Privacy
Privacy Policy
Last updated: 21 July 2026
This Privacy Policy explains how RoastRush Pte. Ltd. collects, uses, discloses, and protects personal data in accordance with the Personal Data Protection Act 2012 (PDPA) of Singapore.
1. Organisation identity
RoastRush Pte. Ltd. (UEN 202531682K) operates the roastrush.life website and the micro-roastery café at 9 Kim Yam Road, #01-04, Singapore 239328. We are the organisation responsible for personal data collected through this website, in-store interactions, bookings, retail purchases, office subscriptions, and related communication channels.
For privacy-related enquiries, contact our Privacy Officer at [email protected] or write to the registered address above. General café enquiries may be sent to [email protected], but please mark privacy requests clearly so they reach the Privacy Officer without delay.
2. Scope
This policy applies to personal data we collect from guests, website visitors, cupping participants, retail customers, office subscription clients, event hosts, job applicants (if listed), and individuals who subscribe to our mailing list. It does not apply to anonymised or aggregated data that cannot reasonably identify an individual, nor to third-party websites linked from our pages.
3. Personal data we collect
Depending on your interaction with us, we may collect:
- Identity and contact data: name, email address, telephone number, billing or delivery address for subscriptions.
- Booking and enquiry data: preferred visit dates, party size, subject of enquiry, message content submitted via our contact form.
- Transaction data: purchase history, payment method type (we do not store full card numbers on our servers when payments are handled by processors), invoice references.
- Technical data: IP address, browser type, device identifiers, pages viewed, referral URL, and cookie identifiers as described in our Cookie Policy.
- Communication records: email correspondence, call notes where you consent to recording or note-taking, feedback on cupping sessions.
- Marketing preferences: mailing list opt-in status, unsubscribe requests, campaign engagement where analytics cookies are accepted.
We do not intentionally collect sensitive personal data such as government ID numbers through the website contact form. If you voluntarily provide such information, we will delete it unless a specific legal obligation requires retention.
4. Purposes of collection and use
We collect and use personal data for purposes that a reasonable person would consider appropriate in the context of operating a specialty coffee café and micro-roastery, including:
- Responding to enquiries submitted through contact.php and email.
- Scheduling and managing cupping sessions, event brewing, and office subscriptions.
- Processing retail and hospitality transactions, issuing receipts, and handling refunds where applicable.
- Operating our roast calendar communications and service updates to existing customers.
- Sending marketing communications where you have provided consent or where permitted under PDPA for existing customers in relation to similar products.
- Maintaining website security, diagnosing technical faults, and preventing fraud or abuse.
- Complying with legal obligations, including tax record-keeping and responses to lawful requests from authorities.
- Improving our menu, roast offerings, and guest experience through aggregated analysis where analytics cookies are consented to.
We will not use your personal data for purposes incompatible with those described unless we notify you and, where required, obtain fresh consent.
5. Legal bases and consent
Under the PDPA, we rely on one or more of the following:
- Consent: for example, when you tick the consent checkbox on our contact form (consent_pdpa), subscribe to a mailing list, or accept non-essential cookies.
- Contractual necessity: processing needed to fulfil a purchase, subscription, or booked service you requested.
- Legitimate interests: such as securing our website and preventing spam, balanced against your rights — for example, honeypot and server log analysis.
- Legal obligation: retaining transaction records as required by Singapore law.
You may withdraw consent for marketing or non-essential cookies at any time without affecting the lawfulness of processing before withdrawal. Withdraw marketing consent via unsubscribe links or by emailing [email protected].
6. Disclosure of personal data
We do not sell personal data. We may disclose data to:
- Service providers who assist with email delivery, website hosting, payment processing, accounting, and analytics (where consented).
- Professional advisers bound by confidentiality obligations.
- Law enforcement or regulators when required by applicable law.
- Successors in the event of a merger or acquisition, subject to continued protection consistent with this policy.
Third-party processors are engaged under contracts requiring appropriate security and use limited to instructed purposes.
7. Cross-border transfers
Some sub-processors (for example email or cloud hosting providers) may store or process data outside Singapore. Where this occurs, we take steps reasonably required under the PDPA to ensure recipients provide a standard of protection comparable to the PDPA, such as contractual clauses and vendor assessment.
8. Retention
We retain personal data only as long as necessary for the purposes collected, unless a longer period is required by law:
| Data category | Typical retention |
|---|---|
| Contact form enquiries | 24 months after last correspondence |
| Transaction records | 7 years for tax and audit purposes |
| Marketing subscriptions | Until unsubscribe plus 12 months suppression log |
| Server logs | 90 days unless needed for security investigation |
| Cookie analytics (if consented) | Per vendor settings, max 26 months |
When data is no longer needed, we delete or anonymise it securely.
9. Security
We implement reasonable administrative, technical, and physical safeguards appropriate to the nature of our operations — including access controls for staff systems, HTTPS on the website, and limited access to guest records. No method of transmission over the Internet is completely secure; we cannot guarantee absolute security but we review practices periodically.
10. Your rights under the PDPA
Subject to exceptions in the PDPA, you may:
- Request access to personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Withdraw consent where processing is consent-based.
- Enquire about how your data has been used or disclosed within the last year.
Submit requests to [email protected]. We may need to verify identity before responding. We aim to respond within thirty days. A reasonable fee may apply to access requests as permitted by law.
11. PDPC contact
If you have concerns about our handling of personal data, contact us first so we can address them. You may also contact the Personal Data Protection Commission (PDPC) in Singapore:
Personal Data Protection Commission
Website: https://www.pdpc.gov.sg
12. Cookies and similar technologies
We use cookies and local storage for strictly necessary functions and, with consent, analytics and preferences. Details appear in our Cookie Policy, including how to change choices via our banner (Accept / Reject / Customise).
13. Children
Our website and café services are directed at adults and general hospitality guests. We do not knowingly collect personal data from children under thirteen without parental consent. Contact us if you believe we have collected such data in error.
14. Third-party links
Our site may link to external platforms (for example map services or social profiles if added). Those sites have their own privacy practices; we are not responsible for their content or policies.
15. Automated decision-making
We do not use automated decision-making or profiling that produces legal or similarly significant effects on individuals. Spam filtering and payment fraud checks may involve automated scoring by processors under their policies.
16. Data breach notification
If a data breach likely to result in significant harm occurs, we will assess obligations under the PDPA and notify the PDPC and affected individuals where required, documenting remedial steps taken.
17. Changes to this policy
We may update this Privacy Policy to reflect operational, legal, or regulatory changes. Material updates will be posted on this page with a revised "Last updated" date. Continued use of the website after changes constitutes acknowledgement where permitted by law.
18. In-store collection
When you visit our Kim Yam Road café, we may collect personal data verbally or in writing for table service, loyalty stamp cards (if offered), or payment receipts. CCTV may operate in public areas of the premises for security purposes with signage displayed at entry. CCTV footage is retained for a limited period unless needed for incident investigation. We do not use facial recognition software to identify guests.
Point-of-sale systems may record transaction times, item totals, and payment method type. Card payments are processed by payment terminals under PCI-DSS practices; we do not store full card numbers in our own databases.
19. Mailing list
Separate from transactional email, our roast calendar mailing list requires explicit opt-in — either through a dedicated signup form or a clearly marked checkbox unrelated to contact-form consent. Each marketing email includes an unsubscribe link. We maintain a suppression list so withdrawn addresses are not re-added without fresh consent.
20. Change log
- 21 July 2026: Initial publication aligned with roastrush.life site launch.