Beginner-friendly guitars, stocked in Singapore PayNow Visa Mastercard Amex Apple Pay

Privacy Policy

Last updated: 26 April 2026

SageGuitar ("we", "us", "our") respects your privacy and is committed to protecting your personal data in accordance with Singapore's Personal Data Protection Act 2012 (PDPA).

This policy explains what personal data we collect, why we collect it, how we use and protect it, and what rights you have. It applies to www.sageguitar.com and any service we provide through phone, email, WhatsApp, or in-person at our showroom.

1. Who we are

SageGuitar is a Singapore-based retailer of beginner-friendly guitars and accessories.

  • Business address: Primz Bizhub, 21 Woodlands Close #07-42, Singapore 737854
  • Email: [email protected]
  • Phone / WhatsApp: +65 8925 2625
  • UEN: 53502192E

2. What personal data we collect

We collect only what we need to run the shop and serve you.

When you place an order: name, delivery address, postal code, email, mobile number, order details (products, quantity, total), and payment confirmation. We do not store full credit/debit card numbers — these are handled by our payment provider.

When you create an account: name, email, password (stored encrypted), order history, and saved addresses.

When you contact us: name, contact details, and the content of your message (email, WhatsApp, contact form, phone).

When you sign up for marketing: email address and/or mobile number, plus your preferences.

When you visit our website (collected automatically): IP address, browser type, device, pages viewed, referring site, time spent, and cookies (see Section 7).

We do not knowingly collect data from children under 13. If you are under 13, please ask a parent or guardian to make purchases on your behalf.

3. Why we collect your data

  1. Process and fulfil orders, including payment, delivery, and after-sales support
  2. Manage your account and order history
  3. Respond to enquiries and provide customer service
  4. Send order confirmations, delivery updates, and service messages (these are not marketing)
  5. Send marketing emails or messages only if you have given consent (see Section 8)
  6. Improve our website, products, and customer experience through analytics
  7. Detect and prevent fraud, abuse, and security incidents
  8. Comply with legal, accounting, and tax obligations

We will not use your data for any new purpose without telling you and, where required, getting your consent.

4. Who we share your data with

We do not sell your personal data. We share it only with trusted third parties who help us run the business:


PartnerPurposeWhere they operate
Stripe | Payment processing (cards, Apple Pay) | United States, Singapore
PayNow / participating banks | Local payment processing | Singapore
Local couriers (e.g. Ninja Van, J&T, SingPost) | Order delivery | Singapore
Cloudflare | Website security, performance, email obfuscation | Global (incl. Singapore edge)
Namecheap (web hosting & email server) | Hosting our website and mailbox | United States
Meta (Facebook, Instagram, WhatsApp) | Advertising, customer chat, Meta Pixel analytics | United States
Google | Website analytics (Google Analytics 4), search performance | United States, Singapore

We may also disclose your data when required by Singapore law, court order, or to protect our legal rights.

5. Overseas transfers

Some of our partners (e.g. Stripe, Meta, Google, Namecheap) process data outside Singapore. When this happens, we ensure that the receiving party provides a standard of protection comparable to PDPA, either through their own legally-binding terms, recognised certifications, or contractual safeguards — as required under PDPA's Transfer Limitation Obligation.

6. How long we keep your data

  • Order records: 5 years after the order, to meet IRAS tax record-keeping rules
  • Account data: until you ask us to delete the account, or 3 years of inactivity
  • Marketing consent: until you withdraw consent
  • Customer service messages: up to 2 years
  • Website analytics: up to 26 months

After these periods, data is deleted or anonymised.

7. Cookies and tracking

  • Necessary cookies — for login, cart, checkout, and security. These cannot be turned off.
  • Analytics cookies — Google Analytics, to understand how visitors use the site so we can improve it.
  • Marketing cookies (Meta Pixel) — to measure ad performance and show relevant ads on Facebook, Instagram, and other Meta platforms.

When you first visit the site, you'll see a cookie banner. You can accept or reject non-essential cookies. You can change your choice anytime by clicking "Cookie Settings" in our website footer.

8. Marketing and your consent

We will only send you marketing emails or SMS/WhatsApp messages if you opt in when creating an account or at checkout, sign up to our newsletter, or are an existing customer and we send you offers about similar products (you can unsubscribe anytime).

Withdrawing consent: Click the unsubscribe link in any marketing email, reply STOP to a marketing SMS, or email us at [email protected]. We will action your request within 10 business days.

We comply with Singapore's Do Not Call (DNC) Registry. If your Singapore mobile is registered with DNC, we will not send you marketing SMS or make marketing calls unless you have given us clear and unambiguous consent.

9. Your rights under PDPA

  • Access the personal data we hold about you
  • Correct any data that is inaccurate or incomplete
  • Withdraw consent for marketing or other non-essential uses at any time
  • Request deletion of your account and associated data (subject to legal retention requirements such as tax records)
  • Receive information about how your data has been used or disclosed within the last year

To exercise any of these rights, email us at [email protected] with the subject line "PDPA Request". We will respond within 30 days as required by PDPA. A reasonable fee may apply for access requests that involve significant time or cost; we will inform you in advance.

10. How we protect your data

  • Encrypted connections (HTTPS) across the entire website
  • Cloudflare web application firewall and DDoS protection
  • Encrypted password storage (we never see your password)
  • Restricted access to customer data — only authorised staff
  • Stripe handles payment card data in a PCI-DSS compliant environment
  • Regular software and security updates

No system is 100% secure, but we work to keep risk as low as reasonably possible.

11. Data breach notification

In the unlikely event of a data breach that is likely to result in significant harm or affects 500 or more individuals, we will:

  1. Notify the Personal Data Protection Commission (PDPC) within 3 calendar days
  2. Notify affected customers as soon as practicable
  3. Take immediate steps to contain and remediate the breach

12. Children's privacy

Our website and products are not directed at children under 13. We do not knowingly collect personal data from children under 13 without verified parental consent. If you believe we have such data, please contact our DPO and we will delete it.

13. Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top will reflect the latest version. For material changes, we will notify customers by email or a notice on the website.

14. Data Protection Officer (DPO)

Questions, complaints, or PDPA requests can be sent to our DPO:

  • Name: Zec
  • Email: [email protected]
  • Postal address: Primz Bizhub, 21 Woodlands Close #07-42, Singapore 737854

If you are not satisfied with our response, you may contact the Personal Data Protection Commission (PDPC) at www.pdpc.gov.sg.

Sageguitar Marketing Agent — Application Privacy

The “Sageguitar Marketing Agent” application (the “App”) is a multi-tenant content publishing tool developed by Sage Guitar and operated through Sifu Ai (Singapore-registered business, UEN 53524893L). The App connects to TikTok, Facebook, Instagram, YouTube, and Threads via official APIs to publish content on behalf of authorized SME owners.

When you authorize the App to access your social media accounts, the App collects:

  • Your account ID, username, and display name (via Login Kit / OAuth)
  • Video files, images, and captions you or your authorized representatives submit for publishing
  • Post metadata (caption text, hashtags, scheduling timestamps)

The App does NOT access: your direct messages, your followers list beyond public counts, your private viewing history, your draft content unrelated to App submissions, or any other private account data.

The App uses the following TikTok scopes:

  • user.info.basic — verify identity of the authenticated SME owner
  • video.publish — publish approved videos to the authenticated SME’s account
  • video.upload — submit draft videos for SME owner review

Content authorization: All posts are published only after explicit approval by the SME owner or their authorized representative. The App will not post autonomously without prior approval.

Data retention: Submitted content and metadata are retained for 90 days for audit purposes, then deleted. Account authentication tokens are stored encrypted and revocable at any time via your TikTok account settings.

Revocation: You may revoke the App’s access at any time via your TikTok account settings (Settings → Manage Account → Apps). On revocation, all account-linked data is purged within 30 days.

For privacy questions, contact: [email protected]

Chat