Privacy Policy
Last updated: 16 July 2026
This policy explains what personal data [COMPANY-NAME] PTE. LTD. (UEN [UEN], [SG-ADDRESS], Singapore — "we", "us") collects when you use the 10min TOCFL websites, web application and iOS application (the "Service"), how we use it, who we share it with, and the choices you have. It is written to comply with the Singapore Personal Data Protection Act (PDPA) and, where applicable, the EU/UK GDPR and other local privacy laws.
1. Data we collect
| Data | When | Purpose |
|---|---|---|
| Email address | Early-access signup form; account creation | Send launch/product updates you asked for; identify your account; send billing receipts and subscription notices |
| Google account profile (name, email, avatar, Google account ID) | When you sign in with Google | Create and authenticate your account |
| Study activity (quiz answers, scores, progress, saved vocabulary) | While you use the Service | Show your results and progress; improve question quality |
| Subscription and payment metadata (plan, status, renewal dates, last 4 digits of card, country) | When you subscribe | Provide the subscription; billing support. Full card numbers are processed by Stripe and never touch our servers. |
| Technical logs (IP address, browser/device type, pages requested) | Automatically, server-side | Security, abuse prevention, debugging |
We do not collect data for advertising, do not sell personal data, and do not use it for cross-app tracking.
2. Third parties we share data with (processors)
| Provider | What they process | Why |
|---|---|---|
| Stripe Payments (stripe.com) | Payment details, email, country | Payment processing for subscriptions |
| Google (Sign in with Google) | Your Google profile at sign-in | Authentication |
| Cloudflare (Workers, D1, KV, Turnstile) | All Service data and traffic; Turnstile anti-bot signals on forms | Hosting, storage, security |
| Apple | In-app purchase data (if you subscribe inside the iOS app) | App distribution and IAP billing |
Each provider processes data under its own contractual and security obligations that provide protection at least equivalent to this policy. Your data may be processed outside your country (including in Singapore, the United States and the EU); where required, transfers rely on appropriate safeguards such as standard contractual clauses.
3. How long we keep data
- Account and study data: kept while your account exists; deleted within 30 days after you delete your account.
- Billing records: kept for as long as required by tax and accounting law (typically 5 years in Singapore), even after account deletion.
- Early-access emails: kept until you unsubscribe or the list is retired.
- Server logs: kept for at most 90 days.
4. Your rights and choices
- Access and correction: you may request a copy of, or corrections to, your personal data.
- Deletion: you can delete your account — and the personal data associated with it — directly in the app's account settings, or by emailing us.
- Withdraw consent: you may withdraw consent to any processing (e.g. unsubscribe from emails via the link in each email, or stop using Google sign-in by deleting your account). We will explain the consequences (usually that the related feature stops working) and will not charge for withdrawal.
- If you are in the EU/UK, you additionally have the rights to data portability, restriction, objection, and to complain to your supervisory authority. Our legal bases are: performance of contract (accounts, subscriptions), legitimate interests (security, logs), and consent (marketing emails).
To exercise any right, email [SUPPORT-EMAIL]. We respond within 30 days.
5. Cookies
The Service uses only strictly necessary cookies and similar storage: a session cookie to keep you signed in, and Cloudflare cookies for security (including Turnstile bot protection). We do not set advertising or cross-site tracking cookies. If we later add analytics cookies, we will ask for consent first where the law requires it.
6. Children
The Service is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has provided us personal data, contact us and we will delete it.
7. Security
All traffic is encrypted with HTTPS/TLS. Data is stored with Cloudflare with access limited to the operator. Payment card data is handled entirely by Stripe, a PCI DSS Level 1 certified processor.
8. Contact / Data Protection Officer
For any privacy question or request, including under the Singapore PDPA, contact our
data protection officer:
[DPO-NAME], [COMPANY-NAME] PTE. LTD.
[SG-ADDRESS], Singapore
[SUPPORT-EMAIL]
9. Changes
We will post any changes to this policy here and update the date above; for material changes we will notify account holders by email or in-app notice.