Operator: The Market Sensus, Singapore. Service: Market Sensus (themarketsensus.com). Last updated: 17 September 2026.
This Privacy Policy explains how The Market Sensus ("Market Sensus", "we", "us") collects, uses, discloses, and protects your personal data when you use Market Sensus (the "Service"), in accordance with Singapore's Personal Data Protection Act 2012 (PDPA). By using the Service you consent to the practices described here.
Marketing communications. We will only send you marketing or promotional emails if you have opted in to receive them. These are kept separate from essential account, billing, and legal-update messages, which you receive as part of the Service. You can withdraw your consent to marketing at any time — by using the unsubscribe link in any marketing email or by contacting us — without affecting essential service communications.
Age requirement. The Service is for professionals aged 18 or over. You confirm this at sign-up; we no longer collect your date of birth.
We collect and use your personal data with your consent, which you give by providing your data and using the Service. You may withdraw consent for any non-essential processing by contacting our DPO; note that withdrawing consent needed to run your account may mean we can no longer provide the Service.
We do not sell your personal data. We share it only with service providers who help us run the Service, under appropriate safeguards: - Stripe — payment processing and billing (card data, billing details). - Supabase — authentication and database hosting (account and profile data); project hosted in the Singapore region. - Netlify — website hosting/delivery. - Resend — sending transactional and, where you have opted in, marketing emails (e.g. account, billing, password emails). A document you choose to send us from the Portfolio tab travels to our support mailbox through Resend as an email attachment. - PostHog (PostHog Inc.), our product analytics provider: page views, clicks and other interactions, device/browser information, and session replays with typed input masked, used to understand how the Service is used and to improve it. Data is processed on PostHog's servers in the United States.
Sign-in providers. If you use “Continue with Google” or “Continue with Apple”, Google (Google LLC) or Apple (Apple Inc.) will know that you have signed in to Market Sensus. They act as independent controllers of that sign-in, not as our processors, and their handling of your data is governed by their own privacy policies rather than this one — see Google’s Privacy Policy and Apple’s Privacy Policy. We share no other personal data with them, and we do not use them to advertise to you.
Advertising measurement (Meta). We advertise Market Sensus on Facebook and Instagram. To tell whether those advertisements actually bring us customers, our public marketing page, our sign-up flow and our subscription page carry Meta's measurement pixel (Meta Platforms, Inc. and Meta Platforms Ireland Ltd). It records that a visit happened and whether it led to creating an account, completing setup, starting a trial, or subscribing. When a subscription payment succeeds, our server tells Meta that a subscription of that plan and amount occurred.
What we do not send Meta is as important as what we do. We have switched off Meta's automatic matching feature, so your email address, name, phone number and any other identifying detail are never passed from your browser to Meta. The events our server sends carry the plan and the amount and nothing about who you are. Meta acts as an independent controller of what it collects through the pixel, not as our processor, and its handling of that data is governed by Meta's own privacy policy rather than this one.
The Portfolio tab carries no pixel at all. We have deliberately excluded the Portfolio page, and every page where your clients' statements, names or policy numbers can appear, from all advertising measurement. No information about your clients is sent to Meta, in any form, ever.
If we engage further processors, we will update this list.
We may also disclose personal data where required by law, regulation, court order, or to a regulator, or to protect our rights and the safety of users.
Some processors process data outside Singapore: for example Stripe (payment data), PostHog (analytics data, processed in the United States), if you choose to use them to sign in, Google and Apple (sign-in data, processed in the United States and in other countries where they operate), and Meta (advertising measurement data, processed in the United States, Ireland and other countries where Meta operates). Where personal data is transferred overseas, we take reasonable steps so that it is protected to a standard comparable to the PDPA, including through the processors' contractual commitments.
We keep personal data only for as long as needed for the purposes above or as required by law (for example, billing and tax records). When no longer needed, we will delete or anonymise it. Account data is kept while your account is active and for as long as required by law (for example, billing and tax records), then deleted or anonymised.
Two limits are fixed. A document you send us from the Portfolio tab is deleted from our storage no later than 30 days after you send it, by an automatic job. When you delete your account, every Portfolio record you created — clients, policies, statements, transactions and the encrypted names — is deleted with it.
We use reasonable administrative and technical measures to protect personal data, including encryption in transit, hashed passwords, two-factor authentication, row-level access controls in our database, and access restrictions. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a data breach affecting your personal data is likely to result in significant harm to you, we will notify you and the Personal Data Protection Commission as the Personal Data Protection Act requires.
Under the PDPA you may request access to the personal data we hold about you and information about how it has been used, and you may request correction of inaccurate or incomplete data. To make a request, contact our DPO (below). We may verify your identity and may charge a reasonable fee for an access request as permitted by the PDPA, and will respond within the timeframe required by law.
The Service uses cookies/local storage that are necessary to sign you in, keep you signed in, and remember preferences (such as light/dark theme). These strictly necessary cookies do not require consent.
We also use analytics cookies set by PostHog, our analytics provider, to understand how the Service is used and to improve it. These record page views, clicks and other interactions, and device/browser information, and enable session replays in which anything you type is masked before it reaches us. By continuing to use the Service you consent to these analytics cookies. If you would like the analytics data associated with your visits deleted, contact us at themarketsensus@gmail.com and we will action it.
On our public marketing page, our sign-up flow and our subscription page we also use advertising cookies set by Meta, so that we can tell which of our advertisements lead to sign-ups. These are not used anywhere inside the Portfolio tab. You can prevent them by using your browser's tracking-prevention settings or an ad blocker, and you can control how Meta uses activity from other websites through the Ad Preferences and Off-Facebook Activity settings in your Facebook or Instagram account. Blocking them does not affect your use of the Service in any way.
We have appointed a DPO to oversee our compliance with the PDPA. You can reach the DPO at: Data Protection Officer, themarketsensus@gmail.com.
We may update this Policy from time to time. Material changes will be notified by email or in-app, with an updated "Last updated" date.
The Market Sensus, themarketsensus@gmail.com.