PDPA Data Protection Notice
Last updated: March 2026
This Data Protection Notice is issued in accordance with the Personal Data Protection Act 2012 (PDPA) of Singapore. It outlines how Ellie N Leo Pte. Ltd. collects, uses, and discloses your personal data, and your rights in relation to it.
1. Your Consent
By providing your personal data to Ellie N Leo (whether via our website, email, registration forms, or other means), you consent to the collection, use, and disclosure of your personal data in accordance with this Notice and our Privacy Policy.
Where we seek your consent for specific purposes (such as marketing communications), we will do so expressly and provide you with a clear opt-in mechanism. You may withdraw consent at any time (see Section 5 below).
2. Purposes for Collecting and Using Your Data
We collect and use your personal data for the following purposes:
Essential Purposes (Contractual Necessity)
- Processing and fulfilling your orders and payments
- Managing toy rental deposits, returns, and late fees
- Facilitating toy exchange listings and transactions
- Creating and managing your user account
- Delivering products to your specified address
- Providing customer support and resolving disputes
- Generating quotations and processing educator bulk orders
Service Enhancement Purposes (Legitimate Interest)
- Administering the loyalty programme (tracking points and tier status)
- Providing personalised toy recommendations based on child profiles
- Verifying educator credentials and institution details
- Improving our website, products, and services
- Conducting analytics to understand usage patterns
Consent-Based Purposes
- Sending promotional emails and marketing communications
- Personalised advertising and product offers
- Requesting reviews and feedback after purchases or rentals
3. Disclosure of Personal Data
We may disclose your personal data to the following categories of recipients, solely for the purposes described above:
- Payment processors (Stripe) for secure transaction processing
- Email service providers (Resend) for transactional and promotional communications
- Hosting and infrastructure providers (Vercel, Neon) for platform operation
- Delivery partners for order and rental fulfilment
- Government or regulatory authorities, where required by applicable law
We do not sell your personal data to third parties.
4. Protection of Your Data
We implement reasonable security measures to protect your personal data from unauthorised access, loss, misuse, or alteration. These include encryption in transit and at rest, secure authentication, access controls, and regular security assessments.
5. Withdrawing Your Consent
You may withdraw your consent for the collection, use, or disclosure of your personal data at any time by contacting us. To withdraw consent:
- Email us at privacy@ellienleo.sg with the subject line "Withdrawal of Consent".
- Include your full name and the email address associated with your account.
- Specify which purposes you wish to withdraw consent for (e.g., marketing emails, personalised recommendations, or all purposes).
- We will process your request within 10 business days and confirm the withdrawal via email.
Please note: withdrawing consent for essential purposes (such as order processing) may result in us being unable to provide certain services. We will advise you of the likely consequences before processing such a withdrawal.
6. Access and Correction
You have the right to:
- Request access to the personal data we hold about you and information on how it has been used or disclosed in the past year.
- Request correction of any inaccurate or incomplete personal data.
Access and correction requests can be made by emailing privacy@ellienleo.sg. We may charge a reasonable fee for access requests to cover administrative costs. We will respond within 30 business days.
7. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. When personal data is no longer needed, it will be securely deleted or anonymised. For detailed retention periods, please refer to our Privacy Policy.
8. Contact Our Data Protection Officer
If you have any questions about this Notice, wish to exercise your rights, or have a complaint regarding our data protection practices, please contact:
If you are unsatisfied with our response, you may lodge a complaint with the Personal Data Protection Commission (PDPC) of Singapore at www.pdpc.gov.sg.