Privacy Policy
Last updated: 22 May 2026
ArcPay SG ("we", "us", "ArcPay") is operated by ArcPay Pte Ltd, a company registered in Singapore. This Privacy Policy explains how we collect, use, share, and protect your personal data when you use our invoicing and accounts automation platform at arcpaysg.com (the "Service").
1. Information We Collect
We collect the following categories of information:
- Account data: Name, email address, business name, UEN, and password (hashed).
- Invoice & financial data: Customer details, invoice line items, payment records, vendor information, and Chart of Accounts entries that you create within ArcPay.
- Bank statement data: When you upload a bank statement PDF, we extract and store transaction descriptions, dates, amounts, and running balances from that document. We do not connect to your bank directly — all bank data enters ArcPay only through files you voluntarily upload.
- Accounting integrations: When you connect Xero, we receive invoice, contact, and account records from Xero to provide reconciliation and sync features.
- Usage data: Page views, feature interactions, device type, browser, IP address, and timestamps — collected via PostHog analytics.
- Error logs: Stack traces and request metadata when errors occur — collected via Sentry.
2. How We Use Your Information
- To provide, maintain, and improve the Service.
- To process invoices and send them to your customers via email.
- To run AI-powered features (categorisation, anomaly detection, payment recommendations, fraud checks). AI processing is performed by Anthropic Claude under our enterprise agreement; your data is not used to train AI models.
- To send service notifications, security alerts, and password reset emails.
- To detect, prevent, and respond to fraud, abuse, and security incidents.
- To comply with our legal obligations under Singapore's Personal Data Protection Act (PDPA).
3. Legal Basis for Processing
We process your personal data on the basis of: (a) your consent at signup; (b) the performance of our contract with you; (c) our legitimate interests in operating and securing the Service; and (d) compliance with legal obligations including the Singapore PDPA.
4. Sharing Your Information
We do not sell your data. We share information only with:
- Service providers: Supabase (database & authentication), Vercel (hosting), Resend (email delivery), Anthropic (AI processing), Sentry (error monitoring), PostHog (product analytics), Xero (only if you connect it).
- Legal authorities: When required by Singapore law or a valid legal request.
- Business transfers: In the event of a merger, acquisition, or sale of assets, with notice to you.
5. Data Retention
We retain your account and invoice data for as long as your account is active. After account deletion, we delete or anonymise your data within 30 days, except where retention is required for tax, accounting, or legal compliance (typically up to 7 years per Singapore IRAS requirements).
6. Bank Statement Data
ArcPay's Bank Ledger feature allows you to upload bank statement PDFs for bookkeeping purposes. The following applies specifically to this data:
- How it is collected: You manually upload PDF files exported from your bank. ArcPay does not scrape bank portals, store your banking credentials, or connect to your bank's systems in any way.
- What is extracted: Transaction dates, descriptions, reference numbers, debit and credit amounts, and running balances. No login credentials, PINs, OTPs, or full account numbers are collected or stored.
- How it is used: Solely for accounting categorisation, invoice reconciliation, and financial reporting within your ArcPay account. Your bank transaction data is never sold, shared with advertisers, or used for any purpose other than providing the Service to you.
- AI processing: Transaction descriptions are sent to Anthropic's Claude API to suggest accounting categories. Anthropic processes this data under our enterprise agreement and does not use it to train AI models.
- Regulatory status: ArcPay is an accounting and bookkeeping tool, not a financial institution, payment service provider, or account aggregation service. We do not hold, transfer, or intermediate funds. No MAS licence is required for our bank statement import feature.
- Storage and security: Bank statement files and extracted transactions are stored in encrypted form in our Supabase database (Singapore-region where available). Access is restricted to your account via Row Level Security.
- Retention: Bank statement data is retained for as long as your account is active. You may delete any imported statement and its transactions at any time from the Bank Ledger page. On account deletion, all bank data is removed within 30 days.
- Your control: You can delete any individual bank statement import, or all your bank data, at any time. Email info@arcpaysg.com to request full deletion.
7. Your Rights
Under the Singapore PDPA you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Withdraw consent for any optional processing.
- Request deletion of your account and associated personal data.
- Lodge a complaint with the Personal Data Protection Commission (PDPC).
To exercise any of these rights, email us at info@arcpaysg.com.
8. Security
We protect your data using industry-standard measures including TLS encryption in transit, encryption at rest, Row Level Security on our database, rate limiting on authentication, and password breach checks. We monitor for security incidents 24/7 via Sentry.
9. International Transfers
Our service providers may process data outside Singapore (notably in the United States). We ensure such transfers comply with the Singapore PDPA and are protected by appropriate contractual safeguards.
10. Children
ArcPay is for businesses and is not intended for use by anyone under 18. We do not knowingly collect data from children.
11. Changes to This Policy
We will notify you of material changes by email or via an in-app notice. The "Last updated" date at the top reflects the most recent revision.
12. Contact
Our Data Protection Officer can be reached at info@arcpaysg.com.