Wonder
Legal

Privacy Policy

Wonder Singapore Data Privacy Notice

Effective Date: 17 March 2026

Who We Are

This Privacy Notice applies to the following Singapore-incorporated entities operating under the Wonder brand:

EntityUEN / Registration
Wonder Tech Singapore Pte. Ltd.202515097W
Wonder Tech Capital Pte. Ltd.202548289Z
Bindo Pte. Ltd.202217737E

References to “Wonder SG”, “we”, “us” or “our” in this Notice refer to the specific entity responsible for collecting and handling your personal data in connection with the services you use.

Wonder Tech Singapore Pte. Ltd. and Wonder Tech Capital Pte. Ltd. are wholly-owned subsidiaries of Wonder Group Holdings Limited (BVI), which is in turn majority-owned by Universal Intelligence Holdings Limited (BVI). Bindo Pte. Ltd. is a wholly-owned subsidiary of Bindo Labs Group Limited (Cayman Islands). All three entities operate under the Wonder brand in Singapore.

1. About This Notice

This Data Privacy Notice ("Notice") explains how Wonder SG collects, uses, discloses, and protects personal data relating to our merchants, customers, cardholders, website visitors, job applicants, and other individuals who interact with us (collectively "you" or "individuals").

This Notice applies to personal data collected through:

(a) our websites, including wonder.app/en-sg and related sub-domains;

(b) our mobile applications;

(c) our payment processing and financial technology platforms;

(d) our customer service channels; and

(e) any other interaction between you and Wonder SG.

By accessing our website, submitting your personal data, or using our products and services, you acknowledge that you have read this Notice and understood how we handle your personal data as described in this Notice.

This Notice should be read together with any product-specific notices or terms and conditions that may be provided to you at the point of collection of your personal data. In the event of any conflict, the more specific notice shall prevail.

2. Definitions

In this Notice, unless the context otherwise requires:

  • "Personal Data" has the meaning given to it under the Personal Data Protection Act 2012 ("PDPA"), and refers to data, whether true or not, about an individual who can be identified from that data, or from that data and other information to which we have or are likely to have access.
  • "PDPA" means the Personal Data Protection Act 2012 of Singapore (No. 26 of 2012), as amended or re-enacted from time to time, including all subsidiary legislation made thereunder.
  • "PDPC" means the Personal Data Protection Commission of Singapore, the regulatory authority responsible for administering and enforcing the PDPA.
  • "DPO" means Data Protection Officer, the designated individual responsible for overseeing data protection compliance within Wonder SG.
  • "Platform" means Wonder SG's payment processing, e-wallet, financial technology services, merchant dashboard, and all related services."Services" means all products and services provided by Wonder SG, including but not limited to the Wonder App, Wonder Terminal, Wonder Card, Wonder Dashboard, Wonder SoftPOS, and Wonder Transit X.
  • "Services" means all products and services provided by Wonder SG, including but not limited to the Wonder App, Wonder Terminal, Wonder Card, Wonder Dashboard, Wonder SoftPOS, and Wonder Transit X.

3. Personal Data We Collect

The categories of personal data we collect will depend on your relationship with us and the services you use. We collect only the minimum personal data necessary for the relevant purpose.

Category of Personal DataExamples
Identity InformationFull name, aliases, NRIC/FIN/Passport number, date of birth, nationality, gender, photographs.
Contact InformationResidential or business address, email address, telephone number(s), preferred communication method.
Financial InformationBank account details, credit/debit card information, billing address, transaction history, account balances.
Payment & Transaction DataTransaction amounts, dates and times, merchant names and identifiers, payment references, payment method details.
eKYC & Verification DataIdentity document scans, selfie/liveness check images, proof of address, business registration documents, beneficial ownership information.
Account & Login InformationUsername, encrypted password, account preferences, login timestamps, device identifiers.
Usage & Technical InformationIP address, browser type and version, operating system, device identifiers, geolocation data, pages accessed, referring URLs, session duration.
Communications DataEnquiries, complaints, feedback, live chat logs, call recordings (where applicable), emails, and other correspondence with us.
Marketing PreferencesSubscription status, communication preferences, survey responses, promotional campaign interactions.
Employment InformationCV/resume, employment history, qualifications, references (for job applicants only).

Special Categories of Personal Data

We do not intentionally collect special categories of personal data (such as race, religion, health, sexual orientation, or biometric data) unless strictly required by applicable law or regulation (e.g., mandatory anti-money laundering checks). Where required, we will seek your explicit consent and process such data in accordance with the PDPA.

4. How We Collect Personal Data

4.1 Directly from You

We collect personal data directly from you when you:

  • Create an account or register for our Services;
  • Complete eKYC (Know Your Customer) or onboarding processes;
  • Make or receive a payment through our Platform;
  • Scan a QR code or use any Wonder payment product;
  • Contact us via email, telephone, live chat, or in person;
  • Submit a form, survey, or application on our website or app;
  • Subscribe to our marketing communications or promotional campaigns;
  • Apply for a position at Wonder SG;
  • Provide feedback or file a complaint.

4.2 Automatically

We collect certain technical and usage data automatically when you interact with our website or Platform, including through cookies, web beacons, and similar tracking technologies (see Section 9 on Cookies).

4.3 From Third Parties

We may also receive personal data from third parties, including:

  • Merchants and business partners who refer you to our Services;
  • Financial institutions, payment networks (e.g., Visa, Mastercard), and acquiring banks involved in processing your transactions;
  • Credit bureaus and identity verification service providers (for eKYC and fraud prevention purposes);
  • Government databases and publicly available sources, to the extent permitted by law;
  • Other entities within the Wonder and Bindo corporate group, where data sharing is necessary to provide you with integrated services.

5. Purposes for Collection, Use & Disclosure

We collect, use, and disclose your personal data only for purposes that are made known to you at the time of collection or that are reasonably expected given the nature of our services. The purposes for which we process your personal data include:

5.1 Account Management & Service Delivery

  • Creating and managing your Wonder account;
  • Providing and maintaining our payment processing services Verifying your identity and processing eKYC checks;
  • Processing payments, transfers, refunds and chargebacks;
  • Issuing Wonder Cards to eligible users;
  • Maintaining and updating our records.

5.2 Regulatory Compliance & Legal Obligations

  • Complying with the PDPA and other applicable Singapore laws;
  • Meeting requirements under the Payment Services Act 2019 ("PSA");
  • Complying with anti-money laundering ("AML"), counter-financing of terrorism ("CFT")g;
  • Responding to requests from MAS, PDPC, law enforcement or other regulatory authorities;
  • Maintaining records and audit trails as required by law.

5.3 Risk Management, Fraud Prevention & Security

  • Detecting, investigating, and preventing fraud, and other illicit activities;
  • Conducting transaction monitoring and sanctions screening;
  • Protecting the security and integrity of our systems;
  • Enforcing our Terms and Conditions.
  • Maintaining records and audit trails as required by law.

5.4 Customer Support & Relationship Management

  • Responding to your enquiries,and complaints;
  • Notifying you of changes to our services, terms, or policies;
  • Providing technical support.

5.5 Marketing & Communications

  • Sending you information about our products, services and promotions (only where we have obtained your consent);
  • Personalising content and communications based on your preferences;
  • Conducting market research and satisfaction surveys.

You may withdraw consent for marketing communications at any time by clicking the unsubscribe link in our emails, or by contacting our DPO at sg_dpo@bindo.com.

5.6 Analytics & Service Improvement

  • Analysing usage trends to improve our website and services;
  • Developing new features and enhancing the user experience;
  • Conducting internal research and business planning.

5.7 Corporate Transactions

  • In connection with a merger, acquisition, restructuring, or sale of assets, your personal data may be transferred to the relevant counterparty, subject to equivalent data protection obligations.

6. Disclosure of Personal Data

We do not sell or rent your personal data to third parties. We may disclose your personal data to the following categories of recipients, only to the extent necessary for the purposes described in Section 5:

6.1 Within the Wonder / Bindo Group

We may share your personal data with related corporations and affiliates within the Wonder and Bindo corporate group for the purposes of group-level reporting, audit, IT infrastructure, and providing integrated services, subject to equivalent data protection standards.

6.2 Payment Network Partners

We share relevant personal data with payment networks (e.g., Visa, Mastercard), acquiring banks, issuing banks, and other financial intermediaries as necessary to process payment transactions.

6.3 Service Providers & Vendors

We engage third-party service providers who process personal data on our behalf, including technology providers, cloud hosting services, eKYC/AML verification platforms, analytics providers, and customer support systems. We require all such providers to implement appropriate contractual and technical safeguards.

6.4 Regulatory & Law Enforcement Authorities

We may disclose personal data to MAS, PDPC, Singapore Police Force, IRAS or other government or regulatory bodies where required or permitted by law.

6.5 Professional Advisers

We may share personal data with our lawyers, auditors, and other professional advisers, subject to obligations of confidentiality.

6.6 Business Transfers

In connection with a merger, acquisition, restructuring, or transfer of all or part of our business or assets, personal data may be disclosed to prospective buyers or transferees.

7. Cross-Border Transfers of Personal Data

In providing our services, we may transfer your personal data to countries outside Singapore. Where we do so, we comply with the requirements of the PDPA in relation to cross-border data transfers.

Countries to which we may transfer personal data include, without limitation: Hong Kong Transfers to these jurisdictions are conducted in accordance with the PDPA's and are subject to appropriate contractual safeguards

8. Retention of Personal Data

We retain personal data for as long as is necessary to fulfil the purposes for which it was collected, or as required or permitted by applicable law. In determining the appropriate retention period, we consider:

  • Legal and regulatory obligations (e.g., AML/CFT records will be retained for at least seven years);
  • Contractual obligations and applicable limitation periods for legal claims;
  • Audit, accounting, and tax requirements;
  • The nature of the data and any risk associated with unauthorised use or disclosure.

When personal data is no longer required, we will take reasonable steps to destroy or anonymise it in a secure manner.

9. Cookies & Similar Technologies

Our website and Platform use cookies and similar tracking technologies to provide a better user experience, for analytics, and for security purposes.

Category of CookiesPurpose
Strictly necessary cookiesEssential for the website and platform to function correctly. These cannot be disabled.
Performance & analytics cookiesHelp us understand how visitors use our website so we can improve functionality and content.
Functional cookiesEnable personalisation of your experience, such as remembering your language preference or log-in status.
Targeting/Marketing cookiesUsed to deliver advertisements relevant to your interest. You may disable these cookies through your browser settings without affecting your use of core services.

You can manage your cookie preferences through your browser settings. For more information on how to disable or delete cookies, please refer to your browser's help documentation. Disabling certain cookies may affect the functionality of some features of our website or Platform.

10. Security of Personal Data

We take the security of your personal data seriously. We have implemented appropriate administrative, physical, and technical measures to protect your personal data against unauthorised access, collection, use, disclosure, copying, modification, disposal, or similar risks.

These measures include, but are not limited to: encryption of data in transit and at rest (including SSL/TLS protocols), access controls and role-based permissions, regular security assessments and adherence to Payment Card Industry Data Security Standard (PCI DSS) requirements where applicable.

We have also established procedures to manage personal data breaches. In the event of a notifiable data breach under the PDPA, we will notify the PDPC within three (3) calendar days of becoming aware of the breach, and affected individuals will be informed in accordance with the PDPA's breach notification obligations.

Notwithstanding the above, no security system is completely impenetrable. We cannot guarantee the absolute security of personal data transmitted to us over the internet or stored in our systems. You are encouraged to use strong, unique passwords and to exercise care when accessing our Services on public or shared networks.

11. Your Rights Under the PDPA

Subject to the exceptions and qualifications set out in the PDPA, you have the following rights with respect to your personal data held by Wonder SG:

11.1 Right of Access

You have the right to request access to the personal data we hold about you, and to information about how such personal data has been or may have been used or disclosed by us in the year preceding your request.

11.2 Right of Correction

You have the right to request that we correct any errors or omissions in the personal data we hold about you. We will correct the data as soon as reasonably practicable, unless there are legitimate grounds under the PDPA for not doing so.

11.3 Right of Withdrawal of Consent

Where we process your personal data on the basis of consent, you may withdraw that consent at any time by written notice to our DPO. Please note that withdrawal of consent may affect our ability to continue providing certain services to you

11.4 Right to Lodge a Complaint

If you are dissatisfied with how we handle your personal data or your access/correction request, you have the right to lodge a complaint with the PDPC at www.pdpc.gov.sg.

To exercise any of the above rights, please submit a written request to our Data Protection Officer at sg_dpo@bindo.com. We will respond to your request within thirty (30) calendar days from receipt, or notify you if additional time is required. We may charge a reasonable administrative fee for access requests in accordance with the PDPA.

Please note that we may not be required to comply with access or correction requests in certain circumstances as specified in the PDPA (e.g., where complying would be contrary to national interest, threaten the safety of another individual, or relate to evaluative purposes).

12. Minors

Our Services are not intended for persons under the age of 18 years. We do not knowingly collect personal data from minors without verified parental or guardian consent. If we become aware that we have inadvertently collected personal data from a minor without appropriate consent, we will take prompt steps to delete such information.

If you believe that we may have collected personal data from a minor, please contact our DPO immediately at sg_dpo@bindo.com.

13. Links to Third-Party Websites

Our website and Platform may contain links to third-party websites and services. This Notice does not apply to such third-party websites, and we are not responsible for their data protection practices. We encourage you to review the privacy notices of any third-party sites you visit.

14. Changes to This Notice

We may update this Notice from time to time to reflect changes in our business practices, the services we provide, or applicable laws and regulations. We will publish the updated Notice on our website at wonder.app/en-sg/privacy-policy and update the effective date accordingly.

For material changes that may significantly affect your rights or the way we process your personal data, we will endeavour to provide you with prior notice through our usual communication channels (e.g., email or in-app notification).

Your continued use of our Services following any changes to this Notice will constitute your acknowledgement of, and where applicable, consent to, such changes.

15. How to Contact Us

If you have any questions, concerns, or requests relating to this Notice or the processing of your personal data, you may contact us at sg_dpo@bindo.com.