top of page
Legal ·
Privacy Policy

Your data, handled the way

we handle our own.

Carefully, on a need-to-know basis, and only for as long as there's a reason to keep it. This policy sets out what we collect, why, who sees it, and what you can ask us to do about it.

Governing Law
Singapore
Applies to
secretsauce.sg
lp.secretsauce.sg
Version
1.0
Effective
13 Aug 2026
The Short Version

Four things worth  knowing up front.

You can see it, fix it, or stop it

Ask what we hold, ask us to correct it, or withdraw your consent. Write to our Data Protection Officer and we'll respond within 30 days.

It lives in a short list of named systems

Our website platform, our client system and our email. Some of those store data outside Singapore, under contractual terms requiring protection comparable to the PDPA.

We use it to reply, and to do the work

Answering you, scoping the job, preparing submissions, and, if you opt in, sending the newsletter. We don't sell personal data and we don't share it for third-party advertising.

We only collect what you hand us

Your name, email, mobile and a description of your concept, because it's what it takes to answer an enquiry properly. We don't ask for NRIC, FIN or financial details through this website.

i. Who we are, and what this policy covers


Secret Sauce Consulting Pte. Ltd. (UEN 202331271Z), trading as Secret Sauce Consulting — "Secret Sauce", "we", "us", "our" — is a Singapore-based F&B licensing, compliance and operations consultancy, incorporated and registered in Singapore.


This policy explains how we collect, use, disclose and look after personal data in connection with this website (secretsauce.sg), our landing pages at lp.secretsauce.sg, and the enquiries and engagements that begin there. It is written to meet our obligations under Singapore's Personal Data Protection Act 2012 (the "PDPA") and the Personal Data Protection Regulations 2021.


The PDPA defines personal data as data, whether true or not, about an individual who can be identified from that data, or from that data together with other information we have or are likely to have access to. On this site that means your name, your contact details, the content of your enquiry, and the technical identifiers your browser sends us.


It does not cover personal data your own business collects from your customers or staff — where we advise on that, it's dealt with in your engagement documents, not here. Nor does it cover third-party websites we link to, or messages you send through platforms operated by others such as WhatsApp, LinkedIn and Instagram, which are also subject to those platforms' own terms.


Our services are offered in and for the Singapore market, and this policy is written to Singapore law. If you're located somewhere with its own data protection regime and you believe it applies to you, write to us and we'll consider your request on its merits.



ii. What personal data we collect


Almost everything we hold, you gave us. The rest is standard technical information that any website receives when a browser connects to it.


•     Your enquiry  —  First name, last name, email address, mobile number, business or concept name, outlet type, and the description of your project you write into the form.

•     Newsletter sign-ups  —  Your email address, and nothing else.

•     Correspondence  —  Whatever you choose to send us by email, WhatsApp or phone — messages, floor plans, tenancy documents, menus, equipment lists, photographs of premises, and the contact details of anyone you copy in.

•     Franchise enquiries  —  Your brand deck or concept overview, current markets and outlet counts, franchise terms, target timeline, and the contact details of the people named in those documents.

•     Technical and usage data  —  Your IP address and the approximate location derived from it, device and browser type, operating system, referring URL, the pages you view and how long you spend on them — collected automatically through cookies and server logs.


We do not ask for NRIC or FIN numbers, passport numbers, bank or card details, or health information through this website, and you shouldn't send them to us through a web form. If a licence application later requires identity or financial documents, we collect them under a signed engagement, through a channel appropriate to their sensitivity, and only to the extent the relevant agency actually requires.


If you fill in the contact form, we know who you are, how to reach you, and what you're trying to open. That's it. Nothing on this site asks for your IC.

iii. Why we collect it, and on what basis


We use personal data to respond to your enquiry and assess whether we're the right fit; to scope, propose and deliver work, including preparing and lodging applications where you engage us; to share the relevant parts of your matter with the specialist partner handling their piece of it; to keep a client record so that when you come back in eighteen months to open your second outlet you don't start from scratch; to send the newsletter where you've asked for it; to understand in aggregate which pages and articles are useful; to show our advertising to people who have already visited the site and measure whether it works, where you have consented to that; and to keep the records we're required to keep, protect the site from misuse, and establish or defend legal claims.

Under the PDPA we generally rely on your consent, given when you submit a form or send us your details, and on deemed consent where you voluntarily provide personal data for a purpose that's obvious in the circumstances — sending us your mobile number so we can call you back, for example.


For a narrow set of activities we rely on the legitimate interests exception in Part 3 of the First Schedule to the PDPA, covering site security, fraud prevention and record-keeping, and on the business improvement exception in Part 5, covering improvements to our services and content using data we already hold. Where another exception under the PDPA applies — for instance where disclosure is required by law — we rely on that instead.


We won't use your personal data for a purpose materially different from those set out above without going back to you first.



iv. Cookies and site analytics


Cookies are small files placed on your device when you visit a website. Some are needed for the site to work at all; others tell us which pages people actually read, and some let us reach people who have already visited us. We treat them in three groups.


Strictly necessary

Set by our website platform to keep your session alive, protect forms against cross-site request forgery, remember your cookie choices, and handle caching, load balancing and error logging. These load on every visit because the site cannot function without them, and the forms will not work if you block them.


Analytics

With your consent, Google Analytics 4 distinguishes visitors and sessions so we can see traffic sources, page popularity and drop-off points in aggregate; Google truncates IP addresses before storage. Where our client system's tracking code is present, HubSpot links a form submission back to the pages that led to it, so we understand which content generates real enquiries.


Advertising and remarketing

With your consent, we set cookies from Meta (for Facebook and Instagram) and Google Ads so that we can show our advertising to people who have already visited this site, and measure whether that advertising works. These are the only cookies that follow you beyond secretsauce.sg, and they are the reason this site asks before it sets anything.


Google Tag Manager container (GTM-TGWK5XJT) sits in this group too, though it does not itself profile you — it is the container that loads and manages the tags above. Our consent platform classifies it as advertising, which means declining advertising also prevents our analytics tags from loading. Accepting analytics alone will not enable them.


Asking first

On your first visit you'll see a consent banner. Until you make a choice, only the strictly necessary cookies load — analytics and advertising cookies are held back and do not run. You can accept everything, reject everything, or choose category by category.


You can change or withdraw that choice at any time using the Cookie settings link in the footer of every page. Withdrawing consent stops the relevant cookies from being set from that point on; it does not undo data already collected while consent was in place, though you can ask us to delete that under section ix.


We do this because the PDPC's Advisory Guidelines on the PDPA for Selected Topics require express consent where cookies collect personal data for personalised advertising targeting, and are explicit that failing to change your browser settings does not count as agreeing. Singapore imposes no blanket banner requirement the way European law does, but for advertising cookies specifically, asking is the only way to get consent that means anything.


Turning them off anyway

Your browser is the backstop. Every major browser lets you block cookies, delete the ones already stored, block third-party cookies specifically, or browse in a private window that discards them on close — usually under Settings, then Privacy. To opt out of Google Analytics across every site you visit, not just this one, use Google's browser add-on at tools.google.com/dlpage/gaoptout.


Reject everything and the site still works — you just lose the parts that help us understand what's useful. Nothing that follows you around the internet runs unless you say yes to it.


v. Marketing, newsletters and the Do Not Call Registry


Our newsletter is opt-in. You get it because you asked for it, and every issue carries an unsubscribe link that works. We act on unsubscribes promptly and keep a minimal suppression record so you aren't added back by mistake. Where the Spam Control Act 2007 applies to a message we send, we comply with its labelling and unsubscribe requirements.


Part 9 of the PDPA establishes the Do Not Call Registry, with separate registers for voice calls, text messages and faxes. Before sending a marketing message to a Singapore telephone number we check the relevant register, unless we hold your clear and unambiguous consent in written or other accessible form. Registry check results are valid for up to 30 days, so we re-check rather than rely on a stale list.


Messages that relate to a live enquiry or an engagement in progress — replying to your question, confirming an appointment, updating you on a submission — are not marketing messages and aren't restricted by the DNC provisions. We'll still stop if you ask us to.


We will never cold-call you off a purchased list. If we're calling, it's because you contacted us — or because you told us we could.


vi. Who sees it, and where it goes


We share personal data only where there's a reason to, and only the part that's needed. We do not sell personal data, and we do not disclose it to third parties for their own advertising.


The systems we use are Wix, which hosts the website and holds form submissions, content collections and newsletter subscriber lists; HubSpot, our client relationship system and system of record for enquiries; and Google, for email, documents and storage through Google Workspace and for measurement through Analytics and Tag Manager. Where you have consented to advertising cookies, Meta Platforms and Google Ads also receive the identifiers those cookies generate, and use them to match you to our advertising on their own platforms.

Beyond those, we disclose personal data to our specialist partners — the fire safety Qualified Person, the property and leasing adviser, the HR systems partner — but only where they're working on your matter, and only what their scope requires. Where you've engaged us to make submissions on your behalf, we disclose what's necessary to the relevant government agencies, which may include SFA, URA, SCDF, NEA, PUB, PLRD and BCA. We also share data with our accountants, insurers and lawyers where that's necessary to run the business or to establish or defend a legal claim, and where we're required to disclose it by law, by a court, or by a regulator with jurisdiction over us.


Data held outside Singapore

Wix, HubSpot and Google all store data outside Singapore — variously in the United States, the European Union and elsewhere. Section 26 of the PDPA, the Transfer Limitation Obligation, requires us to ensure any overseas recipient is bound to a standard of protection comparable to the PDPA's, and Regulation 10 of the Personal Data Protection Regulations 2021 sets out how that's done. We meet it through the data processing terms in our contracts with each provider, and we choose vendors partly on the strength of those terms. If you'd like a summary of the arrangements in place for a particular provider, ask our Data Protection Officer.



vii. How long we keep it


Section 25 of the PDPA requires us to stop retaining personal data once the purpose it was collected for is no longer being served and retention is no longer necessary for legal or business reasons. In practice:

•     Enquiries that don't proceed — 24 months from last contact  —  F&B projects have long lead times, and people who enquire early often come back a year or more later. Keeping the context that long is better for you than making you explain it twice.

•     Client and project records — the engagement, then six years  —  Aligned to the six-year limitation period for contractual claims under the Limitation Act 1959.

•     Accounting and tax records — five years  —  As required under the Companies Act 1967 and by IRAS.

•     Newsletter subscriptions — until you unsubscribe  —  Plus a minimal suppression record afterwards, so we don't add you back.

•     Advertising and remarketing cookies — up to 90 days  —  The identifiers set by Meta and Google Ads expire on their own cycle, and stop being set the moment you withdraw consent.

•     Website analytics — 14 months  —  Google Analytics 4 event-data retention, set to the maximum available on a standard property.


When a retention period ends we delete the data, or remove the means by which it can be associated with you. Backups are overwritten on their own cycle, so a deleted record may persist briefly in backup media before it's cycled out.



viii. How we protect it, and what happens if something goes wrong


Section 24 of the PDPA requires reasonable security arrangements — proportionate to the sensitivity and volume of the data, not perfection. Access is limited to the people who need it; we're a small team, and client files aren't shared more widely than the matter requires. The accounts that hold personal data — email, client system and website platform — are protected with two-factor authentication. The site is served over HTTPS, so form submissions are encrypted between your browser and our platform. We choose vendors on their contractual data protection terms, not just their price. And we don't use NRIC or FIN numbers as authentication credentials anywhere in our systems, in line with the joint PDPC and Cyber Security Agency advisory of June 2025 and the PDPC's February 2026 announcement that private organisations must stop using NRIC numbers for authentication by 31 December 2026.


No system is perfectly secure, and we won't pretend otherwise. What we can commit to is treating a problem seriously and telling you about it.


Part 6A of the PDPA makes breach notification mandatory. A data breach is notifiable if it results in, or is likely to result in, significant harm to affected individuals, or if it affects 500 or more individuals. If we become aware of a breach we assess it expeditiously, and in any event within 30 days. If it's notifiable, we notify the PDPC as soon as practicable and no later than 3 calendar days after completing that assessment. Where significant harm to you is likely, we notify you too — telling you what happened, what data was involved, and what you should do about it.


If your data is caught up in something serious, you'll hear it from us — not from the news.


ix. Your rights, and how to use them


Access

Under Section 21 of the PDPA you can ask what personal data about you we hold or control, and how it's been used or disclosed in the year before your request. We'll respond within 30 days, and if we can't complete the request in that time we'll tell you within 30 days when we will. A reasonable fee may apply to cover the cost of retrieving and compiling the data — if one does, we'll tell you the amount before we start any work, and you're free to withdraw the request.


Correction

Under Section 22 you can ask us to correct an error or omission. We'll make the correction within 30 days unless we have grounds to believe it shouldn't be made, and where relevant we'll send the corrected data to organisations we disclosed it to in the previous year. There's no fee for a correction request.


Withdrawing consent

Under Section 16 you can withdraw consent to our collection, use or disclosure of your personal data at any time, on reasonable notice. We'll tell you the likely consequences first — for an active engagement, withdrawing consent may mean we can't continue to act for you. Withdrawal doesn't affect anything already lawfully done, or data we're required to keep.


Data portability

A data portability obligation was legislated in Part 6B of the PDPA by the Personal Data Protection (Amendment) Act 2020, but it hasn't yet been brought into force pending the accompanying regulations. When it commences, we'll honour requests that fall within its scope.


Making a request

Email our Data Protection Officer using the details in section xi. Please describe the personal data, or the correction you want, clearly enough for us to locate it. We may need to verify who you are before we act — we will not ask for your NRIC to do that. If we decline a request in whole or in part, we'll tell you why, except in the limited cases where the PDPA doesn't require us to.

If you're not satisfied, come to us first; it's usually the fastest way to fix something. If you're still unhappy, you can lodge a complaint with the Personal Data Protection Commission at pdpc.gov.sg.



x. Minors, and other people's sites


This site is intended for business owners, operators and prospective founders. It isn't directed at children, and we don't knowingly collect personal data from anyone under 18 through it. The PDPC's guidance is that a minor of at least 13 can generally be taken to have sufficient understanding to consent on their own behalf; even so, if we learn we've collected data from a minor through this website without appropriate consent, we'll delete it. If you're a parent or guardian and think we hold your child's data, write to our Data Protection Officer and we'll deal with it.

We link out to government agency pages, partner websites, franchise brand sites and our own social profiles. Once you follow a link you're on someone else's property and their privacy policy applies — we don't control those sites and aren't responsible for how they handle your data, though we only link to sources we consider legitimate. The same goes for messaging and social platforms: if you contact us on WhatsApp, LinkedIn or Instagram, that platform processes the message under its own terms as well as ours.



xi. Changes, and how to reach our DPO


We update this policy when what we do changes — a new system, a new purpose, a change in the law. The effective date and version number at the top of this page always tell you which version you're reading. For material changes we'll flag the update on this page and, where we hold your consent to contact you, by email. Continuing to use the site after a change means you accept the updated policy.

Section 11 of the PDPA requires every organisation to designate a Data Protection Officer and to make their business contact information publicly available. Ours is here:

 

DPO DETAILS:

•     Name: Cheryl Tay

•     Email: cheryl@secretsauce.sg, marked for the attention of the DPO.

•     Phone: +65 8946 9788

•     Response: Within 30 days for access and correction requests, in line with the PDPA.

Questions about this document
Entity
Secret Sauce Consulting Pte. Ltd.
UEN: 202331271Z
phone
+65 8946 9788
Rather just ask
Talk to a person

Questions about any of this go to a human, not a ticketing system.

READ →
ALSO WORTH READING
Terms of Use

What this site is for, what it isn't, and the limits of what you should rely on.

READ →
bottom of page