Privacy Policy

Last updated: 1 February 2026

This Privacy Policy explains how personal data is collected, used, disclosed, and protected in accordance with the Personal Data Protection Act 2012 (“PDPA”) of Singapore.

This policy applies to all visitors, customers, and users of our website and services.


1. About This Policy

We are committed to protecting your personal data and handling it responsibly.

This Privacy Policy describes:

  • what personal data we collect,
  • how and why we use it,
  • who it may be shared with, and
  • how you may contact us regarding your personal data.

References to “we”, “us”, or “our” refer to the organisation operating this website and providing the relevant products and services.


2. Personal Data We Collect

Depending on how you interact with us, we may collect the following types of personal data.

a) When you place an order

  • Full name
  • Email address
  • Contact number
  • Delivery address
  • Order details (including selected products and customisation details)
  • Payment confirmation details
    (We do not collect or store full credit or debit card numbers.)

b) When you contact us or submit an enquiry

  • Name
  • Email address
  • Contact number
  • Message content and correspondence

c) When you use our website

  • IP address
  • Browser type and device information
  • Pages visited and interactions
  • Cookies and similar technologies (where applicable)

3. Why We Collect and Use Personal Data

We collect, use, and disclose personal data for the following purposes:

  • To process and fulfil orders
  • To prepare, customise, and package physical parcels
  • To arrange delivery through third-party logistics or courier providers
  • To communicate with you regarding your order, delivery, or enquiries
  • To respond to customer support requests or feedback
  • To process refunds, returns, or cancellations where applicable
  • To comply with legal, regulatory, and accounting requirements
  • To improve our website, products, and services (using aggregated or anonymised data)
  • To send marketing communications where you have opted in

We do not collect personal data beyond what is reasonably necessary for these purposes.


4. Disclosure of Personal Data

We may disclose your personal data to third parties only where necessary, including:

  • Delivery and courier service providers (for fulfilment and delivery)
  • Payment service providers (for payment processing and refunds)
  • Professional advisers (such as accountants or auditors), where required
  • Government or regulatory authorities, where required by law

We do not sell personal data to third parties.


5. Legal Basis for Processing

We collect, use, and disclose personal data based on one or more of the following grounds under the PDPA:

  • Your consent
  • Contractual necessity (to fulfil your order)
  • Compliance with legal obligations
  • Legitimate business purposes permitted under applicable law

6. Marketing Communications

If you choose to subscribe to our mailing list or marketing communications, we may use your contact details to send updates, promotions, or newsletters.

You may opt out of marketing communications at any time by using the unsubscribe link provided or by contacting us directly.


7. Cookies and Website Analytics

Our website may use cookies or similar technologies to enhance user experience and analyse website usage.

These may include cookies used for:

  • website functionality,
  • analytics,
  • remembering preferences.

You may disable cookies through your browser settings. However, some features of the website may not function properly as a result.


8. Protection of Personal Data

We take reasonable administrative, technical, and physical measures to protect personal data against unauthorised access, disclosure, alteration, or destruction.

These measures include:

  • secure systems and access controls,
  • limiting access to authorised personnel,
  • working with reputable third-party service providers.

9. Retention of Personal Data

We retain personal data only for as long as necessary to fulfil the purposes stated in this policy, or as required under applicable laws.

When personal data is no longer required, it will be securely deleted or anonymised.


10. Access, Correction, and Withdrawal of Consent

You may request to:

  • access your personal data,
  • correct inaccuracies,
  • withdraw consent for the collection, use, or disclosure of your personal data (subject to legal and contractual restrictions).

Requests may be submitted using the contact details below.


11. Contact and Data Protection Officer

If you have any questions, concerns, or requests regarding your personal data, please contact us at:

Email: hello@heartstringparcels.com

We will endeavour to respond within a reasonable time in accordance with the PDPA.


12. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws.

The updated version will be published on our website with the revised date.