Fundora respects your privacy. We collect and process personal data to deliver purpose-aligned business guidance and tools while following applicable Singapore regulations.

General Privacy Information

This Privacy Policy explains how Fundora collects, uses, stores and shares personal data when you use our services at purposefun.biz. The policy includes practical examples and real-world scenarios showing typical data flows for account onboarding, goal-setting exercises, automated budgeting, scenario simulations, and anonymised analytics used to improve tools. We describe rights you can exercise and steps to contact us. Our approach focuses on minimizing data collection while enabling explicit, purpose-driven funds management features.

2026-04-24
Fundora Pte. Ltd. (Business ID S1834445A), 227 Tampines Street 23, Singapore, 520211
227 Tampines Street 23, Singapore, 520211

Foundation and Scope

Key definitions

The definitions below clarify terms used across this policy and are illustrated with short scenarios showing how the terms apply in practice. Examples reference typical interactions such as signing up for an account, linking an external account for budgeting, or receiving personalised recommendations.

Personal data means any information relating to an identifiable individual. Example: when a user creates an account and provides name, email and target savings goals to fund a community project, those inputs qualify as personal data.
Processing covers any operation performed on personal data, such as collection, storage, analysis or deletion. Practical case: processing occurs when Fundora analyses monthly transaction patterns to produce a purpose-aligned budget recommendation for a user.
User refers to an individual using Fundora services. Scenario: a Singapore-based freelancer who signs up to structure gains around a community grant becomes a user and can control their data settings.
Service refers to the Fundora platform and related tools hosted at purposefun.biz, which provide budgeting, goal tracking, reporting and scenario simulations to help align funds with a stated purpose.
Cookies and similar technologies are small identifiers stored on a device to enable sessions, preferences and analytics. Example: cookies keep a logged-in user in session while they review several hypothetical allocation scenarios.

What data we collect

We collect data from users when they register, interact with the platform, connect business sources, or request support. Below we outline types of data, accompanied by practical examples showing why each type matters for delivering purpose-aligned funds management.

Collection categories

Data you provide directly

When you sign up or use Fundora features you may provide personal details and purpose-related inputs. Case: a user enters a social-impact savings goal, upload supporting documents for verification, and selects preferred allocation scenarios.

  • Contact details such as name, email and phone number for account setup and notifications.
  • Purpose and goal descriptions, target amounts, timelines and prioritisation preferences used to tailor recommendations.
  • Business account identifiers and transactional metadata when a user links accounts for budgeting and cashflow modelling.
  • Profile information such as occupation, household size and recurring obligations to model realistic scenarios.
  • Uploaded documents and receipts when users request assistance or validation for purpose-driven funding cases.
  • Support communications, questions and feedback submitted via forms or chat for troubleshooting and case resolution.

Automatically collected data

Some data is collected automatically to operate the service and improve user experience. We provide examples showing how automated data supports concrete features like predictive budgeting and scenario comparisons.

  • Usage logs including timestamps, feature usage and session durations to monitor performance and identify common scenario flows.
  • Device and browser metadata to ensure secure and compatible access across devices.
  • Analytics data such as anonymised clickstreams used to refine interactive case simulations and templates.
  • Aggregated performance metrics from automated budgeting engines that help improve allocation logic without exposing personal identifiers.
  • Error reports and diagnostic data when technical issues occur, assisting support teams to resolve individual cases.
  • Location approximations (country-level) to comply with jurisdictional rules and to present relevant local examples and resources.

Data from third parties

We may receive data from third-party providers if you connect external services or use integrations. Below are common third-party sources and an illustrative scenario for each.

  • Business data aggregators when users link bank accounts for transaction categorisation and cashflow modelling.
  • Identity verification services used in certain cases to confirm user identity for compliance or eligibility checks.
  • Analytics and marketing platforms that provide aggregated performance metrics to improve product flows and case studies.

How we use personal data

Purposes and practical scenarios

Fundora uses personal data to provide and improve purpose-aligned funds management. Each purpose below is illustrated with a concrete example demonstrating how the data is applied in practice to deliver a particular feature or outcome.

  • Account management and communication: we use contact details to authenticate users, send transactional notices, and respond to support inquiries. Example: confirming identity when a user requests a change to payout instructions.
  • Personalised budgeting and plans: data such as revenue, expenses and goals is used to build tailored budgets and step-by-step action plans. Case: producing a monthly allocation schedule for a user saving for a community impact grant.
  • Scenario simulation and forecasting: transactional and profile data power simulations that compare different allocation strategies. Scenario: showing the effect of reallocating discretionary spend toward a targeted social project over 12 months.
  • Security and fraud prevention: logs and device data help detect suspicious activity and protect accounts. Example: flagging unusual login attempts from a new region and prompting verification.
  • Product improvement and research: anonymised analytics inform feature enhancements and new templates based on common user scenarios.
  • Compliance and legal obligations: we process necessary data to meet regulatory requirements within Singapore and to respond to lawful requests.
  • Support and dispute resolution: communications and records are used to contribute and resolve user-reported issues or billing inquiries.
  • Marketing and optional communications: with explicit consent, we send updates about new tools, case studies and events relevant to purpose-aligned business practices.

Legal basis for processing

Processing is carried out under legitimate operational needs, user consent where required, and to meet legal obligations. Below we list typical legal bases and an example scenario for each.

Cookies and tracking

Fundora uses cookies and similar technologies to enable basic functionality, maintain sessions and gather anonymous analytics. We describe categories, purposes and how to manage preferences.

Types include essential cookies for authentication, preference cookies to store language and display settings, analytics cookies to measure feature usage, and optional marketing cookies used with consent.

Essential: required for service operation; Preferences: save user settings; Analytics: aggregate usage metrics; Marketing: deliver optional messages about events or partnerships.

You can manage cookie preferences via browser settings or the cookie control panel on purposefun.biz. Disabling certain cookies may affect functionality such as remembering session state or saving scenario inputs.

Read the full cookie policy at purposefun.biz/cookie-policy

Sharing and recipients

We share personal data only where necessary to deliver services, comply with legal requirements, or when you authorise a connection. Each recipient type below is paired with an operational example.

  • Service providers: vendors who host data, process payments or provide analytics for Fundora features.
  • Business aggregators: third parties that provide linked account data when you opt to connect external accounts for budgeting.
  • Professional advisors: with your permission, we may share reports or exported summaries to accountants or business advisers to support case work.
  • Legal and regulatory bodies: where disclosure is required by law or to respond to valid legal requests.
  • Business partners: selected partners may receive aggregated, non-identifiable information for joint educational case studies or events.
  • Successor entities: in the event of a business restructuring, personal data may be transferred as part of a sale or merger subject to contractual protections.

International transfers

Where data is processed or stored outside Singapore, we implement safeguards such as standard contractual clauses, data minimisation, and technical protections. Example: analytics processing may occur in regional data centers with enforced contractual commitments to protect user data.

Safeguards include contractual terms with sub-processors, encryption at rest and in transit, and limited access controls. For specific transfer details, users may request a summary of third-party locations and protections.

Storage and retention

Retention policy

We retain data only as long as necessary for the purposes described, including legal and operational needs. Retention periods are set according to data type and the nature of the service interaction.

Account information and core records are retained while the account is active and for a defined period after deactivation to comply with regulatory and contractual requirements.

Support communications are retained for the duration needed to resolve the matter and to maintain an audit trail, typically up to several years depending on case complexity.

System logs and diagnostic data are retained in aggregated or pseudonymised form for performance monitoring and security analysis for a limited period.

When retention periods expire or upon validated deletion requests, we remove or irreversibly anonymise personal data, except where legal obligations require longer retention.

Security measures

Fundora implements technical and organisational measures to protect personal data from unauthorised access, disclosure or alteration. Measures are chosen to match the sensitivity of the data and the risk scenarios relevant to business and personal information.

  • Encryption in transit and at rest for sensitive account data and transferred files.
  • Access controls and role-based permissions to limit internal access only to staff who require data for operational tasks.
  • Regular security reviews, vulnerability scanning and incident response procedures to detect and address issues quickly.

Your rights and controls

User rights overview

Users have rights to access, correct, restrict, or delete personal data, to object to certain processing, and to request portable data exports. Below are practical steps and examples illustrating how rights are exercised in typical Fundora scenarios.

  • Access: request a copy of the personal data we hold, for example to review goal-setting inputs and related recommendations.
  • Rectification: correct inaccurate or incomplete information, such as updating a target amount or contact details.
  • Erasure: request deletion of personal data where applicable, for example after closing an account and completing pending obligations.
  • Restriction: ask us to limit processing, for example suspending analytics use of your activity while a dispute is contribute.
  • Data portability: obtain a machine-readable export of your data, such as budgets, transaction summaries and saved scenarios to migrate to another tool.
  • Object: object to certain processing based on legitimate interests, such as profiling for product development, while the objection is assessed.
  • Consent withdrawal: withdraw previously provided consents for optional features like marketing communications.
  • Complaint: lodge a complaint with the relevant supervisory authority if you believe your rights are not being respected.

How to make a rights request

Submit requests via our dedicated privacy request form at purposefun.biz/privacy-requests or by mail to Fundora Pte. Ltd., 227 Tampines Street 23, Singapore, 520211. For identity verification we may ask for a copy of an ID or additional information. We process requests proportionately and provide guidance for complex cases such as data portability exports.

[email protected]

We aim to acknowledge rights requests within 5 business days and to provide a substantive response within 30 calendar days. For complex requests requiring additional verification or coordination with third parties, we will communicate an estimated timeline and necessary steps.

How We Handle Personal Data

Fundora collects and processes personal data to provide purpose-aligned funds management services, manage client relationships and comply with legal obligations. We use practical scenarios and case examples to explain what data we collect, why we collect it, and how we keep it secure for clients in Singapore.

  • Data we collect: identifiers (name, email), contact details, limited business information provided voluntarily for budgeting or advisory scenarios, device and usage metadata for service optimization, and records of client communications.
  • Lawful basis and purpose: processing is based on client consent for advisory services and on our legitimate interest to maintain operations, prevent fraud, and fulfill contractual obligations such as subscription management and billing.
  • Data retention and minimization: we retain personal data only as long as needed for the purpose it was collected, e.g., active advisory relationships and regulatory recordkeeping. In practical cases we anonymize historic examples used for internal learning and product development.
  • Security measures: Fundora applies role-based access controls, encrypted storage, secure transmission protocols (TLS), routine vulnerability assessments and documented incident response procedures informed by case-based testing.
  • Data subject rights: clients can request access, rectification, portability or deletion of their personal data, or object to processing where applicable. We describe step-by-step scenarios in our internal guide to help agents respond consistently.
  • International transfers: where data is transferred outside Singapore for service delivery or analytics, we use contractual safeguards and assess destination protections using documented vendor-case reviews.

If you have concerns about how Fundora handles personal data, you can contact the Personal Data Protection Commission (PDPC) in Singapore. We also provide an internal escalation path so that recurring issues identified in case reviews are addressed promptly.

Other Information We Collect

Marketing Communications

With consent, Fundora may send email newsletters, product updates, or event invitations. Marketing content follows a scenario-driven approach: we tailor messages based on the types of service use cases clients have engaged in, such as savings plans or cashflow coaching. Recipients can manage preferences at any time.

To unsubscribe from marketing communications, follow the link at the bottom of any marketing email or update your preferences in your account settings. Unsubscribe requests are processed in the context of documented workflows to ensure timely removal.

Children's Privacy

Fundora's services are intended for adults. We do not knowingly collect personal data from anyone under the age of 18. If we learn we have collected such data, we will promptly follow removal procedures and notify the account holder where applicable.

Links to Third-Party Sites

Our website may include links to third-party sites and embedded tools used in practical case studies. These links are provided for convenience; Fundora is not responsible for the privacy practices of external sites. We document each third-party link as part of our case assessments.

Changes to This Policy

We update our privacy information when operational practices or laws change. Material changes are announced on purposefun.biz and summarized in client communications with examples of how they affect common scenarios. The effective date for the current terms is 22-05-2026.