Privacy Policy

Effective 1 August 2026

This Privacy Policy explains how STINKY BOY PTE LTD, a company incorporated in Singapore with UEN 202634918C (“OpenLocum”, “we”, “us” or “our”), collects, uses, discloses and protects personal data in connection with openlocum.sg and the services we make available through it (collectively, the “Service”).

1. Who this Policy covers

This Policy covers visitors, account holders, doctors, people who contact us and individuals whose information appears in job listings or other source material that we collect. It applies whether information is provided directly, collected automatically or obtained from a third party or public source.

2. Personal data we collect

Depending on how you interact with the Service, we may collect:

  • Account and identity data, such as your email address, account identifier, authentication provider information, name, mobile number, profile image and session information. If you use Singpass, we receive your Singpass-issued subject identifier and the profile fields you consent to share, currently your principal name, mobile number and email address.
  • Professional profile data, such as your full name, MCR number, registration-related information and other credentials or professional details you choose to provide through future features.
  • Job and work activity, such as saved shifts, application-link interactions and channels, clinic follows, recently viewed clinics, dates and advertised rates.
  • Preferences and location, such as notification choices, search preferences, onboarding settings, map position and location information when you choose to enable a location feature.
  • Content and communications, such as reviews, would-return responses, EMR information, free-text entries, support messages, feedback and other material you submit.
  • Technical and usage data, such as IP address, browser and device information, page and feature activity, referring page, timestamps, cookie or analytics identifiers, error information and security logs.
  • Third-party and source data, such as Telegram message content, channel and sender information, names, usernames, phone numbers, application links, job contacts and clinic information obtained from Telegram, clinics, recruiters, public directories, maps or similar sources.
  • Future feature data, such as availability, job preferences, application materials, communications and payment or billing details if you choose to use a feature that requires them.

3. How we collect personal data

We collect personal data:

  • directly from you when you create a profile, use a feature or contact us;
  • automatically through cookies, logs, analytics and similar technology;
  • from authentication, mapping, communications and other services you use;
  • from Singpass when you choose to verify your profile with it;
  • from clinics, recruiters and other users; and
  • from Telegram channels, public directories and other third-party sources.

4. How we use personal data

We may use personal data where reasonably necessary to:

  • provide, administer and secure the Service and user accounts;
  • display, organise, search, save and track job and clinic information;
  • personalise search results, alerts, settings and the presentation of the Service;
  • prepare user-directed application messages and facilitate communications that you choose to initiate;
  • maintain professional profiles, private work records and review features;
  • provide support, respond to requests and communicate about the Service;
  • detect, investigate and prevent fraud, abuse, security incidents and technical issues;
  • measure use, troubleshoot, conduct research and analytics, and develop, test and improve the Service and reasonably related features;
  • moderate content, correct listings and handle rights or removal requests;
  • enforce our terms, establish or defend claims and comply with law; and
  • evaluate or complete a financing, reorganisation, sale or transfer of all or part of our business, subject to appropriate safeguards.

We may send service messages required to operate or secure your account. We will use personal data for optional marketing only where permitted and with the choices required by applicable law.

5. New features and new purposes

We may introduce features that collect additional categories of personal data. Before collecting that data, we will describe the relevant data and purposes in this Policy or through a notice presented with the feature and, where required, ask for consent.

We will not rely on general wording in this Policy as consent to a materially different purpose where fresh consent is required by law. If we use existing data for a new purpose that is not reasonably related to the purposes described above, we will provide additional notice and obtain consent where required.

6. When we disclose personal data

We may disclose personal data to:

  • clinics, recruiters, job contacts and third-party services when you ask us to prepare or facilitate a communication;
  • suppliers that provide authentication, hosting, databases, email delivery, analytics, error monitoring, customer support, workflow automation, artificial intelligence, maps and infrastructure;
  • professional advisers, auditors and insurers where reasonably necessary;
  • authorities or other parties where required or permitted by law;
  • a prospective buyer, investor or successor in connection with a financing, reorganisation, sale or transfer, subject to appropriate confidentiality; and
  • the public where you deliberately submit content for public display.

Current suppliers include Supabase, Vercel, Resend, PostHog, Ahrefs, Upstash, OpenAI, Google, Mapbox and Telegram. Singpass is an optional identity-verification service. Each service receives information relevant to the function it provides; this does not mean that every supplier receives every category of personal data. We may replace a supplier with another serving a similar function and will update this Policy where a change materially affects how personal data is handled.

We do not sell personal data or use it for third-party targeted advertising. If this practice changes, we will provide advance notice and obtain consent where required.

7. User-directed applications and links

When you choose to apply through WhatsApp, Telegram, SMS or another service, we may prepare a message containing your name, MCR number, contact email, mobile number and shift details. You can review and edit the message before sending it. The recipient and third-party service will handle the information under their own terms and privacy practices.

Similarly, if you choose to add a shift to an external calendar or open an external application or map link, the relevant provider may receive the information necessary to complete that action as well as technical information about your visit.

8. Reviews and aggregation

Review data intended for clinic-level insights may be stored separately without a direct account identifier. We may also keep a copy in your private shift history. Because records can sometimes be associated using their contents, shift and timing, we do not promise that a review is irreversibly anonymous in every circumstance.

We may create and retain aggregated or de-identified information that no longer reasonably identifies an individual. We use such information for statistics, research, service improvement and clinic insights.

9. Listing contacts and public-source data

Job posts may contain the personal or business contact information of a poster, recruiter or clinic representative. We use this information to attribute, verify, structure and display listings, provide application methods, maintain provenance, detect abuse and resolve disputes.

If a listing contains your information and you want it corrected or removed, contact our Data Protection Officer. We will assess the source, current availability of the information, the listing’s status, the interests of users and our legal obligations.

10. Cookies and analytics

We use essential cookies and similar storage to authenticate users, maintain sessions, preserve security and remember requested settings. Blocking these technologies may prevent account or other core features from working.

We also use PostHog for product analytics, error monitoring and support, and Ahrefs for web traffic analytics. Depending on our configuration, this may involve an analytics identifier, account identifier, email, page and feature activity, device or browser information, approximate location, IP address and error details. You can block or delete cookies through your browser and may contact us to withdraw consent where consent applies.

11. Overseas processing

Some suppliers and recipients process personal data outside Singapore, including in locations where they or their subprocessors operate. Where the Singapore Personal Data Protection Act 2012 applies, we take steps intended to ensure that transferred personal data receives a standard of protection comparable to that required in Singapore, such as contractual protections and supplier due diligence.

12. Retention

We retain personal data while it is reasonably needed for the purposes described in this Policy or for legitimate legal or business purposes. The period depends on factors including the duration of your account, the nature and sensitivity of the data, listing provenance, safety and fraud prevention, support needs, disputes, applicable limitation periods, legal obligations and backup cycles.

When personal data is no longer reasonably needed, we will delete it, anonymise it or remove the means by which it can be associated with an individual. Deletion from active systems may not immediately remove data from backups or records that must be retained for a lawful purpose.

13. Security

We use reasonable administrative, technical and organisational measures designed to protect personal data against unauthorised access, collection, use, disclosure, alteration, loss and similar risks. No service or transmission method is completely secure, and we cannot guarantee absolute security.

14. Your choices and requests

Subject to applicable law and relevant exceptions, you may:

  • ask for access to personal data we hold about you;
  • ask how we used or disclosed it during the preceding year;
  • ask us to correct inaccurate or incomplete personal data;
  • withdraw consent to collection, use or disclosure with reasonable notice;
  • ask us to delete data that is no longer reasonably required; and
  • unsubscribe from optional marketing communications.

We may need to verify your identity before acting on a request. Withdrawing consent or deleting information required for a feature may prevent us from continuing to provide that feature. We may charge a reasonable fee for an access request where permitted and will tell you the estimated fee in advance.

15. Children

The Service is intended for adults and is not directed to people under 18. If you believe a person under 18 has provided personal data to us, contact our Data Protection Officer so we can review and, where appropriate, remove it.

16. Changes to this Policy

We may update this Policy to reflect changes to the Service, our practices or the law. We will post the updated version and revise the effective date. We will provide reasonable notice of material changes and obtain fresh consent where required.

17. Data Protection Officer

For questions, complaints, withdrawal of consent, access or correction requests, or a request concerning personal data in a listing, contact:

Data Protection Officer
STINKY BOY PTE LTD
UEN 202634918C
Support page

Please describe your request and the information or account concerned. We aim to respond within 30 calendar days. If we need more time, we will tell you within that period when we expect to respond.