Legal
Privacy Policy
Last updated: 3 September 2026
This Policy explains how Always First Capital Pte. Ltd. (UEN 202507495H), a moneylender licensed by the Registry of Moneylenders, Ministry of Law, Singapore under Licence No. 000/2026 (“we”, “us”, “our”), collects, uses, discloses and protects personal data in accordance with the Personal Data Protection Act 2012 (“PDPA”).
It applies to our website at alwaysfirstcapital.com.sg, to enquiries you send us through it, and to personal data we handle in the course of assessing and administering loans. It forms part of our Terms & Conditions.
1. What personal data we collect
“Personal data” means data, whether true or not, about an individual who can be identified from that data, or from that data together with other information we have or are likely to have access to.
From an enquiry on this website
- your name;
- your contact number and email address;
- the loan type you are enquiring about, the subject, and anything you write in the message; and
- technical data described in clause 12.
If you go on to apply for a loan
- identification data, including your NRIC, FIN or passport details, date of birth, nationality and residency status;
- contact and residential address data, and proof of residency;
- employment and income data, including payslips, CPF Contribution History Statements and Income Tax Notices of Assessment;
- financial data, including bank statements and details of your existing loans and financial commitments;
- for a business loan: ACRA information, financial statements, company bank statements, and the personal data of substantial shareholders, directors and any surety; and
- records of your loan account, correspondence with us, and call records.
Where you give us personal data about another individual — a surety, a shareholder, a referee or an emergency contact — you confirm that you have their consent to do so and to our using it as described in this Policy.
2. How we collect it
We collect personal data:
- directly from you, through the enquiry form, by telephone, by email, or in person at our office;
- from documents you submit in support of an application;
- from the Moneylenders Credit Bureau and other credit information sources, where the law permits; and
- from public registers, such as ACRA, for business loan applications.
3. Why we collect, use and disclose it
We use personal data only for purposes a reasonable person would consider appropriate in the circumstances, namely:
- responding to your enquiry and communicating with you about it;
- verifying your identity and assessing your creditworthiness and ability to repay;
- deciding whether to grant a loan, and on what terms;
- preparing the Note of Contract and administering your loan account;
- collecting sums due and, where necessary, recovering them through the courts;
- meeting our obligations under the Moneylenders Act 2008 and the Moneylenders Rules, including record-keeping and reporting to the Registry of Moneylenders;
- meeting anti-money laundering and countering-the-financing-of-terrorism obligations;
- responding to lawful requests from regulators, law enforcement and the courts;
- maintaining the security and integrity of our systems, and preventing fraud; and
- improving our services and our website.
We do not sell personal data, and we do not disclose it for anyone else’s marketing.
4. Consent, and withdrawing it
We collect, use and disclose personal data with your consent, or where the PDPA or another written law permits or requires us to do so without it.
By submitting the enquiry form you consent to our using the personal data in it to respond to your enquiry. That consent is limited to your enquiry.
You may withdraw consent for any purpose at any time by writing to our Data Protection Officer (clause 15). We will tell you the likely consequences before acting on a withdrawal — withdrawing consent for purposes essential to a live loan may mean we cannot continue to administer it, and it does not release you from obligations already incurred, or affect what we are required by law to retain or disclose. We will act on a valid withdrawal within a reasonable time.
5. Who we disclose it to
We disclose personal data only where it is necessary for a purpose in clause 3, and only to:
- the Registry of Moneylenders, the Ministry of Law, and other regulators and government agencies, where required;
- the Moneylenders Credit Bureau;
- our professional advisers, including solicitors and auditors, under a duty of confidence;
- service providers who act for us — for example IT, email and hosting providers — who are bound by contract to protect the data and to use it only on our instructions;
- courts, and parties to proceedings, where required for legal claims; and
- any person you have authorised in writing.
6. Marketing and the Do Not Call Registry
We contact you about your enquiry or your loan account using the details you gave us. Those are service messages, not marketing.
We will not send you marketing messages by telephone call, SMS or fax unless you have given us clear and unambiguous consent in writing, or another exception under the PDPA applies. We check Singapore telephone numbers against the Do Not Call Registry as the PDPA requires. You can ask us to stop marketing at any time by writing to our Data Protection Officer, and we will act on it without charge.
7. Transfers outside Singapore
We store personal data in Singapore wherever we can. Some of our service providers — for example email and hosting providers — may process data on servers outside Singapore. Where that happens we take steps to ensure the recipient is bound to a standard of protection comparable to the PDPA, as section 26 of the PDPA requires.
8. How we protect it
We make reasonable security arrangements to protect personal data against unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks. These include access controls, encryption of data in transit, secure storage of physical documents, and staff training and confidentiality obligations.
No transmission over the internet is completely secure. Please do not send sensitive information through the enquiry form — see clause 14.
9. How long we keep it
We cease to retain personal data, or remove the means by which it can be associated with an individual, as soon as it is reasonable to assume that the purpose for which it was collected is no longer being served by retention and that retention is no longer necessary for legal or business purposes.
In practice: enquiries that do not lead to an application are deleted within 12 months. Records relating to a loan are kept for the period the Moneylenders Act 2008 and the Moneylenders Rules require, and for as long as needed for any legal claim.
10. Accuracy
We make reasonable effort to ensure personal data is accurate and complete where it is likely to be used to make a decision affecting you, or to be disclosed to another organisation. Please tell us promptly if your details change.
11. Access and correction
You may ask us:
- for access to the personal data about you that is in our possession or control, and information about how it has been used or disclosed in the year before the request; and
- to correct an error or omission in it.
Write to our Data Protection Officer (clause 15). We may need to verify your identity before we respond. We will respond as soon as reasonably possible, and normally within 30 days; if we cannot, we will tell you when we will. A reasonable fee may be charged for an access request, and we will tell you the fee before proceeding. There are limited circumstances in which the PDPA allows or requires us to refuse a request; if we refuse, we will tell you why.
12. Cookies and website data
This website does not set advertising or tracking cookies, and we do not run third-party analytics on it.
When you visit, our server records ordinary technical data — your IP address, the pages requested, timestamps and your browser’s user-agent string — in its logs. We use this to keep the site available and secure, and to limit abuse of the enquiry form. Where such data amounts to personal data, we handle it under this Policy.
Fonts are loaded from Google Fonts and the map on our contact page is embedded from Google Maps. Loading those resources discloses your IP address to Google, which handles it under its own privacy policy. If you prefer not to, you can block those resources in your browser; the rest of the site will still work.
13. Third-party services and links
Our website may link to sites operated by others. We do not control them, and this Policy does not apply to them. Please read their privacy policies before giving them your personal data.
14. What we will never ask you for
We will never ask for the password or one-time password to any of your accounts, including Singpass, internet banking and email.
We will never keep your NRIC card, passport, driver’s licence or any other original identity document for safekeeping.
Please do not include your full NRIC number, account passwords, card numbers or one-time passwords in the enquiry form or in an email to us. If you receive a message claiming to be from us that asks for any of these, do not respond — call us on the number in clause 15 and report it to the police.
15. Data Protection Officer
Questions, requests and complaints about personal data should go to our Data Protection Officer:
The Data Protection Officer
Always First Capital Pte. Ltd.
1094 Lower Delta Road, Motorway Building, Singapore 169205
Telephone: +65 6000 0000
Email: dpo@alwaysfirstcapital.com.sg
If you are not satisfied with how we have handled your matter, you may refer it to the Personal Data Protection Commission.
16. Changes to this Policy
We may update this Policy from time to time. The version published here at the time you use the website applies, and the date at the top of this page shows when it last changed. Where a change materially affects how we use your personal data, we will take reasonable steps to notify you.