Privacy Policy

Last updated: 5 August 2026

VCare helps you book appointments and track clinic queues without sitting in the waiting room. To do that, we handle some of your personal data. This policy explains, in plain English, but completely, what we collect, why, how long we keep it, who sees it, and the rights Singapore’s Personal Data Protection Act (PDPA) gives you.

About this policy & who we are#

VCare is built and operated by Vantrexis LLP, a limited liability partnership registered in Singapore. When this policy says “we”, “us” or “VCare”, it means Vantrexis LLP. It covers the VCare patient app, the VCare clinic dashboard, and this website (vcare.sg).

Our Data Protection Officer (DPO), the person accountable for how we handle personal data as the PDPA requires, is Sol Davis. You can reach the DPO at admin@app-vantrexis.com or +65 8837 8515. Please put “Data protection” in the email subject line so your message reaches the right person quickly.

This policy is deliberately written to be read. Each section starts with the plain point, then gives you the detail. If anything is unclear, ask us, a human will reply.

Definitions#

A few terms this policy uses precisely:

  • Personal data, any data about you from which you can be identified, on its own or combined with other data we have access to. Your name, mobile number and queue entry are all personal data.
  • Patient data, the data handled to deliver your care through a clinic: bookings, queue entries and, when those features launch, clinical data such as records and prescriptions. Your clinic controls this data.
  • Account data, the data we hold for our own purposes: your VCare login, app settings, notification tokens, product analytics and website enquiries. We control this data.
  • Clinic, the MOH-licensed healthcare provider you book with through VCare. Your care relationship is with the clinic, not with us.
  • PDPA, Singapore’s Personal Data Protection Act 2012, the law that governs how organisations here handle personal data.
  • Organisation and data intermediary, the PDPA’s two roles for a company handling data. An organisation decides why and how data is used; a data intermediary processes it on another organisation’s behalf under a written contract. We act in both roles, section 3 explains which applies to what.
  • De-identified, stripped of everything that links the data to you, so what remains is anonymous statistics (for example, “average wait was 24 minutes”).

Our two roles under the PDPA#

Under the PDPA we wear two hats, and it matters which hat applies to which data, because it determines who is responsible, and whom you complain to.

  • For patient data, we are your clinic’s data intermediary. Your bookings, queue entries and (later) clinical data are processed on your clinic’s behalf, under a written data-processing agreement signed with each clinic, and only for that clinic’s purposes. Concretely: your clinic decides what happens to this data; we run the systems that make it happen. A clinic can never see another clinic’s patients through VCare.
  • For account data, we are the organisation in our own right, for your VCare login, app settings, notification tokens, de-identified product analytics, and enquiries sent through this website, the full set of PDPA obligations sits with Vantrexis LLP directly.

What this means for you in practice:

  • Questions or complaints about your appointment history, queue records or health data are ultimately decided by your clinic, it is the organisation responsible for that data. Send them to us anyway if that is easier: we will route the request to your clinic and give them the tools to answer it.
  • Questions or complaints about your VCare account, this website or our analytics come straight to us, contact our DPO (section 1) and we answer for it ourselves.

The data we collect#

Today VCare does two things, appointment booking and live queue tracking, and we collect only what those need. Here is the full inventory:

CategoryExamplesWhere it comes fromWhy we use itHow long
Identity & contactName, mobile number, email addressYou, when you create an account or make a bookingSo your clinic knows who the booking is for, and so we can send confirmations and queue updatesLife of your account + 30 days
Appointments & queueClinic visited, appointment date and time, queue number and status, the general visit reason if you choose to give oneYou in the app; your clinic’s dashboardTo run your booking and your place in the queueDe-identified 30 days after your visit
Account & deviceLogin credentials, app settings, push-notification tokenYou and your deviceTo operate your account and deliver notificationsLife of your account + 30 days
Sign-in optionsIf you sign in with Google: your name and email address, received from Google. If you verify with Singpass Myinfo: the profile fields listed on the Singpass consent screen, such as name, NRIC (stored encrypted, shown only masked), date of birth and contact detailsGoogle or Singpass, only when you choose that route and consent on their screenTo create and secure your account without you typing the details yourselfLife of your account + 30 days
Enquiries & demo requestsName, clinic name, contact details, your messageThe enquiry form on this website, or emailTo answer your enquiry and arrange demos12 months
Support requestsMessages to our support team and the details needed to resolve the issueYouTo fix your problem and improve the serviceLife of your account + 30 days
Technical & audit logsIP address, device and browser information, records of who accessed what dataGenerated automatically when VCare is usedSecurity, troubleshooting, and the accountability trail healthcare regulation expectsAudit logs 6 years; routine technical logs far shorter

Sign-in works one way only: Google and Singpass tell us who you are, and we tell them nothing back. Neither provider learns which clinics you visit, what you book, or anything else about your health.

Live since July 2026: your clinic can file documents on your record, such as lab reports, prescriptions, visit summaries, medical certificates, referral letters and invoices, and you can open them in the app. They are stored encrypted, every upload and download is logged, and they are retained for as long as the law requires your clinic to keep medical records.

Coming later, not part of VCare today: structured clinical data such as lab values with reference ranges, immunisation records and QR-verifiable certificates we issue ourselves. When they launch, the categories of data we handle will expand, we will update this policy and notify you before that happens, not after.

Why we use your data#

We collect, use and disclose personal data only for these purposes:

  • Delivering the service, creating and managing your bookings and your place in the clinic queue.
  • Service messages, booking confirmations, queue updates and appointment reminders. These are operational messages, never advertising, and lock-screen previews never contain health details.
  • Running your account, sign-in, settings, and responding to your support requests.
  • Keeping the service secure, detecting misuse and fraud, and maintaining audit records of who accessed what.
  • Improving VCare, using aggregated, de-identified statistics (such as average waiting times) that cannot identify you.
  • Meeting our legal obligations under Singapore law, including responding to lawful requests from authorities.

That list is exhaustive. If we ever want to use your data for a new purpose, we will tell you first and ask for your consent where the law requires it. We do not use your data for advertising, and we do not build marketing profiles from patient data.

When you book an appointment or join a queue, the PDPA treats you as consenting to the data handling that delivering that visit reasonably requires, the law calls this deemed consent. For anything beyond running your care and your account, we ask separately, and saying no never blocks you from using the core service.

You can withdraw consent at any time. Here is how it works:

  • How to withdraw, use the controls in the app (for example, turning off notifications or deleting your account), or email our DPO at admin@app-vantrexis.com with “Withdraw consent” in the subject line. No form, no fee.
  • What happens then, we first explain the practical consequences, so you can decide with full information. For example: without your contact details we cannot send queue updates; withdrawing consent for bookings means closing your VCare account. If you confirm, we stop the collection, use and disclosure you have withdrawn from within a reasonable time, and in any case within 30 days.
  • What withdrawal cannot undo, data we are legally required to keep (such as audit logs, or medical records your clinic must retain under MOH rules) stays for its statutory period, but is no longer used for anything else.

How long we keep data#

The PDPA requires us to stop keeping personal data once it no longer serves a legal or business purpose. This is our retention schedule:

DataKept forThen
Queue entries30 days after your visitDe-identified, only anonymous statistics remain (visit counts, waiting times), with nothing linking back to you
Account dataLifetime of your account + 30 daysDeleted or de-identified
Enquiry-form data12 monthsDeleted
Audit logs6 yearsDeleted
Medical records (future clinical features)Patient’s lifetime + 6 years, as MOH requires of clinicsHandled per your clinic’s statutory duties, this row applies only once clinical features launch

Anything with no legal or service reason to exist, stale notification tokens, expired queue data, dormant records, is purged automatically, not kept “just in case”.

How we protect your data#

The security measures protecting your data today:

  • Encryption everywhere, data is encrypted in transit and at rest.
  • Multi-factor authentication, clinic staff and our own team sign in with MFA.
  • Least-privilege access, every role, ours and the clinic’s, sees only the data it needs to do its job; front-desk roles never see clinical data.
  • Append-only audit logs, every access to patient data is recorded in logs that cannot be edited or deleted, so there is always an accountable trail.
  • Singapore-only hosting, VCare runs on AWS in the Singapore region. Your data does not leave Singapore (see section 10).

To be straight with you about certifications: we hold none yet, and we do not claim any. When VCare is certified against a recognised standard, we will say so here, and not before.

No system is unbreachable, so we also prepare for the worst: if a data breach ever puts you at risk of significant harm, we will notify the affected clinics without undue delay, support their notification to the Personal Data Protection Commission, and notify the PDPC ourselves for data we control.

Who we share data with#

We never sell personal data. Not to advertisers, not to data brokers, not to anyone, and not in any form. Data is disclosed only to:

  • The clinic you visit, your booking and queue details go to the clinic you chose, because they are the point. Other clinics on VCare cannot see them.
  • IT service providers under written contract, the companies that help us run VCare, principally AWS (cloud hosting and email delivery, Singapore region). If we add SMS delivery in future, its provider would be listed here too. Each is bound by contract to protect your data, use it only on our instructions, and never for its own purposes.
  • Authorities, when the law requires it, for example under a court order or a statutory demand from a Singapore regulator. We disclose the minimum required, and we verify every request before acting on it.

That is the whole list. No advertising partners, no data-sharing “affiliates”, no exceptions we have not written down here.

Overseas transfers#

None. VCare is hosted on AWS in the Singapore region, and personal data is stored and processed in Singapore only. We do not transfer your personal data outside Singapore.

If that ever changes, the PDPA requires the receiving country arrangement to protect your data to a standard comparable to Singapore’s, and we would update this policy, name the destinations and safeguards, and notify you before any transfer begins.

Your PDPA rights#

The PDPA gives you rights over your personal data. Here is each one, how to use it, and how fast we respond:

  • Access, ask what personal data we hold about you and how it has been used or disclosed in the past year. Email admin@app-vantrexis.com with “Access request” in the subject. We respond within 30 days; if we ever need longer, we will tell you within those 30 days and give you the date to expect.
  • Correction, ask us to fix data that is inaccurate or out of date. Email with “Correction request”, or simply edit your details in the app. We correct as soon as practicable, and within 30 days.
  • Withdrawal of consent, at any time, as described in section 6.
  • Portability, the PDPA’s data-portability provisions have been enacted but are not yet in force. When they take effect (or sooner, when we ship data export), you will be able to take a machine-readable copy of your data to another provider. Until then, ask us for an export and we will do our reasonable best.

Two practical notes. First, we will verify your identity before releasing data, that protects you. Second, where your request concerns data your clinic controls (such as your appointment history), the clinic decides it under the PDPA: we route the request to them, give them the tooling to answer, and stay on it until you get a response.

Children & family profiles#

Children under 13 cannot hold their own VCare account: a parent or guardian creates and manages their profile and consents on their behalf. Teens aged 13-17 may consent for themselves, and this policy is written so they can genuinely understand it.

One more rule worth knowing: an account holder can consent for their young child, but never for another adult. Adult family members must agree to VCare themselves, if you add a parent or spouse to your family group, they will be asked for their own consent.

Cookies & analytics#

We keep this deliberately boring:

  • Session cookies only, the cookies we set keep you signed in and remember your preferences during your visit. No persistent tracking identifiers.
  • No cross-site tracking, nothing we set follows you around the web.
  • No advertising pixels, no ad networks, no Facebook pixel, no Google advertising tags. None.
  • Simple aggregate analytics, we count which parts of VCare are used so we know what to improve, using de-identified statistics that cannot be traced back to you.

Because we use no non-essential cookies, we do not need to show you a cookie banner, and we would rather earn that than nag you.

The website enquiry form#

If you contact us through this website, an enquiry, a demo request, a clinic sign-up, we collect what you type: your name, clinic name, contact details and message. We use it for exactly one thing: responding to you.

  • Enquiry data is kept for 12 months, then deleted.
  • It is never added to a marketing list. If we ever offer a newsletter, it will be a separate, explicit opt-in.
  • Please do not include health information in the enquiry form, it is a business contact channel, not a medical one. If you do, we delete it from our records.

The launch notification list#

If you ask us to tell you when the VCare patient app is released, we store your email address and nothing else, along with the date you ticked the consent box. We do not ask for your name, and we never add an address to this list from an enquiry, a booking or any other part of VCare. The only way onto it is the sign-up form on our home page.

  • We use it for one message: telling you the app is available. It is not a newsletter and we do not sell, rent or share the list.
  • Every message carries an unsubscribe link that works immediately, with no login and no questions. You can also email admin@app-vantrexis.com and we will remove you by hand.
  • After you unsubscribe we keep a record that consent was withdrawn, and when, so we can prove we honoured it. That record holds no marketing value and is used for nothing else.
  • We delete the list once the launch message has gone out, or 24 months after you signed up, whichever comes first.

Changes to this policy#

When we update this policy, we post the new version here with a new “Last updated” date. For material changes, anything that expands what we collect or how we use it, such as the launch of clinical features, we notify you in the app or by email before the change takes effect, with enough time to read it and ask questions. We keep prior versions available on request, so you can always see what changed.

Complaints & the PDPC#

If you think we have mishandled your personal data, please tell us first, most issues are fixed fastest at the source. Email our DPO at admin@app-vantrexis.com with “Complaint” in the subject line. We acknowledge complaints promptly and aim to resolve them within 30 days.

If the complaint concerns data your clinic controls (appointments, queue history, health data), the clinic is the responsible organisation, we will route your complaint to its DPO and help both sides reach an answer.

And if you are not satisfied with how either of us responds, you have the right to complain to Singapore’s data protection regulator, the Personal Data Protection Commission (PDPC), at www.pdpc.gov.sg. You do not need our permission to do so, and it costs nothing.

Not sure about something? Contact us at admin@app-vantrexis.com, a human will reply.