Effective 11 May 2026
Version 1.0
Applies to primewater.com.sg + customer accounts
This Privacy Policy explains how Strategic Team Consulting (operating as “Prime Water Singapore”, “we”, “our”) handles personal data we collect through primewater.com.sg, customer accounts, demo bookings, orders, and ongoing service. We comply with the Singapore Personal Data Protection Act 2012 (PDPA).
01Who we are
Prime Water Singapore is the trading name of Strategic Team Consulting, a Singapore-registered entity (UEN 201734567X). We are the authorised sole distributor of Prime Water Korean alkaline water ionizers in Singapore, KFDA Reg. No. 5427. Our office address and contact details are available on the Contact page.
02What personal data we collect
We only collect what we need to deliver the demo, sale, install, and ongoing support. Specifically:
- Contact details — name, phone number, email address.
- Delivery / install address — street address, unit, postal code (used to confirm we can install in your area and to schedule the visit).
- Account credentials — email and a hashed password if you sign in to manage your filter schedule, warranty, or affiliate dashboard. Passwords are stored only in hashed form via our authentication provider (Supabase Auth) and are never visible to us.
- Order & warranty information — product model, serial number, install date, filter replacement schedule.
- Communications — messages you send us via WhatsApp, email, contact form, or our admin portal.
- Referral programme data — if you join the affiliate programme, your name, contact details, phone country, and referral codes generated for you.
- Technical data — basic browser/device information (user agent, anonymous session ID) and IP address, logged for security and bot protection. We do not use third-party analytics or advertising cookies as of the effective date.
We do not collect NRIC numbers, FIN numbers, passport numbers, biometric data, financial account numbers, or medical records. We do not require these for any of our services.
03How we use your data
We use your personal data for the following purposes only:
- Fulfilling demo and order requests — scheduling, confirming, and following up on your free home demo or product order.
- Operating your account — letting you sign in to view your warranty status, filter replacement schedule, and order history.
- Customer support — responding to your questions, providing service updates, sending filter-due reminders.
- Affiliate programme administration — tracking referrals and calculating thank-you payouts to programme members.
- Service notifications — transactional WhatsApp / email messages relating to your booking, order, warranty, or filter replacements. These are not marketing messages and follow PDPA Section 11 (deemed consent for service-related communication).
- Security & abuse prevention — detecting bots, blocking malicious submissions, and protecting against fraud.
- Compliance — complying with applicable law, regulatory inquiries, and court orders.
We will not use your data for marketing purposes (newsletters, promotional broadcasts) without your separate, explicit consent.
04Who we share it with
We do not sell or rent your personal data to anyone. We share data only with trusted service providers who help us run our operations, and only the minimum data needed:
- Supabase (database + authentication) — stores your account credentials, orders, bookings, and account history. Supabase processes data in the United States and Europe under standard contractual protections.
- Google (Calendar API) — when you book a demo and we confirm it, an event with your name, address, phone, and visit notes is created on our internal scheduling calendar so our installer knows where and when to visit. Limited to confirmed-booking data only.
- Hostinger (web hosting) — serves the website you are reading. Access logs include IP and browser information by default and are retained per their standard policy.
- WhatsApp (Meta) — if you message us via WhatsApp, your messages and phone number are subject to WhatsApp’s own privacy policy.
- Law enforcement / regulators — only where required by Singapore law or a valid court order.
05Cookies & tracking
We use a small number of cookies and similar storage technologies:
- Strictly necessary cookies — required for the site to work: session storage for keeping you signed in, anonymous IDs for cart / configurator state. These cannot be disabled.
- Preference cookies — remember small UI choices like whether you collapsed the product side-dock. Stored only in your browser’s
localStorage, never transmitted to our servers.
- Analytics cookies — we currently do not deploy any third-party analytics (Google Analytics, Meta Pixel, etc.). If we do in the future, this policy will be updated and you will be asked to opt in via the consent banner before any analytics scripts load.
You can change your cookie preferences at any time using the cookie banner at the bottom of any page, or by clearing your browser’s site data for primewater.com.sg.
06How long we keep your data
- Account data — kept for as long as your account is active, plus 3 years after closure (to support warranty claims).
- Order & warranty records — kept for the full warranty period plus 7 years (Singapore tax record-keeping requirement).
- Demo bookings that didn’t convert — archived after 12 months.
- Contact form / WhatsApp messages — kept while we are actively helping you, then archived after 24 months unless you ask for earlier deletion.
- Anonymous technical / log data — rotated every 90 days.
07Your rights under the PDPA
Under Singapore’s PDPA, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Correct — ask us to fix any inaccurate or out-of-date information.
- Withdraw consent — tell us to stop using your data for any purpose that relies on consent. We will explain any consequences (e.g. we cannot keep delivering filter reminders without your contact details).
- Delete — ask us to delete data we are not legally required to retain.
- Object — raise concerns about how we are processing your data.
To exercise any of these rights, email our Data Protection Officer at primewater.sg@gmail.com with the subject line “PDPA Request”. We will respond within 30 days as required by the PDPA.
08Cross-border transfers
Some of our service providers (Supabase, Google, Hostinger) process data outside Singapore. We rely on industry-standard contractual safeguards (Standard Contractual Clauses or equivalent) to ensure your data is given a comparable standard of protection as required under the PDPA Transfer Limitation Obligation (PDPA Section 26).
09How we protect your data
- All data transmitted between your browser and our servers uses HTTPS encryption.
- Passwords are hashed using industry-standard algorithms (via Supabase Auth) and are never stored or transmitted in plain text.
- Database access is restricted by Row-Level Security policies — you can only read your own data, never another customer’s.
- Administrative access requires email-based authentication and is limited to the named admin account.
- We do not store payment card details on our servers — we currently accept PayNow only, processed directly by your bank.
No system is perfectly secure. If we become aware of a personal data breach that is likely to result in significant harm to you, we will notify the PDPC and affected individuals as required by the PDPA’s Data Breach Notification Obligation (Sections 26A-26E).
10Children’s data
Our services are intended for adult customers (18+). We do not knowingly collect personal data from children under 13. If you believe a child has provided us their data, contact our DPO and we will delete it.
11Changes to this policy
We may update this Privacy Policy from time to time — for example, when we add new features or change service providers. Material changes (anything that affects how we collect, use, or share your data) will be announced via WhatsApp/email to active customers at least 14 days before they take effect, and the “Effective” date at the top of this page will be updated.
生效日期 2026年5月11日
版本 1.0
适用范围 primewater.com.sg + 客户账户
本《隐私政策》说明 Strategic Team Consulting(运营品牌“Prime Water 新加坡”,下称“我们”)如何处理通过 primewater.com.sg、客户账户、上门体验预约、订单和持续服务所收集的个人资料。我们遵守新加坡《2012年个人资料保护法》(PDPA)。
01我们是谁
Prime Water 新加坡为 Strategic Team Consulting 的商号,新加坡注册实体(UEN 201734567X)。我们是韩国 Prime Water 碱性水离子机在新加坡的授权独家分销商,KFDA 注册编号 5427。本公司办公地址及联系方式详见联系页面。
02我们收集哪些个人资料
我们仅收集提供上门体验、销售、安装及后续支持所必需的资料。具体包括:
- 联系资料——姓名、电话号码、电邮地址。
- 送货 / 安装地址——街道地址、单位编号、邮编(用于确认服务范围并安排上门时间)。
- 账户凭证——若您注册账户以管理滤芯计划、保修或推荐人后台,我们会储存您的电邮及加密后的密码。密码仅以哈希形式存储于身份验证服务商(Supabase Auth),我们无法查看明文密码。
- 订单与保修资讯——产品型号、机器序列号、安装日期、滤芯更换计划。
- 通讯记录——您通过 WhatsApp、电邮、联系表单或后台与我们沟通的内容。
- 推荐计划资料——若您加入推荐计划,会保留姓名、联系方式、电话国别及生成的推荐码。
- 技术资料——基本浏览器/设备资讯(user agent、匿名 session ID)及 IP 地址,用于安全防护及防止机器人滥用。生效日期前,我们不使用任何第三方分析或广告 Cookies。
我们不收集 NRIC、FIN、护照号、生物识别资料、金融账户号或医疗记录。我们的服务无需上述资料。
03我们如何使用您的资料
我们仅将您的个人资料用于以下用途:
- 履行上门体验与订单——安排、确认及跟进您的免费上门体验或产品订单。
- 账户运营——让您登录后查看保修状态、滤芯更换计划及订单历史。
- 客户支持——回复您的问题、提供服务更新、发送滤芯到期提醒。
- 推荐计划管理——追踪推荐记录并计算奖励款项。
- 服务通知——关于预约、订单、保修或滤芯更换的交易型 WhatsApp / 电邮通讯。这些并非营销信息,依据 PDPA 第 11 条(服务相关通讯的视为同意)发送。
- 安全与防滥用——检测机器人、阻止恶意提交、防范欺诈。
- 合规——遵守适用法律、监管查询及法院命令。
未经您单独、明确同意,我们不会将您的资料用于营销(如新闻通讯、推广广播)。
04我们与谁共享资料
我们不出售或出租您的个人资料。仅在最低必要范围内与协助我们运营的可信服务商共享:
- Supabase(数据库 + 身份验证)——存储您的账户凭证、订单、预约及账户历史。Supabase 在美国和欧洲处理资料,受标准合同保护条款约束。
- Google(Calendar API)——当您预约上门体验并经我们确认后,系统会在内部排程日历上创建包含您姓名、地址、电话及备注的事件,方便安装人员前往。仅限已确认预约资料。
- Hostinger(网站托管)——提供本网站的托管服务。访问日志默认包含 IP 及浏览器资讯,依其标准政策保留。
- WhatsApp(Meta 旗下)——若您通过 WhatsApp 联系我们,您的消息及电话号码受 WhatsApp 自身隐私政策约束。
- 执法机关 / 监管机构——仅在新加坡法律或有效法院命令要求时披露。
05Cookies 与追踪
我们使用少量 Cookies 及类似存储技术:
- 必要 Cookies——网站运作所必需:保持登录的 session storage、用于购物车 / 配置器状态的匿名 ID。无法禁用。
- 偏好 Cookies——记住一些小型 UI 选择,如您是否收起产品侧栏。仅存储于您浏览器的
localStorage,从不传送至我们服务器。
- 分析 Cookies——目前我们不部署任何第三方分析(Google Analytics、Meta Pixel 等)。若日后启用,本政策将更新,并通过同意横幅请求您选择启用。
您可随时通过页面底部的 Cookie 横幅更改 Cookie 偏好,或清除浏览器中 primewater.com.sg 的网站资料。
06我们保留资料多久
- 账户资料——在账户活跃期间保留,关闭账户后再保留 3 年(用于保修索赔)。
- 订单与保修记录——在完整保修期之外再保留 7 年(新加坡税务记录要求)。
- 未成交的上门体验预约——12 个月后归档。
- 联系表单 / WhatsApp 消息——在为您积极提供帮助期间保留,24 个月后归档,除非您要求更早删除。
- 匿名技术 / 日志资料——每 90 天轮换一次。
07您在 PDPA 下的权利
依据新加坡 PDPA,您享有以下权利:
- 查阅——申请取得我们持有的关于您的个人资料副本。
- 更正——要求我们修正不准确或过时的资料。
- 撤回同意——通知我们停止依据同意进行的任何资料使用。我们会说明可能的影响(例如若无您的联系方式,将无法继续发送滤芯到期提醒)。
- 删除——要求删除法律上无须保留的资料。
- 异议——对资料处理方式提出疑虑。
如需行使上述权利,请以“PDPA Request”为邮件主旨,发送至我们的资料保护官 primewater.sg@gmail.com。我们将在 PDPA 规定的 30 天内回复。
08跨境资料传输
部分服务商(Supabase、Google、Hostinger)在新加坡境外处理资料。我们依靠业界标准的合同保障措施(如 Standard Contractual Clauses 或同等条款),确保您的资料获得与新加坡 PDPA 第 26 条“资料传输限制义务”相当的保护水准。
09我们如何保护您的资料
- 您浏览器与我们服务器之间的所有数据传输皆采用 HTTPS 加密。
- 密码使用业界标准算法(通过 Supabase Auth)哈希化,绝不以明文存储或传输。
- 数据库访问受行级安全策略(Row-Level Security)限制——您仅可读取自己的资料,绝不会看到其他客户的资料。
- 管理员访问需通过电邮身份验证,且仅限指定的管理员账户。
- 我们不在服务器上存储付款卡资料——目前仅接受 PayNow,由您的银行直接处理。
没有任何系统是绝对安全的。若我们发现可能对您造成重大损害的个人资料泄露,我们将依据 PDPA 资料泄露通报义务(第 26A-26E 条)通知 PDPC 及受影响个人。
10儿童资料
本服务面向成年客户(18 岁以上)。我们不会有意收集 13 岁以下儿童的个人资料。若您发现有儿童向我们提交资料,请联系资料保护官,我们将予以删除。
11本政策的变更
我们可能不时更新本《隐私政策》——例如新增功能或更换服务商时。重大变更(涉及资料收集、使用或共享方式的任何变动)将至少在生效前 14 天通过 WhatsApp / 电邮通知活跃客户,本页顶部的“生效日期”亦会更新。
12联系我们的资料保护官