PDPA 2012
Privacy Policy
How RoastDrive Pte. Ltd. collects, uses, discloses and protects personal data when you visit our café, website or contact us.
Last updated: 21 July 2026
RoastDrive Pte. Ltd. ("RoastDrive", "we", "us" or "our") respects your privacy and is committed to protecting personal data in accordance with the Personal Data Protection Act 2012 of Singapore ("PDPA"). This Privacy Policy explains what data we collect, why we collect it, how we use and disclose it, how long we retain it, your rights and how to contact us or the Personal Data Protection Commission (PDPC).
1. Organisation identity
RoastDrive Pte. Ltd. operates a specialty roast-journey café at 215 Upper Thomson Road, #01-04, Singapore 574349 (UEN 202652903M). We provide walk-in hospitality, retail coffee bags, light food service and small wholesale or event brew arrangements. This policy applies to personal data collected through our website (roastdrive.life), contact forms, email, telephone, in-person visits and related wholesale or event enquiries.
2. Personal data we collect
Depending on how you interact with us, we may collect the following categories of personal data:
- Identity and contact data: name, email address, telephone number and organisation name (for wholesale or event enquiries).
- Enquiry and correspondence data: messages you submit via our contact form, email content, subject selections and any attachments you choose to provide.
- Consent records: timestamps and records of PDPA consent checkboxes submitted with forms, and cookie consent choices stored in your browser.
- Technical and usage data: IP address, browser type, device information, pages visited, referral URLs and approximate session duration when you use our website and when optional analytics cookies are enabled with your consent.
- Café visit data (limited): if you join our retail notification list at the counter, we may record your email address and stated coffee preferences. We do not operate facial recognition or covert recording for marketing purposes.
- Wholesale and event data: delivery addresses, billing contacts, event dates, guest counts and brew specifications necessary to fulfil contracted hospitality services.
We do not intentionally collect sensitive personal data such as national registration identity numbers, financial account numbers or health records through our standard café contact channels. Please do not submit medical diagnoses or unrelated sensitive information in general enquiry forms.
3. Purposes of collection, use and disclosure
We collect and use personal data for purposes that a reasonable person would consider appropriate in the context of café hospitality and related operations, including:
- Responding to your enquiries about visits, seasonal batches, retail bags, wholesale orders or event brew bars;
- Coordinating orders, deliveries, rest dates and service logistics for wholesale or event clients;
- Operating and securing our website, including fraud prevention and spam filtering (including honeypot fields on forms);
- Understanding aggregated website traffic patterns when you consent to analytics cookies;
- Complying with legal, regulatory, tax and accounting obligations in Singapore;
- Establishing, exercising or defending legal claims where necessary;
- Internal training and quality review of guest correspondence, using redacted examples where feasible.
We do not sell personal data. We do not use your contact details to imply medical benefits from coffee, to market motoring services or to promote unrelated agency products.
4. Legal bases and consent
Under the PDPA, we rely primarily on consent for marketing-related communications and optional analytics cookies. For responding to enquiries you initiate, fulfilling hospitality contracts and complying with law, we may rely on consent, contractual necessity and legitimate interests assessed in a manner consistent with the PDPA.
Contact form submission requires an explicit, non-pre-ticked consent checkbox (consent_pdpa) acknowledging this Privacy Policy. You may withdraw consent for optional processing by emailing [email protected]; withdrawal does not affect processing already performed lawfully before withdrawal, and we may still retain certain records where required by law.
5. Disclosure to third parties
We may disclose personal data to:
- Email and hosting providers that transmit or store messages and website logs on our behalf under contractual confidentiality obligations;
- Analytics providers only when you accept analytics cookies — currently limited to privacy-oriented or aggregated traffic tools configured to minimise identifiable transfer where practicable;
- Professional advisers such as accountants or legal counsel when necessary and subject to duty of confidence;
- Regulators or law enforcement when required by applicable Singapore law or court order.
We require processors handling data on our behalf to implement appropriate security measures and process data only for specified purposes.
6. Cross-border transfers
Our website hosting, email delivery and certain analytics subprocessors may store or process data on servers located outside Singapore, including in the United States or European Economic Area. Where personal data is transferred overseas, we take steps reasonably required under the PDPA to ensure recipients provide a standard of protection comparable to the PDPA, such as contractual clauses and vendor diligence. Details of specific sub-processors may be requested via [email protected].
7. Retention
We retain personal data only as long as necessary for the purposes described above:
- General enquiry records: typically up to twenty-four months from last correspondence, unless a longer period is needed for dispute resolution;
- Wholesale and event contract records: up to seven years for accounting and legal compliance;
- Cookie consent choices: up to six months in local storage, then re-prompted;
- Server and security logs: typically up to ninety days unless investigation requires extension.
When retention expires, we delete or anonymise data using reasonable technical measures.
8. Security measures
We implement administrative, technical and physical safeguards appropriate to a small hospitality business, including access controls on email accounts, HTTPS transport encryption for the website, form validation and honeypot spam filtering, staff confidentiality expectations and secure disposal of paper records where used. No method of transmission over the Internet is completely secure; we encourage you to use strong passwords on your own email accounts when corresponding with us.
9. Your rights under the PDPA
Subject to exceptions in the PDPA, you may:
- Request access to personal data about you that is in our possession or under our control;
- Request correction of inaccurate or incomplete personal data;
- Withdraw consent for optional processing such as analytics cookies or non-essential marketing lists;
- Request information about how your data has been used or disclosed within the preceding year where required by law.
We may charge a reasonable fee for manifestly unfounded or excessive access requests as permitted by the PDPA. We will respond within reasonable timeframes prescribed by applicable guidance.
10. Privacy Officer contact
For privacy requests, corrections, withdrawal of consent or questions about this policy, contact:
- Email: [email protected]
- Post: Privacy Officer, RoastDrive Pte. Ltd., 215 Upper Thomson Road, #01-04, Singapore 574349
- Telephone: +65 6971 5830 (Wed–Mon 08:30–18:30 SGT)
Please include sufficient detail for us to verify your identity and locate relevant records. We may request supporting information to prevent unauthorised disclosure.
11. PDPC contact
If you believe we have not handled your personal data in accordance with the PDPA, you may contact the Personal Data Protection Commission (PDPC) in Singapore after giving us a reasonable opportunity to address your concern. Visit the PDPC website at www.pdpc.gov.sg for current contact details and complaint procedures.
12. Cookies and similar technologies
Our website uses cookies and local storage as described in our Cookie Policy. Optional analytics and preference cookies are placed only after you accept all cookies or save customised preferences via the cookie banner. Strictly necessary cookies support basic site operation and consent memory.
13. Third-party links
Our website may contain links to third-party sites such as map services or importer pages. We are not responsible for the privacy practices of those sites. Review their policies before submitting personal data.
14. Children
Our website and wholesale enquiries are directed at adults. We do not knowingly collect personal data from children under thirteen without appropriate parental consent. Contact [email protected] if you believe we have collected a child's data in error.
15. Changes to this policy
We may update this Privacy Policy to reflect operational, legal or regulatory changes. The "Last updated" date at the top will change accordingly. Material changes may be highlighted on our website or communicated to wholesale clients where appropriate. Continued use of the website after updates constitutes acknowledgement of the revised policy for new processing activities relying on notice.
16. Change log
- 21 July 2026: Initial publication for roastdrive.life launch — covers website forms, cookie consent, wholesale enquiries and PDPA rights summary.