Store policy
Privacy Policy
Lalaland Juice, Singapore · Last updated 26 July 2026
The promise
Lalaland Juice, Singapore collects the minimum personal data needed to press and deliver your juice, protects it, and complies with Singapore’s Personal Data Protection Act (PDPA). We never sell personal data. Ever.
What we collect
- Identity and contact — name, email address, phone number.
- Delivery — address and postal code, plus the geocoded map point we derive from it to route deliveries.
- Orders — what you bought, your subscription settings, delivery history.
- Payment — handled entirely by Stripe, our payment processor. Card numbers never touch our servers; we hold only a reference to your saved payment method.
- How you found us — a first-touch source (e.g. Instagram, a search engine) and, if you used a referral link, its code.
- Technical — standard server logs (IP address, browser type) kept for security.
What we use it for
- Pressing, charging and delivering your orders — the core of it.
- Service messages you can’t opt out of while a customer: order confirmations, delivery notices, payment-failure alerts.
- Support — answering you when you contact us.
- Keeping the store safe — fraud prevention, security logs.
- Legal obligations — e.g. keeping transaction records for tax.
- Marketing only with your consent, and every marketing message carries a working unsubscribe, per Singapore’s Spam Control Act. We don’t make telemarketing calls or send marketing SMS to Singapore numbers without clear consent, per the Do Not Call registry rules.
Cookies
- Sign-in session — keeps you logged in to your account.
- Cart — remembers what’s in your cart on this device.
- Source — remembers how you first found us, for 30 days.
- Referral — remembers a referral link you clicked, for 30 days.
No third-party advertising trackers run on this site.
Who we share it with
Only processors who need it to serve you, and only what they need:
- Stripe — payment processing.
- Supabase and Vercel — the database and hosting this store runs on.
- Mapbox and OneMap — turning your postal code into a map point for routing.
- Delivery personnel and partners — your name, address and phone number, to hand you the box.
- Authorities — only where the law requires it.
Where it’s stored
Our systems run on cloud infrastructure with servers that may be located outside Singapore (within Asia-Pacific cloud regions). Where personal data is transferred out of Singapore, we ensure — through our contracts with these providers and their certified safeguards — that it receives a standard of protection comparable to the PDPA, as the Act requires.
How long we keep it
For as long as you have an account or an active subscription, and afterwards only as long as the law requires (transaction records are kept at least five years for tax). Then we delete or anonymise it.
Your rights
You may ask us for access to the personal data we hold about you, ask us to correct it, or withdraw consent for uses that rely on consent (which may mean we can no longer deliver to you). Write to our data protection contact below — we respond within 30 days.
If something goes wrong
If a data breach occurs that is notifiable under the PDPA — one likely to cause significant harm, or affecting 500 or more people — we will notify the Personal Data Protection Commission within 3 calendar days of assessing it as such, and tell affected customers promptly and plainly.
Data protection contact
Our data protection officer can be reached through the contact details below. This is also where to send any access, correction, or complaint about personal data.
Questions or complaints
Tell us first — we acknowledge every complaint within 2 working days and work it to a resolution.
Unresolved after that? You may approach the Consumers Association of Singapore (CASE) or the Singapore Mediation Centre.
Related: Terms of Service · Privacy · Delivery · Refunds