crux

Privacy

Privacy policy

Crux (“we”) is a Singapore F&B consultancy that also provides Crux OS, an operations tool for F&B businesses. Crux is operated by Mori Foods (UEN 53485737W), registered in Singapore. This page explains what personal data we collect and what we do with it. It follows Singapore’s Personal Data Protection Act (PDPA).

What we collect on this website

We keep it minimal. This site has no analytics, no ad trackers and no cookies.

  • Contact form: your name, email address and message. We use these to reply to you, and for nothing else.
  • Checklist and resource downloads: your email address, used once to send you the resource. No newsletter, no follow-ups.
  • Server logs: our hosting provider (Vercel) keeps standard technical logs, such as IP addresses, for security and reliability.

Form submissions are relayed to our email by Web3Forms, our form provider, and end up in our business mailbox. We don’t sell or share your details with anyone else.

If your employer uses Crux OS

Crux OS is used by F&B businesses to run their operations, including staff records, schedules, attendance and expense claims. In PDPA terms, your employer is the organisation in charge of that data; Crux processes and hosts it on their behalf as a data intermediary.

  • Each business runs on its own isolated instance. No other client can see its data.
  • Data is hosted in Singapore (AWS Singapore region, via Supabase).
  • Clock-in location is captured only at the moment of punching in or out, never as continuous tracking.
  • Questions about your data in Crux OS (access, correction, deletion) go to your employer first; we support them in carrying it out.

How long we keep things

  • Contact-form messages: up to 2 years, unless we’re actively working together.
  • Resource-download emails: used once, then not used again.
  • Client instance data: kept for the length of the engagement, then deleted within 30 days of the contract ending. The client receives a full export first.

How we protect it

Every connection to this site and to Crux OS is encrypted. Inside Crux OS, access is role-based: each staff member sees only what their access level allows, enforced at the database itself, not just in the app. Passwords are never stored in plain text. We test these protections ourselves, regularly.

If a breach ever puts your data at risk, we will tell the affected business, and the Personal Data Protection Commission where the law requires it.

Your rights

Under the PDPA you can ask us what personal data of yours we hold, ask us to correct it, or withdraw consent for us to use it. Email us and we’ll sort it out, within 30 days at the outside.

Contact

Our Data Protection Officer is Dominic Yu, reachable at hello@cruxsg.com.

If this policy changes, the new version appears here with a fresh date. Last updated: 17 July 2026