Legal
Privacy and data
How Proppy collects, uses, and protects personal data, under Singapore's Personal Data Protection Act 2012 (PDPA). Version: privacy 2026-10-09. Last updated 9 October 2026.
The short version
- Proppy reads supplier invoices for managing agents, so their teams can check, code, and approve them. Proppy never makes payments.
- For invoices and MCST records, your managing agent firm decides what's processed, and Proppy processes it for the firm.
- Our database and app run in Singapore. Invoices are read by an AI model on a paid plan, which may process them outside Singapore, and emailed invoices pass through an email service that keeps its records in the United States.
- Ask Proppy, the assistant inside the app, keeps your questions and its answers for 90 days, then deletes them, and you can clear yours at any time. Google's AI service, on the same paid plan, writes its answers. Don't paste NRIC numbers or bank details into it.
- We don't sell personal data, use it for advertising, or let AI providers train their models on it.
- We don't ask for NRIC numbers. We mask any we read from an invoice, though the file itself is kept as received.
- To see or correct your data, or to withdraw your consent, write to james@talktoproppy.com.
Who we are
Proppy is a service of PEBBLEBLACK PTE. LTD. (UEN 202531369R), a company in Singapore. This notice covers talktoproppy.com, the Proppy app, the demos you book with us, and our free invoice teardowns. In it, "we" means Proppy, and "your firm" means the managing agent you work for. Our Data Protection Officer is at james@talktoproppy.com.
Two kinds of data
Proppy handles personal data in two roles:
- Your account. When your firm sets up Proppy, we collect details about the people who use it, such as names and work email addresses, and what they ask Ask Proppy. For these, and for demo bookings, teardowns, and our own emails to managing agents, Proppy is the organisation responsible under the PDPA.
- Your firm's documents. The invoices, vouchers, and MCST records your firm puts into Proppy can include personal data, such as a supplier's contact person or a sole proprietor's name. For these, Proppy is a data intermediary: we process them only for your firm, under our agreement with it. Your firm, and the MCSTs it manages, stay responsible for them, so requests about them go to your firm, and we help it answer.
What we collect
- Account details: your name, work email address, phone number if you give it, your firm's name, and your role.
- Sign-in and security records: when you sign in, the device and IP address used, and a record of the changes and approvals you make.
- Billing details: your firm's billing contact and its invoices from us. Stripe handles card payments, so we never see or store card numbers.
- Documents your firm sends: invoices, credit notes, statements, and quotations, and what's printed on them, such as supplier names, UENs, addresses, amounts, and bank details for payment.
- Ask Proppy conversations: the questions you type into Ask Proppy, the assistant inside the app, and its answers, with any NRIC number, bank account number, email address, or phone number masked; the look-ups it made in your firm's records to answer you, such as how many invoices are waiting, kept as a summary; which suggested questions it showed and which you chose; and any rating or note you give an answer. Don't paste NRIC numbers or bank details into Ask Proppy. Proppy masks them in your question before it goes to the AI model and before it's kept, but masking is automatic and can miss one.
- Teardown files: the invoices a managing agent sends us for a free teardown, under the data agreement signed first.
- Demo bookings: when you schedule a demo, your name, email address, the time you choose, and anything you write in the booking form.
We don't ask for NRIC numbers, dates of birth, or other details we don't need, following the PDPC's advisory guidelines on NRIC numbers. If an NRIC number appears on an invoice, Proppy masks it in the data it reads from the invoice. The invoice's file is kept as received, as the MCST's record, so the number can still be seen there by your firm's people who may open it.
How we use it
We use personal data only for these purposes:
- To run Proppy for your firm: reading invoices, working out which MCST each belongs to, suggesting the fund and account, checking the amounts and GST, and drafting payment vouchers, and Draft bills in Xero when your firm connects it. Proppy never makes payments: your firm pays its suppliers itself.
- To sign you in, keep accounts secure, and keep a record of who changed or approved what, which audits need.
- To bill your firm, and to send service messages such as email confirmations, password resets, invitations, receipts, and notices about changes to Proppy.
- To answer your questions, and to find and fix problems, using error reports that leave out personal data.
- To measure and improve how accurately Proppy reads your firm's invoices, using your firm's own corrections.
- To answer your questions in Ask Proppy, from what your role can already see in your firm's records. Ask Proppy only reads: it can't change, approve, or delete anything.
- To check the quality of Ask Proppy's answers. The same AI model checks a sample of them automatically, and a weekly report to our team counts the results and lists answers by their IDs only, with no questions or answers in it.
- To arrange and hold the demos you book, and to follow up on them.
- To tell managing agents about Proppy, by email to the business addresses they publish. Every such email says how to stop them.
We need the data for the first three purposes to provide Proppy. We send product news only if you ask for it, and you can stop it at any time. We don't sell personal data, use it for advertising, or use your firm's documents or your Ask Proppy conversations to train AI models.
Who we share it with
We share personal data only with the service providers that run Proppy and take its demo bookings, and only for the purposes above:
- Supabase runs our database and sign-in, in Singapore.
- Railway runs the Proppy app, and keeps a backup copy of documents, in Singapore.
- Google reads invoice documents, and writes Ask Proppy's answers, with its AI models, on a paid plan. See the next section.
- Stripe takes payments and sends billing receipts.
- Xero receives Draft bills, only when your firm connects its Xero organisations, and keeps them under your firm's own agreement with Xero.
- Resend sends sign-in and service emails, from Japan, and receives the invoices emailed to Proppy's addresses, where your firm uses them. It keeps its records in the United States.
- Zoho hosts our email inbox, in Singapore.
- Sentry receives reports of errors in the app, with no invoice contents or personal data, in Germany.
- Calendly takes demo bookings, and keeps them in the United States.
We also disclose personal data when the law requires it.
Data sent outside Singapore
Proppy's database, document storage, and app run in Singapore. To read an invoice, Proppy sends the document to Google's AI service, which may process it in any country where Google has facilities, such as the United States. We use it on a paid plan, under Google's terms for paid services, which don't let Google use the content to improve its products, and let it keep the content for a limited time only to detect misuse and meet legal requirements. To answer a question in Ask Proppy, Proppy sends it to the same service, with what it looked up in your firm's records, such as a supplier's name or an invoice's status, and the automated check of a sample of answers sends the question and answer there too. Resend sends Proppy's sign-in and service emails from Japan, and receives the invoices emailed to Proppy's addresses where your firm uses them. It keeps its records of those emails in the United States, so names, email addresses, and emailed invoices pass through it there. Calendly keeps demo bookings in the United States. Stripe may also process billing details outside Singapore, and Sentry keeps its error reports in Germany.
Each of these providers is bound by its written data processing terms to protect personal data to a standard comparable to the PDPA's, as the PDPA's Transfer Limitation Obligation requires. For your firm's documents, your firm decides, under our agreement with it, and we tell it before we add or change a provider.
How we protect it
- Data is encrypted in transit and at rest.
- Each firm's data is kept separate, and our tests check that one firm can't see another's.
- Each person signs in with their own password, and sees only what their role needs. Proppy has no second sign-in step, so use a strong password you don't use anywhere else.
- Proppy's support opens your firm's account only to help it, read-only, for an hour, with a reason, and your firm sees each visit.
- Ask Proppy reads your firm's records only through a read-only database account that can see just your firm's data, and, for an auditor, condo manager, or council member, just their MCSTs.
- Every change, approval, and posting is recorded in an audit log.
- Our system logs record document IDs, not what's on the documents.
How long we keep it
- Your firm's documents, vouchers, and audit records: as long as your firm's retention setting says: at least 5 years, from the end of the financial year each belongs to. The Building (Strata Management) Act 2004, called the Building Maintenance and Strata Management Act until 1 October 2025, requires an MCST to keep its records that long, and Singapore's tax rules require business records to be kept for 5 years. We keep them that long even if your firm stops paying or closes its account, and then delete them, unless your firm asks us to delete an MCST's records sooner, once it has handed them over to the MCST or its new managing agent. If we ever stop providing Proppy, we give your firm at least 90 days' notice to download them.
- Account details: while the account is open, then 5 years for our own tax and accounting records.
- Ask Proppy conversations: deleted automatically 90 days after you last used them, with their look-ups, ratings, and chosen suggestions. You can delete your own sooner at any time, with Clear at the top of the Ask Proppy panel (a bin icon on a phone). Other people at your firm can't read them in Proppy. A copy in the database's daily backups is deleted when that backup expires, so it can outlast the deletion for a short time.
- Teardown files: deleted 30 days after we deliver the teardown, and we confirm the deletion in writing.
- Demo bookings: up to 2 years after the demo. If your firm signs up, the details you gave become part of your account details.
After that, we delete the data or remove what identifies people in it.
Your choices
- See or correct your data: write to our Data Protection Officer. We'll reply as soon as we reasonably can, and within 30 days, or tell you by then when we will. If we can't do what you ask, we'll say why.
- Withdraw your consent: write to our Data Protection Officer, giving us reasonable notice. We'll tell you what it means for you: if you withdraw consent for data that Proppy needs to run your account, we won't be able to keep providing Proppy to you.
- Ask Proppy: clear your own conversations at any time, as the previous section says. For anything else about them, write to our Data Protection Officer.
- Stop product news: use the unsubscribe link in any product email, or tell us.
- Your firm's documents: ask your firm first, because it decides how they're used. We'll help it answer.
If something goes wrong
If a data breach affects personal data we hold, we act at once to contain it. For your firm's documents, we tell your firm without undue delay, so it can meet its own duties under the PDPA. For account details, we assess within 30 days whether the breach must be notified. If it must, we notify the PDPC no later than 3 calendar days after that assessment, and the people affected as soon as we can where it's likely to cause them significant harm.
Cookies
This website sets no cookies and loads nothing from other sites. Its "Schedule a demo" buttons take you to Calendly's own site, where Calendly's cookie policy applies. The Proppy app uses only the cookies and browser storage it needs to keep you signed in and secure. We don't use advertising or tracking cookies.
Changes to this notice
When we change this notice, we update the date at the top. If a change affects how we use your data, we tell account owners by email before it takes effect, and ask for fresh consent where the PDPA requires it.
Contact our Data Protection Officer
For questions, requests, or complaints about personal data:
Data Protection Officer, ProppyEmail: james@talktoproppy.com
If you're not satisfied with our answer, you can contact the Personal Data Protection Commission at pdpc.gov.sg.