PRIVACY · PDPA
Privacy Policy
Effective 21 July 2026 · Last updated 21 July 2026
This Privacy Policy describes how BrewTrace Pte. Ltd. (UEN 202436182M), operating the specialty coffeehouse and website at brewtrace.pro ("BrewTrace", "we", "us", or "our"), collects, uses, discloses, and protects personal data in accordance with the Personal Data Protection Act 2012 of Singapore ("PDPA"). By using our website, visiting our premises, or submitting enquiries through our forms, you acknowledge that you have read and understood this Policy.
1. Data controller
BrewTrace Pte. Ltd. is the organisation responsible for personal data collected through brewtrace.pro and at our Telok Ayer premises. Our registered address is 28 Telok Ayer Street, #02-04, Singapore 048420. Privacy enquiries may be directed to [email protected] with subject line "Privacy enquiry". We aim to respond within ten business days.
2. Personal data we collect
We collect only data reasonably necessary for our coffeehouse operations, website function, and guest communication. Categories include:
- Contact and identity data: name, email address, telephone number, and any information you voluntarily include in message fields when using our contact form or emailing us directly.
- Booking and event data: preferred dates, group size, dietary notes, and company name when you enquire about cupping sessions, private tastings, or catering.
- Technical data: IP address, browser type, device type, referring URL, pages viewed, and timestamps when you browse brewtrace.pro. This data may be collected through server logs and, if you consent, analytics cookies.
- Cookie preference data: records of your cookie consent choices stored locally in your browser for up to six months.
- In-store transaction data: if you pay by card or PayNow, payment processing is handled by our payment service provider. We do not store full card numbers on our systems.
We do not intentionally collect sensitive personal data such as government ID numbers, health records, or financial account credentials through our website. Please do not submit such information via our contact form.
3. How we collect personal data
Personal data is collected when you:
- Submit our contact form at brewtrace.pro/contact.php, which posts to our secure handler and requires explicit PDPA consent;
- Send email to [email protected] or call +65 6951 2847;
- Book cupping sessions, private tastings, or catering through written correspondence;
- Browse our website, triggering automatic collection of technical data through server infrastructure and optional analytics tools;
- Interact with our cookie consent banner and save preferences;
- Visit our coffeehouse and provide information verbally or in writing for reservations or retail orders.
4. Purposes of collection, use, and disclosure
We use personal data for purposes that a reasonable person would consider appropriate in the context of our relationship with you, including:
- Responding to enquiries about our menu, lot availability, hours, and directions;
- Processing and confirming bookings for public cupping sessions, private tastings, and group visits;
- Coordinating catering and retail wholesale orders;
- Operating, maintaining, and improving brewtrace.pro, including diagnosing technical issues and understanding aggregate traffic patterns;
- Complying with legal obligations, including food safety record-keeping where applicable;
- Protecting our rights, property, and safety, and that of our guests and staff, including fraud prevention;
- Sending service-related communications you have requested, such as booking confirmations.
We do not sell personal data. We may disclose data to:
- Service providers who host our website, deliver email, process payments, or provide analytics — bound by confidentiality and data protection terms;
- Professional advisers (lawyers, accountants) under duty of confidentiality;
- Regulatory or law enforcement authorities when required by applicable law or court order.
5. Legal basis and consent
Under the PDPA, we rely on consent, contractual necessity, and legitimate business interests as appropriate. Our contact form requires a tick-box consent (consent_pdpa) before submission. You may withdraw consent for marketing communications at any time by emailing [email protected]; withdrawal does not affect the lawfulness of processing before withdrawal, and we may retain data where required for legal or operational purposes.
6. Retention
We retain personal data only as long as necessary for the purposes collected:
- Contact form submissions: up to twenty-four months from last correspondence, unless a longer period is required for dispute resolution;
- Booking records: up to thirty-six months after the event date;
- Server logs: up to twelve months;
- Cookie consent records: six months from the date stored;
- Accounting and tax records: as required under Singapore law, typically five to seven years.
When data is no longer needed, we delete or anonymise it using reasonable technical measures.
7. Cross-border transfers
Our website may be hosted on servers located outside Singapore. Where personal data is transferred overseas, we take steps reasonably required under the PDPA to ensure the recipient provides a standard of protection comparable to that under the PDPA, including contractual clauses with hosting and email providers.
8. Security
We implement administrative, technical, and physical safeguards appropriate to the nature of the data we hold, including HTTPS encryption on brewtrace.pro, access controls on staff systems, honeypot spam filtering on contact forms, and secure handling of payment data through certified payment processors. No method of transmission over the Internet is completely secure; we cannot guarantee absolute security but we review our practices periodically.
9. Your rights under the PDPA
Subject to exceptions in the PDPA, you may:
- Request access to personal data we hold about you;
- Request correction of inaccurate or incomplete data;
- Withdraw consent where processing is consent-based;
- Request information about how your data has been used or disclosed in the past year.
Submit requests to [email protected]. We may charge a reasonable fee for manifestly unfounded or excessive requests. We may refuse requests permitted under the PDPA, such as where disclosure would reveal personal data about another individual.
9a. Data breach notification
If a data breach occurs that is likely to result in significant harm or affect a significant number of individuals, we will notify the Personal Data Protection Commission and affected individuals as required under the PDPA, without undue delay.
10. Third-party links
Our website may link to third-party sites such as map services or social platforms. We are not responsible for their privacy practices. Review their policies before providing personal data.
11. Children
Our website is not directed at children under thirteen. We do not knowingly collect personal data from children without parental consent. Contact us if you believe we have collected a child's data in error.
12. Changes to this Policy
We may update this Privacy Policy to reflect legal, operational, or technical changes. The "Last updated" date at the top will change accordingly. Material changes will be noted on our website. Continued use after changes constitutes acknowledgement of the updated Policy.
13. Contact
BrewTrace Pte. Ltd.
28 Telok Ayer Street, #02-04, Singapore 048420
Email: [email protected]
Phone: +65 6951 2847
14. Do Not Call Registry
Where applicable under Singapore telemarketing rules, we honour requests not to receive marketing voice calls or text messages. Operational messages about bookings you have made are not marketing and may still be sent as necessary.
15. Accuracy of personal data
You are responsible for providing accurate contact details when submitting forms. If your email address or phone number changes, notify us so booking confirmations and replies reach you. We are not liable for failed delivery caused by outdated information you provided.
16. Automated decision-making
BrewTrace does not use solely automated processing, including profiling, that produces legal or similarly significant effects on individuals. Spam filtering on contact forms uses automated honeypot checks; submissions caught by honeypots are discarded without human review of personal content.
17. Complaints to the PDPC
If you believe we have not handled your personal data in accordance with the PDPA, you may contact us first at [email protected]. You also have the right to lodge a complaint with the Personal Data Protection Commission of Singapore if the matter is not resolved to your satisfaction.
18. Definitions
In this Policy, "personal data" has the meaning given in the PDPA — data about an individual who can be identified from that data or from that data and other information to which we have or are likely to have access. "Processing" includes collection, use, disclosure, and storage.
19. Language
This Privacy Policy is published in English. If translated versions are provided for convenience, the English version prevails in case of inconsistency. Correspondence regarding personal data may be conducted in English or Mandarin where our team has capacity to respond accurately.
20. Records of consent
When you submit our contact form with the PDPA consent checkbox, we record the fact of consent and the timestamp of submission as part of the enquiry record. We do not store the checkbox state separately from the message content. Withdrawal of consent for future marketing does not delete historical enquiry records required for audit or dispute purposes.
21. CCTV and in-store recording
For security and safety, CCTV may operate in the coffeehouse and shared building areas under building management rules. Signage is displayed at entry. Footage is retained for a limited period and accessed only on a need-to-know basis by authorised staff or building management when investigating incidents. CCTV is not used for marketing or guest profiling.
22. Access request procedure
To request access to personal data we hold about you, email [email protected] with subject line "PDPA access request". Include your full name, contact email, and a description of the data sought. We verify identity before release — typically by confirming details matching our records. We respond within thirty calendar days unless an extension is permitted under the PDPA. We may charge a reasonable fee for manifestly unfounded or excessive requests.
23. Correction request procedure
Correction requests use the same channel as access requests. Specify the data you believe is inaccurate and provide the correct information. We investigate and respond within thirty calendar days. If we disagree with a correction, we note your objection on file and explain our decision.
24. Withdrawal of consent
You may withdraw consent for processing that relies on consent by emailing [email protected]. Withdrawal does not affect the lawfulness of processing completed before withdrawal. Active catering contracts or confirmed bookings may require continued retention of certain contact details for operational and legal reasons.
25. Payment and transaction data
Card and PayNow payments at the coffeehouse are processed through certified payment service providers. BrewTrace receives transaction confirmations and amounts but does not store full card numbers, CVV codes, or magnetic stripe data on our systems. Receipts may include partial card identifiers as required by accounting practice. Refund records are retained as required by tax law.
26. Email and correspondence
When you email [email protected], your message, email address, and attachments are stored in our mail system for as long as needed to resolve the enquiry and maintain business records. Email may transit servers outside Singapore depending on providers. We do not use tracking pixels in routine hospitality correspondence.
27. Service providers and processors
We engage service providers for website hosting, email delivery, payment processing, and accounting. These providers process personal data only on our instructions and under confidentiality obligations. We review provider practices periodically and require reasonable security measures. A list of processor categories is available on request to [email protected].
28. Aggregated and anonymised data
We may create aggregated statistics from website traffic, cupping attendance, or sales patterns that do not identify individuals. Such data supports staffing, lot ordering, and content improvement. Anonymised data that cannot reasonably re-identify individuals falls outside PDPA personal data requirements.
29. Marketing and newsletters
We do not send unsolicited marketing email without opt-in consent. If you subscribe to lot-arrival updates, each message includes an unsubscribe mechanism. Service messages about confirmed bookings, cupping sessions, or catering quotes are not marketing and may be sent without separate marketing consent where necessary to fulfil your request.
30. Employee and contractor data
Personal data of BrewTrace employees and contractors is handled under internal HR policies separate from this website policy. Staff who access guest enquiry data receive briefing on confidentiality and breach reporting. Access to contact form submissions is limited to roles that require it.
31. Data minimisation
We collect only personal data reasonably necessary for the purposes stated in this Policy. Contact forms require name, email, and message — phone is optional. We do not ask for government ID, financial account credentials, or health records through the website. Please do not submit sensitive data via our contact form.
32. Accountability and policy review
BrewTrace reviews this Privacy Policy at least annually and whenever we introduce new data collection channels — for example, online booking widgets or new payment methods. Internal records of processing activities help us respond to access requests and demonstrate PDPA accountability.