Privacy Policy

Last Updated: December 2025

Introduction

Stillwater Retreat is committed to protecting your personal information and respecting your privacy. This policy explains how we collect, use, store, and protect your data when you interact with our services, visit our website, or stay at our facility in Sentosa Cove, Singapore.

We operate in accordance with Singapore's Personal Data Protection Act (PDPA) and international best practices for data protection. This policy applies to all guests, website visitors, and individuals who communicate with us.

Information We Collect

Contact and Booking Information

When you book a stay or inquire about our services, we collect:

  • Name and contact details (email, phone number, postal address)
  • Package preferences and stay dates
  • Payment information (processed securely through authorized payment providers)
  • Special requests or requirements (dietary needs, accessibility considerations)

Guest Information During Your Stay

To provide personalized service, we may collect:

  • Preferences expressed during intake conversations
  • Feedback provided during or after your stay
  • Notes from staff interactions necessary for service coordination
  • Records of services used and activities participated in

Website Usage Data

When you visit our website, we automatically collect:

  • IP address and browser information
  • Pages visited and time spent on each page
  • Referring website or source
  • Device type and operating system

Communication Records

We maintain records of communications including:

  • Email correspondence
  • Phone call notes and recordings (where legally permitted and disclosed)
  • Messages through our contact forms
  • Feedback submissions

Legal Basis for Processing

We process your personal data based on:

  • Consent: When you provide information through our contact forms or booking process, you consent to our processing of that data for the stated purposes.
  • Contract Fulfillment: Processing necessary to deliver the services you've booked and maintain our relationship with you as a guest.
  • Legitimate Interest: Operating our business effectively, improving our services, and maintaining facility security.
  • Legal Obligation: Compliance with Singapore regulations including tax, health and safety, and business licensing requirements.

How We Use Your Information

Your data is used for the following purposes:

Service Provision

  • Processing and confirming bookings
  • Coordinating your stay and personalizing your experience
  • Communicating about your reservation or stay
  • Accommodating special requests and dietary requirements

Communication

  • Responding to inquiries and providing information
  • Sending booking confirmations and updates
  • Following up after your stay (with your consent)
  • Addressing concerns or complaints

Service Improvement

  • Analyzing guest feedback to enhance our offerings
  • Understanding how our website is used
  • Identifying areas for operational improvement
  • Staff training and development

Legal Compliance

  • Meeting tax and financial reporting obligations
  • Maintaining records as required by Singapore law
  • Ensuring health and safety compliance
  • Responding to legal requests or investigations

Data Retention

We retain your information for different periods depending on its type and purpose:

  • Booking and Payment Records: 7 years from transaction date (tax and financial record requirements)
  • Guest Preferences: Until you request deletion or 3 years after your last stay
  • Marketing Communications: Until you unsubscribe or request removal
  • Website Analytics: 26 months from collection
  • Feedback and Reviews: Indefinitely unless removal requested

When retention periods expire, we securely delete or anonymize your data. Some information may be retained in aggregated, non-identifiable form for statistical purposes.

How We Protect Your Data

We implement multiple security measures to protect your information:

Technical Safeguards

  • Encrypted data transmission (SSL/TLS)
  • Secure server infrastructure
  • Regular security updates and patches
  • Restricted access to personal data
  • Secure backup procedures

Organizational Measures

  • Staff training on data protection and confidentiality
  • Privacy agreements for all team members
  • Regular review of data handling procedures
  • Incident response protocols

Breach Response

In the unlikely event of a data breach affecting your personal information, we will:

  • Assess the breach and contain it immediately
  • Notify affected individuals within 72 hours where required by law
  • Report to relevant regulatory authorities as mandated
  • Implement measures to prevent recurrence

Your Rights

Under Singapore's Personal Data Protection Act, you have the following rights:

Right to Access

You may request a copy of the personal data we hold about you. We will provide this within 30 days of your request.

Right to Correction

If your personal information is inaccurate or incomplete, you have the right to request corrections.

Right to Withdrawal of Consent

You may withdraw consent for us to process your data at any time, though this may affect our ability to provide certain services.

Right to Object

You can object to processing based on legitimate interests or for marketing purposes at any time.

Right to Data Portability

Where technically feasible, you may request your data in a structured, commonly used format for transfer to another service provider.

Right to Deletion

You may request deletion of your personal data, subject to legal retention requirements and legitimate business needs.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

Third-Party Services

We work with select third-party providers who may process your data on our behalf:

Payment Processing

Payment information is processed by authorized payment service providers who maintain PCI DSS compliance. We do not store complete credit card numbers on our servers.

Website Analytics

We use analytics services to understand website usage. These services collect anonymous usage data in accordance with their own privacy policies.

Communication Tools

Email and communication platforms may process your messages according to their terms of service. We select providers with robust privacy protections.

All third-party processors are contractually required to protect your data and use it only for specified purposes. We conduct due diligence on their security practices and data handling procedures.

International Data Transfers

Your data is primarily stored and processed in Singapore. If we transfer data outside Singapore, we ensure adequate protection through:

  • Standard contractual clauses approved by data protection authorities
  • Transfers to countries with adequate data protection frameworks
  • Your explicit consent for specific transfers

Cookies and Tracking

Our website uses cookies to enhance your browsing experience and analyze site usage. For detailed information about our cookie practices, including how to manage your preferences, please see our Cookie Policy.

Changes to This Policy

We may update this privacy policy periodically to reflect changes in our practices, technology, legal requirements, or other operational needs. When we make significant changes, we will:

  • Update the "Last Updated" date at the top of this page
  • Notify guests with upcoming bookings via email
  • Display a notice on our website for 30 days

We encourage you to review this policy periodically. Continued use of our services after changes indicates acceptance of the updated policy.

Contact Us

For questions about this privacy policy or our data practices, please contact:

Privacy Inquiries

Email: [email protected]

Phone: +65 6471 3826

Address: 39 Artillery Avenue, Sentosa Cove, Singapore 099958

If you are not satisfied with our response to your privacy concerns, you have the right to lodge a complaint with the Personal Data Protection Commission (PDPC) of Singapore.