Skip to content
DEELAB ACADEMY Home

Privacy Policy

Last updated 07 July 2026  ·  Tailjay Pte. Ltd.

Last updated: 24 April 2026

This Privacy Policy explains what personal information DeeLab Academy collects, why we collect it, how we use it, and what rights you have over it. We have written it in plain language on purpose — if anything is unclear, please ask us.

DeeLab Academy is operated by Tailjay Pte. Ltd., a company registered in Singapore. When this policy says "we", "us", or "our", it means Tailjay Pte. Ltd.

This policy applies to everyone who visits our website, signs up for a course, completes a programme, or receives a certificate through DeeLab Academy.


1. What information we collect

When you create an account or sign up for a course

  • Full name
  • Email address
  • Phone number (optional)
  • Organisation / company name
  • LinkedIn profile URL (optional)
  • Profile photo (optional)
  • Short bio (optional)

When you make a payment

  • Amount paid and currency
  • Payment method used (card via Stripe, bank transfer, Wise, or other)
  • Payment reference (order ID, transaction reference, or bank transfer reference depending on the method)
  • Sender name, where provided by your bank or payment provider

We do not store your card number, expiry date, or CVV. Card payments are processed entirely by Stripe — your card details never pass through our servers. For bank transfers and Wise payments, we receive only the transaction reference and amount confirmed by your bank or Wise.

When you take a course or receive a certificate

  • Course enrolment records (which course, which run, start and end dates)
  • Assessment results and Scorecard (your scored performance record completed by the trainer)
  • Certificate issued (date, certificate code, course name)
  • Programme completion status

When you visit our website

  • Pages visited, time spent, traffic source (via Google Analytics — only if you accept cookies)
  • Browser type, device type, approximate location (country/city level)
  • Whether you arrived from a LinkedIn ad, and which pages you visited (via the LinkedIn Insight Tag — only if you accept cookies)

We use Google Tag Manager with Consent Mode v2. If you decline cookies, Google Analytics and the LinkedIn Insight Tag run in a restricted mode and we receive only aggregate, anonymised data — no personal tracking.

When you sign in with Google (optional)

  • Your Google account email address and display name, passed to us by Google to create or match your account

When you submit a LinkedIn Lead Gen Form

If you submit a lead enquiry form attached to a DeeLab Academy LinkedIn ad, LinkedIn sends us your name, email address, company name, and job title. This data is stored in our system as an enquiry and handled in the same way as an enquiry submitted through our website contact form.


2. Why we collect it and our legal basis

Purpose Legal basis
Creating your account and managing your enrolment Contract — necessary to deliver the service you signed up for
Processing your payment and issuing receipts Contract
Issuing and storing your certificate Contract — the certificate is the product
Sending you course updates, run confirmations, and your certificate Contract
Sending marketing emails about new courses and promotions Consent — you can opt out at any time (see section 6)
Improving our courses and website based on how they are used Legitimate interest
Keeping financial and compliance records Legal obligation
Showing you relevant course ads (Google Ads Customer Match) Legitimate interest — we retarget existing trainees and enquirers with our own course ads only. You can opt out at any time (see section 7).
Showing you relevant course ads on LinkedIn (LinkedIn Matched Audiences) Legitimate interest — we retarget existing trainees and enquirers with our own course ads only. You can opt out at any time (see section 7).
Measuring the effectiveness of LinkedIn ads (LinkedIn Conversions API) Legitimate interest — we send hashed contact data to LinkedIn to attribute purchases and signups to ad campaigns. No raw personal data is shared.
Following up on enquiries submitted via LinkedIn Lead Gen Forms Legitimate interest — to respond to your expressed interest in our courses.

Feedback and testimonials. When you complete a course you can give us feedback and a rating. We use this to improve our courses, and we may publish quotes from it on our website and in marketing materials. Our legal basis is your consent for displaying your full name (which you give on the feedback form and can withdraw at any time by contacting us); for anonymised quotes and aggregate ratings we rely on our legitimate interest in promoting our courses. Where we publish a quote without full-name consent, we show only your first name and last initial (for example, "James P.").

3. Who we share your data with

We do not sell your personal data. We share it only with the service providers listed below, and only to the extent needed to deliver our service.

Stripe — payment processing

Stripe processes all payments on our behalf. When you pay for a course, you interact directly with Stripe secure checkout. Stripe is bound by its own Data Processing Agreement: stripe.com/en-my/legal/dpa

Mailchimp (Intuit) — email delivery

We use Mailchimp to send course confirmation emails, activation links, certificate notifications, and (with your consent) marketing emails. Your name and email address are stored in Mailchimp. Mailchimp Data Processing Agreement: mailchimp.com/legal/data-processing-addendum

Google — analytics and certificate storage

  • Google Analytics / Google Tag Manager: Used to understand how our website is used — only active if you accept cookies.
  • Google Drive: Certificates (PDF and PNG files) are stored in a private Google Drive folder as a secure backup. These files are not publicly accessible.
  • Google Sign-In: If you choose to sign in with Google, your email and name are passed to us by Google. We do not receive your Google password.

Google Ads — personalised advertising

We use Google Ads Customer Match to show targeted course ads to people who have previously enrolled in or enquired about our courses. To do this, your email address is hashed using SHA-256 (a one-way cryptographic hash — the original email cannot be recovered from it) and uploaded to Google Ads, where Google matches it against its own signed-in users to show relevant ads on Google Search and YouTube.

We do this only for our own courses, only for people who have already interacted with us, and we rely on legitimate interest as our legal basis. You can opt out at any time — see section 7 for how.

Google Ads Privacy Policy: policies.google.com/privacy

LinkedIn — analytics, advertising, and lead capture

We use three LinkedIn tools, each described separately:

  • LinkedIn Insight Tag: A JavaScript pixel that loads on our public pages (only if you accept cookies) and tells LinkedIn that you visited. LinkedIn uses this to let us understand our audience demographics and to build retargeting audiences from website visitors. The Insight Tag is operated by LinkedIn Ireland Unlimited Company. LinkedIn Privacy Policy: linkedin.com/legal/privacy-policy
  • LinkedIn Conversions API (CAPI): When you complete a purchase or create an account, we send LinkedIn a set of hashed identifiers — the SHA-256 hash of your email address, first name, and last name (the original values cannot be recovered from the hash) — along with the conversion event type (e.g. "Purchase"). This allows LinkedIn to attribute ad-driven conversions accurately, even when cookies are blocked. Your raw email or name is never sent to LinkedIn. This operates server-side and is not affected by your cookie preference.
  • LinkedIn Matched Audiences: We periodically sync a list of SHA-256 hashed email addresses of our trainees and enquirers to LinkedIn via the LinkedIn DMP Segments API. LinkedIn matches these hashes against its own member database to allow us to show our course ads to matching LinkedIn members. LinkedIn never receives your original email address. You can opt out of this at any time — see section 7.

If you submit a LinkedIn Lead Gen Form in response to one of our LinkedIn ads, LinkedIn sends us your name, email, company, and job title. This is stored in our enquiry system and handled as described in section 1. LinkedIn's data practices regarding Lead Gen Forms are governed by LinkedIn's Privacy Policy.

Moodle — course delivery (where applicable)

Some courses are delivered via a Moodle learning management system. Your name, email, and course completion data may be shared with our Moodle instance to track progress and trigger certification.

All service providers are required to handle your data securely and only for the purposes we specify.


4. Cookies

We use cookies for analytics and advertising measurement. When you first visit our site, a banner asks for your choice:

  • Accept cookies: The following are enabled:
    • Google Analytics — collects visit data (pages visited, traffic source, device type) to help us improve the site.
    • LinkedIn Insight Tag — tells LinkedIn you visited our site, used for audience demographics and retargeting. Operated by LinkedIn Ireland Unlimited Company.
  • Decline cookies: Both run in a restricted/cookieless mode. No personal data is collected — we receive only anonymised, aggregate statistics. The LinkedIn Insight Tag does not load at all until you accept.

Your choice is saved in your browser. You can change it at any time by clearing local storage for deelabacademy.com.

Note on server-side advertising: Google Ads Customer Match, LinkedIn Conversions API, and LinkedIn Matched Audiences operate separately from cookies — they are based on your email address (hashed), not your browser. You can opt out of these independently in your profile settings (see section 7).


5. How long we keep your data

Data type How long we keep it
Account and profile information While your account is active. Deleted or anonymised within 30 days of a deletion request.
Course enrolment and certification records Indefinitely — your certificate is a permanent credential. If you request deletion, we anonymise the linked personal data while retaining the anonymised record.
Payment records 7 years, as required by Singapore accounting and tax law.
Marketing email list Until you unsubscribe or ask to be removed.
Website analytics data 14 months (Google Analytics default). Aggregate data only if you declined cookies.
Google Ads Customer Match (hashed email) Removed from Google's matched audience immediately when you opt out. We do not store a separate copy — the hash is generated at upload time.
LinkedIn Matched Audiences (hashed email) Removed from LinkedIn's audience segment when you opt out. Our weekly sync automatically excludes opted-out users — the hash is not re-synced.
LinkedIn Lead Gen Form submissions Stored as enquiry records. Retained for follow-up; deleted or anonymised on request.

6. Marketing emails

We send marketing emails only with your consent. You can unsubscribe at any time:

  • Click the unsubscribe link at the bottom of any marketing email.
  • Email us at [email protected] and ask to be removed.

Unsubscribing from marketing emails does not stop transactional emails — you will still receive messages about your active enrolments, payments, and certificates.


7. Personalised advertising (Google Ads & LinkedIn)

This is separate from marketing emails. Personalised advertising is about ads shown to you on Google, YouTube, and LinkedIn — not about emails we send you.

We use two advertising platforms for retargeting:

Google Ads Customer Match

Your email address is hashed (SHA-256) and uploaded to Google Ads. Google matches the hash against its signed-in users and shows our course ads on Google Search and YouTube. Google never receives your original email address — only the irreversible hash.

LinkedIn Matched Audiences

Your email address is hashed (SHA-256) and synced to LinkedIn via the LinkedIn DMP Segments API. LinkedIn matches the hash against its member database and may show our course ads to matching LinkedIn members. LinkedIn never receives your original email address — only the irreversible hash. This sync runs automatically on a weekly schedule.

For both platforms, we rely on legitimate interest as our legal basis. We use personalised advertising only to show our own courses to people who have already had contact with us — not for third-party ad networks or profiling.

How to opt out

  • In your account: Go to Edit Profile ? Advertising Preferences, tick "Opt out of personalised advertising", and save. Your email hash is removed from both Google Ads and LinkedIn Matched Audiences. The weekly LinkedIn sync will not re-add you.
  • By email: Email [email protected] with subject "Advertising opt-out" and we will remove you within 1 business day.

Opting out of ads has no effect on your account, course access, or emails (transactional or marketing).

LinkedIn Conversions API: Server-side conversion events (hashed data sent when you purchase or sign up) are used solely for conversion attribution and cannot be opted out of via your profile. If you object to this processing, email us and we will not process future events linked to your account.


8. Your rights

Depending on where you are based, you have some or all of the following rights:

  • Access: Ask us what personal data we hold about you and receive a copy.
  • Correction: Ask us to correct inaccurate or incomplete data.
  • Deletion: Ask us to delete your personal data (subject to legal retention obligations — see section 5).
  • Data portability: Ask for your data in a machine-readable format (applies under GDPR).
  • Object to processing: Ask us to stop using your data for marketing or legitimate-interest purposes.
  • Withdraw consent: Where we rely on consent (e.g. marketing emails), you can withdraw it at any time.

To exercise any of these rights, email [email protected]. We will respond within 30 days.

Singapore (PDPA)

Your rights are governed by the Personal Data Protection Act 2012. If you are not satisfied with our response, you can contact the Personal Data Protection Commission at pdpc.gov.sg.

EU / EEA (GDPR)

The GDPR applies to you. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.


9. How we protect your data

  • All data is transmitted over encrypted HTTPS.
  • Access to personal data is limited to authorised staff only.
  • We never see or store your card details — Stripe handles all payment data.
  • Certificates are stored in a private, access-controlled Google Drive folder.
  • Certificate download links are signed and time-limited.
  • Sensitive API credentials (such as LinkedIn access tokens) are stored encrypted in our database.

In the event of a data breach that affects your personal data, we will notify you and the relevant authorities within the timeframes required by law: within 3 business days under Singapore PDPA, and within 72 hours under GDPR.


10. International data transfers

Tailjay Pte. Ltd. is based in Singapore. Our service providers may process data in other countries, including the United States. These providers operate under recognised data protection frameworks and are bound by Data Processing Agreements.

  • Stripe — United States and EU
  • Mailchimp (Intuit) — United States
  • Google — United States and globally
  • LinkedIn — operated by LinkedIn Ireland Unlimited Company (EU) and LinkedIn Corporation (United States). LinkedIn Privacy Policy: linkedin.com/legal/privacy-policy

11. Changes to this policy

We may update this policy from time to time. We will update the date at the top when we do. For significant changes, we will notify you by email or with a notice on the website.


12. Contact us

Questions about this policy, or want to exercise your rights?

Tailjay Pte. Ltd. — DeeLab Academy
Email: [email protected]
Website: deelabacademy.com