Privacy Policy

Last Updated: October 8, 2025

Yum Cha Restaurant (“we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit our website www.yumcha.com.sg (the “Website”), place orders through our online store, or use our services. This policy complies with the Personal Data Protection Act 2012 of Singapore (“PDPA”).

1. Information We Collect

1.1 Personal Information You Provide

Account Information (if you create an account):

Order and Billing Information:

Delivery Information:

Reservation Information:

Catering Inquiries:

Communication Information:

1.2 Information Automatically Collected

Technical Information:

WooCommerce and E-commerce Data:

Cookies and Similar Technologies: We use cookies and similar tracking technologies to enhance your experience. See Section 6 for more details.

1.3 Information from Third Parties

Payment Processors: We receive transaction confirmation and payment status from payment gateways (e.g., Stripe, PayPal, or other processors we use)

Delivery Partners: If we use third-party delivery services, we may receive delivery status updates and tracking information

Social Media: If you interact with us on social media or use social login features, we may receive information from those platforms

2. How We Use Your Information

We use your personal information for the following purposes:

Order Processing and Fulfilment:

Account Management:

Service Delivery:

Business Operations:

Marketing and Communications:

Legal Compliance:

3. Legal Basis for Processing (PDPA Compliance)

Under the PDPA, we process your personal data based on:

4. How We Share Your Information

We do not sell your personal information. We may share your information with:

4.1 Service Providers

Essential Service Providers:

Analytics and Marketing:

Business Tools:

These service providers are contractually obligated to protect your information and use it only for the services they provide to us.

4.2 Payment Security

Payment card information is collected and processed by our PCI-DSS compliant payment processors. We do not store complete credit card numbers on our servers. Only tokenized or encrypted payment information is retained for authorized transactions.

4.3 Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.

4.4 Legal Requirements

We may disclose your information if required by law, court order, or government authority, or to protect our rights, property, or safety, or that of others.

4.5 With Your Consent

We may share your information with third parties when you have given us explicit permission to do so.

5. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required by law.

Retention Periods:

After the retention period, we will securely delete or anonymize your personal information.

6. Cookies and Tracking Technologies

6.1 What Are Cookies

Cookies are small text files stored on your device when you visit our Website. They help us recognize you and remember your preferences.

6.2 Types of Cookies We Use

Strictly Necessary Cookies:

WooCommerce Specific Cookies:

Performance Cookies:

Functional Cookies:

Marketing Cookies:

6.3 Third-Party Cookies

Our website may use third-party cookies from:

6.4 Managing Cookies

You can control cookies through your browser settings. However, disabling certain cookies may affect your ability to:
To opt-out of marketing cookies specifically, you can adjust your preferences through our cookie consent banner.

7. Your Rights Under PDPA

Under Singapore’s Personal Data Protection Act, you have the following rights:

7.1 Right to Access

You can request a copy of the personal information we hold about you, including your order history and account data.

7.2 Right to Correction

You can request that we correct any inaccurate or incomplete personal information. You can also update most information directly in your account settings.

7.3 Right to Withdraw Consent

You can withdraw your consent for us to process your personal information for marketing purposes at any time. Note that withdrawal of consent may affect our ability to provide certain services.

7.4 Right to Data Portability

You can request that we provide your personal information in a commonly used, machine-readable format.

7.5 Right to Deletion

You can request deletion of your personal information, subject to our legal obligations to retain certain data (e.g., tax records).

7.6 Right to Object

You can object to our processing of your personal information in certain circumstances, such as marketing purposes.

To exercise any of these rights:

We will respond to your request within 30 days as required by PDPA.

8. WooCommerce Data Processing

8.1 Order Processing

When you place an order, we process your personal and payment information to complete the transaction. This includes:

8.2 Checkout Process

During checkout, your information is encrypted using SSL/TLS technology. Payment card details are sent directly to our payment processor and are not stored on our servers (except in tokenized form for authorized future transactions).

8.3 Guest Checkout

If you check out as a guest, we collect only the information necessary to process your order. Your data is retained according to our retention policy but is not used to create a customer account unless you explicitly choose to do so.

8.4 Customer Accounts

If you create an account:

9. Marketing Communications

9.1 Types of Marketing

With your consent, we may send you:

9.2 Opting Out

You can opt-out at any time by:
Even if you opt-out of marketing, we will still send:

10. Data Security

We implement appropriate technical and organizational measures to protect your personal information:

Technical Measures:

Organizational Measures:

However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security. We encourage you to use strong passwords and keep your login credentials confidential.

11. International Data Transfers

Your personal information is primarily stored and processed in Singapore. However, some of our service providers may process data outside Singapore (e.g., cloud hosting services, payment processors, email services).

When we transfer data internationally, we ensure:

12. Children's Privacy

Our Website and services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately, and we will take steps to delete such information.

13. Third-Party Links and Services

Our Website may contain links to third-party websites, social media platforms, or services that are not operated by us. This includes:
We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Yum Cha Restaurant
Data Protection Officer
20 Trengganu Street (Off Temple Street) #02-01 Singapore 058479

For data protection inquiries specifically:
DPO Email: dpo@yumcha.com.sg

For order-related inquiries:
Customer Service: enquiry@yumcha.com.sg

15. Data Breach Notification

In the unlikely event of a data breach that poses a significant risk to your rights and freedoms, we will:

16. Complaints

If you believe we have not handled your personal information in accordance with the PDPA, you have the right to lodge a complaint with the Personal Data Protection Commission (PDPC) of Singapore:

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:
Your continued use of our Website after any changes indicates your acceptance of the updated Privacy Policy.

18. Language

This Privacy Policy is written in English. In the event of any inconsistency between the English version and any translation, the English version shall prevail.

Consent:

By using our Website, creating an account, or placing an order, you acknowledge that you have read, understood, and agree to this Privacy Policy. If you do not agree with this policy, please do not use our Website or provide us with your personal information.

During checkout and account creation, you will be asked to provide explicit consent for:

You can withdraw your consent at any time by contacting us or adjusting your account settings.