Privacy policy

How C:Real.io Pte Ltd collects, uses, discloses, transfers, retains, and protects personal data across the C:Real platform — the Digital Carbon Wallet, WebXR experiences, carbon removal subscriptions, the Public Carbon Ledger, and related Services.


1. Introduction

This Privacy Policy explains how C:Real.io Pte Ltd (“C:Real”, “we”, “us”, or “our”), a company incorporated and registered in Singapore, collects, uses, discloses, transfers, retains, and protects personal data in connection with the C:Real platform at c-real.io, including the Digital Carbon Wallet, WebXR and augmented reality experiences, the Consumer UI, carbon removal subscriptions, receipt capture, the Public Carbon Ledger, Carbon Removal Tokens (“CRTs”), social sharing features, API integrations, and any related services (collectively, the “Services”).

This Privacy Policy is incorporated by reference into our Terms and Conditions and should be read alongside them. Capitalised terms not defined here have the meaning given in the Terms and Conditions.

By accessing or using the Services, you acknowledge that your personal data will be processed as described in this Privacy Policy and in accordance with applicable data protection law.

2. Who we are

C:Real.io Pte Ltd is the data controller (or, in jurisdictions using different terminology, the organisation responsible) for personal data processed through the Services.

Registered address: 18 Boon Lay Way, #06-143, TradeHub 21, Singapore 609966
Privacy enquiries: privacy@c-real.io
General enquiries: support@c-real.io
Legal notices: legal@c-real.io

3. Scope

This Privacy Policy applies to personal data we collect through the Services, including from consumers using the Digital Carbon Wallet and WebXR experiences, and from business contacts at merchants, venues, and partners in connection with onboarding and account management. It does not apply to third-party websites, applications, or services that we do not control, including social media platforms you may choose to share content to, or payment processors’ own services, which are governed by their own privacy policies.

4. Information we collect

4.1 Information you provide

4.2 Information collected automatically

4.3 Information from third parties

4.4 Aggregated and anonymised data

We may create aggregated or anonymised data from the information above, which does not identify you and is not subject to this Privacy Policy once it can no longer reasonably be linked to you.

5. How we use your information

We use personal data to:

5.1 Legal bases (EEA / UK)

Where the GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract with you (account administration, transactions, CRT issuance); compliance with a legal obligation (KYC, tax, sanctions, breach notification); legitimate interests (fraud prevention, platform security, service improvement), balanced against your rights; and consent, where required. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

5.2 Public Carbon Ledger

Individual user data is displayed on the Public Carbon Ledger only where you have opted into a public profile, or where disclosure is otherwise permitted by applicable law. Where you transact anonymously or elect anonymisation, the associated carbon removal is retired with C:Real recorded as the retiring entity rather than you personally (Terms and Conditions, Section 3.2).

6. WebXR, camera, and captured content

WebXR experiences may request access to your device’s camera, motion sensors, or location services, solely for the duration of the experience you initiate. You control this access through your browser or device settings and may revoke it at any time. We do not access device capabilities beyond what is required for the experience, and we do not retain raw camera, sensor, or biometric data beyond the active session unless you choose to save content.

Content you capture, save, or share (screenshots, photos, video, audio) is your responsibility, including obtaining consent from any identifiable third party before capturing or sharing it. This is addressed in full in Terms and Conditions, Section 4.3, which is incorporated into this Policy by reference.

7. How we share your information

We disclose personal data only as reasonably necessary, to:

We do not sell personal data, and we do not share personal data with merchants or venues for their own marketing purposes without your consent.

8. Cookies and similar technologies

We use cookies and similar technologies for essential platform functionality (authentication, security, session management) and, where you consent or as otherwise permitted by applicable law, for analytics and performance measurement. A full Cookie Policy is in development and will be published and linked from this Policy once available. Until then, you can control cookies through your browser settings, which may limit certain Platform functionality.

9. Cross-border data transfers

Given the global nature of the Services and our operational presence across multiple jurisdictions, your personal data may be transferred to and processed in countries other than the one in which you reside, including Singapore, New Zealand, and other jurisdictions where our infrastructure, service providers, payment processors, registry partners, or operational teams are located. Where required by applicable law, we use appropriate safeguards for such transfers, which may include Standard Contractual Clauses, PDPA-compliant transfer mechanisms, or equivalent protections.

10. Data retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, provide the Services, maintain platform integrity, comply with legal, regulatory, tax, and audit obligations, resolve disputes, prevent fraud, and enforce our agreements. Carbon transaction records, CRT data, registry references, and ledger data may be retained for extended periods, or indefinitely, as part of the Carbon Ledger, audit trail, registry reconciliation, and verification processes, consistent with Terms and Conditions, Section 9.4.

11. Data security

We use administrative, technical, and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, and destruction, including encryption in transit, access controls, and vendor due diligence. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

12. Data breach notification

Where a data breach is likely to result in significant harm to affected individuals, or affects 500 or more individuals, we will notify the Personal Data Protection Commission of Singapore (PDPC) within the timeframe required by the Personal Data Protection Act 2012, and will notify affected individuals where the breach is likely to result in significant harm to them. Where other data protection laws impose breach notification obligations (including the GDPR), we will comply with those requirements in parallel.

13. Your privacy rights

Your rights depend on where you are located. To exercise any of the rights below, contact privacy@c-real.io. We will verify your identity before actioning a request and will respond within the timeframe required by applicable law.

13.1 European Economic Area and United Kingdom (GDPR / UK GDPR)

You have the right to access, rectify, erase, restrict, or object to the processing of your personal data, the right to data portability, and the right to withdraw consent at any time. You also have the right to lodge a complaint with your local supervisory authority. C:Real does not currently have a formal Article 27 GDPR representative established in the EU or UK; this is under active review and this Policy will be updated with representative contact details once appointed. In the interim, EEA and UK data subjects should direct enquiries and requests to privacy@c-real.io.

13.2 Singapore (PDPA)

You have the right to access and correct your personal data, to withdraw consent to its collection, use, or disclosure (subject to legal or contractual restrictions), and to request that we stop using your data for marketing. You may lodge a complaint with the Personal Data Protection Commission (PDPC).

13.3 Thailand (PDPA)

You have rights of access, rectification, erasure, restriction, objection, data portability, and to withdraw consent, in accordance with the Personal Data Protection Act B.E. 2562 (2019), and may lodge a complaint with the Personal Data Protection Committee.

13.4 Australia (Privacy Act 1988)

You have the right to access and seek correction of your personal information under the Australian Privacy Principles, and may complain to the Office of the Australian Information Commissioner (OAIC) if you believe we have mishandled your data.

13.5 New Zealand (Privacy Act 2020)

You have the right to access and correct your personal information, and may complain to the Office of the Privacy Commissioner (OPC).

13.6 United States

If you are a California resident, the CCPA (as amended by the CPRA) gives you the right to know, delete, and correct personal information, and to opt out of the sale or sharing of personal information and of certain automated decision-making. We do not currently sell or share personal information for cross-context behavioural advertising, and do not use automated decision-making to make legal or similarly significant decisions about you. We honour Global Privacy Control (GPC) signals where applicable. We will not discriminate against you for exercising a privacy right. Residents of Virginia, Colorado, Connecticut, Utah, and Texas have similar rights under their respective state privacy laws, which we honour to the extent applicable to us.

14. Children’s privacy

The Services are not directed to, and are not intended for use by, anyone under eighteen (18) years of age (Terms and Conditions, Section 1.3). We do not knowingly collect personal data from children. If we become aware that we have collected personal data from someone under 18 without appropriate consent, we will take steps to delete it.

15. Automated decision-making

We do not currently use automated decision-making or profiling to make decisions about you that produce legal or similarly significant effects. If this changes, we will update this Policy and provide any disclosures and opt-out rights required by applicable law, including California’s automated decision-making technology requirements taking effect from 1 January 2027.

16. Third-party links and services

The Services allow you to share content to third-party social media platforms and interact with third-party payment processors, registries, and other service providers. Those third parties have their own privacy policies, and we are not responsible for their privacy practices. We encourage you to review their policies before sharing personal data with them.

17. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified to you via email, in-app notification, or a prominent notice on the Platform, consistent with the notice provisions in our Terms and Conditions, Section 1.5. Each update takes effect when we post the revised Policy.

18. Contact us

Privacy enquiries or to exercise a privacy right: privacy@c-real.io
General enquiries: support@c-real.io
Legal notices: legal@c-real.io
Registered address: 18 Boon Lay Way, #06-143, TradeHub 21, Singapore 609966

© 2025–2026 C:Real.io Pte Ltd (Singapore). All rights reserved.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Contact Us

Have a question or want to explore a C:Real® pilot? Reach out and we’ll get back to you soon.