Legal · PDPA
Privacy Policy
This Privacy Policy explains how Farah ("I", "me") collects, uses, discloses, and protects personal data when you visit dailytrace.life ("DailyTrace", "the site") or contact me through it. I operate this site as a personal blog from Singapore and handle data in accordance with the Personal Data Protection Act 2012 ("PDPA") of Singapore, as amended.
By using the site or submitting the contact form, you acknowledge that you have read this policy. Where consent is required, I will ask for it clearly — for example, through the contact form checkbox or the cookie banner — and I will not pre-tick consent boxes on your behalf.
1. Who is responsible for your data
The data controller for this site is:
Farah
Blk 517 Woodlands Drive 14, #02-88
Singapore 730517
Email: [email protected]
Phone: +65 6228 4526
For privacy-related questions, withdrawal of consent, or access requests, contact me at the email above. I will respond within a reasonable period, typically within thirty calendar days.
2. What personal data I collect
I collect only what is needed to run a small personal website. The categories include:
- Contact form data: your name, email address, and message content when you use the contact form at /contact.php.
- Consent records: whether you agreed to PDPA processing on the contact form, and your cookie preferences stored in your browser's local storage under the key
dailytrace_cookie_consent. - Technical data: if you accept optional analytics cookies, anonymised usage data such as pages viewed, approximate region, browser type, and referral source may be processed by an analytics provider. I do not enable analytics unless you consent.
- Server logs: my hosting provider may automatically record IP addresses, timestamps, requested URLs, and user-agent strings for security and troubleshooting. I do not use server logs to build marketing profiles.
I do not operate user accounts, newsletters, or e-commerce on this site. I do not collect NRIC numbers, payment card data, or sensitive health information through the site.
3. Purposes and legal bases for processing
I process personal data for specific, stated purposes:
- Responding to messages: to read and reply to enquiries you send via the contact form. Legal basis: your consent (PDPA consent obligation) and my legitimate interest in correspondence.
- Site security: to detect spam (including honeypot fields), abuse, and technical faults. Legal basis: legitimate interest in protecting the site.
- Cookie preferences: to remember your choice about optional analytics for up to six months. Legal basis: your consent where required.
- Analytics (optional): to understand aggregate readership — for example, which entries are opened most — only if you accept analytics cookies. Legal basis: consent.
I will not use your contact details for unrelated marketing. I do not sell personal data.
4. How the contact form works
The contact form submits data via POST to /send.php. That script validates your input, checks a hidden honeypot field for bots, verifies that you ticked the PDPA consent box, and sends an email to my inbox. Messages are stored in my email account for as long as needed to respond and keep a record of correspondence.
If validation fails — missing fields, invalid email, or consent not given — you are redirected back to the contact page with an error notice. No email is sent in that case.
5. Cookies and local storage
Essential operation of the site may rely on minimal technical storage. Optional analytics cookies are disabled by default until you choose otherwise through the cookie banner.
Your cookie choice is saved locally in your browser under dailytrace_cookie_consent as a JSON object containing your selection and a timestamp. You may clear this at any time through browser settings; the banner will appear again on your next visit.
Buttons available: Accept all, Reject all, and Customise (where you may allow or deny anonymised analytics separately).
6. Disclosure to third parties
I may share data with:
- Hosting and email providers that transmit or store site files and inbound messages on my behalf, under their own security terms.
- Analytics providers only if you consent to analytics cookies.
- Authorities if required by applicable Singapore law, court order, or to protect rights and safety — though as a personal blog this is unlikely.
I do not transfer personal data outside Singapore unless a service provider does so for hosting; where that occurs, I expect appropriate safeguards consistent with PDPA cross-border transfer requirements.
7. Retention
Contact form emails are kept while the conversation is active and for a reasonable period afterward — typically up to twenty-four months — unless you ask me to delete them sooner. Server logs are retained according to my host's default rotation, usually thirty to ninety days. Cookie consent records live in your browser until you clear them or six months pass, whichever comes first.
8. Your rights under the PDPA
Subject to exceptions in the PDPA, you may:
- Ask whether I hold personal data about you and request access to it.
- Request correction of inaccurate or incomplete data.
- Withdraw consent for processing that relies on consent — for example, analytics or future contact — understanding that withdrawal may limit my ability to respond or provide optional features.
- Request deletion of contact messages you sent, where retention is no longer necessary.
To exercise these rights, email [email protected] with enough detail for me to identify your request. I may need to verify your identity before releasing or changing data.
If you believe I have not handled your data properly, you may contact the Personal Data Protection Commission (PDPC) in Singapore after first giving me a chance to address your concern.
9. Security
I use proportionate measures for a personal site: HTTPS where supported by hosting, spam filtering on forms, and limited access to my email inbox. No method of transmission over the internet is fully secure; I cannot guarantee absolute security, but I aim to avoid collecting more data than necessary in the first place.
10. Children
DailyTrace is written for a general adult audience. I do not knowingly collect personal data from children under thirteen. If you believe a child has submitted data through the contact form, contact me and I will delete it promptly.
11. Changes to this policy
I may update this policy when the site changes or when law requires. The "Last updated" date at the top will change accordingly. Continued use after updates constitutes acknowledgement of the revised policy where permitted by law.
12. Distinction from blog content
Journal entries on DailyTrace are personal writing and memoir. They are not privacy notices and must not be read as statements about how third parties handle data. This page is the authoritative description of my data practices for the site itself.
Data disclaimer
Information on this page describes my practices as site operator only. It does not create a contractual relationship beyond what the PDPA and applicable law require. Examples in journal posts — names of places, strangers, or routines — are narrative devices; they are not invitations to collect data about those individuals through this site.
If you quote or share my entries elsewhere, you become responsible for your own compliance with privacy and copyright rules on those platforms. I am not liable for how third-party sites process data after you leave dailytrace.life.