Privacy Policy
- Data user: Iqreative Design (SSM REGISTRATION NO.)
- Business address: REGISTERED / OPERATING ADDRESS
- Privacy contact: privacy@untng.my · SUPPORT PHONE
- Service: UNTNG (the "Service")
- Effective date: DATE · Version: 1.0
This Policy explains how we handle personal data in the Service. It is issued under the Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024.
1. Summary
- We hold your account details, your business records, and images of the receipts you capture.
- Receipt images are sent to Anthropic (Claude API) in the United States so that the Service can propose the merchant, date, and amount. This is a cross-border transfer — see clause 6.
- Receipts sometimes contain sensitive personal data, most commonly health information on clinic and pharmacy receipts. We treat these differently — see clause 5.
- We do not sell your data, and we do not allow it to be used to train machine-learning models.
- You can refuse automated reading for any individual receipt and enter it manually instead.
2. What we collect
You give us:
| Category | Examples |
|---|---|
| Account | Name, email address, phone number, password (stored hashed), profile photo if provided by your login provider |
| Business | Business name, SSM registration number, address, contact details, tax identifiers |
| Records you enter | Income and expense transactions, daily sales, projects, quotations, invoices |
| People you record | Names and contact details of your customers, suppliers, and staff users |
| Receipt images | Photographs of receipts, invoices, slips, and related documents |
| Support | Messages you send us |
Collected automatically: IP address, device and browser type, timestamps, and application logs, used for security, fraud prevention, and diagnostics.
From third parties: if you sign in with Google or Apple, we receive your name, email address, and account identifier from them. We do not receive your password.
Payment card data is never collected or stored by us. Payments are processed by Razorpay Curlec. We receive only the subscription status, the amount, and a reference.
3. Data about other people
When you photograph a receipt or record a customer, you may give us personal data about third parties. You are responsible for having a lawful basis to do so and for notifying those individuals where the law requires it. We process that data on your instructions in order to provide the Service.
4. Why we process your data, and on what basis
| Purpose | Basis |
|---|---|
| Creating and operating your account | Performance of our contract with you |
| Reading receipts and proposing values | Performance of our contract; explicit consent where the receipt contains sensitive data (clause 5) |
| Storing your records and producing summaries | Performance of our contract |
| Billing and subscription management | Performance of our contract; legal obligation |
| Security, fraud prevention, abuse investigation | Legitimate interest |
| Support and service communications | Performance of our contract |
| Meeting legal and record-keeping obligations | Legal obligation |
| Product announcements and marketing | Consent — you may withdraw at any time |
5. Sensitive personal data
Under the PDPA, sensitive personal data includes information about a person's physical or mental health. Receipts from clinics, hospitals, pharmacies, and similar providers routinely reveal health information, sometimes together with a named individual.
Because of this:
- You choose, at the moment of capture, whether a receipt is sent for automated reading. The Service offers an option to skip automated reading and enter the details yourself. Sensitive documents should use that option.
- Where you do choose automated reading for a receipt containing sensitive personal data, you are giving your explicit consent to that specific processing and transfer, and you may withdraw consent for future receipts at any time.
- Withdrawing consent does not affect processing already carried out.
We do not require sensitive personal data to provide the Service, and we ask you not to upload health-related documents unless you need them in your records.
6. Automated reading and transfer outside Malaysia
To propose the merchant, date, amount, and category, the Service sends a reduced-size copy of your receipt image to our artificial-intelligence provider, Anthropic, PBC (the Claude API), processing in the United States. The full-resolution archive copy is not sent; it remains in our storage in Singapore.
This is a cross-border transfer of personal data. The Personal Data Protection (Amendment) Act 2024 removed the previous "whitelist" mechanism for such transfers. We rely on:
- a written data processing agreement with the provider, incorporating standard contractual clauses, containing protections substantially corresponding to the PDPA;
- the provider's published commitments that prompts and outputs are not retained by default and that retained data is never used to train models without express permission;
- transmission over encrypted connections.
We do not enable any provider feature that would extend retention beyond what is technically necessary to return a result.
If you do not want a document transferred, use the manual-entry option for that document. No image is sent for a receipt entered manually.
7. Who else processes your data
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | Singapore (AWS ap-southeast-1) |
| Anthropic, PBC (Claude API) | Automated reading of receipt images | United States |
| Razorpay Curlec | Payment and subscription processing | CURLEC PROCESSING LOCATION |
| Resend | Sending transactional email (sign-in confirmations, password resets, receipts) | Japan (AWS ap-northeast-1) |
| Cloudflare, Inc. (Pages) | Serving the application's static files (HTML, scripts, styles). No personal data is stored or processed here — all data operations run against Supabase. | Global edge network |
| Cloudflare, Inc. (Email Routing) | Forwarding email you send to our published addresses (support@, privacy@, hello@) to our mailbox. Messages are forwarded in transit and not stored by this service. | Global edge network (Cloudflare, Inc., United States) |
| Google LLC (Gmail) | Receiving and storing email you send to our published addresses | United States |
We may disclose data where required by law, court order, or a lawful request by an authority; to establish or defend legal claims; or to a successor if our business is transferred, in which case we will notify you.
We do not sell your personal data, and we do not share it for advertising.
8. How long we keep data
| Data | Retention |
|---|---|
| Account and business records | While your subscription is active |
| Receipt images and transactions — you cancel | While your subscription is active. Access ends when the period you paid for ends. We then hold the data for 90 days — no access — and delete it |
| Receipt images and transactions — payment lapses | Archived 7 days after the period ends, kept 90 days, then permanently deleted (Refund Policy clause 8) |
| Billing records | 7 years, as required by law |
| Application and security logs | 12 months |
| Support correspondence | 24 months |
What the 90 days is, and what it is not. Access is what your subscription pays for. When the period you have paid for ends, access ends — you cannot sign in, view, or download.
The 90 days is a retention window, not an access window. Its purpose is that if you come back within 90 days, your records are still there, exactly as you left them — returning is charged under Refund Policy clause 10. After 90 days they are deleted and cannot be recovered.
⚠️ This means you must export BEFORE the period you paid for runs out. If you need your records after that, you can resubscribe for one period and export then — but we cannot give you access without a subscription.
⚠️ We are not your archive of record. Section 82 of the Income Tax Act 1967 requires you to keep sufficient records for seven (7) years. Our retention period is shorter than that. Export your data before you cancel, and keep your own copies.
You may request deletion at any time. We will delete or anonymise your data except where we must keep it to comply with a legal obligation or to establish or defend a legal claim.
9. Security
We apply measures including encryption in transit, encryption at rest, hashed passwords, row-level access controls in the database enforced per user, role separation, and access logging. We restrict staff access to what is needed to operate and support the Service.
No system is completely secure. We cannot guarantee absolute security, and you are responsible for keeping your credentials safe and for who you invite to your account.
10. Data breach
If a personal data breach occurs that causes or is likely to cause significant harm, we will notify the Personal Data Protection Commissioner and affected individuals as required by the Personal Data Protection (Amendment) Act 2024, within the time the law prescribes.
11. Your rights
Rights the PDPA gives you:
- Access — ask what personal data we hold about you (s.30).
- Correction — have data that is inaccurate, incomplete, misleading, or out of date corrected (s.34).
- Withdraw consent — stop processing that relies on your consent, including automated reading of receipts and marketing (s.38).
- Prevent processing likely to cause damage or distress — require us to stop or not begin processing that would cause you substantial unwarranted damage or distress (s.42).
- Prevent direct marketing — require us to stop using your data for marketing (s.43).
- Data portability — require us to transmit your personal data directly to another data controller, where that is technically feasible and the data formats are compatible. This right was introduced by the Personal Data Protection (Amendment) Act 2024.
The Act requires such a request to be made in writing by electronic means. Email privacy@untng.my telling us who the receiving controller is. Where direct transmission is not technically feasible — for example where the receiving service has no facility to accept a transfer from us, or uses an incompatible format — we will instead provide your data to you in a structured, machine-readable report so that you can pass it on yourself. We will tell you which of the two we are doing, and why.
In addition, we offer:
- Deletion — ask us to delete your data, subject to clause 8. This is our commitment to you rather than a statutory right.
- Export — download your own records in a machine-readable format at any time, without needing to make a formal request.
Send requests to privacy@untng.my. We will respond within the period the PDPA allows. We may need to verify your identity first. A fee may apply to a data access request as permitted by law.
If you are not satisfied with our response, you may complain to the Personal Data Protection Department (Jabatan Perlindungan Data Peribadi), Malaysia.
12. Cookies and similar technologies
We use cookies and local browser storage to keep you signed in, remember your language and display preferences, and secure the session. We do not use advertising or cross-site tracking cookies. Blocking essential cookies will prevent you from signing in.
13. Children
The Service is for business use and is not directed at persons under eighteen (18). We do not knowingly collect their personal data. If you believe we have, contact us and we will delete it.
14. Changes to this Policy
We may update this Policy. For material changes we will give at least 30 days' notice by email or in-app notice. The current version and its effective date are always shown at the top of this page.
15. Contact
- Iqreative Design — NAME / ROLE OF PRIVACY CONTACT
- REGISTERED / OPERATING ADDRESS
- privacy@untng.my · SUPPORT PHONE