Legal
Privacy Policy
Version 2026-08-01. Maintained by the platform owner to explain how personal data is handled on this platform under PDPA 2010 (Act 709). This page is not an independent certification.
1. Data we collect
- Full name
- Email address
- Phone number
- Sign-in timestamps
- IP address
- Device / browser type and operating system (audit logging)
- Location Data (GPS coordinates) during security verification checkpoints
- Consent records: which legal documents you accepted, when, and from which IP
IP address and device metadata are collected for security purposes: detecting account misuse, credential sharing and unauthorised access.
Location Data (GPS) for Security Verification: To safeguard your account and prevent unauthorized access or prohibited account sharing, our system employs advanced security measures. If suspicious login activity is detected, we reserve the right to request access to your precise physical location (GPS coordinates) prior to granting access to our services. This location data is used strictly for security verification purposes and will never be shared with third parties.
2. OTP handling policy
Connected seller inboxes are read in real time solely to extract a one-time passcode matching an active customer request. No full email content is stored permanently: the platform retains only the matched code, the sender, the subject line and the fields the workspace admin explicitly configured for rule matching, and OTP releases expire automatically.
Continuous inbox monitoring is optional and disabled by default; inboxes are normally checked only when a customer requests a code.
3. Roles under PDPA 2010
The platform acts as Data Processor. Each Workspace Admin is the Data Controller for their own customers and is responsible for obtaining those customers' consent before storing their data here.
4. Access, sharing and isolation
Workspace data is isolated by row-level security: one workspace cannot read another workspace's customers, inboxes, OTP history or audit records. Access is limited to the workspace's Master Admin, their approved Sub-Admins, and the platform owner for operational support and abuse investigation. Data is not sold or shared with advertisers.
5. Retention and data deletion
Customers, subscriptions and OTP history are retained while the subscription is active. Workspace Admins have the right to full deletion of their workspace data upon subscription cancellation; on request the workspace's customers, apps, inboxes, OTP history, backups and alerts are purged. Administrative audit records are retained for legal accountability.
6. Your rights and contact
You may request access to, correction of, or deletion of your personal data, and you may withdraw consent. End-customers should contact the workspace admin who issued their customer ID; workspace admins should contact the platform owner through the channel used for their subscription.
See also the Terms of Service & DPA.