Who We Are and Scope of This Policy
About Klicktify
Klicktify Sdn Bhd (Company Registration No. 202601000123 (1456789-X)) ("Klicktify", "we", "us", or "our") operates https://klicktify.com, a multi-tenant loyalty and rewards platform designed for café and small-business operators in Malaysia. We provide the technology infrastructure that enables café owners ("Merchants") to run digital loyalty programmes, and we enable their customers ("Members") to earn and redeem points across the Merchants they frequent.
This Privacy Policy describes how Klicktify collects, uses, discloses, and safeguards personal data in connection with our platform and services. It applies to all individuals whose personal data we process, including Merchant account holders (café owners and staff), Members who join loyalty programmes through our platform, and visitors to our website.
Who Is NOT Covered by This Policy
This policy does not govern the privacy practices of Merchants themselves. Each Merchant operates its own café or business and is an independent data controller for personal data collected in connection with its own loyalty programme and any other purposes outside of Klicktify's platform. When you interact with a Merchant's programme, that Merchant's own privacy notice governs. We encourage you to review each Merchant's privacy practices directly.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal obligations, or other factors. When we make material changes, we will update the "Last Updated" date at the top of this page and, where required by applicable law, notify you by email or through the platform. We encourage you to review this page periodically.
Personal Data We Collect
Data from Merchant Account Holders (Café Owners and Staff)
When you create a Klicktify account as a Merchant, we collect the following personal data:
- Full name and business name — collected at registration and used to identify your account and display your café profile.
- Email address — used for authentication, account communications, billing notifications, and security alerts.
- Phone number — used for account recovery, two-factor authentication if enabled, and critical service notifications.
- Business address and café location — used to display your café to Members and for regional compliance purposes.
- Password (hashed) — stored using bcrypt; Klicktify never stores or sees your plaintext password.
- Payment and billing information — processed by Stripe; see Section 6 below.
- Uploaded content — logos, café images, menu items, and reward descriptions that you submit through the platform.
Lawful basis for processing: contract performance (providing the service you signed up for) and legitimate interests (fraud prevention, billing, account security).
Data from Members (Loyalty Programme Participants)
When a Member joins a Merchant's loyalty programme through Klicktify, we collect:
- Name — provided directly by the Member when joining a programme.
- Email address — used for account notifications, receipts, and marketing communications where the Member has opted in.
- Phone number — used as the primary identifier for QR check-in and loyalty account access.
- Birthday (optional) — shared by the Member to unlock birthday rewards offered by the Merchant.
- Points balance and tier status — maintained by the points engine and displayed in the Member's account.
- Check-in records — timestamped QR scans at a Merchant's venue, used to calculate points and determine tier progress.
- Reward redemption history — records of rewards the Member has claimed and redeemed.
- Global account QR code — a unique identifier assigned to the Member's account, used across all Merchants.
Lawful basis for processing: contract performance (facilitating the loyalty programme between Member and Merchant) and the Member's consent where required (e.g., for marketing communications).
Derived and Behavioural Data
We may derive certain information from the data above:
- Membership tier (Bronze, Silver, Gold, Ruby) — calculated by the points engine based on accumulated points.
- Visit frequency and recency scores — derived from check-in timestamps; used to personalise rewards recommendations.
- Aggregate engagement metrics for Merchants — aggregated and anonymised statistics shown to Merchant account holders.
Lawful basis for processing: legitimate interests (improving the service and providing Merchant analytics).
Device and Technical Data
When you use our platform, we automatically collect:
- IP address — logged for security, fraud prevention, and regional service optimisation.
- Browser type and version, operating system — used for compatibility and debugging.
- Device identifiers — used for authentication and security.
- Access timestamps and pages viewed — used for debugging, security monitoring, and service improvement.
Lawful basis for processing: legitimate interests (security, fraud prevention, technical operation of the platform).
Data You Choose to Share
From time to time, you may voluntarily provide additional information — for example, through our contact form, support requests, or survey responses. This data is processed on the basis of your consent or our legitimate interests in providing customer support.
How We Use Your Personal Data
Service Provision
We use your personal data to:
- Create and maintain your account (Merchant or Member).
- Authenticate you at each sign-in and protect against unauthorised access.
- Generate and display your unique QR code for Member check-in.
- Calculate and update points balances and tier levels.
- Process reward redemptions and display available rewards.
- Send transactional notifications (e.g., points earned, reward claimed, tier upgraded).
- Facilitate communication between Members and Merchants (e.g., contact form submissions).
- Provide Merchant dashboards and analytics.
Account and Billing Management
We use your personal data to process subscription payments via Stripe, issue invoices, apply fee schedules, and manage plan upgrades, downgrades, and cancellations. See Section 6 for details on payment processing.
Security and Fraud Prevention
We monitor account activity for signs of abuse, including QR screenshot fraud, bot-driven check-ins, and account takeover attempts. Data processed for this purpose includes login records, device identifiers, and behavioural patterns. We may suspend or terminate accounts found to be in violation of our Acceptable Use Policy.
Marketing Communications (Members)
Where a Member has opted in to marketing communications, we may send emails or messages about rewards, promotions, and new Merchant programmes. Members can withdraw consent at any time via the unsubscribe link in each message or through their account settings.
Note: marketing is sent by Klicktify on behalf of the Merchant, or by Klicktify itself for cross-platform promotions. Merchants also send their own marketing and are responsible for their own consent obligations under the PDPA.
Service Improvement and Analytics
We analyse aggregated and de-identified usage data to understand how the platform is used, identify performance issues, and prioritise product improvements. This analysis never identifies individual users.
Cookies and Similar Technologies
What We Use and Why
Klicktify uses cookies and similar local-storage technologies for the following purposes:
- Essential/authentication cookies — required for sign-in sessions (both Merchant and Member), session tokens, and security controls. These cannot be disabled without making the service unusable.
- Preferences cookies — store display settings, language preferences, and UI state.
- Analytics cookies (optional) — we do not enable analytics tracking by default. If analytics are activated by a Merchant or for internal debugging, they are subject to the Member's consent and the applicable cookie consent framework.
Managing Cookies
You can control cookie settings through your browser. Disabling essential cookies will prevent you from signing in or using core platform features. For more detail, see our Cookie Policy at /legal/cookies.
Data Sharing
Merchants as Independent Data Controllers
A core feature of Klicktify is its multi-tenant architecture. When a Member joins a Merchant's loyalty programme, the Merchant acts as an independent data controller for the Member's personal data processed in connection with that Merchant's programme. Klicktify processes this data as a data processor on the Merchant's instructions. This means:
- Each Merchant determines the purposes and means of processing personal data of its own Members.
- Klicktify provides the technical infrastructure but does not use Member data for purposes unconnected to the contracted service.
- The relationship between a Member and a Merchant is governed by the Merchant's own terms and privacy notice.
- A Member's data is isolated per Merchant — a Merchant cannot access data belonging to a Member's membership at a different Merchant.
See our Data Processing Agreement at /legal/dpa for the full terms governing the Merchant–Klicktify processor relationship.
Stripe (Payment Processing)
Subscription payments are processed by Stripe, a certified PCI DSS Level 1 payment processor. Klicktify never stores raw card numbers. When you subscribe to a paid plan, Stripe receives your payment details directly; Klicktify receives only a tokenised payment method reference. See Section 6 and Stripe's privacy policy at stripe.com/privacy.
Hosting and Infrastructure
We use Neon (Lakebase Postgres) for database hosting. All data is stored on servers within Southeast Asia (Singapore and/or Hong Kong). Our infrastructure provider is contractually bound to process data only on our instructions.
Email Delivery
Transactional and marketing emails are sent via third-party email delivery services (such as Resend). These providers process email addresses and message content solely for the purpose of delivering our emails.
Legal Disclosures
We may disclose personal data if required by law, court order, or government request; to enforce our Terms of Service or Acceptable Use Policy; to protect the rights, property, or safety of Klicktify, our users, or the public; or in connection with a corporate transaction (merger, acquisition, or sale of assets) subject to appropriate confidentiality obligations.
Data We Do NOT Sell
Klicktify does not sell, rent, or trade personal data to third parties for commercial purposes. We do not share Member personal data with Merchants other than the one the Member has chosen to interact with, except in aggregate and de-identified form for platform-wide analytics.
Payment Processing
Stripe as Payment Processor
Klicktify uses Stripe for all subscription billing. When you upgrade to a paid plan, you are redirected to Stripe's secure hosted checkout. Klicktify's current plan names are: Free, Growth (RM89/month), and Scale (RM139/month).
What Klicktify Does and Does Not Store
- Klicktify stores: billing email, plan name, subscription status, billing cycle, and the Stripe customer and subscription IDs.
- Klicktify does NOT store: card number, CVV, card expiration date, or billing address.
Security of Payment Data
Stripe is PCI DSS Level 1 certified — the highest level of payment card security. All card data is encrypted in transit and at rest within Stripe's infrastructure. For more information, visit stripe.com/security.
International Data Transfers
Our Primary Data Location
Klicktify's primary database is hosted on Neon (Lakebase Postgres) with servers in Southeast Asia. Member and Merchant personal data is stored in this region.
Sub-Processors Outside Malaysia
Certain service providers (such as Stripe and our email delivery service) may process or store data in data centres outside Malaysia, including in the United States. All such transfers are covered by standard contractual clauses or equivalent data protection commitments with those providers.
PDPA Compliance for Cross-Border Transfers
Under the PDPA, transfers of personal data outside Malaysia must be protected by contractual obligations equivalent to those in the PDPA, or must be made to a jurisdiction with data protection laws at least as stringent as the PDPA. We comply with this requirement through our agreements with sub-processors.
Data Retention
Retention Schedule
We retain personal data only for as long as necessary to fulfil the purposes described in this policy, subject to legal, accounting, and regulatory retention obligations. The following table summarises our typical retention periods:
| Data Category | Retention Period | Deletion Trigger |
|---|---|---|
| Merchant account data (name, email, phone, billing info) | Duration of account + 7 years | Account closure + statutory period |
| Member account data (name, email, phone, birthday) | Duration of membership + 2 years | Member requests deletion or account archived |
| Check-in and points records | Duration of membership + 2 years | Member requests deletion or account archived |
| Reward redemption history | Duration of membership + 2 years | Member requests deletion or account archived |
| Transaction and billing records | 7 years from transaction date | Statutory accounting obligations |
| Support and contact form submissions | 3 years from submission date | Resolution of query + retention period |
| Security and access logs | 1 year from log date | Log rotation and deletion policy |
| Marketing consent records | Duration of consent + 2 years | Withdrawal of consent |
Deletion Upon Account Closure
When a Member requests account deletion or a Merchant closes their account, we will delete or anonymise personal data in accordance with the retention schedule above, subject to any overriding legal obligations. Transaction and billing records are retained for the statutory period regardless of account status.
Data Security
Our Security Measures
Klicktify implements the following technical and organisational security measures:
- Encryption in transit: all data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher.
- Encryption at rest: database storage is encrypted using industry-standard AES-256.
- Password hashing: account passwords are hashed using bcrypt with a cost factor of at least 12.
- Access controls: database access is restricted by IP allow-lists and least-privilege role grants.
- Tenant isolation: each Merchant's data is logically isolated at the database level using row-level security policies.
- Two-session model: Merchant (NextAuth) and Member (separate member-auth) sessions are fully separated with no cross-session token reuse.
- Secure development: code changes are reviewed before deployment; we do not commit secrets to version control.
Security of Shared Responsibility
While we implement robust security measures, data security is a shared responsibility. Merchants must protect their account credentials, use strong passwords, enable two-factor authentication where available, and ensure that devices accessing the platform are not compromised. Members must protect their account QR codes and login credentials. Klicktify is not liable for loss or misuse of credentials that are not caused by a failure of our own security systems.
Security Incident Response
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify affected users and the Personal Data Protection Officer (PDPO) within 72 hours of becoming aware of the breach, in accordance with the requirements of the PDPA as amended.
Your Rights Under the PDPA
Overview of Your Rights
Under Malaysia's Personal Data Protection Act 2010 (Act 709) ("PDPA"), you have the following rights as a data subject. These rights apply to personal data processed by Klicktify in Malaysia. Note that certain rights are subject to conditions and exceptions under the PDPA.
Right to Access
You may request a copy of the personal data we hold about you, including the purposes for which it is processed and the parties to whom it has been disclosed. To exercise this right, contact us at privacy@klicktify.com. We will respond within the time prescribed by the PDPA. A reasonable fee may be charged for this request.
Right to Correct
You may request correction of inaccurate or incomplete personal data held by us. You can update most of your own data directly through your account settings. For data that cannot be self-corrected, contact privacy@klicktify.com.
Right to Withdraw Consent
Where processing is based on your consent (e.g., marketing communications), you may withdraw that consent at any time by: (a) using the unsubscribe link in any marketing email; (b) updating your preferences in your account settings; or (c) contacting privacy@klicktify.com. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
Right to Limit Processing
You may request that we limit the processing of your personal data in certain circumstances, such as while we investigate a dispute about data accuracy. Contact privacy@klicktify.com to make this request.
Right to Lodge a Complaint with JPDP
If you believe we have processed your personal data in a manner that contravenes the PDPA, you have the right to make a complaint to the Personal Data Protection Commissioner ("PDPC") or the Jabatan Perlindungan Data Peribadi (JPDP), the body responsible for administering the PDPA in Malaysia. You may also contact JPDP directly:
- Website: jpdp.gov.my
- Address: Jabatan Perlindungan Data Peribadi, Aras 6, Blok Pentadbiran, Presint 1, 62000 Putrajaya, Malaysia
Before lodging a complaint with JPDP, we encourage you to contact us first so we have an opportunity to address your concerns directly.
Children
Minimum Age
Klicktify's services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a person under 18, please contact privacy@klicktify.com immediately so that we can delete the data.
How to Contact Us
General Enquiries
For general questions about this Privacy Policy or our data practices, please contact us at support@klicktify.com.
Privacy-Specific Requests
For data access requests, correction requests, or to withdraw consent: privacy@klicktify.com.
Data Protection Officer
Our Data Protection Officer (PDPO) can be reached at dpo@klicktify.com. The PDPO is responsible for overseeing our data protection obligations and can assist with queries about this policy or our PDPA compliance.