1. The short version
Four things happen automatically in the background when you visit the Site:
- Analytics. We measure which pages people read, how far they scroll, and where visitors come from, so we know which content works.
- Ad tracking. If a Meta or Google ad brought you here, we tell them you arrived. So we don’t waste money on ads that don’t work.
- Session replays. Microsoft Clarity records anonymous mouse movement and clicks on the homepage, so we can spot confusing parts of the page.
- Concierge submissions. If you complete the four-question Service Concierge, your answers are sent to our team Slack. If you book a call, your name and email come along too.
We don’t sell your data. We share it only with the third parties listed in this policy, and we keep only what the business needs. If we work with you at an event, additional collection may happen there (see section 3).
2. What we collect, specifically
2.1 When you visit the Site
Collected automatically, without you doing anything:
- Pages visited and how you navigate between them;
- Time on page and scroll depth;
- Where you came from (a search engine, an ad, or direct);
- Browser and device type;
- Approximate location: country and city derived from your IP address, not GPS;
- Anonymous recordings of interactions on the page, with form inputs masked by default.
2.2 When you use the Service Concierge
If you complete the four-question concierge tool, we collect your four answers (event type, what’s at stake for your organisation, timing, and budget range) and we return a recommended program.
2.3 When you book a Brief Diagnostic
Clicking “Book a Brief Diagnostic” takes you to our scheduling provider, zcal, which asks for your name, email, and an optional message. zcal handles this data per their own privacy policy. When a booking is confirmed, the booking details and selected time are pushed to our team Slack so we can prepare.
2.4 When you email us
Anything you send to hello@mochicollective.com stays in our inbox until you ask us to delete it.
3. Event and attendee data
Impact measurement is part of what we do: for client engagements, we may collect data before, during, and after an event, such as attendance, survey responses, sentiment, and behavioural signals. Events we design may also be photographed or filmed.
Two things to know about that:
- When we measure on a client’s behalf, we generally act as a data intermediary (processor) for that client under the PDPA. The client decides what is collected and why; we process it under their instructions and our agreement with them. Notices and consents for attendees are agreed with the client as part of the engagement, and wherever practicable we work with aggregated or de-identified data for reporting.
- If you attend an event we run and want to access, correct, or remove personal data collected there, including photographs, contact us at the address in section 10 and we will either handle it or route your request to the client who controls the data.
This section describes our general approach; the specific terms for any engagement are set out in the applicable Statement of Work.
4. Consent and our legal bases
Where the PDPA requires consent, we rely on the consent you give when you submit a form, book a call, or email us; the purpose is evident from the interaction (using the concierge means you want a recommendation; booking a call means you want us to hold the slot and prepare). For background analytics and site improvement, we rely on the PDPA’s deemed consent and legitimate interests provisions, applied narrowly and never to override your interests.
You can withdraw consent at any time by emailing us (see section 10). We will stop the relevant collection, use, or disclosure within a reasonable time of your notice, though withdrawing consent may mean we can’t continue a conversation or engagement that depends on it. Withdrawal does not require us to delete data we are entitled or required to retain.
We only send marketing communications to people who have opted in or with whom we have an ongoing relationship, and every marketing email includes a working unsubscribe. We do not send telemarketing messages to Singapore numbers without checking the Do Not Call Registry or holding clear consent.
5. Who we share data with
| Third party | What they do for us | How your data is handled |
|---|---|---|
| Meta (Facebook/Instagram) | Ad tracking via the Meta Pixel and Conversions API | Name and email are hashed (one-way encrypted) before transmission; Meta matches against its existing users without seeing the actual values |
| Google Analytics 4; email hosting via Google Workspace | Anonymous behavioural data; email infrastructure for hello@mochicollective.com | |
| Microsoft | Clarity session recordings and heatmaps | Anonymous interaction data |
| Insight Tag for B2B analytics and retargeting | Anonymous visit data; matched to your LinkedIn profile via LinkedIn’s cookie only if you’re logged in | |
| zcal | Booking and calendar | Their privacy policy applies once you book a call |
| Vercel | Website hosting | Infrastructure provider |
| Slack | Internal team communication | Concierge submissions and booking notifications are routed here |
We don’t sell your data to data brokers or anyone else. We may disclose personal data where required by law, or to professional advisers under confidentiality obligations.
Cross-border transfers. Some of the providers above store data outside Singapore (typically in the United States or the European Union). Where personal data leaves Singapore, we take steps required under the PDPA to ensure it receives a comparable standard of protection, through the providers’ contractual commitments and data protection certifications.
6. Your rights
Your rights under this policy are those provided by Singapore’s PDPA, and we extend the same treatment to visitors everywhere:
- Access. Email hello@mochicollective.com with “Data request” in the subject and we’ll tell you what personal data we hold about you, and how it has been used or disclosed within the past year. We respond within 30 days; if we need longer, we’ll tell you when to expect an answer. We may charge a reasonable fee for access requests and may decline requests in the circumstances the PDPA permits (for example, requests that are frivolous, vexatious, or would reveal another person’s data or our confidential commercial information).
- Correction. Same email. If something we hold about you is inaccurate, we’ll correct it as soon as practicable.
- Withdrawal of consent. Same email (see section 4). We’ll stop the relevant use of your data, subject to any retention we’re entitled or required to keep.
- Deletion requests. Singapore law doesn’t provide a general right to erasure, but in practice we hold very little, and if you ask us to delete your data we will do so where we have no continuing business or legal need for it. Data held by the third parties in section 5 is subject to their own processes.
- Ad tracking opt-out. Use a browser ad-blocker or extension (e.g. uBlock Origin), or account-level settings: Meta Off-Facebook Activity or Google Ads Settings.
7. How long we keep things
| Data | Retention |
|---|---|
| Anonymous analytics (GA4, Clarity) | Up to 14 months (platform defaults) |
| Concierge submissions in Slack | For as long as they’re useful to us, or until the channel is cleared |
| Confirmed bookings in our calendar | Until the booking has taken place, then archived |
| Email correspondence | For as long as we need it for our records |
When data no longer serves a business or legal purpose, we delete or anonymise it.
8. Cookies
The tools listed in section 5 set first-party cookies; we don’t set any of our own beyond that. They expire between 30 days and 2 years depending on the tool. You can clear them at any time in your browser settings. The only effect is that we won’t recognise you on a repeat visit; the Site itself works fine without them. If you’re visiting from a jurisdiction that requires consent for non-essential cookies, you can decline or clear them without losing any functionality.
9. Security, and if something goes wrong
We limit access to personal data to the people who need it, use reputable providers with strong security practices, and keep the amount of data we hold deliberately small. No method of internet transmission or storage is completely secure, but holding less data is itself a security measure.
If a data breach occurs, we will assess it promptly and notify the Personal Data Protection Commission and affected individuals where and when the PDPA requires it.
10. Data protection officer and contact
Our Data Protection Officer oversees our compliance with the PDPA and is the right contact for anything in this policy:
- Data Protection Officer Email: hello@mochicollective.com, with “Data request” or “Privacy” in the subject line
- Mochi Collective Pte. Ltd., 68 Circular Road, #02-01, Singapore 049422
11. Updates to this policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date at the top of this page.
Mochi Collective Pte. Ltd. (UEN 202538712H) is a private limited company registered in Singapore.
Registered office: 68 Circular Road, #02-01, Singapore 049422.