JxW / Privacy
Privacy information for a simple enquiry path.
What this covers
This page describes the information JxW Services may receive when you use this website or contact JxW through the links provided. The website is a static information site and does not require an account.
Contact form and enquiry information
The secondary contact form is for a service enquiry or a request for a quotation conversation. It may collect your full name, email address, phone number, preferred reply method, service, property/site type, postal code, timing, company and enquiry details. Email or phone is optional individually, but at least one of them is needed if you use the form. The form also creates a random submission reference and records limited technical information needed to prevent abuse and operate the capture process.
We use this information to understand what you need, contact you using the method you choose, discuss scope, prepare a quotation conversation and arrange the next step you request. We record the privacy-notice version presented at submission. Do not send information that is not needed for the enquiry. The form does not accept photo or video uploads.
Cloudflare and the form anti-abuse check
Cloudflare Pages hosts this website and its Pages Function receives the contact-form request. Cloudflare D1 stores limited pseudonymous operational records such as the submission reference, timestamps, state changes, keyed identity fingerprints, allowlisted selections, privacy-notice version, provider identifiers and bounded outcome or error categories. D1 is not intended to store raw names, email addresses, phone numbers, company details, postal codes, addresses or free-text enquiry details.
Cloudflare Turnstile checks that a form request is likely to come from a person rather than an automated abuse attempt. Turnstile and Cloudflare may process request and device information for that purpose under their own terms and privacy practices.
Zoho CRM and recovery processing
For a contact-form enquiry, JxW sends the validated enquiry information to Zoho CRM, which is our system of record for handling enquiries. A Zoho Lead and structured Note are created for the enquiry; a follow-up Task may also be created. Zoho therefore receives the form information needed for staff to respond and manage the enquiry.
If the required Zoho capture cannot be confirmed, Resend may conditionally send one protected recovery copy to the controlled JxW operational inbox when that recovery route is enabled. This is an internal recovery copy, not a normal customer email path. Resend accepting the request does not prove mailbox delivery, display, reading or staff action. We do not send a recovery copy when the required Zoho capture is confirmed.
If enabled, an optional Telegram staff alert contains a random submission reference, a Singapore-time (SGT) timestamp and a short capture or recovery instruction. A confirmed Zoho capture may also include the Zoho Lead ID and a link to that Lead; a known Lead ID may be included in a recovery alert. These are restricted operational identifiers and links, not a copy of the provider record. The alert contains no customer PII or enquiry content: it does not contain your name, contact details, address, enquiry text, photographs or videos. Telegram is not a capture record or a delivery/read guarantee.
WhatsApp and other contact routes
WhatsApp remains available when you prefer that route, including for sending photos and videos that help explain an installation. It is also the recovery route to use if the form shows a temporary error or if capture is uncertain. WhatsApp, your phone provider and your email provider process information according to their own terms and privacy practices once you leave this site or use your device’s communication app.
Cross-border processing
Cloudflare Pages, D1 and Turnstile, Zoho CRM, Resend, Telegram, Google and WhatsApp may process information in Singapore and in other countries, including countries outside Singapore. Their services and supporting providers may therefore involve cross-border processing under their own terms and privacy practices. JxW uses these services only for the purposes described here and applies reasonable access and configuration controls, but we cannot promise that every copy remains in Singapore or that a provider will always be available.
Website measurement
Google Tag Manager (GTM) deploys Google Analytics 4 (GA4) on this website for basic measurement. GA4 may receive only non-personal parameters such as page path, event name, contact method, CTA location, CTA ID, contact purpose, service taxonomy and package identifier.
Google Analytics may use cookies or similar identifiers. JxW does not intentionally send names, email addresses, phone numbers, enquiry or message contents, photographs, videos, postal addresses, postal codes or other direct identifiers to GA4.
We use this information to understand how visitors use the site, measure contact-channel engagement and improve website content and enquiry paths. Google processes this information under its own terms and privacy practices. For more information, read Google's privacy information.
Retention and operational ownership
We keep information only for the operational period below, subject to lawful requirements, active work and provider backup or recycle-bin practices that JxW cannot control directly. The approved retention responsibilities are:
- CRM Administrator owns spam/unqualified Leads 30 days after classification, with monthly review/deletion/anonymisation.
- CRM Administrator owns genuine unengaged Leads for 12 months after the last meaningful interaction, with monthly review.
- Active opportunities are owned by Business Owner + CRM Administrator until closed, then 12 months, with quarterly review.
- Notes follow the parent Lead.
- Tasks are owned by Enquiry Operations Owner until completed/cancelled, then 12 months, with monthly review.
- D1 receipts/events/HMACs are owned by Technical Owner for 90 days, with monthly purge/quarterly control review.
- Resend fallback inbox is owned by Enquiry Operations Owner; delete within 7 days of confirmed capture/triage and maximum 30 days, with weekly review.
Access, deletion and staff changes
Access to Zoho CRM, D1 operational records, the controlled recovery inbox and any Telegram alert destination is limited to staff who need it for enquiry operations, technical support or business oversight. Provider record IDs and keyed fingerprints are pseudonymous personal data and are handled as restricted operational information.
You may contact us to ask what personal information we hold about your enquiry, or to request correction or deletion where the request is legally and operationally available. We may need to verify your identity and the relevant enquiry before acting. We will consider the request against active work, legal or security needs, the retention rules above and copies held by providers or backups; we do not promise that every provider or backup copy can be removed immediately. If a D1 record is no longer reasonably linkable to you, we may not be able to identify it from a general request.
When a staff member leaves or no longer needs access, the relevant owner reviews and removes their access and group membership, and revokes or rotates credentials where appropriate. Handover records and operational copies remain subject to the retention rules above. Offboarding reduces staff access but does not automatically erase records held by Zoho, Cloudflare, Resend, Telegram or other providers.
Security incidents
If JxW becomes aware of suspected unauthorised access, loss or disclosure, we will assess and contain it, investigate as appropriate and make any notification required by applicable law. Please tell us promptly if you believe an enquiry or access route has been misused.
Contact
For a privacy question, contact JxW Services Pte Ltd at jxwservices@gmail.com.