Privacy
Privacy Policy
Effective date: 21 July 2026 · Governed by Singapore PDPA 2012
1. Organisation identity
BeanRush Pte. Ltd. (UEN 202519847C), located at 48 Club Street, #01-03, Singapore 069425, is the data organisation responsible for personal data collected through our café operations, this website (beanrush.pro), and related hospitality services including bookings, mailing lists, retail orders, office bean subscriptions, and event catering enquiries.
We operate a specialty espresso bar and café. We are not a marketing agency, software vendor, or online course provider. Personal data is collected only for lawful hospitality and business purposes described in this policy.
2. Privacy Officer contact
For access, correction, withdrawal-of-consent, or general privacy enquiries, contact our Privacy Officer:
Email: [email protected]
Postal: Privacy Officer, BeanRush Pte. Ltd., 48 Club Street, #01-03, Singapore 069425
Phone: +65 6912 8473 (Tue–Sun 08:00–18:00 SGT)
We aim to acknowledge privacy requests within ten business days and resolve straightforward access or correction requests within thirty days, subject to PDPA exceptions.
3. Personal data we may collect
Depending on how you interact with BeanRush, we may collect:
- Identity and contact data: name, email address, phone number, company name, billing or delivery address for retail and subscription orders.
- Enquiry and booking data: messages submitted via our contact form, preferred visit dates, catering headcount, dietary or allergen notes you voluntarily provide.
- Transaction data: purchase history, payment method type (not full card numbers stored by us when processed by payment providers), subscription schedules.
- Marketing preferences: mailing-list opt-in status where you have given consent.
- Technical data: IP address, browser type, device identifiers, pages viewed — primarily via cookies and analytics where you have consented (see our Cookie Policy).
- CCTV: our shophouse premises may use CCTV for security; signage is displayed on site.
We do not intentionally collect sensitive personal data unless required for a specific lawful purpose (for example, allergen information you choose to share for catering safety) and with your knowledge.
4. Purposes of collection, use and disclosure
We collect and use personal data for purposes including:
- Responding to visit, booking, catering, retail and wholesale enquiries submitted through our website or email.
- Processing café orders, retail bean purchases, and office subscription deliveries.
- Managing payments and issuing receipts or tax documentation where applicable.
- Operating mailing lists and promotional communications where you have opted in.
- Improving our website and guest experience through analytics where consented.
- Complying with legal obligations, including food-safety traceability, accounting, and lawful requests from authorities.
- Protecting our staff, guests, and premises through reasonable security measures including CCTV where posted.
We do not sell personal data. We disclose data to service providers only where necessary — for example email delivery, payment processing, accounting, delivery logistics, and analytics vendors — under contractual obligations requiring appropriate protection.
5. Legal bases and consent
Under the Personal Data Protection Act 2012 (PDPA), we rely on:
- Consent: contact form submissions require an explicit PDPA consent checkbox that is not pre-ticked. Mailing-list sign-ups require separate opt-in.
- Contractual necessity: processing orders and subscriptions you request.
- Legal obligation: retaining records required by tax or regulatory rules.
- Legitimate interests: site security, fraud prevention, and improving hospitality operations — balanced against your rights and with opt-out where applicable.
You may withdraw consent for marketing or optional analytics at any time by contacting the Privacy Officer. Withdrawal does not affect processing already lawfully completed.
6. Cookies and similar technologies
Our website uses strictly necessary cookies for basic operation and, with your consent, optional analytics and preference cookies. Details including categories, vendors, retention, and how to change consent appear in our Cookie Policy. Cookie consent choices are stored locally for approximately six months unless you clear browser storage sooner.
7. Retention
We retain personal data only as long as necessary for the purposes collected:
- Enquiry records: typically up to twenty-four months unless a transaction follows.
- Order and subscription records: duration of relationship plus period required by Singapore tax and accounting law (generally five to seven years for financial records).
- Marketing lists: until you unsubscribe or withdraw consent.
- Analytics logs: per vendor defaults, typically thirteen to twenty-six months where consented.
- CCTV footage: rolling retention per on-site policy, generally not exceeding thirty days unless required for incident investigation.
When data is no longer needed, we delete or anonymise it using reasonable measures.
8. Access, correction and portability
You may request access to personal data we hold about you or correction of inaccurate data by writing to the Privacy Officer. We may charge a reasonable fee for manifestly unfounded or excessive requests as permitted by PDPA. We will verify identity before disclosing data.
Where technically feasible and required by law, we will provide data in a commonly used machine-readable format for requests relating to data you provided with consent.
9. Security measures
We implement reasonable administrative, technical, and physical safeguards appropriate to a small hospitality business — including access controls for staff systems, HTTPS on this website, secure handling of payment data through PCI-compliant processors, and locked storage for paper records where used.
No method of transmission over the internet is completely secure. We encourage you to use strong passwords for any accounts we provide and to contact us promptly if you suspect unauthorised access.
10. Cross-border transfers and sub-processors
Some service providers (email, analytics, cloud hosting, payment gateways) may process data on servers outside Singapore. Where personal data is transferred overseas, we take steps required under PDPA — including contractual clauses ensuring comparable protection — and disclose this transparency in vendor agreements where applicable.
Current categories of sub-processors may include: web hosting within Asia-Pacific regions, transactional email providers, payment processors, and analytics platforms when consented. Specific vendor names appear in our Cookie Policy for analytics; other vendors may be listed on request.
11. Children's data
Our website and café services are directed at general audiences, not children under thirteen. We do not knowingly collect personal data from children without parental consent. Contact the Privacy Officer if you believe we have collected a child's data in error.
Where families visit the café together, any loyalty or mailing-list registration must be completed by a parent or guardian. We do not profile children's behaviour through optional analytics cookies without appropriate consent frameworks.
12. Marketing communications
We send promotional email or messaging only where you have opted in with clear affirmative consent — for example ticking a separate mailing-list box at the counter or on a future subscription form. Every marketing message includes an unsubscribe link or reply-to-stop instruction. We do not purchase third-party email lists or append data from unrelated "rush" or finance marketing databases.
Operational messages about your order, subscription delivery, or a reply to your enquiry are service communications, not marketing, and do not require separate marketing consent though they still use your contact details proportionately.
13. Data breach notification
If a data breach likely to result in significant harm occurs, we will assess promptly and notify the Personal Data Protection Commission (PDPC) and affected individuals as required under Singapore law.
14. PDPC contact
If you remain unsatisfied after contacting us, you may lodge a complaint with the Personal Data Protection Commission (PDPC), Singapore:
Website: https://www.pdpc.gov.sg
15. Third-party links
This website may link to external sites (for example maps or social platforms). Their privacy practices are governed by their own policies. We are not responsible for third-party handling of your data.
16. Changes to this policy
We may update this Privacy Policy to reflect operational or legal changes. Material updates will be posted on this page with a revised effective date. Continued use of our services after posting constitutes notice of the update where permitted by law.
Change log
- 21 July 2026 — Initial policy published for beanrush.pro launch.