Privacy Policy
What we collect, why, how long we keep it, and what you can ask us to do about it — under Singapore's Personal Data Protection Act 2012.
Version 1.0 · Effective · Last updated
1. Summary
| Question | Answer |
|---|---|
| Do you sell my data? | No. Never have, never will. |
| Do you show me ads? | No advertising in any app. |
| Do you train AI on my content? | No. |
| Where is my data? | Singapore by default. |
| Can I get it all back? | Yes, any time, in CSV and JSON. |
| Can I have it deleted? | Yes — from your account page or by emailing our DPO. |
2. Who is responsible for your data
Coregate Solutions Pte Ltd, 105 Cecil Street, #11-00, The Octagon, Singapore 069534, is the organisation responsible for your personal data under the Personal Data Protection Act 2012 ("PDPA").
As the PDPA requires, we have appointed a Data Protection Officer, contactable at admin@coregatesolutions.com, marked for their attention.
3. What we collect
You give us
- Account details — name, email address, password (stored only as a salted hash), country and timezone.
- Billing details — billing country, tax status and payment records. Card numbers go directly to our payment provider; we never receive or store them.
- What you put in the apps — workouts, body metrics and dietary preferences in Corefitness; transactions, categories and receipt images in Corepocketexpense; availability, bookings and invitee details in Corecalendar.
- Messages — support enquiries and, in Corefitness, messages between you and your coach.
We collect automatically
- Technical data — IP address, browser and device type, and pages viewed, used to keep the Service secure and working.
- Diagnostics — error reports when something breaks. These do not include the contents of your entries.
4. Why we use it
| Purpose | What it covers |
|---|---|
| Providing the Service | Running your account, storing your entries, generating your plans and charts, sending confirmations |
| Billing | Taking payment, calculating GST, issuing receipts, handling refunds |
| Support | Answering your questions and investigating problems you report |
| Security | Detecting fraud and abuse, protecting accounts, keeping audit logs |
| Improving the apps | Aggregate, non-identifying analysis of which features are used |
| Legal obligations | Tax and accounting records, and responding to lawful requests |
| Marketing | Only with your consent, and only by email — see section 10 |
5. Consent
Under the PDPA we collect, use and disclose personal data with your consent, or where the PDPA otherwise permits it (for example for legitimate interests such as fraud prevention, or to comply with the law).
By creating an account you consent to us handling your data for the purposes in section 4. Marketing consent is separate, optional, and can be withdrawn without affecting your subscription.
You may withdraw consent at any time by emailing admin@coregatesolutions.com or using your account settings. We will tell you the likely consequences — for example, withdrawing consent to process your entries means we can no longer provide the apps, so your subscription would end.
6. Who we share it with
We share personal data only with service providers who help us run Core, under contracts requiring them to protect it and use it only on our instructions:
| Category of provider | Purpose | Location |
|---|---|---|
| Cloud hosting | Hosting, databases, storage, backups | Singapore |
| Payment processing | Card payments and refunds | Singapore / global |
| Transactional email | Account and receipt emails | Singapore / global |
| SMS delivery | Booking reminders (Corecalendar only) | Global routing |
We will name the specific providers in each category on request — email admin@coregatesolutions.com and we will send you the current list.
We may also disclose data where required by Singapore law or a lawful request from an authority, or in connection with a merger or acquisition — in which case we would notify you.
We do not sell personal data, and we do not share it with advertisers or data brokers.
7. Where your data is stored
Your data is stored in Singapore by default. Where a provider processes data outside Singapore, we take steps required by section 26 of the PDPA to ensure a comparable standard of protection, through contractual commitments binding that provider.
8. How long we keep it
- Active accounts — for as long as your account is open.
- After cancellation — 90 days, so you can return or export. Then deleted.
- Backups — roll off after 35 days.
- Billing and tax records — 5 years, as Singapore tax law requires.
- Support messages — 2 years.
- Abandoned signups — 12 months, then deleted.
9. Your rights under the PDPA
| Right | What it means | How |
|---|---|---|
| Access | Ask what personal data we hold and how it has been used in the past year | Account → Privacy & data, or email the DPO |
| Correction | Have inaccurate data corrected | Account → Profile, or email the DPO |
| Withdraw consent | Stop us using your data for a stated purpose | Email the DPO |
| Portability | Get a copy in a common machine-readable format | Account → Privacy & data |
| Deletion | Have your account and data erased | Account → Privacy & data, or email the DPO |
We respond to requests within 30 days. If we need longer we will tell you why. Access requests are free; we may charge a reasonable fee only for repeated or excessive requests, and we will tell you before doing so.
If you are unhappy with how we have handled your data, please contact our DPO first. You may also complain to the Personal Data Protection Commission (PDPC) of Singapore.
10. Marketing
We send marketing email only if you opt in, and every message has a working unsubscribe link that we action immediately. We comply with the Spam Control Act 2007.
We do not make marketing phone calls and we do not send marketing SMS, so Singapore's Do Not Call Registry provisions are not engaged by us. Transactional messages — receipts, renewal notices, security alerts and booking reminders you have asked for — are not marketing and are sent regardless of marketing preferences.
11. Security and data breaches
We protect your data with TLS 1.3 in transit, AES-256 at rest, hashed passwords, role-based internal access, mandatory two-factor authentication for our staff, and encrypted backups tested quarterly. Full detail on the security page.
If a notifiable data breach occurs, we will notify the PDPC and affected individuals within 3 calendar days of assessing that it is notifiable, as required by Part 6A of the PDPA, and tell you what happened and what to do.
12. Children
Core is not directed at children under 13 and we do not knowingly collect their personal data. Users aged 13 to 17 may use the Service only through an account held by a parent or guardian. If you believe a child has given us personal data, contact admin@coregatesolutions.com and we will delete it.
13. Changes to this policy
We may update this policy. For material changes we give at least 30 days' notice by email and on the site, and where the PDPA requires it we will seek fresh consent.
14. Contact our Data Protection Officer
Data Protection Officer
Coregate Solutions Pte Ltd
105 Cecil Street, #11-00, The Octagon, Singapore 069534
Email: admin@coregatesolutions.com (marked for the attention of the DPO)
Document control. Version 1.0, effective . Issued by Coregate Solutions Pte Ltd, 105 Cecil Street, #11-00, The Octagon, Singapore 069534.
Questions? Email admin@coregatesolutions.com — mark it for the attention of the DPO if it concerns personal data.