Privacy Policy
Last updated: 23 March 2026
1. Introduction
Qanvast Pte. Ltd. ("Company", "we", "us") operates the Open Maison platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. We are committed to protecting your privacy in compliance with the Personal Data Protection Act 2012 (PDPA) of Singapore.
2. Information We Collect
2.1 Information You Provide
- Account information: Name, email address, phone number, studio name, role
- Business data: Lead details, project information, quotes, invoices, and client communications uploaded to the platform
- Payment information: Billing details processed through our third-party payment provider
- Communications: Messages sent through the platform's chat feature
2.2 Information Collected Automatically
- Usage data: Pages visited, features used, actions taken within the platform
- Device information: Browser type, operating system, IP address, device identifiers
- Cookies and similar technologies: See our Cookie Policy for details
2.3 Third-Party Data
- Gmail integration: When you connect your Gmail account for lead ingestion, we access email metadata and content from whitelisted sender domains only. OAuth tokens are encrypted with AES-256-GCM at rest.
- AI processing: Content you submit for AI analysis (quotes, images, floor plans) is processed by third-party AI providers under data processing agreements.
3. How We Use Your Information
We use collected information to:
- Provide, operate, and maintain the Service
- Process your transactions and manage your account
- Generate AI-powered insights, suggestions, and analyses
- Improve and personalise your experience
- Communicate with you about updates, security alerts, and support
- Detect, prevent, and address technical issues and security threats
- Comply with legal obligations
4. Data Sharing and Disclosure
We do not sell your personal data. We may share information with:
- Service providers: Third-party vendors who assist in operating the Service (hosting, AI processing, email delivery, payment processing)
- Within your studio: Team members within your studio workspace can access shared business data according to their role permissions
- Legal requirements: When required by law, regulation, or legal process
- Business transfers: In connection with a merger, acquisition, or sale of assets
5. Data Security
We implement industry-standard security measures to protect your data, including:
- HMAC-SHA256 signed session cookies
- AES-256-GCM encryption for sensitive credentials (e.g., OAuth tokens)
- Rate limiting on authentication endpoints
- HTTPS encryption for all data in transit
- Role-based access control within studio workspaces
While we strive to protect your information, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. Upon account deletion, we will delete or anonymise your personal data within 90 days, except where retention is required by law.
7. Your Rights
Under the PDPA and applicable data protection laws, you have the right to:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Withdrawal of consent: Withdraw consent for data processing (this may affect your ability to use certain features)
- Data portability: Request your data in a structured, machine-readable format
- Deletion: Request deletion of your personal data, subject to legal retention requirements
To exercise these rights, contact us at hello@openmaison.ai.
8. International Data Transfers
Your data may be processed in jurisdictions outside Singapore where our service providers operate. We ensure that adequate safeguards are in place through data processing agreements that comply with the PDPA's transfer limitation obligation.
9. Children's Privacy
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through a prominent notice on the Service. Your continued use after such notification constitutes acceptance.
11. Contact Us
For privacy-related enquiries or to exercise your data protection rights, contact our Data Protection Officer at hello@openmaison.ai.
Qanvast Pte. Ltd.
Singapore