Privacy Policy | PLAYON

How PlayOn collects, uses, discloses and protects your personal data under Singapore's PDPA.
Jun 8, 2026

PlayOn Park Pte. Ltd. (UEN: 202609749H) — 1 Pasir Ris Close, Downtown East, #01-339/345/346/347, Singapore 519599

1. Introduction and Who This Notice Covers

This Privacy Policy and Data Protection Notice ("Notice") explains how PlayOn Park Pte. Ltd. (UEN: 202609749H) ("PlayOn", "we", "us" or "our") collects, uses, discloses and protects personal data in accordance with the Personal Data Protection Act 2012 of Singapore ("PDPA"). It applies to personal data in our possession or under our control, including personal data held by organisations we have engaged to process personal data for our purposes.

This Notice applies to all individuals whose personal data we handle ("you"), including: customers and account holders; participants (including minors); parents and guardians who make or manage bookings; party and event guests; visitors to our website (playon.com.sg); individuals who contact us with enquiries, feedback or complaints; and individuals who appear on CCTV at our venue at 1 Pasir Ris Close, Downtown East, #01-339/345/346/347, Singapore 519599.

"Personal data" means data, whether true or not, about an individual who can be identified from that data, or from that data together with other information to which we have or are likely to have access. Other terms have the meanings given in the PDPA where the context permits. This Notice is an information notice: it tells you how we handle personal data. Where the PDPA requires consent for a particular use, we rely on the specific consents described below, not on a single blanket consent.

2. Personal Data We Collect

Depending on how you interact with us, we may collect:

  • Contact details — name, email address and mobile number.
  • Booking and payment data — session date and time, ticket items, order amount and payment confirmation and, for online purchasers, the Terms version accepted at checkout, order reference and timestamp. Card details are collected and processed directly by our payment provider (Stripe); we do not store your full card number.
  • Account data — if you create a PlayOn account, your login email and authentication information. Passwords are stored only in protected, non-readable form.
  • Incident records — if an accident or incident occurs, details of what happened, the persons involved, first aid given and follow-up actions.
  • Information you volunteer to staff — see Section 4.
  • CCTV footage — images and video recorded at our venue for safety and security purposes (see Section 10).
  • Website usage data — basic technical information such as device type, browser and pages visited.

3. Purposes for Which We Collect, Use and Disclose Personal Data

We collect, use and disclose personal data for the following distinct purposes:

  • Providing our services: processing and confirming bookings, issuing tickets, managing admission, processing payments and refunds, managing accounts and any PlayPass, membership or party booking, and responding to enquiries, requests, complaints and feedback. We do not require, as a condition of providing our services, consent to collect, use or disclose personal data beyond what is reasonable to provide those services.
  • Safety, incidents and legal obligations: maintaining the safety and security of participants, staff and property; responding to and managing incidents, injuries and emergencies, including arranging medical assistance; keeping incident records; and complying with applicable laws, regulations and lawful requests from authorities.
  • Marketing (separate, withdrawable consent): see Section 5.
  • Photography for publicity (separate consent): we will only use identifiable images of an adult in our marketing materials with that adult's separate, express consent. For a Minor, consent must be provided by the Minor's parent or legal guardian. This is never a condition of entry.

Some purposes may continue to apply for a reasonable period after your relationship with us ends, including any period needed to deal with claims or enforce contractual rights.

4. Health and Safety Information You Volunteer

We do not routinely collect health information. If you voluntarily inform our staff of health or safety information relevant to participation or emergency assistance (for example, an allergy or a condition our first aiders should know about), we will use it only for that purpose, restrict access to staff who need to know, share it with first aiders, ambulance or medical personnel where necessary in an emergency, and not retain it longer than needed.

5. Marketing and the DNC Registry

We will only send you marketing communications if you have given consent (for example, by opting in during booking). You may withdraw marketing consent at any time using the unsubscribe link in our emails or by contacting our Data Protection Officer; withdrawal does not affect your bookings or our other services. If we conduct marketing by SMS, voice call or messaging application to a Singapore telephone number, we will comply with the applicable Do Not Call (DNC) requirements. Electronic marketing messages will include a clear opt-out method, and you may also ask us at any time to stop marketing calls or messages.

6. Disclosure of Personal Data

We do not sell your personal data. We may disclose personal data:

  • to service providers and agents engaged for the purposes above — including our payment processor (Stripe), booking platform, email delivery provider, cloud hosting and IT support providers — under confidentiality obligations and only to the extent needed;
  • to our insurers, legal advisers and auditors, where needed to manage claims, obtain advice or meet audit obligations;
  • to medical and emergency services, where needed to respond to an incident; and
  • to governmental and regulatory authorities, where required or authorised by law.

7. Cookies

Our website uses cookies and similar technologies. These fall into the following categories: (a) strictly necessary cookies, required for the site and booking flow to function; (b) analytics cookies, which help us understand site usage; and (c) marketing cookies, if used, which support advertising measurement. Non-essential cookies are used only with your consent, which you can give or withdraw through our cookie banner or settings page; you can also control cookies through your browser settings. Strictly necessary cookies cannot be switched off without affecting site functionality.

8. Protection of Personal Data

To safeguard personal data from unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks, we maintain appropriate administrative, physical and technical measures, including appropriate access controls, encryption and authentication measures where applicable, system maintenance, staff access restrictions and other measures proportionate to the nature of the personal data. No method of transmission or storage is completely secure; we regularly review and enhance our security measures.

9. Data Breach Notification

We assess suspected data breaches promptly and, where required under the PDPA, will notify the Personal Data Protection Commission and affected individuals as soon as practicable, in accordance with the PDPA data breach notification obligations.

10. CCTV

CCTV operates at our venue for the safety and security of visitors and staff and the protection of property. Signage is displayed at entrances. Footage is retained for a limited period and then overwritten, unless required for an incident investigation, an insurance or legal claim, or a lawful request from authorities. Access to footage is restricted to authorised personnel.

11. Retention of Personal Data

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, or as required or permitted by law, after which it is securely deleted or anonymised. We retain incident and related records for as long as reasonably necessary for safety, insurance, legal and claims-management purposes, taking into account applicable limitation periods and, where relevant, the age of a minor. Our retention periods are documented in our internal retention schedule.

12. Transfer of Personal Data Outside Singapore

Some of our service providers may process personal data outside Singapore — principally our payment processor, email delivery and cloud hosting providers. Where personal data is transferred outside Singapore, we take steps, including contractual safeguards, to ensure it receives a standard of protection at least comparable to that under the PDPA.

13. Your Requests and Choices: Access, Correction, Withdrawal and Deletion

You may, by writing to our Data Protection Officer:

  • Access — request a copy of the personal data we hold about you, and information about how it has been used or disclosed within the past year. A reasonable fee may apply and will be notified to you in advance.
  • Correction — request correction of an error or omission in your personal data.
  • Withdrawal of consent — withdraw any consent you have given. We will process withdrawal requests within a reasonable time and will notify you of any consequences, including services we may no longer be able to provide. Withdrawal does not affect processing that is permitted or required without consent under applicable law.
  • Deletion requests — the PDPA does not provide a general right to erasure, but you may ask us to delete personal data that is no longer necessary, and we will accommodate such requests where we are not required or permitted to retain the data for legal, safety, insurance or business purposes.

We respond to access and correction requests as soon as reasonably possible, generally within thirty (30) days; if we need longer, we will tell you in writing when we will respond. If we cannot fulfil a request, we will generally explain why, except where the PDPA does not require us to.

14. Accuracy of Personal Data

We generally rely on personal data provided by you or a person authorised by you. Please keep your personal data up to date by informing our Data Protection Officer of any changes.

15. Data Protection Officer

PlayOn has designated a Data Protection Officer responsible for our compliance with the PDPA. You can reach the DPO at:

  • Email: [email protected]
  • Address: Data Protection Officer, PlayOn Park Pte. Ltd., 1 Pasir Ris Close, Downtown East, #01-339/345/346/347, Singapore 519599

16. Changes to This Notice

We may update this Notice from time to time. The current version is the one published on our website. If we make material changes, we will notify you by reasonable means — for example, a notice on our website or an email to account holders — before or when the changes take effect.


Effective date: 3 July 2026    Version: 2.5 (supersedes version published 8 June 2026)

Privacy Policy | PLAYON