Skip to main content
Ancourage Academy privacy policy

Privacy Policy

Ancourage Academy's privacy policy explains how we collect, use, and protect personal data in accordance with Singapore's PDPA. We collect student and parent information for educational services, apply security measures, and give you rights to access, correct, or withdraw consent.

Last Updated: 12 September 2026

Introduction

Ancourage Academy Pte. Ltd. (UEN 202408404R) is the organisation responsible for the personal data described in this Privacy Policy. We operate under the names Ancourage Academy and Art by Ancourage (together, "we", "us", "our", or the "Centre"), and we are committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, disclose, and protect personal data in accordance with the Personal Data Protection Act 2012 ("PDPA") of Singapore.

This Privacy Policy applies to all personal data collected from students, parents/guardians, website visitors, and any individuals who interact with our services.

By enrolling at Ancourage Academy or providing us with your personal data, you consent to the collection, use and disclosure of that data for the purposes described in this Privacy Policy. Three of the things covered by that consent are optional and separable from your enrolment — photographs and videos, the student-work licence, and marketing messages: you may decline any of them at the outset or withdraw them later, and doing so does not affect your child's enrolment. By browsing this website you consent, on Singapore's implied-consent model, to the cookies, analytics, advertising measurement, error monitoring and embedded maps described below, and you can opt out of the analytics and advertising parts at any time in your cookie preferences.

This Privacy Policy should be read together with our Terms & Conditions and Enrolment & Attendance Policies. Where a term in one cannot be reconciled with a term in another, the Terms & Conditions govern, then the Enrolment & Attendance Policies, then this Privacy Policy; if a term is ambiguous, the interpretation more favourable to you applies. Our Editorial Policy is provided for transparency only and does not form part of this agreement.

Data Protection Officer

We have appointed a Data Protection Officer (DPO) who is responsible for overseeing our data protection practices and ensuring compliance with the PDPA.

If you have any questions, concerns, or requests regarding the protection of your personal data, please contact our DPO:

Data Protection Officer: Min

Email: tuition@ancourage.net

Phone: +65 8849 8106

Personal Data We Collect

We collect the following categories of personal data:

1. Student Information

  • Full name and preferred name
  • Date of birth and age
  • Gender
  • School name, grade level, and subject levels
  • Academic records and assessment results
  • Attendance records
  • Homework completion and progress tracking
  • Medical conditions, allergies, and medications
  • Special educational needs or learning requirements
  • Photographs and videos (for documentation and marketing — consented to on enrolment, withdrawable at any time)
  • Student artwork, essays, and project work

We do not collect NRIC, FIN or passport numbers. Under the PDPC's Advisory Guidelines on the PDPA for NRIC and Other National Identification Numbers, an organisation may collect these numbers only where the law requires it, or where it must establish identity to a high degree of fidelity — and the same treatment applies to work permit and birth certificate numbers. Neither exception applies to tuition enrolment, so we do not ask for these numbers in full or in part, for enrolment, record-keeping, identity verification or any other purpose. We identify students and parents by name and by the contact details you register with us.

2. Parent/Guardian Information

  • Full name
  • Contact details (mobile number, email address, home address)
  • Emergency contact information — where you give us another person's details, please make sure they know and agree
  • Payment information (bank account details, transaction records)
  • Communication records (WhatsApp messages, emails, and our notes of phone calls)

3. Website and Online Data

  • IP addresses and device information
  • Browser type and version
  • Pages visited and time spent on website
  • Referral source and navigation patterns
  • Cookies and similar tracking technologies (see Section on Cookies below)

4. Sensitive Personal Data

We may collect sensitive personal data where you give it to us or consent to our collecting it, including:

  • Medical conditions, allergies, and health information
  • Special educational needs or disabilities
  • Psychological or behavioural assessments (if provided by parents)

Sensitive data is collected only when necessary — for the safety and well-being of students, or to verify an absence or assess a related request for credits, a transfer or an extension under our Terms — and access to it is limited to the staff who need it.

What we need from the document. Where a document is sent to support an absence or a related request, we need only your child's name, the dates it covers, and the clinic's or hospital's letterhead or stamp.

Redaction and identification numbers. You are free to redact everything else, including the diagnosis, and we ask you not to send identification numbers — we do not collect NRIC, FIN or passport numbers; if one reaches us anyway, we black it out on arrival and do not record it.

Filing and removal. We do not file the document with your child's record, and we keep it no longer than we need it.

5. Premises (CCTV)

Closed-circuit television operates at our Bishan and Woodlands centres and records images of students, parents/guardians, staff and visitors in and around the premises. We use this footage to keep the premises and the people in them safe, and to investigate incidents, accidents and security concerns. How long footage is kept is set out under “Data Retention” below.

How We Collect Personal Data

We collect personal data through the following methods:

  • Registration: Information you give us when you register your child, usually over WhatsApp or by email
  • Direct Communication: WhatsApp messages, emails, phone calls, in-person conversations
  • Assessment and Progress: Academic evaluations, homework tracking, attendance records
  • Observations: Teacher observations of student behaviour, learning style, and progress
  • Payment Transactions: Bank transfer details, PayNow information, cryptocurrency wallet addresses and transaction IDs
  • Website Interactions: Cookies and similar identifiers, and analytics about how you browse the site
  • Photography/Videography: Photos and videos taken during classes, events, or activities (consented to on enrolment, withdrawable at any time)
  • CCTV: Closed-circuit cameras recording our premises at both centres, for safety, security and incident investigation
  • Third Parties: In limited cases, from schools or previous tutors (with your consent), and from someone referring you under our referral programme (they need not be a customer of ours). We ask a referrer to get your permission before sharing your contact details with us

How We Use Personal Data

We use your personal data for the following purposes:

1. Educational Services

  • Managing enrolment, class placement, and scheduling
  • Delivering lessons, assessments, and educational activities
  • Following each student's progress and giving feedback on it
  • Adjusting how we teach to each student's learning needs
  • Preparing homework, worksheets, and learning materials

2. Communication

  • Keeping you informed about class schedules, events, and cancellations
  • Sending you progress updates and teacher feedback
  • Answering your enquiries and support requests
  • Sending announcements and important notices about your child's classes

3. Payment Processing

  • Processing enrolment fees and lesson package payments
  • Issuing receipts and maintaining financial records
  • Managing payment reminders and late payment follow-ups

4. Health and Safety

  • Ensuring student safety during classes and activities
  • Responding to medical emergencies and contacting emergency services
  • Maintaining allergy and medical condition records for teacher awareness
  • Complying with health-related government regulations when required
  • Verifying an absence or assessing a related request for credits, a transfer or an extension under our Terms & Conditions — for which we need only your child's name, the dates the document covers, and the issuing clinic's or hospital's letterhead or stamp

5. Marketing and Promotion

  • Showcasing student work and achievements on our website and social media (consented to on enrolment, withdrawable at any time)
  • Creating promotional materials, brochures, and advertisements
  • Sharing testimonials and success stories (with consent)
  • Sending marketing communications about new programmes or events to existing contacts

DNC & Spam Control Compliance: Where we have an ongoing relationship with you — your child is enrolled with us, or recently was — paragraph 1(1)(e) of the PDPA's Eighth Schedule takes messages about that relationship outside the Do Not Call rules, so we may send them without first checking the register.

Where the exclusion does not reach. That exclusion does not extend to a one-off contact: if you have only enquired once and not enrolled, we check the Do Not Call Registry before sending you marketing messages addressed to a Singapore telephone number.

Opting out. Either way, every WhatsApp broadcast carries an easy opt-out by reply, and you may opt out at any time (see Your Rights below).

6. Legal Compliance

  • Complying with applicable laws and regulations in Singapore (e.g., PDPC obligations, IRAS record-keeping)
  • Responding to legal requests or court orders
  • Maintaining records for tax and accounting purposes
  • Investigating complaints or disputes

7. Analytics and Improvement

  • Analysing website traffic and user behaviour
  • Improving teaching methods and curricula
  • Evaluating programme effectiveness
  • Internal training and quality improvement

Consent Framework

1. General Consent

By enrolling at Ancourage Academy or providing your personal data, you consent to our collection, use and disclosure of that data as described in this Privacy Policy and for the purposes outlined above. Photography and video, the student-work licence, and marketing messages are optional and separable from your enrolment — you may decline any of them at the outset or withdraw them later, and doing so does not affect your child's enrolment.

2. Consent for Children Under 13

For students under 13 years of age, we require parental/guardian consent. By enrolling a child under 13, parents/guardians provide consent on behalf of the child for the collection, use, and disclosure of the child's personal data (PDPC Children's Privacy Guidelines 2024).

3. Consent for Children Aged 13-17

For students aged 13-17 years, the student may give valid consent if they can understand the purposes and consequences of the data collection. In education contexts, we may still seek parental consent as a prudent practice to ensure clarity and transparency.

4. Withdrawal of Consent

You may withdraw consent for specific purposes at any time by providing written notice to our Data Protection Officer at tuition@ancourage.net, or by WhatsApp message to our Centre number.

Some of what we hold is what makes the classes work. What each one would affect:

  • Contact details — we would have no way to reach you about a schedule change or a cancellation
  • Medical information — we would not know about an allergy or a condition in an emergency
  • Payment processing — we would not be able to take payment, so we could not keep the enrolment running

We tell you the likely consequences of withdrawing. The timetable for giving effect to a withdrawal, what happens to your enrolment, and what happens to money you have already paid are set out under “Right to Withdraw Consent” in Your Rights Under PDPA below.

Disclosure of Personal Data

We may disclose your personal data to the following parties, and otherwise only where Singapore law requires or permits it — for example to our professional advisers or insurers, to recover an unpaid amount, to protect a child's safety, or if the business is sold:

1. Internal Parties

  • Teachers and instructors (for educational purposes)
  • Administrative staff (for enrolment, billing, and communication)
  • Centre management (for oversight and quality assurance)

2. Service Providers

We engage third-party service providers to support our operations. Each handles personal data under its own terms; where we hold no agreement with a provider covering the data at all, the entry or the note below says so:

  • Payment Processors: Banks, PayNow service providers, cryptocurrency exchanges (for processing payments)
  • Website Hosting: Vercel or other hosting providers (for website infrastructure)
  • Communication Platforms: WhatsApp, email providers (for messaging)
  • Online Class Platform: Microsoft Teams (live audio and video for online lessons). We do not routinely record lessons. If we ever record one — to review a technical problem, or because you asked us to — we tell you before that lesson starts, you may ask us not to, and the recording is used for that purpose, and where necessary to look into an incident or complaint, and kept only as long as that purpose needs it
  • Analytics & Advertising Tools: Google Analytics 4 (website analytics), Microsoft Clarity (heatmaps and session recordings), Meta/Facebook Pixel and Conversions API, and TikTok Pixel and Events API (advertising measurement and conversion matching). For the Meta Conversions API and the TikTok Events API we send events from our own servers, which include your IP address, browser user-agent, the page URL and the advertising cookie identifiers described below; events we send to the TikTok Events API also include the page you came from. Events we send to the Meta Conversions API also include your approximate country, city and region, derived from your IP address and sent in hashed form. We also send some events to Google Analytics from our own servers (the Measurement Protocol); those carry only an analytics identifier and the event details, not your IP address or browser user-agent
  • Error Monitoring: Sentry (application error and performance diagnostics, which may capture your IP address, browser and the page URL when something goes wrong, and on a small random sample of ordinary page loads used to measure performance)
  • Maps: Google Maps (embedded centre maps on our homepage and location pages, which load when you scroll to them and send Google your IP address and browser user-agent). Your browser contacts Google directly for these maps, so we never receive that information — and because the maps need no account or key on our side, we hold no data-protection agreement with Google covering them. Google handles what it receives under its own privacy policy
  • Cloud Storage: Google Drive or similar services (for document storage)

Note: Service providers acting as data intermediaries — our hosting, cloud storage, online-class platform (Microsoft 365), Google Analytics and error-monitoring providers — handle personal data on our behalf, under their own published terms. (a) WhatsApp and our email provider are not on that list. You choose to message us there; your messages sit on their servers under their own terms, and we hold no data-protection agreement with either of them covering the conversation. (b) Meta and TikTok are not data intermediaries: under their advertising terms they decide their own purposes for the pixel and conversion data they receive, so they act as independent controllers. You can switch the advertising cookies off at any time. (c) Microsoft Clarity is not a data intermediary either: under Microsoft's terms it acts as an independent controller of the session data it collects on this site, may use it to provide Microsoft Advertising and to improve its products, and handles it under the Microsoft Privacy Statement; opting out of analytics cookies signals your choice to Clarity in the same way.

3. Government Authorities

We may disclose personal data to government agencies when required by law, including:

  • Inland Revenue Authority of Singapore (IRAS) for tax purposes
  • Personal Data Protection Commission (PDPC) for data breach notifications or compliance enquiries
  • Law enforcement agencies if required by court order or legal investigation
  • Other regulatory authorities as required by applicable Singapore law

4. Emergency Services

In medical emergencies, we may disclose relevant health information to ambulance services, hospitals, or medical professionals to ensure proper treatment.

5. No Sale of Personal Data

We do not sell, rent, or trade your personal data to third parties for marketing purposes. Where we measure advertising results, any contact details are converted into a one-way hash (which we still treat as personal data) before being sent to Meta or TikTok, and are used to match a conversion to an advertisement and to improve how our advertising is delivered. What each platform does with data it receives is governed by its own terms, which we do not control.

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected or to comply with legal obligations.

Retention Periods:

  • Student Records (enrolment, attendance, progress and assessment): while the student is enrolled, and afterwards for as long as reasonably necessary for the purposes in this policy or for legal or business purposes
  • Documents Supporting an Absence or a Related Request (medical certificates, hospital slips): kept no longer than we need them. The Student Records period does not apply
  • Financial Records: 7 years: the tax and accounting record-keeping period is 5 years, and we keep them for 7 so that they run on the same clock as the enrolment conversation record below, which covers the 6-year time limit for a contract claim
  • Online Lesson Recordings (Microsoft Teams, made only where we have told you in advance): kept only for as long as the purpose we told you about needs it
  • Enquiries That Do Not Lead to Enrolment: we review these at least once a year and keep an enquiry only for as long as it is still serving the purpose it was collected for, or we still need it for a legal or business reason — including where the record is reasonably necessary for an ongoing or reasonably anticipated complaint, investigation or legal proceeding
  • Conversations With Enrolled Families: the messages that record enrolment, your acceptance of our Terms, package terms, agreed changes, withdrawal or termination sit in the same WhatsApp, email or text conversation as everyday messages about lessons, and we have no way to separate the two. We therefore keep the conversation as a whole — normally for 7 years after that enrolment or package ends, and longer only where reasonably necessary for an ongoing complaint, investigation or legal proceeding. We keep it that long because there is no separate signed enrolment form: these messages are the record of what was agreed between us, and the general time limit for bringing a contract claim in Singapore is 6 years (Limitation Act 1959, s.6(1)(a))
  • Marketing Materials (Photos/Videos of Students): for as long as we are still using the material to showcase our programmes. There is no fixed end date, because a published photo or video keeps serving that purpose for as long as it stays published. It ends when you withdraw consent, or when we stop using the material — whichever comes first. See “Photos, Videos, and Marketing Content” below for how to withdraw and how quickly we remove things
  • Website Analytics Data: 14 months (GA4 event data retention; Google-signals has separate retention controls)
  • Session Recordings & Heatmaps (Microsoft Clarity): recordings 30 days; recordings we label or favourite, a randomly selected sample of recordings that Microsoft keeps whether or not we labelled them, and heatmap and click data, up to 9 months — per Microsoft's published retention schedule
  • Advertising Measurement Data (Meta, TikTok): retained by those platforms under their own published schedules; we do not control their retention periods
  • CCTV Footage: Typically 30 days, or longer where necessary for incident investigation. We display signage explaining purpose and DPO contact details (PDPC Selected Topics Guidelines)

Where more than one of these periods could apply to the same record, the more specific one governs.

Student Records needed for an ongoing or reasonably anticipated complaint, investigation or legal proceeding, or that the law requires us to keep, are kept for as long as that need continues.

Data Deletion:

After the applicable retention period ends, we securely delete or destroy the records, or anonymise the data so that it can no longer be associated with a particular person. Where we delete, we:

  • Delete personal data from the systems we control
  • Destroy physical documents containing personal data
  • Remove personal data from our own backups as routine backup cycles overwrite them

Data Security

We implement reasonable security measures to protect your personal data from unauthorised access, collection, use, disclosure, copying, modification, disposal, or similar risks.

Security Measures:

  • Access Controls: Limited access to personal data on a need-to-know basis
  • Provider Account Controls: The provider accounts that hold personal data are protected by access controls appropriate to the data they hold
  • Multi-Factor Authentication (MFA): Used, where the provider supports it, on provider accounts that hold personal data, to reduce the risk of unauthorised access
  • Encryption: HTTPS/SSL encryption for website data transmission
  • Encryption at Rest: Cloud documents encrypted at rest where supported
  • Staff Training: We communicate our data-protection policies, practices and relevant updates to staff
  • Disposal: Personal data is deleted or destroyed when we no longer need it, as set out under “Data Deletion” above

Limitations:

No method of transmission or storage is completely secure, so we cannot promise absolute security. A few things stay on your side:

  • Keeping your WhatsApp account and email passwords confidential
  • Not sharing sensitive information via insecure channels
  • Reporting suspicious activity or potential security breaches immediately

Data Breach Notification

In accordance with the PDPA (Amendment) Act 2020, we assess every breach against the notifiability thresholds below. Where a breach is notifiable we tell the Personal Data Protection Commission (PDPC); we tell affected individuals where the breach is one that is likely to result in significant harm to them.

Our Commitment:

  • Investigate a suspected data breach and assess whether it is notifiable, in a reasonable and expeditious manner
  • Notify PDPC as soon as is practicable, and in any case within 3 calendar days of determining that the breach is notifiable
  • Notify affected individuals, as soon as practicable, where the breach is likely to result in significant harm to them
  • Provide information on steps being taken to mitigate harm
  • Cooperate with PDPC investigations

Exceptions to individual notification. The PDPA sets each of the following.

Harm made unlikely. We do not have to notify you individually where we have taken action, or already had a technological measure in place, that makes significant harm unlikely.

PDPC waiver. The PDPC can waive individual notification on our written application.

Law enforcement or PDPC direction. We must not notify you where a prescribed law enforcement agency instructs us not to, or the PDPC directs us not to — typically while an investigation is running.

Scale-only breaches. Where a breach is notifiable only because of its scale, the PDPA requires us to notify the PDPC rather than each individual.

Notifiable Data Breach Thresholds:

We will notify PDPC if a data breach:

  • Is likely to result in significant harm to affected individuals, OR
  • Affects ≥ 500 individuals (significant scale threshold), even if significant harm is not likely

What Constitutes Significant Harm:

Significant harm may include:

  • Identity theft or fraud
  • Financial loss
  • Damage to reputation
  • Physical or psychological harm
  • Loss of employment or business opportunities

That list describes effects. The law also works the other way round: under the Personal Data Protection (Notification of Data Breaches) Regulations 2021, some breaches count as causing significant harm because of the kind of data involved, without anyone having to predict an outcome. Broadly, that is your full name, an alias or an identification number together with one of the categories of personal data those Regulations prescribe (they include financial and account information), or your account name or number together with a password, security code or other data used to get into that account. Where a breach falls within one of those categories, and none of the exceptions in those Regulations applies, we treat it as notifiable without waiting to see whether any of the harms listed above actually happens.

If you believe your personal data has been compromised, please contact our DPO immediately at tuition@ancourage.net.

Your Rights Under PDPA

Under the Personal Data Protection Act, you have the following rights:

1. Right of Access

You may request a copy of your personal data held by us. We will respond as soon as reasonably possible. If we cannot respond within 30 days, we will inform you within 30 days of the reason and when we will respond.

Access includes information on how your data has been used or disclosed in the past year (disclosure history).

We may charge a reasonable fee reflecting the incremental cost of responding to an access request, and we will give you a written fee estimate before proceeding.

2. Right to Correction

You may request correction of inaccurate or incomplete personal data. We will make reasonable efforts to correct the data within 30 days, or inform you within 30 days if more time is needed.

3. Right to Withdraw Consent

You may withdraw consent for specific purposes (e.g., marketing communications, photography) at any time on reasonable notice. We give effect to a withdrawal as soon as reasonably practicable after we receive it. Withdrawing consent does not stop us keeping or using personal data where the PDPA or another written law requires or allows it without your consent, or keeping records for as long as retention is still necessary for a legal or business purpose — for example the financial records we must keep for tax, and records reasonably necessary for an ongoing or reasonably anticipated complaint, investigation or legal proceeding. Where a withdrawal would affect your child's enrolment, when it takes effect is set out under “Consequences if the enrolment ends” below and in clause 6 of our Terms & Conditions.

Note: some data is what makes the classes work — how we reach you, how we keep your child safe, and how we take payment. If you withdraw consent for those, we may not be able to keep the enrolment running and may have to end it.

Consequences if the enrolment ends. If it does come to that, we never treat it as anything you have done wrong: the enrolment ends as a withdrawal by you, with your notice running from the day we receive your request; on the ordinary timetable that is notice enough, and any enrolment deposit we hold is returned to you in full within 14 days. What happens to money you have already paid is set out in clause 6 of Refunds and Withdrawals in our Terms & Conditions, and that clause applies here in full. Where an amount is due from you, the deposit is applied to it first, up to the outstanding amount, as clause 3 of Refunds and Withdrawals sets out, and the withdrawal of consent takes effect when clause 6 says it does. An instalment deposit on a 24-lesson package paid in blocks is different: because the enrolment ends as a withdrawal by you before the package is complete, it is forfeited under clause 1 of Refunds and Withdrawals, and it is never returned in cash.

Withdrawals that do not affect enrolment. This does not apply to photographs and video, the student-work licence, or marketing messages: withdrawing any of those does not affect your child's enrolment.

4. How to Exercise Your Rights

To exercise any of the above rights, please submit a written request to our Data Protection Officer:

Email: tuition@ancourage.net

Subject Line: "Data Access Request" or "Data Correction Request"

Required Information:

  • Your full name, and the email address or mobile number you registered with us — we verify your request against the contact details already on your record. We will not ask for your NRIC, FIN or passport number to process a request
  • Student name (if applicable)
  • Specific data you wish to access/correct
  • Where to reply: we reply only to the email address or WhatsApp number already on your record, or after another check we consider reliable — never simply to a new address given in the request. If you have changed number, tell us from the old one first, or come to the centre. Where two adults each claim rights over the same child's record, we may ask for evidence of legal authority before releasing anything.

Limits on access requests. There are limits on this, and they run in two directions. Some things we are not required to give you. Those include an examination we conduct and, before the results are released, the results themselves; anything covered by legal privilege; and a request that is frivolous or vexatious, or one where the burden of answering would be out of proportion to what it is worth to you. They also include opinion data we keep solely in order to decide something about a person — a place or an award, say — which is not the same thing as your child's ordinary progress notes, and those you can have.

Material we must not release. Other things we are forbidden to give you. The PDPA says we must not release material where doing so could reveal personal data about another individual, reveal who told us something about another individual, threaten another person's safety or physical or mental health, cause you immediate or grave harm, or be contrary to the national interest. That is why a request made in complete good faith can still be one we have to decline in part — a class record naming another child is the ordinary example. It does not reach your own messages to us, or the record of what you did on our site, even where another person is mentioned in them: that material stays available to you. This exception is about other people's data and identities only; the other legal limits above still apply.

When something is held back. Where any of this applies we give you the rest of what you asked for, tell you that something has been held back and why, except in the one case set out below, and keep a copy of whatever we refused for at least 30 days — longer while a review or appeal is running — so that you can ask the PDPC to look at our decision.

One limit we cannot waive. Where we have given personal data about you or your child to the police or another prescribed law enforcement agency, under a written law and without your consent, the PDPA does not permit us to tell you that we did. On that one point we cannot give you the reason, and it is the Act that decides that, not us. While an investigation or proceedings and any appeal from them are still running, we may also decline to confirm or deny whether information of that kind exists, or has been used or disclosed. Everything else you asked for still reaches you.

Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance user experience and analyse website traffic.

What Are Cookies?

Cookies are small text files stored on your device when you visit a website. They help the website remember your preferences and understand how you use the site.

Singapore Implied Consent Model

Cookie Consent Approach: We use Singapore's implied consent model for cookies. Analytics and marketing cookies are enabled by default, but you may opt-out at any time via our cookie preferences (click "Cookies" in footer). Essential cookies cannot be disabled as they are required for website functionality.

What opting out does and does not do: (a) Opting out signals your choice to Google Analytics, Meta, TikTok and Microsoft Clarity, and stops the server-side advertising events we send to Meta and TikTok. (b) Opting out of marketing also stops us writing the first-party advertising identifiers — _aeid, _fbp and _fbc — and expires the ones we set. Cookies set by other parties, and any other cookies already stored on your device, are cleared in your browser settings. (c) We also keep a record of how you reached us — your campaign and referral details — in your browser’s own storage rather than in a cookie; opting out clears it on your next visit, and clearing site data in your browser settings removes it immediately. (d) Error-monitoring diagnostics (Sentry) are not covered by the cookie preferences: for error monitoring and for the embedded Google map we rely on the PDPA's legitimate-interests exception, having assessed that the benefit outweighs any effect on you.

Types of Cookies We Use:

  • Essential: ancourage_consent (12 months), which stores your cookie choices, and a sign-in session on our staff-only admin pages — cannot be disabled
  • Analytics: Google Analytics and Microsoft Clarity to measure website traffic, user behaviour, heatmaps and session recordings
  • Marketing: Meta Pixel and TikTok Pixel to measure ad performance and conversions, plus the three first-party identifiers listed below

Cookies We Set Ourselves:

In addition to the third-party cookies below, our own website sets these first-party identifiers:

  • _aeid (12 months): a randomly generated visitor identifier, sent to Meta and TikTok in hashed form to match conversions
  • _fbp (90 days): a browser identifier in Meta's format, used for advertising measurement
  • _fbc (90 days): records the Facebook click identifier when you arrive from a Meta advertisement

Third-Party Cookies:

We use the following third-party services that may set cookies or otherwise receive data about your visit:

  • Google Analytics (GA4): Analyses website usage and traffic sources. Event data retention is set out under Data Retention above
  • Facebook Pixel: Tracks conversions from Facebook ads. We also send server-side conversion events via the Meta Conversions API
  • TikTok Pixel: Tracks conversions from TikTok ads, with server-side events sent via the TikTok Events API. TikTok's own identifiers are _ttp (a browser identifier set by TikTok) and ttclid (the TikTok click identifier, recorded when you arrive from a TikTok advertisement), both of which our server-side events carry in addition to the _aeid identifier described above
  • Microsoft Clarity: Records heatmaps and session replays of how visitors interact with pages
  • Sentry: Captures application errors and performance diagnostics

Managing Cookies:

You can control and delete cookies through:

Photos, Videos, and Marketing Content

1. Consent for Photography/Videography

By enrolling at Ancourage Academy, you consent to us capturing and using photographs, videos, and testimonials featuring your child for the purposes set out below. This consent is optional and separable from your enrolment — you may withdraw it at any time (see “Opt-Out Option” below), and doing so does not affect your child's enrolment.

Adult learners. If you enrol as an adult learner, this applies directly to you: it covers your own photographs, videos, testimonials and work, for the purposes set out below, and you may decline or withdraw it without affecting your enrolment.

Organisation bookings. Where an organisation books a programme for its people, its booking does not by itself cover a participant's photographs or videos — before we use them for these purposes we give that participant this notice and ask them — or their parent or guardian, where the participant is a child or cannot give consent for themselves — unless someone validly authorised to act for them has already answered.

We may use photos and videos for:

  • Documenting student learning and progress (internal use)
  • Displaying student work in the Centre
  • Posting on our website and social media — currently Instagram, Facebook, TikTok, YouTube and LinkedIn — including our own advertising on those platforms
  • Creating promotional materials (brochures, flyers, advertisements)
  • Sharing success stories and testimonials

2. Privacy Safeguards

We are mindful of student privacy and will:

  • Avoid publishing full names unless you provide explicit permission
  • Not disclose personal contact details, such as phone numbers and home addresses, in public materials
  • Use first names only or pseudonyms when appropriate
  • Ensure images are appropriate and respectful

3. Opt-Out Option

You may opt out at any time — for all five purposes above, not only the marketing ones — by:

  • Emailing our DPO at tuition@ancourage.net
  • Replying via WhatsApp message to our Centre number
  • Subject line: "Photo/Video Opt-Out - [Student Name]"

The same request also withdraws our permission to show work your child has made here — artwork, writing, projects. You do not need to ask for the two separately: unless you tell us you mean only one of them, a request to stop using photos, videos or work featuring your child covers both. That permission is set out under Student Work in our Terms & Conditions.

4. Removal of Published Content

Upon receiving an opt-out request, we will:

  • Cease future use of your child's photos/videos
  • Remove content from our website and social media where reasonably practicable
  • Have anyone processing it on our behalf stop using it, unless the PDPA or another written law requires or allows the use to continue

Note: For the digital surfaces we control, we complete removal as soon as reasonably practicable, ordinarily within 14 days. We cannot remove content already in circulation (e.g., printed brochures distributed, third-party websites, or search engine caches).

5. Parent Photography Rules

At Centre events, please photograph only your own child — other families have made their own choices about this. You must not photograph or record another child unless that child's parent has agreed, and where that is not respected we may exclude the person concerned from future events.

Overseas Data Transfer

Your personal data may be transferred to, stored, or processed in locations outside Singapore, including:

  • Cloud Storage: Google Drive (servers in USA and other jurisdictions)
  • Online Class Platform: Microsoft Teams (servers in the USA and other jurisdictions). Live lesson audio and video passes through it, and any recording we make is kept there for the period set out under “Data Retention” above
  • Website Hosting: Vercel (servers globally distributed)
  • Analytics: Google Analytics and Microsoft Clarity (servers in USA)
  • Marketing: Facebook/Meta and TikTok (servers in USA and other jurisdictions)
  • Error Monitoring: Sentry (servers in USA)
  • Maps: Google Maps (servers in USA and other jurisdictions)
  • Communication Platforms: WhatsApp and our email provider (servers in the USA and other jurisdictions). The enrolment conversation itself is held here, and we keep it for years rather than months — see “Data Retention” above.

How we handle overseas transfers

What we do about the PDPA's Transfer Limitation Obligation:

  • Where enrolment, scheduling and lesson records are held overseas, that is because holding them there is reasonably necessary to conclude or perform the tuition contract between you and us
  • Conducting due diligence on service providers' data protection practices

For the PDPA's Transfer Limitation Obligation — the rules that govern the transfer itself — we rely on the steps above, not on your consent. You are not asked to agree to overseas transfers as a condition of using our services.

The providers that handle data on our behalf — hosting, cloud storage, our online-class platform, Google Analytics and error monitoring — do so under their own published terms. WhatsApp and our email provider are different: they carry your messages rather than handle data on our instructions, and we hold no data-protection agreement with either of them. The embedded Google maps are another case where we hold no agreement: your browser fetches those directly, so nothing covers them on our side. Meta and TikTok are different again: under their advertising terms they decide their own purposes for the pixel and conversion data they receive, so they are not our data intermediaries. For those, the control is yours — turn the advertising cookies off in your cookie preferences and the server-side events stop with them. Microsoft Clarity is in the same position for the same reason: under Microsoft's terms it is an independent controller of the session data it collects, which it may use for Microsoft Advertising and to improve its products under the Microsoft Privacy Statement; the analytics cookie switch is the control for it.

Children's Privacy

Our services are directed mainly at children and young people, from age 3 through to junior college level, and we also run some programmes open to adults. We take children's privacy seriously and comply with PDPA requirements for collecting children's personal data.

Parental Consent:

  • For children under 13, parental consent is required and obtained during enrolment
  • For children 13-17, the child may consent if they understand the purposes and consequences of the data collection, and we may still seek parental consent as a prudent practice
  • Parents or legal guardians may exercise all rights on behalf of their children, including access, correction, and withdrawal of consent

Protection Measures:

  • Access to children's data is restricted to authorised personnel only
  • We share children's personal data with third parties for marketing only within the photography and testimonial consent described under “Photos, Videos, and Marketing Content” above — which a parent may decline or withdraw at any time without affecting enrolment. We do not share children's personal data with third parties for any other marketing purpose

Updates to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or business operations.

Notice of Changes:

  • The "Last Updated" date at the top of this page will be revised
  • (a) Except as set out in (c), changes take effect from the date they are published and do not change how we handled your data before then. (b) For a material change we will tell you directly, using the contact details we hold for you; if you would rather not accept it, you may withdraw your consent or end your enrolment on the terms in our Terms & Conditions. (c) Where we rely on your consent, a change to how we use data you have already given us takes effect 14 days after we tell you directly, unless you tell us within that time that you do not accept it; we do this only where we have assessed that the change is not likely to have an adverse effect on you, and never for marketing messages, which always need your consent. (d) Simply continuing to use the site is not agreement to a change

Complaints and Queries

Internal Complaints:

If you have concerns or complaints about how we handle your personal data, please contact our Data Protection Officer:

Data Protection Officer: Min

Email: tuition@ancourage.net

Phone: +65 8849 8106

We will look into your complaint and reply as soon as reasonably practicable.

External Complaints:

If you are not satisfied with our response, you may file a complaint with the Personal Data Protection Commission:

The Commission's contact details and complaint process are published at www.pdpc.gov.sg.

Contact Information

For general enquiries about this Privacy Policy or our data protection practices, please contact:

Ancourage Academy

Bishan Branch:

152 Bishan St.11, #01-215, 2nd Floor, Singapore 570152

Woodlands Branch:

Vista Point, 548 Woodlands Drive 44, #02-16, Singapore 730548

Email: tuition@ancourage.net

Phone: +65 8849 8106

WhatsApp: +65 8849 8106 (opens WhatsApp in new tab)

Acknowledgement and Consent

By enrolling at Ancourage Academy or providing us with your personal data, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use and disclosure of your personal data as described in it. By browsing this website you consent to the cookies, analytics, advertising measurement, error monitoring and embedded maps described above; you can manage the analytics and advertising parts at any time in your cookie preferences. For the PDPA's Transfer Limitation Obligation we rely on the steps set out under Overseas Data Transfer rather than on your consent.

This Privacy Policy should be read together with our Terms & Conditions and Enrolment & Attendance Policies. Where a term in one cannot be reconciled with a term in another, the Terms & Conditions govern, then the Enrolment & Attendance Policies, then this Privacy Policy; if a term is ambiguous, the interpretation more favourable to you applies. Our Editorial Policy is provided for transparency only and does not form part of this agreement.