Legal

Privacy Policy

Updated: 13 September 2026

Effective date: 13 September 2026

Status: Published

This Privacy Policy explains how TABBDOC AIRCRAFT PTE. LTD., trading as TabAir, collects, uses, discloses, transfers and retains personal data when you use https://www.tabairtrade.com and related marketplace services. TabAir is the organisation responsible for this policy. The Data Protection Officer may be contacted at support@tabairtrade.com.

1. Scope and roles

  • This policy applies to visitors, Buyers, Sellers, Agents, staff and staff applicants, team members, representatives, beneficial owners, delivery contacts and other persons whose data is processed through TabAir.
  • For most platform administration, account, communications and security processing, TabAir determines the purposes and means of processing. Marketplace participants may separately be responsible for personal data they receive or submit for their own commercial purposes.

2. Personal data we collect

  • Account and identity data: name, email, telephone number, country, company, role, profile photograph, professional information, account status, authentication identifiers, login method and verification status.
  • Verification and compliance data: government identification, business registration, beneficial-ownership details, addresses, licences, sanctions-screening information, proof of authority, and records supplied to support product provenance or certification.
  • Marketplace data: listings, product information, photographs, serial and part numbers, certificates, enquiries, quotations, opportunities, saved items, reviews, messages, replies, reactions, edits, links, GIFs, attachments, transaction records and user actions.
  • Payment and fulfilment data: platform-fee records, payment status and evidence, seller payment instructions shared in restricted Seller–Admin workflows, delivery addresses, pickup details, carrier and tracking data. TabAir does not intentionally display Seller banking details to Buyers or Agents.
  • Technical data: IP address, browser and device information, session and authentication data, cookies, access logs, security events, error reports and approximate location inferred from network information.
  • Notification and analytics data: communication preferences, browser-push subscriptions and delivery results, transactional-email delivery records, pages and features used, session events and aggregated usage measurements.
  • Workforce and administration data: staff role, permissions, assigned regions, attendance or shift records, tasks, internal team communications and operational activity where relevant to authorised personnel.
  • Support and correspondence data: communications with TabAir, complaints, requests, preferences and records required to resolve an issue.

3. How we collect data

  • We collect data directly from you, from your organisation or authorised representative, through your activity on the platform, from other transaction participants, from service providers, and from lawful public or commercial sources used for verification and compliance.

4. Purposes

  • We use personal data to create and secure accounts; support password or Google sign-in; verify identity, business status and eligibility; operate listings, saved items, reviews, enquiries, opportunities, communications, attachments, notifications, transactions and shipping workflows; process platform fees and paid plans; administer authorised staff operations; prevent fraud and misuse; enforce agreements; meet legal, tax, audit, sanctions and export-control duties; provide support; maintain records; measure and improve performance; and establish, exercise or defend legal claims.
  • We may send service messages by in-platform notification, email or browser push about account security, verification, listings, enquiries, messages, transactions, payments, shipping, disputes, staff assignments and policy changes. These are operational communications, not optional marketing, although device-level push permission may be withdrawn in the browser.
  • We will use consent where required, including for non-essential cookies or direct marketing. You may withdraw consent prospectively, but this does not affect prior lawful processing or processing based on another lawful ground.

5. Legal grounds and consent

  • Depending on the jurisdiction and context, processing may be necessary to perform or prepare a contract, comply with law, pursue legitimate interests such as marketplace security and fraud prevention, protect vital interests, establish legal claims, or be based on consent.
  • Under Singapore’s Personal Data Protection Act, we will notify individuals of relevant purposes, obtain consent where required, allow withdrawal subject to legal and contractual consequences, and rely on statutory exceptions where applicable.

6. Disclosure

  • We disclose data only as reasonably necessary to: the relevant marketplace participant through the role-separated workflow; authorised TabAir personnel and contractors; identity, compliance, authentication, payment, email, hosting, database, monitoring, analytics, storage, messaging and support providers; carriers and logistics providers where instructed; professional advisers, insurers, auditors, regulators, courts and law-enforcement bodies; and a buyer or successor in a corporate transaction subject to appropriate safeguards.
  • Buyers do not receive unrestricted access to Seller or Agent communications. Sellers and Agents do not receive unrestricted access to Buyer communications. Information is relayed or displayed according to the applicable workflow, permissions and transaction need.
  • We do not sell personal data. We do not disclose private Seller banking details to a Buyer merely because the Buyer is involved in the transaction.

7. Service providers and international transfers

  • Current infrastructure may include Supabase for authentication, database, storage and realtime services; Vercel for hosting and delivery; Resend for transactional email; Sentry for error and performance monitoring; Google for optional sign-in and consent-based analytics; Giphy for user-selected GIF search and delivery; Upstash for server-side rate limiting, queues or scheduled operations; browser push services operated by browser or device providers; and Stripe or Razorpay for applicable platform-fee or paid-plan processing.
  • A user’s selection of a GIF or external link may cause the browser to contact the relevant third-party content host. Those providers may receive technical request data under their own privacy terms.
  • Data may be processed outside Singapore and your country. We use contractual, organisational and technical measures intended to provide protection comparable to applicable requirements. For transfers governed by the GDPR or UK GDPR, we will use an adequacy decision or recognised safeguards such as standard contractual clauses where required.

8. Security

  • We use role-based access, server-side authorisation, encryption in transit, restricted service credentials, audit and security logging, private workflows, backups and vendor controls proportionate to the data and risk. No system is completely secure, and users must protect credentials, devices and payment-verification channels.
  • If we become aware of a personal-data breach, we will assess it and notify affected individuals and authorities where required by applicable law.

9. Retention

  • We apply retention criteria based on the purpose, sensitivity, legal duties, fraud and security needs, transaction lifecycle and potential claims. Transaction, payment, tax, compliance and material marketplace records may be kept for up to seven years after the transaction or account relationship, or longer where law, an investigation or a claim requires.
  • Incomplete, rejected or abandoned applications and security or access records are retained only for a period reasonably justified by verification, re-application, fraud-prevention, audit and security needs. Operational delivery logs and analytics records are kept for proportionate periods and may be aggregated or de-identified.
  • Account deactivation, closure and permanent deletion are different operations. Deactivation or closure may block access while preserving the account and transaction history. A permanent-deletion request is assessed against legal, security, payment, dispute and record-retention requirements and may result in deletion, restriction or de-identification rather than immediate erasure of every record. We delete or anonymise data when retention is no longer justified.

10. Your choices and rights

  • Subject to applicable law, you may request access or correction and may also request deletion, restriction, portability, objection, withdrawal of consent, or information about how your data was used or disclosed. The precise rights and response periods vary by location and may be limited by legal, security, confidentiality and record-retention requirements.
  • To make a request, email support@tabairtrade.com with “Data Rights Request” in the subject. We may verify identity and authority before responding. You may complain to the Personal Data Protection Commission of Singapore or another competent supervisory authority.

11. Children

TabAir is not intended for anyone under 18. We do not knowingly permit minors to create accounts.

12. Automated decisions

TabAir may use rules, screening results and risk signals to flag activity for review. We do not intend to make decisions producing legal or similarly significant effects solely by automated means without appropriate safeguards where prohibited.

13. Third-party links

Third-party sites, carriers and payment providers have their own privacy practices. TabAir is not responsible for their independent processing.

14. Changes

We may update this policy. Material changes will be notified on the platform or by email and will state the revised effective date.

15. Contact and DPO

Data Protection Officer, TABBDOC AIRCRAFT PTE. LTD., 77 Jurong East Street 13, #09-01, Westmere, Singapore 609653. Email: support@tabairtrade.com.