Consumer Privacy Policy
Last updated: 10 July 2026
1. Overview
This Consumer Privacy Policy (“Policy”) explains how MarlinX Technologies Pte. Ltd. (operating as “Directo”, “we”, “us”, “our”) collects, uses, discloses, and protects your personal data when you use Directo as a customer.
This Policy applies to individuals who use:
- the Directo Merchant Network;
- Discovery;
- Directo-powered storefronts;
- a Directo consumer account;
- Merchant links and QR codes; and
- ordering, payment, delivery, and related customer features.
Directo is a merchant network and technology service that enables customers to discover participating Merchants, access Merchant storefronts, place orders directly with Merchants, save stores, and return to order again.
Each Merchant is an independent seller of its own goods and services. When you place an order, you enter into a contract of sale directly with the relevant Merchant, not with Directo.
Directo may act in different capacities depending on the purpose for which personal data is processed:
- As an organisation: where we determine the purposes and means of processing, including for consumer accounts, Discovery, saved stores, customer-store attribution, Merchant Channel and Discovery channel attribution, payment and settlement support, fraud prevention, security, analytics, service improvement, dispute handling, and compliance and enforcement.
- As a data intermediary: where we process personal data solely on behalf of a Merchant and for that Merchant’s purposes, such as order fulfilment, delivery, and Merchant customer-support tools.
Each Merchant is a separate, independent organisation and may process your personal data in connection with its orders, fulfilment, refunds, customer service, and marketing activities where separately notified to you, permitted under the applicable Directo terms, and carried out with any consent required by applicable law.
We handle personal data in accordance with the Personal Data Protection Act 2012 (“PDPA”) of Singapore.
2. How Directo and Merchants Handle Data
Directo acts as an organisation under the PDPA where we determine the purposes and means of processing personal data for the operation of the Directo Merchant Network, including consumer accounts, Discovery, saved stores, customer-store attribution, payment and settlement support, fraud prevention, security, analytics, service improvement, dispute handling and legal compliance.
Directo may act as a data intermediary where we process personal data solely on behalf of a Merchant and for that Merchant’s purposes, such as enabling order fulfilment, delivery and Merchant customer-support tools.
When you place an order, the relevant Merchant acts as an independent organisation for the personal data it uses to sell and fulfil its goods or services, provide customer support, handle cancellations, returns and refunds, and comply with its legal obligations.
A Merchant receives only the personal data reasonably required for its own transactions with you. Merchants do not receive access to your full Directo profile, saved stores, or your activity and spending across other Merchants or the wider Directo Merchant Network.
3. Personal Data Collected by Directo
Depending on how you use Directo, we may collect the following categories of personal data. The same category of personal data may be processed by Directo as an organisation or as a data intermediary depending on the purpose of the processing, as described in Section 2.
| Category | Examples | Source |
|---|---|---|
| Account and Identity Data | Name (where collected), email address, telephone number, Directo account identifier, Google Sign-In identifier, authentication and OTP records, account status and preferences | Provided directly by you; from authentication providers; generated when your account is created or used |
| Order and Transaction Data | Merchant and store, items ordered, order value, discounts, delivery or collection method, order date and status, cancellations, refunds, disputes, transaction references | Provided by you; generated through your order; received from Merchants and transaction service providers |
| Contact and Fulfilment Data | Name, telephone number, delivery address, delivery instructions, collection information, communications relating to an order | Provided by you; received from Merchants and delivery providers |
| Payment Status Data | Payment status, payment method type, payment provider, transaction reference, refund, reversal or chargeback status, and limited or masked payment information supplied by a payment provider. This category does not include full card numbers or CVV. | Received from payment and settlement providers; generated through your order |
| Discovery, Attribution and Preference Data | Stores viewed, saved stores, Merchant links or QR codes used, whether an order originated from a Merchant Channel or Discovery, customer-store attribution, interactions with Directo storefronts and Discovery, and search or filter activity (where these features are used) | Generated through your use of Directo |
| Usage and Technical Data | IP address, device and browser information, operating system, cookie or similar technology identifiers, session data, access times, security and diagnostic logs, and push-notification token (where enabled) | Automatically collected from your device |
| Communications and Support Data | Enquiries, complaints, feedback, support correspondence, and records relating to disputes or suspected misuse | Provided by you; generated through our handling of your request |
Depending on the interaction, we may collect personal data directly from you, automatically from your device, from Merchants, from authentication providers, from payment and settlement providers, from delivery providers, and as generated through your use of Directo.
4. Personal Data We Generally Do Not Collect
Directo is designed to collect only the personal data reasonably necessary to provide our services. In particular:
- Payment card data: Directo does not collect or store your full payment card number or CVV. Full payment credentials are handled by third-party payment service providers. Directo may receive payment status, transaction reference, payment method type, limited or masked payment information, and refund or chargeback status. Third-party payment service providers process payment data under their own terms and privacy policies.
- National identification numbers: We do not generally request your NRIC, FIN, passport number or other government-issued identification number unless this is specifically required by law or for a clearly notified service.
- Biometric data: We do not collect fingerprints, facial recognition data, or other biometric identifiers.
- Sensitive personal data: Please do not provide health, financial, government identification or other sensitive information unless it is specifically requested for a clearly stated and lawful purpose.
5. How We Use Your Data
We use personal data for the following purposes:
- creating and administering Directo consumer accounts;
- authenticating users and maintaining account security;
- operating Directo storefronts and Discovery;
- allowing you to view and save stores;
- enabling you to return to saved stores and order again;
- determining and maintaining customer-store and channel attribution;
- processing and supporting orders, cancellations, refunds and disputes;
- providing relevant order information to the Merchant you select;
- supporting payments, settlements and delivery;
- sending account, order, service and security notifications;
- detecting and preventing fraud, abuse, fake transactions and attribution manipulation;
- responding to enquiries, complaints and support requests;
- generating analytics and measuring the performance of Directo;
- maintaining, improving and developing Directo;
- enforcing the Consumer Terms and other applicable policies;
- complying with legal and regulatory obligations; and
- establishing, exercising or defending legal claims.
We do not sell or rent identifiable personal data.
We may send Directo promotional communications only where permitted by applicable law and in accordance with your communication preferences. You may opt out at any time.
We may generate aggregated or de-identified information from personal data and usage data. We may use such information for analytics, benchmarking, reporting, service improvement and other lawful business purposes, provided that it does not identify and cannot reasonably be used to identify an individual.
6. Sharing and Disclosure
We do not sell or rent identifiable personal data. We may disclose personal data, where necessary, to:
- Merchants: When you place an order with a Merchant, we may disclose the information reasonably required by that Merchant to accept and fulfil the order, provide customer support, and handle cancellations, returns or refunds. A Merchant does not receive access to your full Directo profile, saved stores, or your activity or spending across other Merchants.
- Payment and settlement providers: To process payments, refunds, and settlement, support fraud prevention and risk controls, and resolve transaction disputes.
- Delivery providers: Only the personal data reasonably required to complete delivery of your order.
- Authentication providers: Such as Google Sign-In, to enable account sign-in, subject to their own terms and privacy policies.
- Technology and service providers: Cloud hosting, security, communications, and customer-support providers that support the operation of Directo, engaged under appropriate contractual protections.
- Professional advisers: Lawyers, accountants, auditors, and insurers, where necessary and subject to confidentiality obligations.
- Authorities: Government, regulatory, law enforcement, court, or other public authorities where required or permitted by applicable law.
- Business transfers: In connection with a merger, reorganisation, financing, acquisition, or sale of assets, subject to applicable legal requirements.
We do not disclose one Merchant’s customer information to another Merchant, except where you separately interact or transact with that other Merchant.
7. Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, or as required by applicable law.
| Category | Retention Period |
|---|---|
| Account and profile data | Until your account is closed or becomes inactive for a prolonged period, plus a reasonable further period for account recovery, disputes, security, and legal obligations. |
| Saved stores and preferences | Until you delete them, your account is closed, or they are no longer needed to provide the relevant feature. |
| Order, transaction, payment-status and attribution records | For as long as reasonably necessary to complete and support the service, settlement, refunds, and dispute handling, and to meet audit, fraud-prevention, accounting, and legal obligations. |
| Security and technical logs | For as long as reasonably necessary for security, fraud prevention, diagnostics and legal purposes. |
| Support and dispute records | Until the matter is resolved, plus a reasonable further period for legal or dispute-related purposes. |
Closing or deleting your Directo account does not necessarily result in immediate deletion of transaction, payment, attribution, fraud-prevention, dispute or legal records that we or the relevant Merchant are required or reasonably entitled to retain.
When personal data is no longer required, we will delete it, anonymise it, or otherwise cease retaining it in accordance with applicable law.
8. Security
We implement reasonable administrative, technical, and organisational measures to protect personal data against unauthorised access, use, disclosure, alteration, or loss. These measures may include:
- access controls;
- encryption where appropriate;
- logging and monitoring;
- service-provider controls; and
- incident-response procedures.
No system or method of transmission is completely secure, and we do not guarantee absolute security. If you believe your Directo account has been compromised, please contact us at support@marlinxtech.com.
9. Your Rights
Subject to the exceptions and limitations set out in the PDPA, you may:
- request access to, or correction of, personal data we hold about you;
- withdraw your consent where we rely on consent to process your personal data, though this will not affect processing already carried out and may impact our ability to provide certain services;
- opt out of Directo marketing communications at any time; and
- request closure of your Directo account, subject to the retention requirements described in Section 7.
We handle requests relating to personal data that we control as an organisation. Where a request concerns personal data controlled by a Merchant in its own capacity as an independent organisation, we may refer you to the relevant Merchant, or assist in passing your request to that Merchant.
We may request information reasonably necessary to verify your identity before processing a request.
To submit a request, please contact our Data Protection Officer at support@marlinxtech.com. If you are dissatisfied with how we have handled your request or complaint, you may lodge a complaint with the Personal Data Protection Commission of Singapore at www.pdpc.gov.sg.
10. Overseas Transfers
We may engage service providers located outside Singapore in connection with operating and supporting Directo. Where personal data is transferred outside Singapore, we take reasonable steps to ensure that the receiving party provides a standard of protection comparable to that required under the PDPA, including through appropriate contractual protections where applicable.
Overseas recipients may include cloud, authentication, communications, security, payment-support and customer-support providers used in operating Directo.
11. Data Breach
In the event of a data breach involving personal data for which Directo acts as an organisation, we will assess the breach and notify the PDPC and affected individuals where required by the PDPA.
Where Directo processes personal data as a data intermediary on behalf of a Merchant, we will notify the relevant Merchant without undue delay after becoming aware of, or having reason to believe that there has been, a data breach affecting such data.
12. Cookies and Similar Technologies
Directo uses cookies and similar technologies, including local storage, session identifiers, authentication tokens, device or browser identifiers, and similar technologies.
We use these technologies for purposes such as authentication, session management, saved preferences, security, fraud prevention, functionality, and diagnostics.
You may manage cookies through your browser settings, but blocking essential cookies or storage may prevent account, ordering or other Directo features from working correctly.
13. Data Collected by Merchants
When you place an order, the relevant Merchant receives the personal data reasonably required to fulfil your order, such as your name, contact details, and delivery or collection information.
Each Merchant is an independent organisation responsible for its own sale and fulfilment of goods or services, refunds, customer service, and any marketing activities that are separately notified to you, permitted under the applicable Directo terms, and carried out with any consent required by applicable law.
A Merchant’s handling of your personal data is governed by that Merchant’s own privacy policy, which you should review for information about its data practices.
Directo does not provide a Merchant with your full activity or spending records across other Merchants.
If you have questions about how a Merchant handles your personal data in its own capacity, please contact that Merchant in the first instance.
Directo may still process and retain, in its own capacity as an organisation, personal data relating to orders, payment status, attribution, fraud prevention, analytics, and disputes as described in this Policy.
14. Minors
Directo is not intended for children under 13 to create or operate an account independently. If you are under 13, you should use Directo only with the involvement and consent of a parent or legal guardian. If you are between 13 and 17, you should read this Policy carefully and seek help from a parent or guardian if you do not understand it.
If we become aware that personal data of a child has been provided without valid consent or an appropriate legal basis, we may restrict the relevant account or take reasonable steps to delete or anonymise the data, subject to legal and transaction-record retention requirements.
A parent or guardian who believes that a child’s personal data has been collected inappropriately may contact our Data Protection Officer.
15. Changes
We may update this Policy periodically to reflect changes in our data practices or applicable legal requirements. We will update the “Last updated” date at the top of this page. Where changes are material, we will provide notice through appropriate channels, which may include the account interface, the Directo website or storefront, email, or other appropriate notice channels.
16. Contact and Data Protection Officer
For questions, access or correction requests, consent withdrawals, account-closure requests, complaints or other matters relating to this Policy, please contact our Data Protection Officer at:
MarlinX Technologies Pte. Ltd.
Email: support@marlinxtech.com
Singapore
If you are not satisfied with our response, you may contact the Personal Data Protection Commission of Singapore at www.pdpc.gov.sg.