reliability badges remain visible only to people taking part in that game.
Hosts who receive participant information are required by our Terms of Service to use it only to run that specific game, not to retain or share it, and to comply with the PDPA. We ask you to bear in mind that once another user has seen information about you, we cannot recall it on your behalf.
7.4 Legal and safety disclosures
We may disclose your personal data to law enforcement or regulatory authorities where:
- Required to comply with Singapore law or a lawful request
- Necessary to investigate fraud, security incidents, or material breaches of our Terms of Service
- Necessary to protect the rights, property or personal safety of Mixly, our users, or the public
- Necessary to act on a safety or incident report, in which case we share only what is needed with the people or authorities involved in resolving it
7.5 Business transfers
If Mixly Pte. Ltd. is involved in a merger, acquisition, or sale of all or part of its business, your personal data may be transferred as part of that transaction. You will be notified in advance of any such transfer.
7.6 Aggregated and anonymised insights
We may create aggregated and de-identified statistics and insights that do not identify any individual, for example, trends in sports participation by area, venue, time or sport. Because this information cannot be used to identify you, it is not personal data under the PDPA, and we may use, retain and share it with third parties (including commercial and venue partners) for research, analytics and business purposes. We will never sell data that identifies you.
7.7 Our website (mixly.sg)
Our website uses no analytics, no advertising or behavioural tracking, no cookies, and no consent banner. We do not track visitors. Two limited third-party data flows exist:
- Google Fonts: the site loads fonts from Google’s content delivery network, which transmits your IP address to Google in the process. Privacy policy: policies.google.com/privacy
- Form submissions (formsubmit.co): when you submit our access-request or contact form, the email address and message you provide are processed by formsubmit.co to deliver the submission to us. Privacy policy: formsubmit.co
8. Data retention
In accordance with the Retention Limitation Obligation (Section 25, PDPA), we retain personal data only for as long as it serves the purposes for which it was collected, or as required by law.
| Data | How long we keep it |
|---|---|
| Account data | For as long as your account is active. |
| Location data | Processed in real time only, never stored persistently. |
| Activity and analytics logs | Up to 12 months, for product improvement, security and fraud prevention. |
| Crash and error logs | Only as long as needed for debugging, in line with our error-reporting provider’s retention settings. |
| Attendance and reliability records | Up to 12 months, after which the underlying records are deleted. |
| Cost-sharing records (amounts, paid/unpaid status) | 12 months from the date of the game, so that a dispute can be looked at and reliability calculated. These are not Mixly’s financial records, Mixly is not a party to the payment and receives nothing, so no statutory financial retention period applies to them, and we do not keep them beyond what the service needs. |
| Safety and incident reports | Up to 24 months from resolution, so that repeat behaviour can be identified. |
| Support communications | Up to 24 months from the date of the last interaction. |
| Deleted accounts | All personal data permanently deleted within 30 days of a deletion request, except where retention is required by Singapore law. |
Mixly’s own corporate and tax records, which relate to the Company’s own transactions, not to money moving between users, are retained for at least five years as required by the Companies Act 1967 and the Income Tax Act 1947.
Anonymised and aggregated data, which cannot identify you, may be retained indefinitely for analytics, service improvement and the purposes described in Section 7.6.
9. Data security
In accordance with the Protection Obligation (Section 24, PDPA), we implement reasonable security arrangements to protect your personal data:
- All data in transit is encrypted using Transport Layer Security (TLS 1.2 or higher)
- Passwords are stored using industry-standard one-way hashing, never in plain text
- We store no card numbers, bank account numbers or payment credentials, because we do not process payments. The only payment-related information we hold is the total a host typed in, the share the app calculated, who ticked that they had paid, and any PayNow identifier a host chose to publish to their own players
- Personal identifiers are stripped from crash and error reports before they are sent to our error-reporting provider
- Access to user personal data is restricted to authorised personnel on a need-to-know basis
- Production systems use multi-factor authentication and access logging
- Database access rules are configured so that users can read and write only the data they are entitled to
- We review our security practices regularly and update them as threats evolve
While we take security seriously, no system is fully impenetrable. We cannot guarantee absolute security, but we commit to continuously improving our safeguards.
10. Data breach notification
In accordance with the Data Breach Notification Obligation (Sections 26A to 26E, PDPA), if we become aware of a data breach that results in, or is likely to result in, significant harm to affected individuals, or that affects 500 or more individuals, we will:
- Notify Singapore’s Personal Data Protection Commission (PDPC) within 3 calendar days of assessing the breach
- Notify affected individuals as soon as practicable, unless an exemption applies
- Take immediate remedial action to contain and mitigate the breach
11. Cross-border data transfers
In accordance with the Transfer Limitation Obligation (Section 26, PDPA), where we transfer personal data outside Singapore, we ensure the receiving party is bound by legally enforceable obligations to provide a standard of protection comparable to the PDPA. This is achieved through one or more of:
- Contractual clauses with the receiving party (including ASEAN Model Contractual Clauses)
- Recognised certification under the APEC Cross-Border Privacy Rules (CBPR) or Privacy Recognition for Processors (PRP) systems
- Transfer to jurisdictions that the PDPC has assessed as having data protection standards comparable to Singapore
Our cloud infrastructure, analytics, error-reporting, mapping and email providers may process certain operational or diagnostic data in data centres located outside Singapore, subject to the safeguards above. PostHog, Sentry, CARTO and Resend process data in the United States; Photon processes data in Germany. The only identifier reaching PostHog or Sentry is your pseudonymous user ID, with no email and no stored IP address.
12. Your rights under the PDPA
12.1 Right of access
You may request a copy of the personal data we hold about you and how we have used it in the past 12 months. We respond within 30 days (Section 21, PDPA). Email privacy@mixly.sg.
12.2 Right of correction
You may correct your name, email and profile photo directly in the app. For anything else, email privacy@mixly.sg. We respond within 30 days (Section 22, PDPA).
This includes your reliability record. If you believe an absence or a late cancellation has been recorded against you incorrectly, you may ask us to correct it. We will review the records available to us, and where we cannot resolve a dispute of fact, we will record your position alongside the entry.
12.3 Right to withdraw consent
You may withdraw consent to the collection, use or disclosure of your personal data at any time via privacy@mixly.sg or by deleting your account. Withdrawal may prevent us from continuing to provide the service.
12.4 Right to delete your account and data
You may delete your account at any time via Settings > Account > Delete Account. Deletion is permanent. It is not a deactivation, and the account cannot be recovered.
What is deleted: your profile, name, email, photo, sports and skill levels, your game history, your chat messages, your reliability record, any saved PayNow identifier, and your cost-sharing records. All of it is permanently deleted within 30 days.
What is not deleted:
- Anonymised and aggregated statistics, which cannot identify you
- Records we are required to keep by Singapore law
- Safety and incident reports, where retaining them is necessary to protect other users, and only for as long as that remains necessary
- Information other users have already seen, and their own records of games you took part in. We cannot recall or delete another person’s records on your behalf
If you owe money for a shared-cost game, please settle it before you delete your account. Deleting your account removes our record of the amount and you will no longer be able to see it. It does not cancel the obligation. That is a debt between you and the host, and it exists independently of Mixly.
12.5 Right of data portability
Once the Data Portability Obligation is fully operational under the PDPA, you may request transmission of your personal data in a structured, commonly used format to another organisation. We will accommodate such requests in line with the PDPC’s implementing regulations.
12.6 Right to lodge a complaint
If you believe we have not handled your personal data in accordance with the PDPA, you may contact our DPO at privacy@mixly.sg, or lodge a complaint with the PDPC at www.pdpc.gov.sg.
13. Marketing communications and the Do Not Call Registry
We respect Singapore’s Do Not Call (DNC) Registry under the PDPA and the Spam Control Act 2007:
- We will not send marketing communications by phone, SMS or fax without your prior express consent
- Marketing emails will include an unsubscribe link in every message, in accordance with the Spam Control Act
- Operational notifications about games you have joined or hosted are not marketing and will continue to be sent unless you turn them off
14. Minimum age
Mixly is for people aged 16 and over. We do not knowingly collect personal data from anyone under 16.
If we discover that we have collected personal data from someone under 16, we will delete that data and close the account promptly. If you believe someone under 16 has provided personal data to us, contact privacy@mixly.sg.
Users aged 16 and 17 should have the awareness and consent of a parent or guardian before using Mixly, before attending any in-person game arranged through the platform, before taking part in a shared-cost game where money may be owed to a host, and before adding a PayNow number to a game they host, which makes their mobile number visible to that game's players (see Section 3.7).
15. App store privacy disclosures
This Privacy Policy is consistent with our disclosures in the App Store’s Privacy Nutrition Label. Because Mixly uses no advertising identifiers and does not track you across other companies’ apps or websites, data collected through Mixly is not used to track you in the sense defined by Apple’s App Tracking Transparency framework.
If there is any inconsistency between this Policy and a store disclosure, this Privacy Policy is the authoritative source, and we will reconcile any difference as soon as practicable.
16. Governing law and jurisdiction
This Privacy Policy is governed by, and construed in accordance with, the laws of the Republic of Singapore. Any dispute arising out of or in connection with it is subject to the exclusive jurisdiction of the courts of Singapore. Nothing in this clause limits your statutory rights under the PDPA or your right to lodge a complaint with the PDPC.
17. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will:
- Update the Last Updated date at the top of this document
- Notify you in the app or by email of any material change at least 14 days before it takes effect
- Maintain the latest version at https://mixly.sg/privacy-policy
- Maintain a version history at the end of this Policy
Where a change introduces a new category of personal data or a new recipient of it, we will seek fresh consent rather than relying on your continued use. Otherwise, your continued use of Mixly after the effective date of an update constitutes acceptance of the revised Policy. If you do not agree, you should stop using Mixly and may delete your account.
18. Contact our Data Protection Officer
In accordance with the Accountability Obligation (Section 11, PDPA), we have appointed a Data Protection Officer responsible for PDPA compliance.
- Email: privacy@mixly.sg
- General support: support@mixly.sg
- Website: https://mixly.sg
- Registered office: 4 Binjai Hill, Singapore 589921
We acknowledge receipt of privacy-related enquiries within 5 business days and provide a substantive response within 30 days, in line with PDPA timelines.
Version history
We keep a record here of every published version of this Policy, so you can see what has changed and when.
- v1.3, current. Accuracy pass against the shipped app. Section 4 now describes when your device actually asks for location, which is during account setup rather than only while browsing.
- v1.2. The app now has an optional PayNow field: a host may add an identifier, typically a mobile number, when posting a shared-cost game, and it is shown to the players who joined that game. Sections 3.7, 7 and 8 describe what we hold and who sees it, and the under-17 caution is back because it is relevant again. No QR code is collected, so nothing exposes a bank-registered name.
- v1.1. Corrected to describe the app as it actually ships. We do not collect a host's payment details, so every reference to holding or displaying a PayNow identifier or QR code has been removed. Reliability is a record of attendance and teammate thumbs up; the "strike" mechanism described in v1.0 does not exist, and whether a shared cost was paid has no effect on it.
- v1.0. First published version.