How TWS Branding Pte Ltd collects, uses, discloses and protects personal data — across this website, our client engagements, our course platform, and the internal advertising tools we operate on behalf of authorised accounts.
TWS Branding Pte Ltd ("TWS", "we", "us", "our") is a company incorporated in Singapore, operating as an F&B growth studio. We provide brand strategy, creative production, digital marketing, paid media management and software tooling to restaurant and hospitality businesses.
Our registered correspondence address is 16 Shaw Road, Kin Building, #03-07, Singapore 367954. Our website is www.twsbranding.com.
We are the organisation responsible for the personal data described in this policy. Where we handle data on behalf of a client — for example, data inside a client's own advertising account — we act as a data intermediary under that client's instructions and the terms of our engagement agreement.
This policy applies to:
It does not cover the independent privacy practices of third-party websites, platforms or services we link to or integrate with. Those are governed by their own policies.
| Where | What we collect |
|---|---|
| Enquiry / contact form | Your name, email address, restaurant or group name, business stage, the services you are interested in, preferred engagement type, and the content of your message. |
| Course signup and account | Your name, email address and restaurant or group name. We also store your subscription tier, sign-in timestamps, and your lesson progress and quiz responses within the members area. |
| Payments | Payments are processed by Stripe. We do not receive or store your full card number, CVC or expiry date. We retain the Stripe customer and checkout session identifiers, the billing email address, the subscription status and the transaction record. |
| Direct correspondence | Email, WhatsApp and phone correspondence you send us, including any information you choose to include in it. |
| Client engagements | Business contact details of your team, brand and operational information you share with us, and materials supplied for creative or campaign work. |
When you visit our website, our hosting provider records standard server and request information: IP address, browser type and version, device and operating system, referring page, pages requested, and timestamps. This is used for security, abuse prevention, diagnostics and aggregate traffic understanding.
We do not knowingly collect special categories of sensitive personal data — such as health, biometric, racial, religious or political information — through this website. Please do not include such information in enquiry messages.
We use personal data for the following purposes:
We do not sell personal data. We do not rent or trade personal data with third parties for their own marketing purposes.
We collect, use and disclose personal data in accordance with the Singapore Personal Data Protection Act 2012 (PDPA).
In most cases we rely on your consent, given when you submit a form, create an account, or enter into an engagement with us. In some cases we rely on other permitted bases under the PDPA, including performance of a contract you are party to, legitimate interests such as network and system security, and compliance with legal obligations.
Where you provide us with personal data about another individual — for example a colleague's contact details — you confirm that you are authorised to do so and that they have been informed of and consent to this policy.
TWS operates a private, internal operations tool that connects to the Google Ads API. This section describes how that tool handles data, and applies in addition to the rest of this policy.
Acting under OAuth 2.0 authorisation granted by a Google user with the necessary permissions, the tool may read account hierarchy, campaigns, ad groups, ads, assets, keywords, budgets, bidding settings, targeting, entity status, performance metrics and change history. It may also create, update, pause or resume approved campaign entities.
The tool does not perform permanent deletion of entities, does not make account billing changes, and does not use the App Conversion Tracking or Remarketing APIs.
Access exists only while an account remains linked to our manager account and the relevant Google user retains permission. An account owner may revoke our access at any time through Google Ads account linking and user-access controls, or by contacting us. Revocation takes effect immediately for future API calls.
Access is restricted to authorised TWS employees and approved contractors working under our supervision and subject to confidentiality obligations. Public and anonymous access is prohibited. Requests pass through a TWS-controlled gateway that validates the user, the account scope and the requested operation before any call is made.
Live changes require explicit approval by a qualified internal user. The system records the requesting user, the account, the timestamp, the operation, the approval, before-and-after values, the API response status and a post-change verification read-back. Credentials are excluded from these records.
OAuth client secrets, refresh tokens and the developer token are stored in Google Secret Manager, encrypted at rest, and transmitted only over HTTPS. They are not embedded in source code, browser pages, logs or messages. If any credential is believed to be exposed, it is rotated immediately.
Our use of the Google Ads API is subject to the Google Ads API Terms and Conditions, applicable Google Ads policies, and the Google API Services User Data Policy, including its Limited Use requirements. Where those requirements are stricter than this policy, those requirements govern.
Where we manage Meta, TikTok, Google Business Profile or other marketing platforms for a client, the same principles apply: access is granted by the account owner, data is used only for that account's reporting and optimisation, and access can be revoked by the owner at any time.
In the course of an engagement we may process personal data contained within systems a client asks us to operate — for example customer contact lists, reservation records, review data or CRM entries.
For that data:
Our website uses cookies and equivalent browser storage for the following purposes:
You can block or delete cookies through your browser settings. Blocking strictly necessary cookies will prevent you from signing in to the members area.
Our checkout flow is served by Stripe, which sets its own cookies for fraud prevention and payment processing under Stripe's privacy policy.
We share personal data with a small number of service providers who process it on our behalf, under contract, and only as needed to run our services:
| Provider | Purpose |
|---|---|
| Vercel | Website and application hosting, server logs, edge delivery. |
| Supabase | Account database and authentication for the members area. |
| Stripe | Payment processing, subscription billing and fraud prevention. |
| Resend | Transactional email delivery, including sign-in links and confirmations. |
| Google Cloud / Google Ads | Secret storage, hosted services, and advertising account operations. |
| Professional advisers | Accountants, auditors and legal advisers, where necessary. |
We may also disclose personal data where required by law, by a court, or by a regulator; where necessary to establish, exercise or defend legal claims; or to prevent fraud, harm or a security threat.
If our business is sold or reorganised, personal data may be transferred as part of that transaction, subject to the recipient continuing to observe protections at least equivalent to those in this policy.
Some of our service providers operate infrastructure outside Singapore. Where personal data is transferred overseas, we take reasonable steps to ensure the recipient is bound to a standard of protection comparable to that required under the PDPA, through contractual terms, the provider's data processing agreement, or applicable certification.
We keep personal data only for as long as it serves the purpose it was collected for, or as long as we are legally required to keep it.
We apply reasonable technical and organisational measures appropriate to the sensitivity of the data we hold, including:
No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we will notify affected individuals and the Personal Data Protection Commission where a data breach is notifiable under the PDPA.
Subject to the PDPA and applicable exceptions, you may:
To exercise any of these, email ernest@twsbranding.com. We may need to verify your identity before acting. We will respond within a reasonable time and in any event within the period required by law.
Withdrawing consent may mean we can no longer provide part or all of a service — for example, we cannot maintain your members area account without your email address.
Our website, services and course are intended for business users and are not directed at individuals under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
Our site links to third-party websites and platforms, including social media and the software products we deploy for clients. We are not responsible for their content or privacy practices. Review their policies before providing personal data to them.
We may update this policy from time to time. The effective date at the top of this page shows when it was last revised. Material changes will be communicated by email to account holders or by a prominent notice on this site. Continued use of our website or services after a change takes effect constitutes acceptance of the revised policy.
For any question, request or complaint about privacy or personal data, contact our data protection contact:
TWS Branding Pte Ltd
Attn: Data Protection Officer
16 Shaw Road, Kin Building, #03-07
Singapore 367954
Email: ernest@twsbranding.com
Phone: +65 8791 3291
If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commission of Singapore.