Legal
Privacy Policy
Last updated: 28 August 2026
This Privacy Policy explains how Raffles Concierge Pro ("we", "us", "our") collects, uses, discloses, and protects personal data when you visit rafflesconciergepro.pro, contact us, or use our concierge and lifestyle management services in Singapore. We handle personal data in accordance with the Personal Data Protection Act 2012 (PDPA) of Singapore and applicable subsidiary legislation.
1. Who we are
Raffles Concierge Pro is an independent concierge service operating from 10 Collyer Quay, #10-01, Ocean Financial Centre, Singapore 049315. We are not affiliated with Raffles Hotel, Fairmont Singapore, or any hospitality group using the Raffles name. For privacy-related enquiries, contact us at hello@rafflesconciergepro.pro or +65 6227 4194.
2. Scope of this policy
This policy applies to personal data collected through our website, email correspondence, telephone calls, contact forms, and direct engagements for concierge services. It does not apply to third-party websites linked from our pages, or to services provided solely by our partners once you have agreed to their separate terms.
3. Personal data we collect
Depending on how you interact with us, we may collect the following categories of personal data:
- Identity and contact data: name, email address, telephone number, postal address, and company name where relevant.
- Request and preference data: details you provide about concierge requests, including travel dates, dining preferences, dietary requirements, accessibility needs, gift recipients, and emergency contacts for membership clients.
- Communication records: copies of emails, form submissions, and notes from phone conversations related to your enquiries and active requests.
- Technical data: browser type, device information, IP address, and cookie preference stored locally on your device when you use our website.
- Billing data: invoicing details and payment references where you engage us on a paid basis. We do not store full credit card numbers on our servers.
Providing certain data is necessary to fulfil your requests. If you choose not to supply information we reasonably need, we may be unable to complete the coordination you asked for.
4. How we collect personal data
We collect personal data when you:
- Submit our contact form or email us directly;
- Call our office line or meet with a coordinator by appointment;
- Become a membership client and complete a preference profile;
- Browse our website, where essential and functional cookies may apply as described in our Cookie Policy;
- Are referred to us by a corporate client who has authority to share delegate details for visitor programmes.
5. Purposes of collection, use, and disclosure
We use personal data for purposes that a reasonable person would consider appropriate in the context of concierge services, including:
- Responding to enquiries and providing quotations;
- Coordinating bookings, transfers, reservations, and errands on your behalf;
- Maintaining membership preference profiles to improve repeat service;
- Communicating updates, confirmations, and changes to scheduled arrangements;
- Issuing invoices and maintaining financial records;
- Complying with legal obligations and responding to lawful requests from authorities;
- Improving our website and internal processes through aggregated, non-identifying analysis.
We disclose personal data to third parties only when necessary to perform a confirmed request — for example, sharing your name and party size with a restaurant, or pickup details with a chauffeur company. We instruct partners to use data solely for the specified purpose. We do not sell personal data to marketers or data brokers.
6. Legal basis and consent
Under the PDPA, we rely on consent, contractual necessity, and legitimate business interests as appropriate. By submitting an enquiry or engaging our services, you consent to the collection and use of your personal data as described here. You may withdraw consent for marketing communications at any time; withdrawal does not affect processing already completed or processing necessary to fulfil active service obligations.
Where we process data on behalf of a corporate client about visiting delegates, the corporate client is responsible for ensuring it has authority to share that data with us. We process delegate information solely to deliver the agreed visitor programme.
7. Retention
We retain personal data only as long as needed for the purposes collected, unless a longer period is required by law or needed to resolve disputes. Contact form submissions and correspondence are typically retained for up to twenty-four months after the last interaction. Membership preference profiles are retained for the duration of membership plus twelve months. Financial records follow applicable retention requirements for business documentation in Singapore.
When retention periods expire, we delete or anonymise data so it can no longer be associated with you, except where archival copies are required for legal compliance. Anonymised aggregate statistics may be retained indefinitely for internal service improvement.
8. Security
We implement reasonable administrative, technical, and physical safeguards to protect personal data against unauthorised access, alteration, disclosure, or destruction. Measures include access controls for staff, secure storage of preference profiles, sanitisation of form inputs, and restricted access to server-side logs. No method of transmission over the internet is completely secure; we encourage you to use strong passwords for any accounts associated with our services and to notify us promptly of suspected unauthorised access.
9. Cross-border transfers
Our primary systems and coordinators are based in Singapore. If we transfer personal data overseas — for example, when coordinating international travel or communicating with a hotel abroad — we take steps to ensure recipients provide a standard of protection comparable to that under the PDPA, including contractual safeguards where appropriate.
When you correspond with us from outside Singapore, you acknowledge that data may be processed in Singapore where our servers and staff are located. Singapore's PDPA applies to our handling of your personal data regardless of your country of residence, subject to mandatory local laws that may also apply to you.
10. Your rights
Subject to exceptions under the PDPA, you may:
- Request access to personal data we hold about you;
- Request correction of inaccurate or incomplete data;
- Withdraw consent where processing is consent-based, subject to contractual and legal limits;
- Ask how your data has been used or disclosed in the past year.
Submit requests to hello@rafflesconciergepro.pro. We respond within thirty days unless an extension is permitted. We may charge a reasonable fee for manifestly unfounded or excessive access requests.
If you believe we hold inaccurate preference data — for example an outdated dietary note — tell us and we will correct it promptly. Corrections apply to future bookings; they do not alter arrangements already confirmed with third parties unless those parties agree to changes.
11. Children
Our services are directed at adults. We do not knowingly collect personal data from individuals under eighteen without parental or guardian involvement. If you believe we have collected a child's data in error, contact us and we will delete it promptly.
12. Third-party links and embedded content
Our contact page may embed Google Maps after you accept functional cookies. Google processes data under its own privacy policy. External links to restaurants, venues, or transport providers are provided for convenience; their data practices are governed by their respective policies.
When we share your name or contact details with a restaurant or chauffeur to fulfil a confirmed booking, that third party becomes an independent controller or processor of the data needed to deliver their service. We encourage you to review venue privacy notices when you have specific concerns about how they handle guest information.
13. Data breach notification
If we become aware of a data breach likely to result in significant harm, we will notify affected individuals and the Personal Data Protection Commission as required under Singapore law, and describe steps taken to mitigate harm.
14. Changes to this policy
We may update this Privacy Policy to reflect changes in law, technology, or our services. The "Last updated" date at the top will change accordingly. Material changes will be highlighted on this page. Continued use of our website or services after updates constitutes acceptance of the revised policy where permitted by law.
15. Marketing communications
We do not send unsolicited marketing email. If you are an active client, we may occasionally share service updates or seasonal reminders relevant to your membership. You may opt out at any time by replying to any message or contacting hello@rafflesconciergepro.pro. Opting out of marketing does not affect transactional messages related to confirmed bookings or active requests.
16. Automated decision-making
We do not use automated decision-making or profiling that produces legal or similarly significant effects on individuals. Coordinator assignments and service recommendations involve human review of your stated preferences.
17. Records of processing
We maintain internal records describing categories of personal data processed, purposes, retention periods, and categories of recipients. These records are available to the Personal Data Protection Commission upon lawful request. Clients may request a summary of how their data has been handled in connection with a specific engagement.
18. Contact
For privacy questions, access requests, or complaints:
- Email: hello@rafflesconciergepro.pro
- Phone: +65 6227 4194
- Address: 10 Collyer Quay, #10-01, Ocean Financial Centre, Singapore 049315
If you are not satisfied with our response, you may contact the Personal Data Protection Commission in Singapore. We cooperate with regulatory enquiries and will provide reasonable assistance to resolve complaints in good faith.