Privacy Policy

Last updated: 21 July 2026

BeanSpark Pte. Ltd. ("BeanSpark", "we", "us", "our") respects your privacy and is committed to protecting personal data in accordance with the Personal Data Protection Act 2012 of Singapore ("PDPA"). This policy explains what information we collect, why we collect it, how we use and safeguard it, and the choices available to you when you visit beanspark.life or our specialty coffee court at 11 Purvis Street, #02-02, Singapore 188590.

1. Data controller

The data controller responsible for personal data processed through our website and café is BeanSpark Pte. Ltd., UEN 202447291N. Privacy enquiries: [email protected]. Telephone: +65 6953 4172. We will respond to PDPA requests within thirty calendar days unless a longer period is permitted under the PDPA.

2. Scope

This policy applies to personal data collected when you visit beanspark.life, submit our contact form, email or telephone us, visit our coffee court, place orders, attend events, or enquire about catering and retail partnerships. It does not apply to third-party websites linked from our pages. We encourage you to review the privacy practices of any external site you visit.

3. Personal data we collect

Contact form: When you submit an enquiry, we collect your full name, email address, optional telephone number, enquiry type, message content, and PDPA consent confirmation. You must tick the consent checkbox before submission.

In-store: When you visit the court, we may collect your name and contact details for table bookings, event reservations, or catering orders. Point-of-sale transactions record order details; card payments are processed by our payment terminal provider and we do not store full card numbers on our systems.

Website technical data: Our web server may log IP address, browser type, referring URL, pages viewed, and timestamps. We use essential cookies and localStorage as described in our cookie policy. We do not deploy third-party advertising trackers on this site.

CCTV: For security and safety, CCTV operates in the coffee court and shared building areas under building management rules. Signage is displayed at entry. Footage is retained for a limited period and accessed only on a need-to-know basis.

4. Purposes of collection and use

We collect and use personal data for legitimate business purposes including: responding to enquiries submitted via the website, email, or telephone; processing table bookings, private cuppings, and event requests; arranging catering and retail partnership discussions; fulfilling orders and providing customer service at the court; complying with legal, regulatory, and accounting obligations; protecting the security of our premises, staff, and guests; improving our website through aggregated, non-identifying analytics where applicable; and sending service-related communications you have requested or that are necessary to perform a contract with you.

We will not use your personal data for purposes incompatible with those described above without notifying you and, where required, obtaining fresh consent.

5. Legal basis and consent

Under the PDPA, we rely on consent, contractual necessity, legal obligation, and legitimate interests as appropriate to each processing activity. Contact form submissions require explicit PDPA consent via checkbox. You may withdraw consent at any time by emailing [email protected], though withdrawal does not affect processing already lawfully completed.

6. Disclosure to third parties

We do not sell personal data. We may share data with service providers who assist with email delivery, hosting, accounting, or payment processing, bound by confidentiality and data protection obligations; professional advisers (lawyers, auditors) where necessary; and public authorities when required by law or court order. Where data is transferred outside Singapore, we take reasonable steps to ensure recipients provide a standard of protection comparable to the PDPA.

7. Retention

We retain personal data only as long as necessary for the purposes collected. Contact form records are typically retained for twenty-four months unless a longer period is needed for ongoing business correspondence. CCTV footage follows our internal retention schedule and building management policy. Cookie consent choices are stored for six months via localStorage. When data is no longer required, we securely delete or anonymise it.

8. Security

We implement appropriate administrative, technical, and physical safeguards to protect personal data against unauthorised access, collection, use, disclosure, copying, modification, or disposal. Our website is served over HTTPS. Staff receive PDPA briefing on handling guest information. No method of transmission over the internet is completely secure; we encourage you to use strong passwords for any accounts you maintain with us.

9. Your rights under the PDPA

Subject to exceptions in the PDPA, you may request access to personal data we hold about you; request correction of inaccurate or incomplete data; withdraw consent for processing that relies on consent; and enquire about our data protection policies and practices. Submit requests to [email protected]. We may charge a reasonable fee for manifestly unfounded or excessive access requests. We will verify your identity before releasing data. If you are not satisfied with our response, you may contact the Personal Data Protection Commission (PDPC) of Singapore at www.pdpc.gov.sg.

10. Marketing communications

We do not send unsolicited marketing email without opt-in consent. If you subscribe to updates, each message includes an unsubscribe mechanism. Service-related messages (booking confirmations, catering quotes) are not marketing and may be sent without separate marketing consent where necessary to fulfil your request.

11. Do Not Call Registry

Where we telephone individuals for marketing purposes, we will check against the Do Not Call Registry unless an exception applies. Service calls related to existing bookings or catering orders are not marketing and may be placed as necessary to fulfil your request.

12. Children

Our website and coffee court are not directed at children under thirteen. We do not knowingly collect personal data from children without parental consent. Contact us if you believe we have collected a child's data in error.

13. Data breach notification

In the event of a data breach that is likely to result in significant harm or affect a significant number of individuals, we will notify the PDPC and affected individuals as required under the PDPA. Our internal incident response procedure includes containment, assessment, remediation, and documentation steps designed to minimise impact and prevent recurrence.

14. Automated decision-making

BeanSpark does not use automated decision-making or profiling that produces legal or similarly significant effects on individuals. Contact form routing and spam filtering may use automated rules (such as honeypot fields) but do not affect your legal rights or access to our services.

15. Changes to this policy

We may update this privacy policy to reflect legal, operational, or business changes. The "Last updated" date at the top will change accordingly. Material changes will be highlighted on the website where practicable. Continued use of our services after updates constitutes acknowledgement of the revised policy.

16. Contact

BeanSpark Pte. Ltd., 11 Purvis Street, #02-02, Singapore 188590
Email: [email protected] · Telephone: +65 6953 4172

Related: Legal notice · Terms of use · Cookie policy

17. Definitions

In this policy, "personal data" means data about an individual who can be identified from that data, or from that data and other information to which we have or are likely to have access, as defined under the PDPA. "Processing" includes collection, use, disclosure, and storage. "Website" means beanspark.life and its subpages. "Coffee court" means our physical premises at 11 Purvis Street, #02-02.

18. Categories of individuals

We process personal data relating to website visitors who browse or submit forms; café guests who order, book tables, or attend events; catering and retail partners who correspond with us commercially; job applicants if we advertise roles; and suppliers or contractors who provide goods or services to BeanSpark. Each category is handled only for purposes relevant to that relationship.

19. Accuracy of personal data

We take reasonable steps to ensure personal data we use is accurate and complete. If you notify us that your contact details have changed, we update booking records and correspondence files promptly. You may request correction of inaccurate data under section 9 above. We rely on you to provide truthful information when submitting enquiries — false details may delay or prevent us from responding.

20. Notification of purposes

Before or at the point of collection, we inform individuals of the purposes for which personal data is collected, unless exceptions under the PDPA apply. Our contact form displays a PDPA consent statement before submission. In-store, staff explain why name and phone number are requested for bookings. We do not collect personal data for unstated purposes without fresh notification and consent where required.

21. Access requests — process

To submit an access request, email [email protected] with subject line "PDPA access request" and include your full name, contact email, and a description of the data you seek. We verify identity before release — typically by confirming details matching our records. We respond within thirty calendar days unless an extension is permitted. Access may be refused where the PDPA allows, including where disclosure would reveal confidential commercial information or personal data about another individual without consent.

22. Correction requests — process

Correction requests follow the same channel as access requests. Specify the data you believe is inaccurate and provide the correct information. We investigate and respond within thirty calendar days. If we disagree with a correction request, we note your objection on file and inform you of our decision and reasons.

23. Withdrawal of consent

You may withdraw consent for processing that relies on consent by emailing [email protected]. Withdrawal does not affect the lawfulness of processing completed before withdrawal. Some services — such as responding to an active catering contract — may require continued retention of certain data for legal or operational reasons even after marketing consent is withdrawn.

24. Data protection officer contact

BeanSpark is a small hospitality operator. Privacy enquiries and PDPA requests are handled by our management team reachable at [email protected]. We do not maintain a separate data protection officer mailbox, but we treat privacy correspondence with the same priority as guest service issues.

25. Employee and staff data

Personal data of BeanSpark employees and contractors is handled under internal HR policies separate from this website policy. Staff who access guest data receive briefing on confidentiality, secure handling, and reporting suspected breaches. Access to contact form submissions and booking records is limited to staff who need it for their role.

26. Payment data

Card payments at the coffee court are processed through our payment terminal provider. We receive transaction confirmations and amounts but do not store full card numbers, CVV codes, or magnetic stripe data on BeanSpark systems. PayNow and other electronic payments similarly flow through certified processors. Receipts may include partial card identifiers as required by accounting practice.

27. Email communications

When you email [email protected], your message, email address, and any attachments are stored in our mail system for as long as needed to resolve the enquiry and maintain a business record. Email may transit servers outside Singapore depending on your provider and ours. We do not use email tracking pixels on routine correspondence.

28. Aggregated and anonymised data

We may create aggregated statistics from website traffic or sales patterns that do not identify individuals. Such data may be used to improve menu planning, staffing, and website content. Anonymised data falls outside PDPA personal data requirements when individuals cannot reasonably be re-identified.

29. Complaints to the PDPC

If you believe we have not handled your personal data in accordance with the PDPA, contact us first at [email protected] so we can investigate. If you remain unsatisfied, you may lodge a complaint with the Personal Data Protection Commission of Singapore at www.pdpc.gov.sg. We cooperate with regulatory enquiries as required by law.

30. Records of processing

We maintain internal records of key processing activities including contact form handling, booking management, CCTV operation, and third-party service providers. These records help us respond to access requests and demonstrate accountability under the PDPA accountability obligation.