Privacy Policy
What we collect, why, and who we share it with — in plain English, under Singapore's PDPA.
1. Who We Are
This site is operated by Cambridge Learning Group (“we,” “us”), a Singapore-registered tuition centre. We are the data controller for personal data collected on book.topstudentsecrets.com.
2. What We Collect
We collect only what we need to fulfil your order and communicate with you:
- Contact details — first name and email address (from the landing-page form).
- Shipping details — delivery name, street address, unit/floor, postal code, and phone number (collected at checkout by Stripe for SG-only delivery).
- Order details — items purchased, amount, date, and Stripe session/payment reference.
- Payment details — handled entirely by Stripe; we do not see or store your full card number, CVV, or expiry. Stripe may return the last 4 digits of the card for our records.
- Technical data — IP address and browser user-agent captured in Vercel server logs for security and debugging. Not used for tracking individuals.
3. Why We Use It
- To process your order, charge your payment, and ship your book.
- To email you order confirmations, shipping updates, and ebook download links.
- To provide customer support when you email us.
- To send occasional product updates or related offers (only if you have not unsubscribed). You can unsubscribe from any such email by replying “unsubscribe” or using the unsubscribe link when present.
- To comply with Singapore tax and record-keeping laws.
4. Who We Share Data With
We share the minimum necessary data with the following third parties, each of whom has their own privacy practices:
- Stripe (payment processor) — stripe.com/privacy
- Resend (transactional email delivery) — resend.com/legal/privacy-policy
- Vercel (site hosting and infrastructure) — vercel.com/legal/privacy-policy
- Google Drive (ebook file backup) — policies.google.com/privacy
- Singapore Post and/or courier services (physical book delivery).
We do not sell, rent, or trade your personal data to third parties for their marketing purposes.
5. Cookies & Tracking
The site uses minimal cookies necessary for checkout (set by Stripe during payment). If we add analytics or advertising pixels in the future (for example Meta Pixel or Google Analytics), we will update this policy before enabling them.
6. Data Retention
- Order and payment records — kept for at least 5 years to comply with Singapore tax and accounting requirements.
- Lead data (name + email submitted but no purchase) — up to 12 months, then deleted.
- Customer support correspondence — up to 2 years from the last interaction.
7. Your Rights Under the PDPA
Under Singapore's Personal Data Protection Act (PDPA), you have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to correct information that is inaccurate.
- Withdraw consent — ask us to stop using your data for marketing. Note that we must still keep order records for tax purposes.
To exercise any of these rights, email book@topstudentsecrets.com. We aim to respond within 30 days.
8. Security
We use industry-standard security measures, including HTTPS across the whole site, encrypted environment variables for credentials, HMAC-signed ebook download URLs with 30-day expiry, and Stripe's PCI-compliant payment infrastructure. No method of online storage or transmission is 100% secure; we make reasonable efforts to protect your data but cannot guarantee absolute security.
9. Children's Privacy
The book is written for parents about their children's education. We do not knowingly collect personal data from anyone under the age of 13. If you believe we have inadvertently collected data from a child, please contact us and we will delete it.
10. Cross-Border Data Transfers
Our hosting (Vercel), email (Resend), payment (Stripe), and file backup (Google Drive) providers may process data on servers outside Singapore, including in the United States and European Union. Where we transfer your personal data internationally, we rely on the data-protection standards contractually committed to by those providers, in accordance with PDPA guidance.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top indicates when it was last changed. Material changes will be announced by email to existing customers where appropriate.
12. Contact
Privacy questions and data-rights requests: book@topstudentsecrets.com