Privacy Policy
Last updated: 14 August 2026.
This policy explains how IntelliCoach Pte Ltd handles personal data when you visit or use the IntelliCoach Courses platform. It applies alongside the Singapore Personal Data Protection Act and, where applicable, the EU General Data Protection Regulation and UK data protection law.
Who is responsible
IntelliCoach Pte Ltd is the controller for the platform data described here.
IntelliCoach Pte Ltd 7 Temasek Boulevard #12-07 Suntec Tower One Singapore 038987
For privacy questions or rights requests, contact dpo@intellicoachcourses.com.
Data we handle
- Account and authentication data. We process your name, email address, account role, login records, session identifiers, IP address, and browser signals needed to deliver and protect your account. Session security may compare current connection signals with those recorded when the session started.
- Newsletter data. If you subscribe, we process your email address, name if supplied, language preference, subscription status, and campaign delivery events in our self-hosted newsletter system.
- Purchase and access data. Whop processes checkout and payment information as our Merchant of Record. We receive the identifiers, email address, product, access status, and event data needed to grant and maintain access.
- Messages and requests. We process the details you submit through support, feedback, contact, preview-request, or similar forms so we can answer and prevent abuse.
- Consent evidence. Our self-hosted consent service records a pseudonymous subject identifier, the purposes you selected, the policy and version, the decision time, language, jurisdiction, interface source, and related policy metadata. Consent evidence does not store your IP address or user-agent string.
- Usage statistics. Only after measurement consent, we record the page path, locale, approximate country, referring domain, allowed campaign parameters, device and browser category, pseudonymous visitor and session identifiers, and whether a visit came from a visitor, customer, or staff account. We do not store a raw IP address, a full browser identifier, form content, or complete page URLs with query strings in the analytics record.
- Operational and security logs. Hosting, security, and email systems create technical logs needed to deliver the service, investigate errors, defend accounts, and document incidents. These can include IP addresses, timestamps, request details, and mail-routing information. We do not use these logs for advertising profiles.
The platform uses a local GeoLite2 database to turn an IP address into an approximate country. The IP address is used for that lookup and is not stored in the analytics record. This product includes GeoLite2 Data created by MaxMind, available from MaxMind.
Why we use the data
- To provide accounts, purchased content, support, requested previews, and newsletters under our contract with you or at your request.
- To send usage statistics only when you have consented. You can withdraw that consent at any time.
- To secure the platform, prevent abuse, diagnose faults, and maintain service integrity where we have a legitimate interest that does not override your rights.
- To meet accounting, tax, consumer-protection, dispute, and other legal duties.
Where the law requires consent, refusing or withdrawing it does not affect strictly necessary processing or processing already lawfully completed.
Regional privacy choices
Visitors in the EEA, United Kingdom, and Switzerland, and visitors whose location cannot be determined, receive an explicit choice before measurement starts. The United States policy supports opt-out treatment and Global Privacy Control. Other known locations do not receive an unnecessary banner. You can reopen the privacy controls from the site and change your choice.
How long we keep data
- Consent evidence. A consent decision is valid for 365 days. We keep its evidence for 24 months after that validity ends so we can demonstrate and investigate the decision. If a legacy or incomplete record has no validity date, we delete it 36 months after the decision time. The nightly maintenance task removes expired audit records first, then consent records and their orphaned pseudonymous subjects and policy decisions.
- Usage statistics. Raw pseudonymous page views and the `dpp_vid` browser identifier expire after 30 days. The session identifier in session storage ends with the browser session. Daily aggregate summaries and report-delivery records are kept for 24 months.
- Accounts and access. We keep account and entitlement data while the account or product access is active, then only as long as needed for support, security, legal obligations, and disputes.
- Newsletter records. We keep an active subscription while you remain subscribed. We may keep the minimum suppression record needed to honour an unsubscribe request.
- Purchase and legal records. Whop keeps payment records under its policy. We keep the records we need for access, accounting, tax, fraud prevention, and disputes for the applicable legal period.
- Messages and logs. We keep them only as long as needed for the request, service operation, security review, or a legal claim. Incident evidence may be retained for the life of the incident and any related claim.
Backups follow the platform backup schedule. A deletion may remain in an encrypted backup until that backup expires, but we do not restore deleted data for ordinary use.
Who receives data
- Hetzner, for application and database hosting in Helsinki, Finland.
- Cloudflare, for DNS, reverse-proxy protection, and Turnstile bot checks.
- Whop, as Merchant of Record for checkout, payment, tax, and purchase administration.
- Listmonk, Better Auth, PostgreSQL, Payload CMS, Postfix, and Stalwart, which we operate on our own infrastructure for newsletters, accounts, content, databases, and email.
- Professional advisers, authorities, or other recipients when required by law or needed to establish or defend a legal claim.
We do not sell personal data and do not provide it to advertising networks. Plerdy session recording is not active.
Some providers may process data outside Singapore, the EEA, or the United Kingdom. Where transfer rules apply, we rely on the provider's contractual safeguards or another lawful transfer mechanism.
Your rights
Depending on where you live, you may ask for access, correction, deletion, restriction, objection, or portability of personal data. You may withdraw consent at any time and may complain to the relevant data-protection authority. Singapore residents may request access and correction and may withdraw consent under the PDPA, subject to legal exceptions.
Send a request to dpo@intellicoachcourses.com from the email address linked to your account or transaction. We may ask for enough information to verify your identity. Some records cannot be deleted immediately when a legal duty or active claim requires them.
Security and children
We use HTTPS, access controls, encrypted secret management, private service networks, backups, and monitoring appropriate to the platform. No online service can guarantee absolute security.
The platform is intended for adults. We do not knowingly collect personal data from children. Contact the DPO if you believe a child has provided data.
Cookies and changes
Our Cookie Policy explains browser cookies and similar storage. If this policy changes materially, we will update the date and provide an appropriate notice. Earlier lawful processing remains governed by the policy and law that applied at the time.