Legal & Compliance

Privacy Policy

Entity: MiFi Singapore Pte. Ltd. • Effective Date: September 2026 • Jurisdictions: Singapore (PDPA) & Philippines (DPA)

Your privacy matters to us. This Privacy Policy explains how MiFi Singapore Pte. Ltd. (“the Company”, “MiFi SG”, “we”, “us”, or “our”) collects, stores, processes, uses, discloses, and protects your personal data when you register for, download, or use the MiFi Mobile Application (“the App”) and our associated financial data, analytics, and platform services.

MiFi SG operates as the parent entity of Migrant Finance Company (MiFi Philippines) and acts as a related technology and processing service provider to Provider Stores (provider.sg). By registering an account on the App, conducting transactions, or submitting an application, you consent to the collection, use, and disclosure of your personal data in accordance with this Privacy Policy, the Personal Data Protection Act 2012 (No. 26 of 2012) of Singapore (“PDPA”), and the Philippine Data Privacy Act of 2012 (RA 10173, “DPA”).

1. Corporate Structure and Our Services

MiFi Singapore Pte. Ltd. is the central technology, infrastructure, and processing hub for its group entities and business partners. We provide localized and cross-border services including:

  • The core MiFi mobile application infrastructure.
  • Advanced credit assessment models and risk scorecards.
  • Data consolidation, processing, and transaction management services for our regional subsidiaries (including Migrant Finance Company / MiFi Philippines) and affiliated partner ecosystems (including Provider Stores / provider.sg).

2. Information We Collect

To process your requests, deliver goods, assess loan eligibility, and maintain account security, we collect unique and personally identifiable data that you provide directly or that we obtain automatically via the App:

  • Identity Data: Full name, date of birth, nationality, and national identification numbers (such as NRIC, FIN, Passport, or Government IDs).
  • Contact Data: Mobile number, email address, residential address, billing address, and delivery coordinates.
  • Financial & Employment Data: Income details, employment parameters, bank account frameworks, credit histories, loan purposes, or payment tracking.
  • Transaction Data: Specifics regarding goods ordered, delivery requests, loan application parameters, and regional disbursement or collection logs.
  • Device, Technical & Network Data: Device type, OS version, SIM card number, IP address, mobile network metrics, and comprehensive app usage logs.
  • Location Data: Real-time GPS or network-based location metrics (subject to device permission triggers).
  • Reference & Third-Party Data: Personal reference contacts, educational background metadata, and official credit bureau or lawful third-party verification registries.

3. Purposes and Lawful Bases of Processing

We process personal data based on explicit consent, contractual necessity, legal/regulatory compliance (including Anti-Money Laundering frameworks), and legitimate business interests (such as risk evaluation and fraud prevention). Processing purposes include:

  • Fulfilling transaction requests, delivery of goods, and processing loan allocations on behalf of our subsidiaries or business partners.
  • Executing advanced identity verification, strict Know-Your-Customer (KYC) routines, and anti-money laundering checks.
  • Generating customized risk scorecards and algorithmic credit scores to determine eligibility for financial services.
  • Maintaining precise platform audit logs, deploying fraud prevention shields, and protecting our legal rights.

4. Marketing Communications and Do Not Call (DNC) Provisions

By providing your contact information and registering an account, you explicitly consent to receiving updates, special offers, promotional campaign notifications, and transaction-related check-ins from the Company, our regional subsidiaries (including MiFi Philippines), and our business partners (including Provider Stores).

  • Communication Channels: Marketing and updates may be dispatched via voice calls, SMS, WhatsApp, MMS, or alternative digital messaging systems.
  • DNC Register Override: This consent applies notwithstanding that your specific contact coordinates are currently, or will be, listed on the "Do Not Call Register" maintained by the Personal Data Protection Commission (PDPC) of Singapore.
  • Withdrawal of Consent: You agree that this marketing consent can only be revoked by serving an explicit written notice to our Data Protection Officer. A subsequent general listing on the DNC Register does not automatically invalidate or withdraw the specific consent granted under this policy.

5. WhatsApp and Meta Policy Compliance

  • Operational Messaging: We utilize WhatsApp to deliver operational order tracking updates, ongoing customer support, account alerts, and tailored marketing messages (where consented).
  • Instant Opt-Out: You retain the right to cancel WhatsApp communications instantly at any time by replying with the keyword "STOP".
  • Advertising Safeguards: We strictly comply with Meta’s operational platform policies and applicable regional data protection laws. We do not share your personal data with third parties for independent advertising purposes.

6. Sharing and Disclosure of Personal Information

To deliver high-fidelity ecosystem services, your personal information will be cross-shared internally and externally under protected conditions:

  • Group Entities & Subsidiaries: Data is shared dynamically with our current or future corporate branches, including Migrant Finance Company (MiFi Philippines) and affiliated entities like Provider Stores (Singapore), to manage unified user data and application logic.
  • Business & Financial Partners: Information is routed securely to partner financial institutions, credit registries, tax authorities, or background screening networks.
  • Delegated Third-Party Suppliers: In limited operational scenarios, we share necessary data fragments with certified logistics providers, payment processors, customer service hubs, and collections vendors tasked with executing services on our behalf.
  • Legal Mandates: We share information when compelled by competent courts, active regulations, or governing authorities across applicable jurisdictions.

7. Data Sovereignty, Security, and Breach Notification

  • Cross-Border Processing: As MiFi SG provides infrastructure services across Singapore and the Philippines, data may be transferred, hosted, and processed in secure cloud repositories optimized with industry-grade defensive walls. We deploy Standard Contractual Clauses (SCCs) and strong encryption protocols to match or exceed PDPA and regional data laws.
  • Information Security Shield: The Company deploys rigid organizational, physical, and technical measures to secure data transit and storage, insulating it from loss, unauthorized adjustments, unauthorized access, disclosure, or accidental destruction.
  • Data Breach Notification: In the event of a security incident or data breach assessed to cause significant harm or affect a prescribed volume of users under applicable laws, we will notify the Personal Data Protection Commission (PDPC), the National Privacy Commission (NPC), and affected individuals in accordance with mandatory regulatory timelines.

8. Retention and Disposal Guidelines

We retain personal data only for the timeline required to fulfill the operational processing metrics for which it was originally collected, or to align with mandatory statutory retention limits (such as Anti-Money Laundering frameworks which require records to be stored for a minimum of five (5) years). When data leaves its compliance or operational utility window, it is systematically deleted, destroyed, or fully anonymized.

9. App Permissions and Digital Tracking

The App mandates specific system permissions (such as camera access for identity verification and location sweeps for transaction security) to activate financial features. Note: In compliance with mobile ecosystem standards, mobile applications do not harvest or access device contact lists or call logs. Our digital channels also deploy cookies and app analytics trackers to personalize user navigation, run risk assessment models, and enhance platform security.

10. Your Rights as a Data Subject

Depending on your jurisdiction, you maintain statutory privileges regarding your information under the Singapore PDPA or Philippine DPA:

  • Access & Information: The right to request information on how your data has been used and obtain a copy of your personal data profile.
  • Correction: The right to request rapid corrections or updates to inaccurate, outdated, or incomplete data records.
  • Erasure or Blocking (Philippines DPA): The right to suspend, withdraw, or order the blocking/removal of inaccurate, incomplete, or unlawfully processed data.
  • Object to Processing (Philippines DPA): The right to object to automated profiling or marketing processing.
  • Withdrawal of Consent: The right to formally withdraw consent for data processing (subject to contractual realities—withdrawing functional operational data may prevent continued use of the App).
  • Lodge Complaints: The right to file a complaint with the Personal Data Protection Commission (PDPC) in Singapore or the National Privacy Commission (NPC) in the Philippines.

11. Policy Modifications

We reserve the right to modify this Privacy Policy periodically to match technological updates or legal mandates. Significant structural edits will be communicated via in-app push notifications, the registered email profile, or SMS alerts. Continued execution of transactions or interaction with the App following an update constitutes active acceptance of the edited terms.

12. Contact Our Data Protection Officer (DPO)

For questions concerning this data notice, requests to execute your legal data access/correction rights, or to file a formal consent withdrawal, please reach our group privacy office:

Data Protection Officer

MiFi Singapore Pte. Ltd.

Email: dpo@mifi.sg

Corporate Gateway: provider.sg / mifi.ph

Jurisdiction Addendum

SCHEDULE A: PROVISIONS FOR USERS IN INDIA

(To take effect automatically upon commercial launch of MiFi services and LSP operations in India)

This Schedule applies specifically to users residing in India or accessing services provided by MiFi SG or its Indian entities/LSP partners in India, pursuant to the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Reserve Bank of India (RBI) Guidelines on Digital Lending.

1. Data Localization Mandate

In strict compliance with RBI directives, all personal data, financial information, credit assessments, and transaction logs relating to Indian borrowers are stored and hosted exclusively on secure cloud servers situated physically within India.

2. Regulated Entity Disclosures

MiFi SG operates as a Loan Service Provider (LSP) in India in technology partnership with RBI-Regulated Entities (REs)—including licensed Banks and Non-Banking Financial Companies (NBFCs). A complete, live list of our active RE partners, along with direct links to their official websites, will be made available upon market launch.

3. Restricted Device Permissions

For Indian users, our mobile applications do not access, harvest, or request permissions for phone contact lists, call logs, SMS content, or external media files. Device permissions requested (e.g., camera for KYC photo capture or one-time location for fraud check) are sought explicitly on an opt-in basis with clear usage explanations.

4. Specialized Data Principal Rights (India)

In addition to rights listed in Section 10 of the main policy, Indian users hold:

  • Right to Nominate: The right to nominate another individual to exercise your data privacy rights in the event of death or incapacity.
  • Grievance Redressal: The right to a dedicated, time-bound grievance resolution mechanism.

5. Indian Grievance Redressal Officer

(Details to be populated prior to commercial launch in India)

Name: [To be assigned]

Designation: Grievance Redressal Officer (India)

Email: grievance.india@mifi.global

Contact Address: [India Office Address]

Resolution Timeline: Grievances will be acknowledged within 24 hours and resolved within 15–30 days as prescribed by RBI and DPDP regulations.