Privacy policy
We ask for as little as we can, use it only for what you asked, and give you a one-click way to take it all back. This page says exactly what that means — no defined terms, no “may share with partners”.
Version 2026-09-05.1 · in effect 2026-09-05 · Singapore Personal Data Protection Act 2012
We are not collecting any personal data yet. Email capture is built but switched off, so no address has been given to us and none is being stored. This policy is published ahead of that — so you can read what we intend to do before we do any of it, rather than after. It describes the service as it will work the day capture is switched on; nothing below is happening today.
The short version
- We don't need your email to give you a verdict. The free verdict has no sign-up. You're only ever asked for an address after you've read it, and only if you want something emailed to you.
- Marketing is a separate box, unticked. You get what you asked for whether or not you tick it.
- We never sell or rent your address, and we never buy lists.
- You can export or delete everything, any time — from this page, without asking us. Deletion means deleted, including from our email provider.
What we collect, and when
Only if you give it to us. Your email address, and — when you save a verdict or set up an alert — which property it was about. That's the whole of it. There are no accounts and no passwords.
The property details you type into the tool. An address, or the facts of a unit — its floor, its size, the asking price. We don't ask you for a listing link. We use what you type to produce your report, and we send the address to OneMap (Singapore Land Authority) to turn it into map coordinates so we can measure distances.
Automatically, as you use the site. Which pages and steps get used, and errors when something breaks. Two deliberate limits on that:
- Our analytics never receives your email address, phone number or the property address — it is blocked in code, not by policy, and a property address in a link is stripped out before anything is sent.
- Our error monitoring is configured not to attach your IP address, cookies or the contents of your request.
- If your browser sends a “Do Not Track” signal, we record no analytics events at all.
What we never collect: passwords, NRIC or identity-document numbers, income or bank details, or payment card data. When paid reports launch, card details will be handled by the payment provider and will not reach us.
Cookies and similar technologies
Our analytics sets cookies to recognise a returning browser so that a visit isn't counted twice. We may set one small cookie holding a random identifier if we're running a page-design test, so you keep seeing the same version — it holds nothing about you. We don't use advertising cookies today; see the next section for what will change when we advertise.
Advertising, pixels and audiences
We don't run advertising today, and there are no advertising or social-media pixels on this site. We're telling you now what will happen when we start, so nothing about it is a surprise:
- Conversion measurement. Advertising tags from Google and Meta that record when a visit from an ad leads to a free verdict or a purchase — so we can tell which ads are worth running.
- Remarketing. A record that you visited certain pages, used to show you Verdari ads elsewhere. You will be able to opt out, and people who have already bought will be excluded.
- Hashed-audience matching. If — and only if — you have opted in to marketing, we may send an irreversibly hashed form of your email address to an advertising platform so it can match you to an account you already have there, or exclude you from ads for something you've already got. The platform does not receive your address in a readable form. Withdrawing marketing consent, or deleting your data, removes you from these audiences.
When any of this goes live, this section will be updated to say so plainly and the version number at the top of the page will change. Advertising will never be a reason we use an address given for a service email only — that is what keeps the two consents separate.
What we rely on to use your data
Under the PDPA we rely on your consent, and we ask for it in two separate pieces, because they are two different decisions:
- Service email — the thing you asked for: a link back to your verdict, the sample report, or an alert when a project's data moves. Asking for it is consenting to it.
- Marketing email — our research and product updates. A separate, unticked box. Never required, never assumed, and refusing it never withholds anything.
We keep a record of what you agreed to and the exact wording you were shown at the time, so the answer to “what did I actually sign up for?” is checkable rather than a matter of memory. You can withdraw consent at any time, and it takes one click — no reason needed and nothing to log in to. Withdrawing stops what comes next; it doesn't undo what was already sent.
Email only. We don't make marketing calls and we don't send marketing SMS — not to numbers you give us, and not to numbers we've found elsewhere. We don't ask for a phone number at all. That is consistent with Singapore's Do Not Call provisions under the PDPA, and it is simply how we intend to work.
Who your data reaches
We don't sell, rent or trade personal data. It reaches these service providers because they run part of the service, and nothing else:
| Who | What for | Where |
|---|---|---|
| Vercel | Hosting and delivering this site. | United States and global edge network |
| Supabase | The database holding your email address, your consent record and what you asked for. | Singapore (ap-southeast-1) |
| Resend(not yet in use) | Sending the emails you ask for. Not in use until we turn email on. | Japan (ap-northeast-1) |
| PostHog | Product analytics — which pages and steps get used. We never send your email address, phone number or property address to it. | European Union |
| Sentry | Error monitoring, so a broken page reaches us. Configured not to attach your IP address, cookies or request body. | European Union (Germany) |
| OneMap (Singapore Land Authority) | Turning a property address into map coordinates so we can measure distances. We send the property address, never your email. | Singapore |
Your email address and consent record are stored in Singapore. Analytics and error data sit in the European Union, and the site itself is served from a global network — so some data is handled outside Singapore. Where that happens we require the provider, by contract, to protect it to a standard comparable to the PDPA, as the Act's transfer rules require.
We'd also disclose data if the law required it of us — a court order or a regulator. We'd tell you unless we were forbidden to.
How long we keep it
| What | How long |
|---|---|
| Your email address, consent record and saved verdicts / alerts | Until you delete them, or until 24 months after you last opened one of our emails or used the site — whichever comes first. |
| An unconfirmed sign-up (you never clicked the confirmation link) | 30 days, then deleted. |
| Export and deletion request links | The link expires in 24 hours; the request record is deleted with your account. |
| A record that a deletion happened | Kept indefinitely, but it holds only a timestamp, row counts, whether the mailing-list removal succeeded, and why — your request, an expired sign-up, or dormancy — nothing that identifies you. |
Your rights, and how to use them
- See what we hold. Ask for a copy and you get a machine-readable file of everything — your address, every consent event with the wording you were shown, and whatever you signed up for.
- Correct it. Tell us and we'll fix it.
- Withdraw consent. One click, from any email or the manage page.
- Delete everything. Not “deactivate” — deleted. Your address, your consent record, your saved verdicts and alerts, and your entry in our email provider's list. All we keep is a dated note that a deletion happened, with no address, name or identifier in it.
Use the manage page. We send a link to the address itself, because proving control of the address is the only honest way to be sure we're acting for the right person. We aim to respond within 30 days, as the PDPA requires.
How it's protected
- Everything is served over HTTPS.
- The database is locked down by default — no public access — and only our server can read or write it.
- Confirmation and deletion links are stored only as one-way hashes. Someone who read our database could not use them, and confirmation links stop working the moment they're used.
- If a breach affected you and posed a real risk, we'd notify you and the PDPC, as the Act requires.
Our Data Protection Officer
Questions, requests or complaints about your data go to our Data Protection Officer at dpo@verdari.com. If you're not satisfied with our answer, you can complain to Singapore's Personal Data Protection Commission.
Who this service is for
Verdari is for adults making a property decision, and it isn't directed at children. We don't knowingly collect personal data from anyone under 18. If you believe a child has given us an address, tell our Data Protection Officer and we'll delete it.
If this policy changes
We'll update this page and change the version number at the top. Consents you've already given stay attached to the version you actually read — a new policy does not silently re-consent you to anything. If a change materially affects how we use data you gave us, we'll ask again rather than assume.