Contact details
Your name, work email, phone number, role, company name, and correspondence with our team.
Your expense data is among your most confidential business information. Ng's Value protects it with clear controls, careful access, and direct accountability.
This policy explains how we collect, use, store, and protect personal and financial information when we provide expense tracking, analysis, reporting, and recommendations to Singapore businesses. We follow Singapore's Personal Data Protection Act (PDPA) and apply data minimisation to every engagement.
We ask for information that helps us understand your operating costs and communicate with the right people. Nothing more.
Your name, work email, phone number, role, company name, and correspondence with our team.
Invoices, receipts, categories, supplier information, budgets, transaction values, and other records you choose to share.
If you authorise a connected account, we may receive access credentials or tokens limited to the permissions you approve.
We record page visits, enquiry activity, device details, and basic usage analytics to maintain and improve our service.
Your information stays tied to the work you ask us to do. We do not use client expense records to build unrelated marketing profiles.
We use your information to assess spending patterns, prepare reports, compare relevant cost categories, identify avoidable leakage, and make practical recommendations for your business. We also use contact details to schedule consultations, answer requests, manage our agreement, and meet legal obligations.
Reports are shared with the authorised contacts you nominate. We seek consent before using identifiable client results for a case study or public communication.
Security is part of the service. We review access and handling practices as the engagement changes.
Data is encrypted in transit and at rest using safeguards appropriate to the information handled.
Access is limited to people who need it for the agreed work, with permissions reviewed when roles change.
We conduct security checks, update operating controls, and investigate suspected incidents promptly.
We retain information only for as long as it supports the engagement, legitimate business records, or a legal requirement. When retention ends, we securely delete or anonymise it. Approved service providers may process data for hosting or business operations under confidentiality and security obligations; we do not disclose it for unrelated purposes without the required consent.
You can ask to understand and control the personal data we hold about you. We will verify the request and respond within the time required by applicable law.
Some records must be retained to meet legal, accounting, or dispute-resolution duties.
Send privacy questions, access requests, or concerns about how we handle expense information to our Data Protection Officer. Please include enough detail for us to identify your organisation safely.