UNTNG · Iqreative Design

Privacy Policy

This Policy explains how we handle personal data in the Service. It is issued under the Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024.


1. Summary

2. What we collect

You give us:

CategoryExamples
AccountName, email address, phone number, password (stored hashed), profile photo if provided by your login provider
BusinessBusiness name, SSM registration number, address, contact details, tax identifiers
Records you enterIncome and expense transactions, daily sales, projects, quotations, invoices
People you recordNames and contact details of your customers, suppliers, and staff users
Receipt imagesPhotographs of receipts, invoices, slips, and related documents
SupportMessages you send us

Collected automatically: IP address, device and browser type, timestamps, and application logs, used for security, fraud prevention, and diagnostics.

From third parties: if you sign in with Google or Apple, we receive your name, email address, and account identifier from them. We do not receive your password.

Payment card data is never collected or stored by us. Payments are processed by Razorpay Curlec. We receive only the subscription status, the amount, and a reference.

3. Data about other people

When you photograph a receipt or record a customer, you may give us personal data about third parties. You are responsible for having a lawful basis to do so and for notifying those individuals where the law requires it. We process that data on your instructions in order to provide the Service.

4. Why we process your data, and on what basis

PurposeBasis
Creating and operating your accountPerformance of our contract with you
Reading receipts and proposing valuesPerformance of our contract; explicit consent where the receipt contains sensitive data (clause 5)
Storing your records and producing summariesPerformance of our contract
Billing and subscription managementPerformance of our contract; legal obligation
Security, fraud prevention, abuse investigationLegitimate interest
Support and service communicationsPerformance of our contract
Meeting legal and record-keeping obligationsLegal obligation
Product announcements and marketingConsent — you may withdraw at any time

5. Sensitive personal data

Under the PDPA, sensitive personal data includes information about a person's physical or mental health. Receipts from clinics, hospitals, pharmacies, and similar providers routinely reveal health information, sometimes together with a named individual.

Because of this:

We do not require sensitive personal data to provide the Service, and we ask you not to upload health-related documents unless you need them in your records.

6. Automated reading and transfer outside Malaysia

To propose the merchant, date, amount, and category, the Service sends a reduced-size copy of your receipt image to our artificial-intelligence provider, Anthropic, PBC (the Claude API), processing in the United States. The full-resolution archive copy is not sent; it remains in our storage in Singapore.

This is a cross-border transfer of personal data. The Personal Data Protection (Amendment) Act 2024 removed the previous "whitelist" mechanism for such transfers. We rely on:

We do not enable any provider feature that would extend retention beyond what is technically necessary to return a result.

If you do not want a document transferred, use the manual-entry option for that document. No image is sent for a receipt entered manually.

7. Who else processes your data

ProcessorPurposeLocation
SupabaseDatabase, authentication, file storageSingapore (AWS ap-southeast-1)
Anthropic, PBC (Claude API)Automated reading of receipt imagesUnited States
Razorpay CurlecPayment and subscription processingCURLEC PROCESSING LOCATION
ResendSending transactional email (sign-in confirmations, password resets, receipts)Japan (AWS ap-northeast-1)
Cloudflare, Inc. (Pages)Serving the application's static files (HTML, scripts, styles). No personal data is stored or processed here — all data operations run against Supabase.Global edge network
Cloudflare, Inc. (Email Routing)Forwarding email you send to our published addresses (support@, privacy@, hello@) to our mailbox. Messages are forwarded in transit and not stored by this service.Global edge network (Cloudflare, Inc., United States)
Google LLC (Gmail)Receiving and storing email you send to our published addressesUnited States

We may disclose data where required by law, court order, or a lawful request by an authority; to establish or defend legal claims; or to a successor if our business is transferred, in which case we will notify you.

We do not sell your personal data, and we do not share it for advertising.

8. How long we keep data

DataRetention
Account and business recordsWhile your subscription is active
Receipt images and transactions — you cancelWhile your subscription is active. Access ends when the period you paid for ends. We then hold the data for 90 days — no access — and delete it
Receipt images and transactions — payment lapsesArchived 7 days after the period ends, kept 90 days, then permanently deleted (Refund Policy clause 8)
Billing records7 years, as required by law
Application and security logs12 months
Support correspondence24 months

What the 90 days is, and what it is not. Access is what your subscription pays for. When the period you have paid for ends, access ends — you cannot sign in, view, or download.

The 90 days is a retention window, not an access window. Its purpose is that if you come back within 90 days, your records are still there, exactly as you left them — returning is charged under Refund Policy clause 10. After 90 days they are deleted and cannot be recovered.

⚠️ This means you must export BEFORE the period you paid for runs out. If you need your records after that, you can resubscribe for one period and export then — but we cannot give you access without a subscription.

⚠️ We are not your archive of record. Section 82 of the Income Tax Act 1967 requires you to keep sufficient records for seven (7) years. Our retention period is shorter than that. Export your data before you cancel, and keep your own copies.

You may request deletion at any time. We will delete or anonymise your data except where we must keep it to comply with a legal obligation or to establish or defend a legal claim.

9. Security

We apply measures including encryption in transit, encryption at rest, hashed passwords, row-level access controls in the database enforced per user, role separation, and access logging. We restrict staff access to what is needed to operate and support the Service.

No system is completely secure. We cannot guarantee absolute security, and you are responsible for keeping your credentials safe and for who you invite to your account.

10. Data breach

If a personal data breach occurs that causes or is likely to cause significant harm, we will notify the Personal Data Protection Commissioner and affected individuals as required by the Personal Data Protection (Amendment) Act 2024, within the time the law prescribes.

11. Your rights

Rights the PDPA gives you:

The Act requires such a request to be made in writing by electronic means. Email privacy@untng.my telling us who the receiving controller is. Where direct transmission is not technically feasible — for example where the receiving service has no facility to accept a transfer from us, or uses an incompatible format — we will instead provide your data to you in a structured, machine-readable report so that you can pass it on yourself. We will tell you which of the two we are doing, and why.

In addition, we offer:

Send requests to privacy@untng.my. We will respond within the period the PDPA allows. We may need to verify your identity first. A fee may apply to a data access request as permitted by law.

If you are not satisfied with our response, you may complain to the Personal Data Protection Department (Jabatan Perlindungan Data Peribadi), Malaysia.

12. Cookies and similar technologies

We use cookies and local browser storage to keep you signed in, remember your language and display preferences, and secure the session. We do not use advertising or cross-site tracking cookies. Blocking essential cookies will prevent you from signing in.

13. Children

The Service is for business use and is not directed at persons under eighteen (18). We do not knowingly collect their personal data. If you believe we have, contact us and we will delete it.

14. Changes to this Policy

We may update this Policy. For material changes we will give at least 30 days' notice by email or in-app notice. The current version and its effective date are always shown at the top of this page.

15. Contact