Repocket Privacy Policy
Last updated: 3 July 2026
Version: 2.0
This Privacy Policy explains how REPOCKET PTE. LTD. (“Repocket,” “we,” “us,” or “our”) collects, uses, processes, discloses, and protects personal information in connection with the Repocket software, bandwidth sharing functionality, and related websites (collectively, the “Services”).
This Privacy Policy applies to Repocket desktop applications (including Windows and macOS), Repocket mobile applications (including iOS and Android), and any associated websites operated under Repocket brand. This Privacy Policy forms part of and should be read together with the Repocket Terms of Service (“Terms”). By installing, accessing, or using the Services, you acknowledge that your personal information will be processed as described in this Privacy Policy.
For the purposes of applicable data protection laws, REPOCKET PTE. LTD. (with address at 60 Paya Lebar Road, #11-03 Paya Lebar Square, Singapore 409051) is the data controller responsible for the processing of personal information described in this Privacy Policy. Our email is [email protected]
We may update this Privacy Policy from time to time to reflect changes to the Services, our practices, legal requirements, or platform requirements. The “Last Updated” date at the top of this Privacy Policy indicates when it was most recently revised. If we make material changes, we will take reasonable steps to provide notice, such as by posting an updated version on our website or providing notice within the Services. Your continued use of the Services after an updated Privacy Policy becomes effective constitutes your acceptance of the updated Policy.
If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have concerns about how your information is handled, you may contact us using the details above.
1. INFORMATION WE COLLECT
1.1. Information we collect. We collect personal information and related technical data only to the extent necessary to provide, secure, and improve the Services. The categories of information we collect are described below.
| Category of Information | What We Collect | Purpose of Collection |
|---|---|---|
| Information You Provide | Email address; hashed account password; support communications (including attachments); optional profile details (if provided) | Account creation and management; authentication; user support; service communications |
| Account and Consent Records | Terms acceptance records; Bandwidth Sharing acceptance records; timestamps of consent; IP address at time of consent; app version, device type, or platform at acceptance | Demonstrate contractual acceptance; maintain compliance records; legal defense; security auditing |
| Bandwidth Sharing Data | External IP participation in proxy network; routing-related metadata; abuse prevention logs; network integrity monitoring data | Operate managed proxy network; allocate routing; monitor misuse; ensure compliance and security |
| Technical and Device Data | Operating system version; device model name; app version; hashed MAC-derived identifier (on supported non-mobile environments only); session identifiers; login timestamps; country or region inferred from IP address | Service operation; Compatibility and troubleshooting; fraud prevention and device integrity; abuse detection; regional service delivery and compliance. |
| Security and Abuse Logs | IP addresses associated with account activity; device identifiers linked to enforcement events; abuse detection signals; investigation and enforcement records; evidence preservation logs. | Prevent fraud, abuse, cyberattacks, and policy violations; support investigations; respond to lawful requests; enforce the Terms of Service |
| Analytics and Diagnostic Data | Usage patterns and feature interaction data; performance metrics; error and crash reports; bandwidth contribution statistics. | Analyse usage patterns; improve features and performance; troubleshoot errors; optimise service delivery. |
1.2 Processing Overview. We process personal information only where necessary to provide the Services, maintain security, comply with legal obligations, and operate the bandwidth sharing model described in this Privacy Policy. The table below summarizes the categories of personal information we process, the purposes for which we process them, and the applicable legal bases:
| Category of Data | Purpose of Processing | Legal Basis (EEA/UK) |
|---|---|---|
| Account Information (email, credentials) | Create and manage user accounts; authenticate access; provide customer support | Performance of contract |
| Payment and Payout Data | Payout method details (e.g., wallet address or payment destination); transaction records; payout request history; withdrawal threshold status. | Process payouts; prevent payment fraud; comply with financial and tax obligations; maintain transaction records. |
| Consent Records | Maintain evidence of acceptance of the Terms and Bandwidth Sharing participation | Legal obligation; Legitimate interests (compliance and legal defense) |
| Bandwidth Sharing Data | Operate and manage proxy network participation; allocate routing; monitor integrity | Performance of contract; Legitimate interests (network operation and security) |
| Technical and Diagnostic Data | Troubleshoot errors; improve performance; detect misuse | Legitimate interests |
| Security and Abuse Logs | Prevent fraud, abuse, cyberattacks, and policy violations | Legitimate interests; Legal obligation (where applicable) |
| Analytics Data | Analyze usage patterns; improve features; optimize performance | Legitimate interests |
| Legal Request Data | Records of lawful requests received from governmental authorities, courts, or regulators; information disclosed in response to such requests. | Respond to lawful requests and regulatory requirements; comply with applicable law. |
1.3. Identifiers We Do Not Collect. We do not collect full device fingerprints, container identifiers, hardware serial numbers, or raw MAC addresses. On certain supported non-mobile environments, we may process a hashed MAC-derived identifier as described in Section 1.1 for fraud prevention and device integrity purposes. This identifier is derived using a one-way hash and cannot be used to reconstruct the original MAC address. We do not collect raw MAC addresses on mobile applications.
1.4. Children's Data. We do not knowingly collect personal information from individuals who are under sixteen (16) years of age or below the age of legal majority in their jurisdiction, whichever is higher. If we become aware that personal information has been collected from a user who does not meet the applicable age requirement, we will take reasonable steps to delete such information and terminate the associated account, unless retention is required for legal purposes. If you believe that a minor has provided personal information in violation of this Policy, you may contact us at [email protected]. Parents or legal guardians who believe that their child has submitted personal information to us without authorisation may request that we delete such information.
1.5. Sensitive personal information. We do not intentionally collect or process sensitive personal information as defined under applicable data protection laws, such as health data, biometric data, racial or ethnic origin, political opinions, religious beliefs, or sexual orientation. The Services are not designed to collect such information, and we request that you do not submit sensitive personal information to us.
2. BANDWIDTH SHARING DISCLOSURE
2.1 Nature of Traffic. The Services include participation in bandwidth sharing, as further described in the Bandwidth Sharing Policy. Where bandwidth sharing is active, your device's external IP address may be used as part of a managed proxy network operated through Repocket infrastructure. In this context, your IP address functions as a routing endpoint for authorised third-party network requests. As a result, certain third-party internet traffic may egress from, and may appear to originate from, your external IP address. Third-party traffic routed through the proxy network is limited to controlled and monitored commercial use cases, such as web data collection, ad verification, price monitoring, and similar commercial research activities; is subject to technical allocation and filtering controls; and does not provide third parties with access to your device, local files, local network resources, localhost services, browser state, accounts, or applications. Bandwidth sharing does not allow remote control of your device.
2.2 Safeguards. We implement technical safeguards designed to reduce misuse of the proxy network, including:
- Automated detection systems;
- Maintained blocklists and destination restrictions;
- Traffic monitoring for abuse prevention;
- Response procedures for valid abuse reports.
We may block, suspend, or restrict traffic categories or destinations to comply with legal, security, or platform requirements. Repocket does not inject, alter, redirect, or manipulate traffic generated by third-party applications installed on your device for advertising or monetization purposes.
3. HOW WE SHARE INFORMATION
3.1 Categories of Recipients. We may share personal information with the following categories of recipients where necessary to operate the Services:
- Service providers that assist with fraud detection, abuse prevention, security monitoring, and compliance management.
- Affiliated entities within the Repocket corporate group, where necessary for operational, security, or administrative purposes.
- Governmental authorities, courts, regulators, or law enforcement agencies where disclosure is required by applicable law or lawful process.
All third-party service providers are required to process personal information only for authorized purposes and in accordance with applicable data protection laws.
We may also share personal information in connection with a merger, acquisition, restructuring, financing transaction, or sale of assets, personal information may be disclosed to relevant parties, subject to appropriate confidentiality safeguards.
3.2 Explicit Disclosures. We do not sell or share personal information, including within the meaning of the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), for cross-context behavioural advertising purposes. We do not access, monitor, or share your personal browsing activity on third-party websites or applications. In connection with the operation of the proxy network, we may process routing metadata, including destination-level information such as domain categories, for the purposes of abuse prevention, blocklist enforcement, and network integrity as described in Section 2.
3.3 International Transfers. Personal information may be processed in Singapore and in other jurisdictions where our service providers or infrastructure partners are located. Where personal information is transferred across international borders, we implement appropriate safeguards consistent with applicable data protection laws. Such safeguards may include:
- Contractual data protection clauses (including standard contractual clauses, where applicable);
- Data processing agreements with service providers;
- Technical and organizational measures designed to protect personal information during transfer and processing.
Our Services rely on cloud-based infrastructure and distributed network systems, which may involve processing in multiple regions. We take reasonable steps to ensure that personal information remains protected in accordance with this Privacy Policy regardless of where it is processed.
4. DATA RETENTION
We retain personal information only for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, enforce our agreements, and maintain security. Retention periods vary depending on the type of information and the purpose for which it was collected. In general:
- Account information is retained while your account is active and for a reasonable period thereafter for administrative, legal, and security purposes.
- Consent records may be retained as necessary to demonstrate compliance with legal and contractual requirements.
- Security, abuse prevention, and technical logs are retained for limited periods appropriate to operational and security needs.
- Aggregated or anonymized information that does not identify you may be retained for longer periods for analytics and service improvement.
When personal information is no longer required for the purposes described in this Privacy Policy, we will delete it or anonymise it in accordance with applicable law. Where an account is dormant for twelve (12) consecutive months, we may close the account and treat remaining data in accordance with this Section and the Payment and Rewards Policy.
5. DATA SECURITY
We implement reasonable technical and organizational measures designed to protect personal information against unauthorized access, disclosure, alteration, misuse, or destruction. These measures include encryption of data in transit where appropriate, role-based access controls, internal confidentiality obligations, system monitoring to detect abuse or unauthorized activity, and established incident response procedures. Access to personal information is limited to authorized personnel and service providers who require such access for legitimate operational purposes. While we take appropriate steps to safeguard personal information, no method of transmission over the internet or electronic storage system can be guaranteed to be completely secure. Accordingly, we cannot guarantee absolute security.
If we become aware of a security incident that may affect personal information, we will take appropriate action in accordance with applicable data protection laws.
6. RIGHTS FOR EEA / UK USERS
If you are located in the European Economic Area (“EEA”) or the United Kingdom (“UK”), you may have certain rights under applicable data protection laws, including the General Data Protection Regulation (“GDPR”) and the UK GDPR. These rights may include the following:
Right of Access. You have the right to request confirmation as to whether we process personal information about you and, where we do, to request access to that information together with details about how it is used.
Right to Rectification. You have the right to request correction of inaccurate personal information and to have incomplete personal information completed.
Right to Erasure. You have the right to request deletion of your personal information in certain circumstances, including where the information is no longer necessary for the purposes for which it was collected, or where processing is based on consent and you withdraw that consent.
Right to Restriction of Processing. You have the right to request that we restrict the processing of your personal information in certain situations, such as where you contest the accuracy of the data or object to processing.
Right to Object. You have the right to object to processing based on our legitimate interests where your particular situation gives rise to such objection. You also have the right to object to processing for direct marketing purposes (although we do not use traffic for direct marketing).
Right to Data Portability. Where processing is based on contract or consent and carried out by automated means, you may have the right to receive certain personal information in a structured, commonly used, and machine-readable format and to request its transfer to another controller where technically feasible.
Right to Withdraw Consent. Where we rely on your consent as the legal basis for processing, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
Right to Lodge a Complaint. You have the right to lodge a complaint with a supervisory authority in the EEA or the UK if you believe that our processing of your personal information violates applicable data protection laws.
To exercise any of these rights, you may contact us using the contact details provided in this Privacy Policy. We may request information necessary to verify your identity before responding to your request. We will respond to valid requests without undue delay and, in any event, within one month, unless a longer period is permitted by applicable law.
7. RIGHTS UNDER SINGAPORE LAW
If you are located in Singapore, you may have certain rights under the Personal Data Protection Act 2012 (PDPA). These rights include the following:
Right of Access. You have the right to request access to your personal data that is in our possession or under our control, and to be informed of how such data has been or may have been used or disclosed within the year preceding your request.
Right to Correction. You have the right to request correction of any error or omission in your personal data that is in our possession or under our control.
Right to Withdraw Consent. You have the right to withdraw your consent for the collection, use, or disclosure of your personal data at any time. We will process your withdrawal request within a reasonable time and will inform you of the likely consequences of doing so. If you withdraw consent to bandwidth sharing, you may no longer be able to use the Services, as bandwidth sharing is a core function of the product. Withdrawal of consent does not affect any collection, use, or disclosure carried out before withdrawal, and we may continue to process personal data where permitted or required by law.
To exercise any of these rights, you may contact our Data Protection Officer at [email protected]. We may request information necessary to verify your identity before responding to your request. We will respond to valid requests within thirty (30) days, unless an extension is permitted by applicable law. We may charge a reasonable fee for access requests as permitted under the PDPA. If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commission (PDPC) of Singapore.
8. PLATFORM DISCLOSURES
Repocket is distributed through various platforms, including desktop operating systems and mobile application stores. Certain permissions and technical functionalities are required to provide bandwidth sharing. Depending on the platform and device settings, the application may operate in the background to maintain bandwidth sharing functionality. Background behavior may vary depending on operating system restrictions, platform policies, and user-configurable settings.
Behaviour of bandwidth sharing functionality, may differ depending on the device type, operating system, or distribution channel. Some app store versions may limit or restrict certain background or network capabilities in accordance with platform requirements. We design and operate the Services in a manner intended to comply with applicable platform policies and technical requirements.
9. COOKIES AND SIMILAR TECHNOLOGIES
Our website at repocket.com may use cookies and similar technologies to operate the site, maintain session state, and analyse usage. Cookies used on our website fall into the following categories:
Strictly necessary cookies are required for the website to function and cannot be disabled. These include session cookies and authentication cookies.
Analytics cookies collect aggregated, anonymised information about how visitors use the website, such as pages visited and time spent on the site. These cookies help us improve website performance and user experience.
We do not use profiling cookies or cookies for cross-context behavioural advertising. You can manage or disable cookies through your browser settings. Disabling certain cookies may affect the functionality of the website.