VANTA Private Members Club is committed to protecting the privacy of its members, guests, and website users. This policy describes what personal data we collect, how we use it, who we share it with, and the rights you have, in accordance with Singapore's Personal Data Protection Act 2012 (PDPA).
About This Policy
This policy applies to personal data collected by VANTA Private Members Club through our website, mobile applications, reservation systems, member concierge, in-club interactions, and all connected services (collectively, "Services"). By using our Services or providing personal data to VANTA, you acknowledge that you have read and understood the practices described here.
Effective date: 18 August 2026. Version 2.0.
Data Protection Officer
VANTA has appointed a Data Protection Officer (DPO) responsible for overseeing compliance with the PDPA and handling data protection enquiries.
Daisy
Data Protection Officer, VANTA Private Members Club
daisy@vantamembers.com
You may contact the DPO for any data protection question, to exercise your rights, or to file a complaint.
Data We Collect
We collect personal data you provide directly, data generated through your use of our Services, and data received from third parties acting on your behalf. Categories include:
- Identity: full name, date of birth, photograph, national identification (where legally required), profile bio and interests.
- Contact: email, phone number, postal address, emergency contact.
- Membership: tier, membership number, initiation and renewal history, house account.
- Access: NFC card ID, entry check-in timestamps, on-premises presence.
- Device location (optional): we may use your device's location, only while the member application is open and only if you grant permission, to detect when you are physically at the club so we can show you which other members are on premises. Approximate location only, never stored beyond your active session, never used for tracking outside the club.
- Reservations and events: RSVPs, dining bookings, guests brought, attendance and no-show history, dietary preferences and allergens.
- Benefit bookings: requests, approval status, partner-facing information you share.
- Community activity: chat room messages, direct messages, reactions, uploaded images, and, when enabled by you, profile visibility in the member directory.
- Concierge conversations: messages exchanged with the VANTA concierge assistant and human staff.
- Payment: billing details processed by our payment providers; we do not store full card numbers on our systems.
- Device and usage: IP address, device type, browser, session logs, notification tokens.
- Photography: images taken at club events for editorial and marketing use where consent has been given.
Purposes and Legal Basis
Under the PDPA we collect, use, and disclose your personal data only for purposes that a reasonable person would consider appropriate in the circumstances, and for which you have given consent (or where consent is deemed or an exception applies). Specifically:
- Processing your membership application, activation, renewal, and billing.
- Verifying your identity and controlling access to the premises.
- Managing reservations, guest lists, and event participation.
- Providing the concierge service and responding to enquiries.
- Enabling community features you opt into, such as the member directory, chat rooms, and Circle introductions.
- Sending operational communications (booking confirmations, service updates, safety notices).
- Sending marketing communications where you have given separate consent (which you may withdraw at any time).
- Protecting members, staff, and the club against fraud, abuse, and unlawful activity.
- Meeting legal, tax, and regulatory obligations.
- Improving our Services through anonymised analytics.
Consent and Withdrawal
Where consent is required, we ask for it clearly at the point of collection, and again when we introduce a new purpose. Your consent is recorded together with the policy version, timestamp, and the device you used.
You may withdraw consent for any non-essential processing at any time by adjusting the toggles in your account settings, unsubscribing from marketing emails, or writing to daisy@vantamembers.com. Withdrawing consent may limit or end our ability to provide the affected services, and we will explain any such consequences before your withdrawal takes effect.
Disclosure to Third Parties
We do not sell your personal data. We disclose it only to the following categories of recipients, each bound by written data-processing terms limiting their use of your data to the specified purpose:
- Infrastructure: our cloud hosting provider, database, backup, and content delivery services.
- Reservations: SevenRooms and other reservation platforms used to manage bookings on your behalf.
- Notifications: our push-notification, SMS, and email delivery providers.
- Concierge assistant: the AI concierge provider processes your concierge messages to generate responses. Conversations may be reviewed by VANTA staff to improve service quality.
- Customer relationship management: our CRM platform for membership lifecycle management.
- Payment processing: licensed payment gateways and financial institutions.
- Professional advisors: auditors, lawyers, and accountants under professional confidentiality obligations.
- Event partners: venues and suppliers when your participation requires it (with the minimum data necessary).
- Authorities: where disclosure is required by Singapore law, court order, or valid regulatory request.
The DPO maintains a current list of processors and can provide it on request.
Overseas Transfers
Some of our processors host or process data outside Singapore. Before transferring your personal data overseas we take reasonable steps to ensure the recipient is bound by legally enforceable obligations that provide a standard of protection comparable to the PDPA, as required by section 26 of the PDPA and the Personal Data Protection Regulations 2021.
Retention
We retain personal data only for as long as it is necessary for the purposes it was collected for, or as required by applicable law and internal governance policy. Indicative retention periods:
- Active membership records: for the duration of membership, and up to seven years thereafter for legal, tax, and audit purposes.
- Concierge conversations: up to twelve months, unless flagged for service-quality review.
- Chat room messages: retained while the room is active; summarised and pruned periodically.
- Access logs and NFC entry records: up to twenty-four months.
- Uploaded media: for the duration of membership, or until you delete the content.
- Marketing consent records: for as long as consent is active, plus two years to evidence withdrawal.
When retention is no longer justified, we securely delete or anonymise the data.
Your Rights
Under the PDPA you have the right to:
- Access the personal data we hold about you and information about how it has been used or disclosed in the past twelve months.
- Correct personal data that is inaccurate or out of date.
- Withdraw consent for any purpose that relies on your consent.
- Port your data by requesting a copy in a commonly used electronic format.
- Opt out of marketing communications at any time.
- Delete your account from within the app; on request we will erase or anonymise your personal data, subject to legal retention obligations.
- Complain to the DPO, and if unresolved, to the Personal Data Protection Commission (PDPC) of Singapore at www.pdpc.gov.sg.
We will respond to verifiable requests within thirty days. Some rights may be limited where required or permitted by law.
Website Cookies and Technologies
Our public website uses cookies and similar technologies for essential functions, analytics, and, where applicable, marketing attribution (such as Meta Pixel and Google Analytics). You may adjust cookie preferences through your browser. Disabling cookies may affect certain features.
The member application uses only strictly necessary storage to keep you signed in and remember your preferences.
Security
VANTA implements administrative, technical, and physical safeguards proportionate to the sensitivity of the data, including transport encryption, encrypted backups, role-based access controls, audit logging, and regular reviews. No system is entirely secure and we cannot guarantee absolute security, but we investigate every incident and act on lessons learned.
Data Breach Notification
Where a data breach is likely to result in significant harm to affected individuals, or is of a significant scale, we will notify the PDPC and affected individuals in accordance with section 26D of the PDPA, generally within seventy-two hours of establishing that the incident is a notifiable breach.
Children
Membership is limited to adults aged eighteen years or older. We do not knowingly collect personal data from anyone under this age. If you believe we have inadvertently collected such data, please contact the DPO and we will delete it.
Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or applicable law. Material changes will be notified through the member application or by email. Your continued use of the Services after notification constitutes acknowledgement of the revised policy.
How to Reach Us
For any data-protection question, access or correction request, or to withdraw consent:
Daisy, Data Protection Officer
VANTA Private Members Club
40A Orchard Road, MacDonald House
Singapore 238838
daisy@vantamembers.com