Legal

Privacy Policy

What we collect, why, how long we keep it, and what you can ask us to do about it — under Singapore's Personal Data Protection Act 2012.

Version 1.0 · Effective · Last updated

The short version. We collect what we need to run your account and the apps. We do not sell your data, we do not run ads, and we do not train AI models on your content. You can download or delete everything at any time.

1. Summary

QuestionAnswer
Do you sell my data?No. Never have, never will.
Do you show me ads?No advertising in any app.
Do you train AI on my content?No.
Where is my data?Singapore by default.
Can I get it all back?Yes, any time, in CSV and JSON.
Can I have it deleted?Yes — from your account page or by emailing our DPO.

2. Who is responsible for your data

Coregate Solutions Pte Ltd, 105 Cecil Street, #11-00, The Octagon, Singapore 069534, is the organisation responsible for your personal data under the Personal Data Protection Act 2012 ("PDPA").

As the PDPA requires, we have appointed a Data Protection Officer, contactable at admin@coregatesolutions.com, marked for their attention.

3. What we collect

You give us

  • Account details — name, email address, password (stored only as a salted hash), country and timezone.
  • Billing details — billing country, tax status and payment records. Card numbers go directly to our payment provider; we never receive or store them.
  • What you put in the apps — workouts, body metrics and dietary preferences in Corefitness; transactions, categories and receipt images in Corepocketexpense; availability, bookings and invitee details in Corecalendar.
  • Messages — support enquiries and, in Corefitness, messages between you and your coach.

We collect automatically

  • Technical data — IP address, browser and device type, and pages viewed, used to keep the Service secure and working.
  • Diagnostics — error reports when something breaks. These do not include the contents of your entries.
Sensitive data. Corefitness may involve health-related information such as weight, body measurements and dietary requirements. We treat this with particular care, you provide it voluntarily, and you can delete it at any time.

4. Why we use it

PurposeWhat it covers
Providing the ServiceRunning your account, storing your entries, generating your plans and charts, sending confirmations
BillingTaking payment, calculating GST, issuing receipts, handling refunds
SupportAnswering your questions and investigating problems you report
SecurityDetecting fraud and abuse, protecting accounts, keeping audit logs
Improving the appsAggregate, non-identifying analysis of which features are used
Legal obligationsTax and accounting records, and responding to lawful requests
MarketingOnly with your consent, and only by email — see section 10

5. Consent

Under the PDPA we collect, use and disclose personal data with your consent, or where the PDPA otherwise permits it (for example for legitimate interests such as fraud prevention, or to comply with the law).

By creating an account you consent to us handling your data for the purposes in section 4. Marketing consent is separate, optional, and can be withdrawn without affecting your subscription.

You may withdraw consent at any time by emailing admin@coregatesolutions.com or using your account settings. We will tell you the likely consequences — for example, withdrawing consent to process your entries means we can no longer provide the apps, so your subscription would end.

6. Who we share it with

We share personal data only with service providers who help us run Core, under contracts requiring them to protect it and use it only on our instructions:

Category of providerPurposeLocation
Cloud hostingHosting, databases, storage, backupsSingapore
Payment processingCard payments and refundsSingapore / global
Transactional emailAccount and receipt emailsSingapore / global
SMS deliveryBooking reminders (Corecalendar only)Global routing

We will name the specific providers in each category on request — email admin@coregatesolutions.com and we will send you the current list.

We may also disclose data where required by Singapore law or a lawful request from an authority, or in connection with a merger or acquisition — in which case we would notify you.

We do not sell personal data, and we do not share it with advertisers or data brokers.

7. Where your data is stored

Your data is stored in Singapore by default. Where a provider processes data outside Singapore, we take steps required by section 26 of the PDPA to ensure a comparable standard of protection, through contractual commitments binding that provider.

8. How long we keep it

  • Active accounts — for as long as your account is open.
  • After cancellation — 90 days, so you can return or export. Then deleted.
  • Backups — roll off after 35 days.
  • Billing and tax records — 5 years, as Singapore tax law requires.
  • Support messages — 2 years.
  • Abandoned signups — 12 months, then deleted.

9. Your rights under the PDPA

RightWhat it meansHow
AccessAsk what personal data we hold and how it has been used in the past yearAccount → Privacy & data, or email the DPO
CorrectionHave inaccurate data correctedAccount → Profile, or email the DPO
Withdraw consentStop us using your data for a stated purposeEmail the DPO
PortabilityGet a copy in a common machine-readable formatAccount → Privacy & data
DeletionHave your account and data erasedAccount → Privacy & data, or email the DPO

We respond to requests within 30 days. If we need longer we will tell you why. Access requests are free; we may charge a reasonable fee only for repeated or excessive requests, and we will tell you before doing so.

If you are unhappy with how we have handled your data, please contact our DPO first. You may also complain to the Personal Data Protection Commission (PDPC) of Singapore.

10. Marketing

We send marketing email only if you opt in, and every message has a working unsubscribe link that we action immediately. We comply with the Spam Control Act 2007.

We do not make marketing phone calls and we do not send marketing SMS, so Singapore's Do Not Call Registry provisions are not engaged by us. Transactional messages — receipts, renewal notices, security alerts and booking reminders you have asked for — are not marketing and are sent regardless of marketing preferences.

11. Security and data breaches

We protect your data with TLS 1.3 in transit, AES-256 at rest, hashed passwords, role-based internal access, mandatory two-factor authentication for our staff, and encrypted backups tested quarterly. Full detail on the security page.

If a notifiable data breach occurs, we will notify the PDPC and affected individuals within 3 calendar days of assessing that it is notifiable, as required by Part 6A of the PDPA, and tell you what happened and what to do.

12. Children

Core is not directed at children under 13 and we do not knowingly collect their personal data. Users aged 13 to 17 may use the Service only through an account held by a parent or guardian. If you believe a child has given us personal data, contact admin@coregatesolutions.com and we will delete it.

13. Changes to this policy

We may update this policy. For material changes we give at least 30 days' notice by email and on the site, and where the PDPA requires it we will seek fresh consent.

14. Contact our Data Protection Officer

Data Protection Officer
Coregate Solutions Pte Ltd
105 Cecil Street, #11-00, The Octagon, Singapore 069534
Email: admin@coregatesolutions.com (marked for the attention of the DPO)


Document control. Version 1.0, effective . Issued by Coregate Solutions Pte Ltd, 105 Cecil Street, #11-00, The Octagon, Singapore 069534.

Questions? Email admin@coregatesolutions.com — mark it for the attention of the DPO if it concerns personal data.