Privacy Notice
1. What we collect
| Data | From | Required? |
|---|---|---|
| Name, email address, password (stored only as a secure hash) | You, when you create an account | Yes — needed to create your account |
| Mobile number | You (optional at sign-up, or when you use phone sign-in) | Optional, except for phone sign-in and property enquiries |
| Google account name and email | Google, if you choose “Continue with Google” | Optional |
| Bookings, table reservations, tickets, food orders, service requests, property enquiries and notes you add to them | You, when you use the app | Needed to provide what you ask for |
| Points, tier, vouchers and spend recorded at KWRC outlets | You and our outlet staff | Part of membership |
| For property owners: unit, maintenance invoices, payment receipts you upload | You and the management office | Needed for the owner portal |
| Profile photo | You | Optional |
| Technical data: sign-in times, device/browser type, IP address in security logs | Automatically | Needed to keep accounts secure |
We do not collect your card or bank details in the app, and we do not use advertising trackers.
2. Why we use it
- To create and secure your account and verify it is you.
- To pass your booking, reservation, order or request to the hotel, restaurant, attraction or team that fulfils it, and to tell you when its status changes.
- To run the KWRC Rewards programme: points, tiers, vouchers.
- For owners: to issue maintenance invoices, record payments and share building documents.
- To respond to property sales and rental enquiries you make.
- To send offers and event news — only if you opt in. You can opt out at any time in Account → Settings.
- To prevent fraud and abuse, and to meet legal, tax and accounting obligations.
3. Who we share it with
- KWRC hotels, outlets, attractions and the property management office — only what each needs to serve you.
- Service providers that run the app for us: Supabase (database, sign-in and file storage, hosted in Singapore) and Cloudflare (website hosting and bot protection). If you use them: Google (sign-in) and our SMS/email delivery providers.
- Authorities, when the law requires it.
We do not sell your personal data.
4. Transfer outside Malaysia
Our database is hosted in Singapore. We only use providers bound by contractual data-protection commitments, as permitted by section 129 of the Act.
5. How long we keep it
While your account is open. When you delete your account, your profile, points, vouchers, bookings, orders, requests and notifications are deleted. Records we must keep by law — such as maintenance invoices and payment receipts for owned units — are kept for up to 7 years and then deleted. Security logs are kept for up to 12 months.
6. Your rights
- Access and portability: Account → Privacy & My Data → Download my data gives you a copy of everything linked to your account.
- Correction: edit your name and phone in Account → Edit Profile, or contact us.
- Withdraw consent / delete: Account → Privacy & My Data → Delete my account. You can also stop marketing messages at any time.
- Limit processing or ask a question: contact our Data Protection Officer below.
We reply to requests within 21 days.
7. Security
Data is encrypted in transit and at rest. Each person can only see their own records; staff access requires a staff account with two-factor authentication and every change staff make is logged. If a personal data breach is likely to harm you, we will notify you and the Personal Data Protection Commissioner as required by law.
8. Children
You must be 18 or older to create an account. Parents or guardians may book on behalf of children.
9. Contact
Data Protection Officer: [name] · [email]
If you are not satisfied with our response you may contact the Personal Data Protection Department (JPDP), Malaysia.
Notis Privasi
1. Data yang kami kumpul
Nama, alamat e-mel dan kata laluan (disimpan sebagai cincangan selamat sahaja); nombor telefon bimbit (pilihan); nama dan e-mel akaun Google jika anda memilih log masuk dengan Google; tempahan, tempahan meja, tiket, pesanan makanan, permintaan perkhidmatan dan pertanyaan hartanah; mata ganjaran, tahap dan baucar; bagi pemilik hartanah: unit, invois penyelenggaraan dan resit bayaran yang dimuat naik; foto profil (pilihan); dan data teknikal seperti masa log masuk dan alamat IP dalam log keselamatan. Nama, e-mel dan kata laluan adalah wajib untuk membuka akaun; yang lain diperlukan hanya untuk perkhidmatan yang anda minta.
2. Tujuan
Untuk membuka dan melindungi akaun anda; menyampaikan tempahan, pesanan atau permintaan anda kepada hotel, restoran, tarikan atau pasukan yang berkaitan dan memaklumkan status kepada anda; mengendalikan program KWRC Rewards; bagi pemilik, mengeluarkan invois dan merekod bayaran; menjawab pertanyaan hartanah; menghantar tawaran dan berita acara hanya jika anda bersetuju; mencegah penipuan; dan mematuhi undang-undang.
3. Pendedahan
Kepada hotel, outlet, tarikan dan pejabat pengurusan hartanah KWRC (setakat yang perlu); penyedia perkhidmatan kami — Supabase (pangkalan data, di Singapura) dan Cloudflare (pengehosan); Google dan penyedia SMS/e-mel jika anda menggunakannya; dan pihak berkuasa jika dikehendaki undang-undang. Kami tidak menjual data peribadi anda.
4. Pemindahan ke luar Malaysia
Pangkalan data kami dihoskan di Singapura oleh penyedia yang terikat dengan komitmen perlindungan data secara kontrak, seperti yang dibenarkan oleh seksyen 129 Akta.
5. Tempoh simpanan
Selagi akaun anda dibuka. Apabila anda memadam akaun, profil, mata, baucar, tempahan, pesanan, permintaan dan pemberitahuan anda dipadam. Rekod yang wajib disimpan mengikut undang-undang (seperti invois dan resit penyelenggaraan) disimpan sehingga 7 tahun.
6. Hak anda
Anda boleh mengakses dan memuat turun data anda (Akaun → Privasi & Data Saya → Muat turun data saya), membetulkan butiran anda, menarik balik persetujuan atau memadam akaun anda (Akaun → Privasi & Data Saya → Padam akaun), dan berhenti menerima mesej pemasaran pada bila-bila masa. Kami menjawab permintaan dalam masa 21 hari.
7. Keselamatan
Data disulitkan semasa penghantaran dan penyimpanan. Setiap pengguna hanya boleh melihat rekod sendiri; akses kakitangan memerlukan pengesahan dua faktor dan setiap perubahan direkodkan. Jika berlaku pelanggaran data yang mungkin memudaratkan anda, kami akan memaklumkan anda dan Pesuruhjaya Perlindungan Data Peribadi seperti yang dikehendaki undang-undang.
8. Hubungi kami
Pegawai Perlindungan Data: [nama] · [e-mel]. Jika tidak berpuas hati, anda boleh menghubungi Jabatan Perlindungan Data Peribadi (JPDP).