✦

DREAMSCAPE ONE

Powered by Guru Kids Pro

Privacy and data protection

Privacy Policy

This Policy explains how Guru Kids Pro collects, uses, discloses, protects, retains, corrects, anonymises and deletes personal data across Dreamscape One, Guru Kids Pro-managed access, affiliate activities, Education Licences and related support services.

Effective date24 August 2026
Policy versionprivacy-v2-2026-08-24
Data protection contactadmin@gurukidspro.com
Children:For a child below 13, a parent or legal guardian must provide the consent required for us to collect, use and disclose the child's personal data. A paid Dreamscape purchase for a user below 18 must be approved and completed by a parent, guardian or authorised organisation under our platform rules.

On this page

ScopeData collectedHow data is collectedChildrenHow data is usedPaymentsService providersOverseas transfersCookiesSecurityAccount deletionRetentionYour choices and rightsMarketingPolicy changesContact

Related pages

Terms & ConditionsAffiliate TermsAffiliate application
1

Who we are and who this Policy covers

Dreamscape One is operated by Guru Kids Pro, UEN 53232375X, of Blk 4 Queen's Road, #02-127, Singapore (“Guru Kids Pro”, “Dreamscape”, “we”, “us” or “our”).

This Policy covers personal data relating to:

  • public Dreamscape students and account holders;
  • Guru Kids Pro students, parents and guardians;
  • teachers, curriculum personnel, administrators and other staff users;
  • Affiliate applicants and approved Affiliate partners;
  • Education Licence applicants, customers, administrators and linked students;
  • website visitors, support contacts and business enquiries;
  • persons who make or manage Dreamscape subscription payments; and
  • other persons who interact with Dreamscape or Guru Kids Pro.

This Policy should be read with our Terms & Conditions, any applicable programme terms, order form, consent notice and other notices provided at the point of collection.

2

Personal data we may collect

Account and identity information

  • name or display name;
  • username;
  • email address and authentication identifiers;
  • date of birth, age and age band where provided;
  • school level, curriculum level or learning level;
  • country or general location information where relevant;
  • parent or guardian name, email and relationship information for younger users where needed;
  • account role, organisation link, permissions and staff access status; and
  • profile preferences, avatar or customisation choices.

Learning, progress and platform activity

  • missions, subjects, topics and quizzes selected or completed;
  • questions attempted, answers submitted and answer history;
  • correct and incorrect answers, scores, accuracy, timing and completion records;
  • progress by subject, topic, mission, level, skill and activity;
  • teacher assignments, recorded attempts and dashboard information;
  • Dream Tokens, Dream Gems, achievements and rewards;
  • rover, equipment, home, outfit or feature upgrades;
  • Business Builder, Milo Exchange, virtual property and simulation activity;
  • referral participation and reward status;
  • login, session, security, device and general usage records; and
  • support requests, bug reports and communications.

Subscription, billing and transaction information

  • selected plan, billing cycle and price;
  • subscription status, renewal status, pause status, paid-through date and plan-change information;
  • payment-provider customer, checkout, subscription, invoice and transaction references;
  • payment status, refund status, chargeback or dispute status;
  • billing contact information; and
  • records needed for accounting, tax, reconciliation and fraud prevention.

Parent, teacher and organisation information

  • name, email, mobile number and organisation details;
  • student-account relationships and assignment records;
  • teacher, curriculum or administrator permissions;
  • licence package, invoice, renewal and onboarding records;
  • organisation membership, roster and seat-assignment information; and
  • consent, terms acceptance and support history.

Affiliate and business-partner information

  • legal and display name, email, mobile number and country;
  • business name, UEN or registration number and website;
  • social-media profiles, audience size, audience description and locations;
  • promotion channels, proposed activities and expected referrals;
  • application, approval, review and internal administration records;
  • referral code, referral attribution, commission and payout records;
  • PayNow mobile number or UEN, payee name and payout verification records where applicable; and
  • programme and policy acceptance records.

Technical and device data

  • IP address and network information;
  • device, operating system and browser information;
  • login timestamps, request logs and security events;
  • cookie, session and authentication information;
  • referral source and attribution data; and
  • diagnostic information reasonably required to protect, troubleshoot and operate the platform.
3

How we collect personal data

We may collect personal data:

  • directly from a user, parent, guardian, teacher, Affiliate, organisation administrator or business contact;
  • when an account, application, checkout, order, form or support request is submitted;
  • automatically when Dreamscape is accessed or used;
  • from a linked organisation, teacher, parent or guardian authorised to provide it;
  • through Google sign-in or another selected authentication provider;
  • through Stripe, HitPay or another payment provider used for the relevant transaction;
  • through referral links, codes and approved marketing channels; and
  • from service providers where necessary to maintain security, deliver a service or reconcile a transaction.

Where another person provides personal data to us, that person must have authority to do so and must provide any legally required notice or consent.

4

Children and younger users

  1. Where we rely on consent to collect, use or disclose personal data about a child below 13, we require consent from the child's parent or legal guardian.
  2. We aim to present notices in language and formats appropriate to the user and to minimise collection that is not reasonably needed for the service.
  3. A paid Dreamscape purchase for a user below 18 must be made or authorised by a parent, guardian or authorised organisation under our platform rules.
  4. Parents and guardians may contact us about a younger user's account, subject to appropriate identity and authority verification.
  5. Teachers and Education Licence organisations must obtain any required parent or guardian consent before directing a child to create an account or sending us personal data for student assignment.

If we learn that personal data about a child was provided without required authority or consent, we may restrict the account and take reasonable steps to correct, delete or otherwise address the data.

5

How we use personal data

We may use personal data to:

  • create, authenticate, secure and administer accounts;
  • provide Learning Missions, quizzes, simulations and other features;
  • save progress, answers, rewards, achievements and profile assets;
  • personalise age-appropriate explanations, recommendations, missions or interface elements;
  • show relevant parent, teacher and organisation dashboards;
  • assign students, roles, permissions and Education Licence access;
  • process subscriptions, plan changes, pauses, resumptions, renewals, cancellations, invoices and payment status;
  • process and audit account-correction and account-deletion requests;
  • review Affiliate and licence applications;
  • attribute referrals, calculate commission and administer payouts;
  • provide technical, account, onboarding and customer support;
  • send essential account, payment, security and programme messages;
  • send promotional communications where consent or another permitted basis applies;
  • improve content, usability, reliability, safety and performance;
  • conduct internal analytics using data that is aggregated, de-identified or minimised where reasonably appropriate;
  • detect fraud, abuse, account sharing, security threats and policy violations;
  • keep records, resolve disputes and enforce agreements; and
  • comply with legal, tax, accounting and regulatory obligations.

We do not sell student personal data. We do not disclose student personal data to third parties for their own direct marketing without appropriate authority, notice or consent.

6

Payments and financial information

  1. Public Dreamscape subscriptions are generally processed through Stripe.
  2. Guru Kids Pro-managed access and certain legacy arrangements may use HitPay or another payment method communicated to the payer.
  3. We may receive plan and order details, billing contact information, payment status, subscription status, invoice or transaction references, refund information and dispute status.
  4. We do not normally receive or store complete payment-card details. Those details are handled by the relevant payment provider.
  5. Affiliate PayNow details, where collected, are used for payout administration and access is limited to authorised personnel and systems.
7

When we disclose personal data

We may disclose personal data where reasonably necessary to provide, secure or administer Dreamscape, including to current service providers such as:

  • Supabase for authentication, database, storage and backend services;
  • Vercel for website hosting and server processing;
  • Resend for transactional and approved marketing email;
  • Google where Google sign-in or another Google service is selected;
  • Stripe for public Dreamscape checkout, subscription and payment processing;
  • HitPay for Guru Kids Pro-managed or applicable legacy payment processing;
  • analytics, security, communications or support providers enabled for the platform from time to time;
  • professional advisers, auditors, insurers and service contractors;
  • teachers, parents, guardians or organisations with appropriate authority;
  • regulators, courts, law-enforcement bodies or other persons where required or permitted by law; and
  • a purchaser, successor or adviser in connection with a genuine business reorganisation, financing, transfer or sale, subject to appropriate safeguards.

Service providers receive only the data reasonably needed for their role and are expected to handle it under appropriate contractual, security and privacy safeguards. Providers may change as our systems evolve; this Policy describes the categories and current principal providers rather than an immutable vendor list.

8

Overseas processing and transfers

Some service providers may store or process information outside Singapore. Where personal data is transferred outside Singapore, we take reasonable steps to ensure it receives a standard of protection comparable to the protection required under Singapore's Personal Data Protection Act 2012, including through appropriate provider terms and safeguards.

9

Cookies and similar technologies

  • Essential cookies or local-storage items support login, authentication, security, sessions and core functionality.
  • Preference technologies may remember user choices, settings and interface state.
  • Referral or attribution technologies may record the source of an approved referral or affiliate visit.
  • If non-essential analytics or advertising technologies are enabled, we will provide suitable notice and obtain consent where required.
  • Blocking essential technologies may prevent parts of Dreamscape from working correctly.
10

Security and data incidents

We use reasonable administrative, technical and organisational measures to protect personal data. Depending on the system, these may include role-based access controls, authentication, encrypted transmission, restricted administrator access, logging, backups, provider safeguards and security monitoring.

No online service can guarantee absolute security. Users must protect login credentials, avoid sharing accounts and notify us promptly of suspected unauthorised access.

If a personal-data breach occurs, we will assess it and notify the Personal Data Protection Commission and affected individuals where notification is required by applicable law.

11

Account closure, deletion and anonymisation

Dreamscape distinguishes between stopping a subscription, pausing a membership and deleting an account. These actions have different effects.

Self-service deletion

Eligible users may request permanent account deletion from their account settings. Before deletion, we may verify the account and check whether there are unresolved staff, organisation, licence or non-Stripe billing responsibilities. Some staff, organisation-managed, Guru Kids Pro-managed or legacy accounts therefore require assisted closure through Support.

What happens when an eligible account is deleted

  • the Dreamscape authentication account is disabled or soft-deleted so the user can no longer sign in;
  • an active public Stripe subscription linked to that eligible account is cancelled as part of the self-service deletion workflow so it cannot renew;
  • active learning entitlements are removed and paid learning access ends;
  • profile identifiers such as email, username and date of birth are deleted, redacted or replaced with non-user-facing deletion values where a database record must be retained;
  • learner progress, quiz responses, Dream Token and Dream Gem records, virtual holdings, referral relationships and other account-specific learning data are deleted where applicable to the account and system;
  • retained Dreamscape billing or accounting records are anonymised or minimised where reasonably possible; and
  • we retain a restricted deletion-audit record so we can show that the request was processed and investigate operational, security or legal issues if necessary.

A deletion audit may contain a deletion-request identifier, the former internal user identifier and a cryptographic hash of the former email address. Because such data may still be linkable in limited circumstances, we treat it as restricted data and retain it only as long as reasonably necessary for audit, security, dispute or legal purposes.

Payment providers such as Stripe or HitPay may retain their own transaction records under their legal, regulatory and business obligations. Account deletion from Dreamscape does not require those providers to erase records they are independently required or permitted to retain.

Deleting an account does not automatically issue a refund for payments already completed. Refund rights, if any, are handled separately under the applicable purchase terms and law.

Secure backups may continue to contain historical data for a limited backup-rotation period. Backup copies are not used as active account records and are overwritten or deleted in the ordinary backup lifecycle, subject to legal or security requirements.

12

Retention

We keep personal data only for as long as reasonably necessary for the purposes described in this Policy, to protect users and the platform, resolve disputes, maintain appropriate audit records and meet legal, tax, accounting and contractual obligations. Different record types require different periods.

Record typeGeneral retention approach
Active account and profile informationWhile the account is active and for a reasonable period needed for account administration, unless deletion or another lawful request is completed earlier.
Learning and progress recordsGenerally while access is active and up to 24 months after access ends, unless deleted earlier through an eligible account-deletion process or needed for an active dispute or organisation requirement.
Deleted-account learner/profile dataDeleted or anonymised as part of the deletion workflow, subject to technical completion, restricted audit data, backups and records that must lawfully be retained.
Deletion audit recordsGenerally up to 7 years after completion, or longer where reasonably necessary for a dispute, investigation or legal obligation.
Payment, invoice and accounting recordsAt least 5 years from the relevant accounting or tax period where required, and longer if reasonably necessary for tax, audit, dispute or legal purposes.
Incomplete Affiliate applicationsGenerally up to 6 months.
Rejected Affiliate applicationsGenerally up to 12 months.
Active Affiliate recordsWhile active and as required for administration.
Affiliate commission and payout recordsAt least 5 years from the relevant transaction or accounting period where required.
Education Licence financial recordsAt least 5 years from the relevant accounting or tax period where required.
Support enquiriesGenerally up to 24 months after resolution, longer if connected to a dispute or security matter.
Security and system logsGenerally up to 12 months, longer where needed to investigate or document a security incident.
Terms, consent and authority recordsFor the relationship and for a reasonable period afterwards, commonly up to 7 years where needed to establish consent, authority, contractual rights or defend claims.

These are general periods, not promises that every record will be held for the maximum period. We may shorten retention where information is no longer needed, and may retain a record longer where required by law or reasonably necessary for an active dispute, investigation, fraud-prevention, tax, accounting or security purpose. Where continued identification is no longer needed, we may anonymise data instead of retaining identifiable personal data.

13

Access, correction, withdrawal, deletion and complaints

A person may contact us to request:

  • access to personal data in our possession or control and information about how it has been used or disclosed, subject to applicable exceptions;
  • correction of inaccurate or incomplete personal data;
  • withdrawal of consent for future collection, use or disclosure where consent is the applicable basis;
  • account closure or deletion where the account and applicable records are eligible for that process;
  • review of a privacy concern or complaint; or
  • any other data-protection right that applies under Singapore law.

We may need to verify identity, authority and the scope of a request before acting. A parent, guardian, teacher or organisation administrator requesting data about another person must show appropriate authority.

Withdrawal of consent affects our future collection, use or disclosure for the relevant purpose and may prevent us from continuing a service. Withdrawal does not automatically require destruction of every existing record. We may continue to retain information where required or permitted by law or reasonably necessary for legal or business purposes.

14

Marketing choices

  1. Promotional communications are sent only where consent or another permitted basis applies.
  2. A recipient may unsubscribe using the method provided in a marketing communication or by contacting us.
  3. Unsubscribing from marketing does not stop essential account, payment, security, application, support, legal or programme messages.
  4. We do not use student personal data for third-party direct marketing without appropriate authority, notice or consent.
15

Changes to this Policy

We may update this Policy to reflect legal, technical, programme, vendor, payment, account-management or operational changes. The current version, policy version identifier and effective date will be published on this page.

Where a change materially affects how we use personal data or the rights and choices available to affected users, we will provide reasonable additional notice through email, the platform or another appropriate channel where required.

Data protection contact

Contact Guru Kids Pro

Guru Kids Pro · UEN 53232375X
Blk 4 Queen's Road, #02-127, Singapore

Contact us about access, correction, consent withdrawal, account deletion, privacy complaints or other data-protection matters.

admin@gurukidspro.com

Dreamscape One — Powered by Guru Kids Pro · privacy-v2-2026-08-24

Terms & ConditionsAffiliate TermsBack to top