Privacy policy
The Chart Room · Singapore
Last updated: 17 August 2026
We collect birth data. That is unusually personal information — it is not just a date, it is the specific hour of your birth, and it is not something you can change if it leaks. So this policy is written to be read, not to be scrolled past.
1. Who we are
The Chart Room is the organisation responsible for your personal data under Singapore’s Personal Data Protection Act.
Data Protection Officer: the owner of the business, contactable at ding@thechartroomco.com. As required by section 11(3) of the PDPA, one individual is designated and reachable at that address.
2. What we collect, and why — purpose limitation
We collect the minimum needed to do the work, and we use it for that and nothing else. Under the PDPA we may only use personal data for purposes you would consider appropriate in the circumstances and that we have told you about. Here they are, in full.
| What | Why | Where it lives |
|---|---|---|
| Date, time and place of birth | To compute your chart. This is the only purpose. | Our intake form provider and our own working files |
| Your birth-time confidence (certain / approximate / unknown, and the range) | To judge how firmly the hour-dependent sections of your reading can be written | Same |
| Your current question (the decision spotlight) | To write that section of your report | Same |
| Name and email | To deliver the report, answer follow-ups, and process refunds | Shopify, our intake provider, our email |
| Payment details | To take payment | Shopify Payments / Stripe only. We never see or store your full card number. |
| Order records (order number, date, amount, name) | Legal and tax record-keeping | Shopify |
| Marketing consent status, if you opted in | To send occasional notes | Shopify |
What we do NOT do with your birth data
- We do not use it for marketing, targeting, segmentation, or lookalike audiences.
- We do not sell, rent, license, or trade it. Not ever, not to anyone.
- We do not use it to train machine-learning models, ours or anyone else's.
- We do not analyse it in aggregate for research or publication.
- We do not pass it to advertising platforms — see §4, which is the most important section here.
- We do not use it to read the chart of anyone other than the person it belongs to.
Third-party birth data
If you provide someone else's birth details, you must have their consent — this is your obligation under the PDPA as well as ours, and a condition of every order. We may ask you to confirm it, and we will decline the order if we are not satisfied. If someone contacts us to say their birth data was submitted without their agreement, we delete it and tell them we have.
3. Consent
We rely on your express, informed consent, given by ticking an unticked box on the intake form. The box is never pre-ticked and the form cannot be submitted without it. The wording states what you are consenting to in plain English.
Marketing consent is entirely separate. The checkout marketing checkbox is unticked by default, and email sign-up uses double opt-in — you confirm by clicking a link before we send you anything.
Withdrawing consent. You may withdraw at any time by emailing ding@thechartroomco.com. We will act within seven days and confirm. Note the consequence: if you withdraw consent for us to process your birth data before your report is delivered, we cannot produce it, and we will refund you in full.
4. No advertising or analytics trackers on the intake form
This is a deliberate architectural decision, and we would have to rebuild the form to break it.
Our intake form pages carry no advertising pixels and no third-party analytics. No Google Ads tag, no Meta pixel, no TikTok pixel, no session-recording tool, no heatmaps. Your birth data is never transmitted to, observed by, or inferable by an advertising vendor.
Why it needs saying: on most e-commerce sites, every form field a customer touches is potentially visible to a stack of marketing tools. Birth data should not be in that stack, and the only reliable way to guarantee it is not is to keep the collection surface clean and to say so publicly so we can be held to it.
Where trackers do run: the Shopify storefront (product pages, cart, checkout) runs Shopify's own analytics and — once advertising begins — a Google Ads conversion tag and a Meta advertising pixel. Those see that a page was viewed, that a purchase happened, and what it was worth. They never see birth data, because birth data is not collected anywhere on the Shopify storefront. The two are separated on purpose, and §9 sets out the pixel's boundaries in full.
5. Who we share data with
Only these, and only for the function named. Each is a data intermediary processing on our instructions.
| Provider | Function | Data they receive |
|---|---|---|
| Shopify (incl. Shopify Payments/Stripe) | Store, orders, payments, transactional email | Name, email, order details, payment data. No birth data. |
| Tally | Intake form | Birth data, your question, name, email |
| Our email provider | Delivering reports and correspondence | Name, email, report attachment |
| Judge.me | Review requests | Name, email, order reference. No birth data. |
| Zoom (Private Session clients only) | Video consultation | Name, email |
| Cal.com (Private Session clients only) | Scheduling | Name, email, chosen slot |
| Meta (Facebook/Instagram) | Advertising measurement, once ads begin | Anonymous storefront behaviour and purchase events, from storefront pages only. No birth data, ever. No customer list is ever uploaded — see §9. |
| Google Ads / Google Analytics | Advertising measurement, once ads begin | Anonymous storefront behaviour and purchase events. No birth data, ever. |
Some of these providers store data outside Singapore. Under section 26 of the PDPA we take reasonable steps to ensure comparable protection abroad — in practice this means using established providers with contractual data-protection commitments and, for most of them, GDPR-grade obligations.
We do not use data brokers, enrichment services, or advertising audience-matching tools. That includes uploading a customer list to an advertising platform to build an audience from it, which we do not do on any platform, for any campaign.
We disclose data to no one else, except where compelled by Singapore law or a court order.
6. Retention — how long we keep things
| Data | Kept for | Then |
|---|---|---|
| Birth data, intake responses, chart files, report | Retained for as long as we hold you as a client of the practice — see the paragraph below | Deleted whenever you ask, within 7 days. There is no automatic expiry date. |
| Intake data for an order that is cancelled or refunded before writing | 30 days | Deleted |
| Name, email, order history | 5 years | Deleted, except tax record below |
| Transaction records required for tax (order number, date, amount, payer name — no birth data) | 5 years as required under the Income Tax Act and GST record-keeping rules | Deleted |
| Marketing list membership | Until you unsubscribe | Removed on unsubscribe |
| Private Session recordings | 90 days, only if you asked for a recording | Deleted. Not recorded at all by default. |
Why we keep your chart, and for how long
We retain your chart and report so that you can return — for a Year Reading, a follow-up, or a future chart — without re-establishing everything. You can ask us to delete everything at any time, and we do it within seven days and confirm in writing.
That is the whole purpose, stated as the PDPA requires it to be stated: your birth data is kept because it is what makes continuing to serve you possible, and for no other reason. There is no separate marketing purpose, no analytics purpose, and no secondary use — §2 lists every purpose we have.
We are not setting a fixed expiry date, and we would rather say so than publish a number we do not act on. A chart does not go stale: the reading you bought in 2027 is the document a 2032 Year Reading is written against, and deleting it on a timer would mean asking you to submit your birth details again to get back to where you already were. What replaces the timer is your control, which is stronger than a date: erasure on request, within seven days, no reason needed, confirmed in writing (§7). We also review the file annually and erase clients we no longer hold an engagement with; if you would prefer not to wait for that, ask and it is done in the week.
7. Your rights under the PDPA
Access. Ask for a copy of the personal data we hold about you and how it has been used in the past year. We respond within 30 days. There is no charge.
Correction. Tell us anything is wrong and we correct it. If the correction changes your chart, we recompute and reissue the report at no charge.
Withdraw consent. Any time, as in §3.
Deletion. This is the one people actually want. Email ding@thechartroomco.com with "delete my data". Within 7 days we delete your birth details, intake responses, chart files and report from our systems and from our intake provider, and confirm in writing. We do not ask for a reason and it does not affect any refund you are separately entitled to. The only thing retained is the bare tax record in §6, which contains no birth data.
Complain. Write to us first — we would rather fix it. If we do not resolve it, you may complain to the Personal Data Protection Commission of Singapore (pdpc.gov.sg).
To exercise any of these, email ding@thechartroomco.com. We may ask a question to confirm you are who you say you are, because handing someone's birth data to the wrong person is exactly the harm this policy exists to prevent.
8. Security
- Files containing birth data are held encrypted at rest, on access-controlled storage.
- Access is limited to the one person who writes the reports. There are no employees, contractors or virtual assistants with access to client data.
- Multi-factor authentication is on every account in §5 that supports it.
- We do not store card numbers. We could not disclose them if we were compelled to.
- Reports are delivered by email as attachments. Email is not end-to-end encrypted; if you would prefer a password-protected PDF or a link-based delivery, ask and we will do that.
- If a data breach affecting your data occurs, we will notify you and the PDPC in line with the PDPA's mandatory breach-notification obligations — promptly, and without waiting to have a full explanation first.
9. Cookies and the storefront
The storefront uses cookies for the cart and session (strictly necessary), Shopify's own analytics, and — once advertising begins — Google Ads conversion measurement and a Meta advertising pixel.
On the Meta pixel, precisely. Once advertising begins, the storefront also runs a Meta advertising pixel. It loads on storefront pages only — product pages, cart and checkout. It never loads on the intake form, which is on a separate domain and carries no advertising or analytics code of any kind. It never loads on the chart-cast, or on any other page that asks you when you were born. The pixel sees that a page was viewed and that a purchase happened, with its value. It never sees birth data, because birth data is not collected anywhere on the storefront.
What we still will not do, and this is not softened by the above: we do not upload customer lists to Meta or to any other advertising platform, and we do not build audiences by matching your details against one. No customer-list custom audiences, no value-based lookalikes from purchase data, no data brokers, no enrichment services. Measuring whether an advertisement worked does not require handing anybody your details, so we do not.
We also do not use TikTok pixels, session recording, or heatmapping. You can block cookies in your browser; the cart may then misbehave, but nothing else will.
Again: the intake form is a separate surface and carries none of this.
10. Children
Our services are for adults. We do not knowingly collect personal data from anyone under 18, and we do not produce readings for anyone under 18, including at a parent's request. If we learn we hold a minor's data, we delete it.
11. Changes
If this policy changes materially, we will email everyone whose birth data we currently hold. We will not quietly re-date the page and rely on you to notice.
Contact for anything in this policy: ding@thechartroomco.com
The Chart Room · Singapore.