Privacy Policy
Last updated: 15 January 2026
This Privacy Policy describes how Leyline Labs Pte Ltd, operating acgevents.sg ("we", "us", or "our") collects, uses, and protects your personal data in compliance with Singapore's Personal Data Protection Act 2012 (PDPA).
Quick Navigation
1. What Data We Collect
We collect personal data that you provide to us directly and automatically through your use of our services:
1.1 Information You Provide
- Account Information: Name, email address, username, and profile picture (via Google OAuth)
- Booth Profile Information: Business name, description, product categories, social media links, and uploaded media
- Event Applications: Application details, custom responses to event-specific questions
- Event Attendance: Your status as an attendee at specific events and your role (e.g., Cosplayer, Photographer)
- Communications: Messages sent through our contact forms or email
1.2 Information Collected Automatically
- Authentication Cookies: Session tokens for secure login
- Cookie Preferences: Your consent choices for cookies
- Technical Information: IP address, browser type, device information (only when necessary for security or functionality)
2. How We Use Your Data
We collect and use your personal data for the following purposes:
- Provide Services: Enable account creation, booth profile management, and event applications
- Authentication: Securely verify your identity and maintain login sessions
- Communication: Send important updates about your applications, events, and account
- Event Management: Allow event organizers to review and manage booth applications
- Creator Discovery: Display booth profiles in our public creator directory (only if you choose to make your profile public)
- Platform Improvement: Understand usage patterns to improve our services (only with your consent for analytics cookies)
- Legal Compliance: Comply with legal obligations and protect against fraud or abuse
3. Data Sharing & Disclosure
We do not sell your personal data. We may share your data in the following circumstances:
3.1 With Event Organizers
When you apply to participate in an event, your booth profile and application details are shared with the event organizer for review purposes.
3.2 Public Information
If you set your booth profile to "Public", your business information and media will be visible in our vendor directory to all visitors.
Additionally, when you indicate that you are attending an event (e.g., as a Cosplayer, Photographer, or General Attendee), your attendance status is public by default. You can choose to hide your attendance from public lists, though event organizers will always be able to see who is attending their event. Aggregate attendance numbers are always public.
3.3 Service Providers
We use trusted third-party service providers to help operate our platform:
- Cloudflare: Hosting, database (D1), and file storage (R2)
- Google: OAuth authentication
- Postmark: Transactional email delivery
3.4 Legal Requirements
We may disclose your data if required by law, legal process, or government request.
5. Your Rights Under PDPA
Under Singapore's Personal Data Protection Act, you have the following rights:
Right to Access
Request a copy of the personal data we hold about you. You can access most of your data through your account settings.
Right to Correction
Request correction of inaccurate or incomplete personal data. You can update most information through your profile settings.
Right to Withdraw Consent
Withdraw consent for data processing at any time (where consent is the basis for processing). Note that withdrawal may affect service availability.
Right to Data Portability
Request your data in a commonly used, machine-readable format.
To exercise any of these rights, please contact our Data Protection Officer using the details in the Contact section.
6. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, or misuse:
- All data transmitted is encrypted using HTTPS/TLS
- Authentication via Google OAuth with secure session management
- Regular security assessments and updates
- Access controls limiting who can view personal data
- Secure cloud infrastructure with Cloudflare
7. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy:
- Account Data: Retained while your account is active, plus a reasonable period after deletion for legal compliance
- Application Data: Retained for the duration of the event and a reasonable period thereafter for record-keeping
- Session Cookies: Automatically deleted when you log out or after 30 days
- Consent Preferences: Retained until you clear them or for 1 year
8. Cross-Border Data Transfers
Your personal data may be processed and stored on servers located outside of Singapore (via Cloudflare's global network). We ensure that such transfers comply with PDPA requirements and that adequate protection measures are in place.
9. Changes to This Policy
We may update this Privacy Policy from time to time. If we make significant changes, we will notify you via email or through a prominent notice on our website. Your continued use of our services after such changes constitutes acceptance of the updated policy.
10. Contact Us
Data Protection Officer
As required by the Personal Data Protection Act, we have appointed a Data Protection Officer who is responsible for ensuring compliance with PDPA.
Email:
staff@acgevents.sgGeneral Inquiries:
staff@acgevents.sgWe will respond to your inquiry within 30 days as required by PDPA.
If you have concerns about how we handle your personal data and are not satisfied with our response, you may contact the Personal Data Protection Commission (PDPC) at www.pdpc.gov.sg.