Privacy Policy & Personal Data Protection Notice
Versi Bahasa Malaysia: Notis Perlindungan Data Peribadi
This policy explains what personal data GuestNet collects, why, who we share it with, how long we keep it and the rights you have. It is our written notice under section 7 of Malaysia's Personal Data Protection Act 2010 (the "PDPA", as amended).
1. Who we are
GuestNet (the website guestnet.my and the web app app.guestnet.my, together the "Service") is operated by BBJCreative LLP, a limited liability partnership registered in Malaysia (LLP No. [LLP registration number]), [registered business address], Malaysia ("we", "us", "our"). For the PDPA, we are the data user for the personal data described in this policy.
Privacy contact: sales@bbjcreative.com (please put "Privacy" in the subject line).
2. The short version
- We collect only what we need to run your account: your email, business name, password (stored only as a secure hash), and the cards you design.
- Your WiFi password is never saved in our database. It is used in your browser for the preview and sent once, over an encrypted connection, when you export a card. The exported file contains the QR code, which encodes the password, so we keep only your latest export per card and delete it when you delete the card or your account.
- We do not sell your data, show ads, use advertising or analytics trackers, or send marketing email without your consent.
- You can delete your account and all its cards, uploads and exported files at any time from Settings.
3. Data we collect
| Category | What | Source | Required? |
|---|---|---|---|
| Account data | Email address; business (organisation) name; account password, which we store only as an Argon2 hash and never in readable form; the date and version of the Terms and this policy you accepted. | You, at sign-up and in Settings | Yes. Without it we cannot create or secure your account. |
| Card content | Card names, WiFi network names (SSIDs), security type, design choices (template, font, colours, header and footer text) and any logo or background image you upload. | You, in the app | Yes, to create cards. Uploads are optional. |
| Exported files | The PNG or PDF files generated when you export a card. They contain the QR code, which encodes your WiFi password (see section 4). | Generated by the Service at your request | Only if you export |
| Payment data (once paid plans launch) | Plan purchased, amount, currency, date, payment status and the payment provider's transaction reference. Card, bank and e-wallet details are entered on the payment provider's page and are not received or stored by us. | You and our payment providers | Only if you buy a paid plan |
| Technical and security data | IP address, browser and device type, date and time, pages and API endpoints requested, and response codes, recorded in server and network logs. Sign-in attempts are rate-limited by IP address. | Automatically, when you use the Service | Yes. Needed to deliver and protect the Service. |
| Communications | What you send us by email and our replies. | You | Optional |
We do not intentionally collect sensitive personal data (as defined in the PDPA). Please do not include it in card text, file names or uploads.
4. Your WiFi password and exported files
A WiFi QR code only works if it contains the network password, so we want to be precise about how that password is handled:
- Preview. The QR preview is drawn in your browser. Typing the password does not send it to us.
- Export. When you export, the password is sent once over HTTPS so our server can draw the print file. It is not written to our database or application logs, and it is not included in the request-body logging of our servers.
- The file. The exported PNG or PDF contains the QR code, and anyone who can see or scan the QR can join the network. The file is stored on our servers at a long, random, unguessable address so you can download it again. It is marked so it is not stored by browser or network caches and not indexed by search engines.
- Retention. We keep only the latest export for each card and each format. A new export replaces the previous file. Deleting a card deletes its exports, and deleting your account deletes all of them.
Treat exported files and their links like the password itself. Don't post them publicly online unless you intend anyone to join. We strongly recommend using a separate guest network for your card, not your main business network.
5. Why we use your data (purposes)
We process personal data only for these purposes:
- to create, operate and secure your account and sign you in;
- to provide the Service: saving your designs, rendering previews and exports, and storing your uploads;
- to process payments, apply your plan and keep transaction records, once paid plans launch;
- to respond to your enquiries and send service messages, such as security, account, billing or policy-change notices, which are not marketing;
- to detect, prevent and investigate abuse, fraud, security incidents and violations of our Terms of Service;
- to maintain and improve the reliability and performance of the Service, using technical data;
- to comply with law, regulatory requests and court orders, and to establish, exercise or defend legal claims.
We rely on your consent, given when you create an account and use the Service, and on the other grounds the PDPA allows, including where processing is necessary to perform our contract with you, to comply with a legal obligation, or to protect your vital interests. We will not use your data for a purpose not directly related to these without asking you first. We will only send marketing email if you opt in, and every such email will let you opt out.
6. Who we share it with
We do not sell or rent personal data. We disclose it only to the following classes of third parties, and only as needed for the purposes above:
- Hosting and infrastructure: our cloud server provider (currently Hostinger), which stores the database and files.
- Network, DNS and security: Cloudflare, which carries all traffic to guestnet.my and app.guestnet.my, protects against attacks and may set security cookies.
- Payments (once launched): Billplz and/or Stripe, which process your payment under their own privacy policies.
- Email: the email service provider we use to receive and answer your messages.
- Professional advisers: lawyers, accountants and auditors, under confidentiality.
- Authorities: regulators, law enforcement, courts or other parties where required or permitted by law, or where necessary to protect our rights, users or the public.
- Business transfer: a buyer or successor of the Service in a merger, acquisition or restructuring, bound by this policy.
Our service providers act on our instructions and must protect the data. They may not use it for their own purposes, except payment providers acting as independent controllers of payment data.
7. Transfers outside Malaysia
Some providers, including Cloudflare's global network and our hosting and payment providers, may process or store data outside Malaysia. Where personal data is transferred abroad, we do so as permitted by section 129 of the PDPA. We use reputable providers with appropriate safeguards and contractual protections, so that your data receives protection comparable to the PDPA. By using the Service you consent to these transfers.
8. Cookies and local storage
We use only strictly necessary technologies, so no cookie banner is required:
- Sign-in cookie (
refresh_token, app.guestnet.my): an encrypted, HttpOnly, secure cookie that keeps you signed in for up to 30 days. It is removed when you log out. - Cloudflare security cookies (for example
__cf_bm,cf_clearance): used to tell people from bots and to block attacks. - App offline cache: the app stores its own files and your recent card list on your device so it loads quickly and works with a weak signal. You can clear this in your browser's site settings.
We do not use advertising, cross-site tracking or third-party analytics cookies.
9. How long we keep data
- Account, cards and uploads: for as long as your account exists. When you delete your account in Settings, your organisation, users, cards, uploaded images and exported files are deleted from our live systems immediately. Removing an image from a design does not delete the uploaded file; it is deleted with your account.
- Exported files: only the latest per card and format, deleted with the card or account (section 4).
- Payment and transaction records: for as long as tax, accounting and other laws require, generally 7 years, even after you delete your account.
- Server and security logs: kept for a short period for security and troubleshooting, then rotated and deleted automatically.
- Backups: if we keep backups, deleted data is removed from them in the normal backup cycle, within 35 days.
- Emails with us: as long as needed to handle your request and any follow-up, normally up to 2 years.
We may keep data longer where needed to comply with law or to establish, exercise or defend legal claims.
10. Security
We take practical steps to protect personal data from loss, misuse, modification, unauthorised or accidental access or disclosure, alteration and destruction, as the PDPA's Security Principle requires. These include:
- encryption in transit (HTTPS/TLS) for all traffic;
- passwords hashed with Argon2;
- short-lived access tokens;
- rate-limited sign-in;
- server access restricted to key-based administration;
- no storage of WiFi passwords in our database.
No online service can be completely secure. You are responsible for choosing a strong account password and keeping it confidential. If we become aware of a personal data breach that is likely to cause significant harm, we will notify the Personal Data Protection Commissioner and affected users as the PDPA requires.
11. Your rights and choices
Under the PDPA you may:
- Access the personal data we hold about you and obtain a copy;
- Correct data that is inaccurate, incomplete, misleading or out of date. You can edit your business name and email yourself in Settings;
- Withdraw consent and ask us to stop processing, which normally means deleting your account;
- Prevent processing likely to cause you damage or distress, and object to direct marketing;
- Data portability: ask for your data to be transmitted to another data user, where technically feasible and provided by law;
- Delete your account at any time in Settings → Delete account.
Email sales@bbjcreative.com with the subject "Privacy request". We will verify your identity, usually by asking you to write from your account email, and respond within 21 days as the PDPA requires. We do not charge for reasonable requests; we may charge a fee as permitted by the PDPA regulations for repeated or excessive requests, or refuse them where the law allows. If you withdraw consent, or don't provide required data, we may be unable to provide the Service.
If you are unhappy with our response, you may complain to the Department of Personal Data Protection (Jabatan Perlindungan Data Peribadi), Malaysia.
12. Your guests' data
GuestNet does not collect any data from people who scan your card. Scanning happens on the guest's phone and connects it to your network; it does not contact us. GuestNet does not provide internet access, captive portals or guest tracking. If you collect guest data on your own network, for example through your router or a separate WiFi portal, you are the data user for it and responsible for complying with the PDPA.
13. Children
The Service is for businesses and is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us data, contact us and we will delete it.
14. Changes to this policy
We may update this policy, for example when paid plans launch or if we add providers. We will post the new version here with a new "last updated" date. If a change materially affects how we use your personal data, we will tell you by email or in the app before it takes effect and, where required, ask for your consent.
15. Contact us
BBJCreative LLP (operator of GuestNet)
[registered business address], Malaysia
Email: sales@bbjcreative.com
If there is any inconsistency between the English and Bahasa Malaysia versions of this notice, the English version prevails, to the extent permitted by law.
Notis Perlindungan Data Peribadi (Bahasa Malaysia)
Notis ini diberikan menurut seksyen 7 Akta Perlindungan Data Peribadi 2010 ("APDP"). GuestNet (laman guestnet.my dan aplikasi app.guestnet.my) dikendalikan oleh BBJCreative LLP, perkongsian liabiliti terhad yang didaftarkan di Malaysia (No. LLP [nombor pendaftaran LLP]), [alamat perniagaan berdaftar], Malaysia ("kami").
Data yang kami kumpul
- Data akaun: alamat e-mel, nama perniagaan, kata laluan akaun (disimpan hanya sebagai cincangan Argon2), dan tarikh serta versi Terma dan notis ini yang anda terima.
- Kandungan kad: nama kad, nama rangkaian WiFi (SSID), jenis keselamatan, pilihan reka bentuk, serta logo atau imej latar yang anda muat naik.
- Fail eksport: fail PNG/PDF yang dijana apabila anda mengeksport kad. Fail ini mengandungi kod QR yang mengekod kata laluan WiFi anda.
- Data pembayaran (apabila pelan berbayar dilancarkan): pelan, jumlah, tarikh, status dan rujukan transaksi. Butiran kad atau bank dimasukkan di laman penyedia pembayaran dan tidak diterima atau disimpan oleh kami.
- Data teknikal: alamat IP, jenis pelayar dan peranti, masa, dan permintaan yang dibuat, dalam log pelayan dan rangkaian.
Kata laluan WiFi anda
Kata laluan WiFi anda tidak disimpan dalam pangkalan data kami. Pratonton QR dijana dalam pelayar anda. Kata laluan dihantar sekali melalui sambungan HTTPS yang disulitkan semasa anda mengeksport, untuk menjana fail cetakan. Fail eksport mengandungi kod QR, jadi kami simpan hanya eksport terkini bagi setiap kad dan format, dan memadamkannya apabila anda memadam kad atau akaun. Layan fail eksport seperti kata laluan itu sendiri.
Tujuan pemprosesan
Kami memproses data peribadi untuk:
- mewujudkan, mengendalikan dan melindungi akaun anda;
- menyediakan Perkhidmatan (menyimpan reka bentuk, menjana pratonton dan eksport);
- memproses pembayaran dan menyimpan rekod transaksi;
- menjawab pertanyaan dan menghantar notis perkhidmatan;
- mengesan dan mencegah penyalahgunaan, penipuan dan insiden keselamatan;
- menambah baik kebolehpercayaan Perkhidmatan;
- mematuhi undang-undang dan mempertahankan tuntutan undang-undang.
Kami tidak menjual data anda dan tidak menghantar e-mel pemasaran tanpa persetujuan anda.
Pihak ketiga yang menerima data
Data hanya didedahkan kepada pihak berikut, setakat yang perlu:
- penyedia pengehosan pelayan (kini Hostinger);
- Cloudflare (rangkaian, DNS dan keselamatan);
- penyedia pembayaran Billplz dan/atau Stripe (apabila dilancarkan);
- penyedia e-mel;
- penasihat profesional;
- pihak berkuasa, apabila dikehendaki oleh undang-undang;
- pengganti perniagaan, sekiranya berlaku penggabungan atau pengambilalihan.
Sesetengah penyedia mungkin memproses data di luar Malaysia; pemindahan sedemikian dibuat menurut seksyen 129 APDP.
Kuki
Kami hanya menggunakan kuki yang benar-benar perlu:
- kuki log masuk
refresh_token(sehingga 30 hari); - kuki keselamatan Cloudflare;
- cache luar talian aplikasi pada peranti anda.
Tiada kuki pengiklanan atau analitik pihak ketiga.
Tempoh penyimpanan
- Data akaun, kad dan muat naik disimpan selagi akaun wujud, dan dipadam serta-merta apabila anda memadam akaun di Tetapan.
- Rekod transaksi disimpan selama yang dikehendaki oleh undang-undang cukai dan perakaunan (lazimnya 7 tahun).
- Log pelayan diputar dan dipadam secara automatik.
- Sandaran (jika ada) dipadam dalam kitaran biasa, dalam tempoh 35 hari.
Wajib atau sukarela
Data akaun dan kandungan kad adalah wajib untuk menggunakan Perkhidmatan; jika tidak diberikan, kami tidak dapat menyediakan Perkhidmatan. Muat naik logo atau imej, data pembayaran dan komunikasi adalah sukarela.
Hak anda
Anda berhak untuk:
- mengakses dan mendapatkan salinan data peribadi anda;
- membetulkan data yang tidak tepat;
- menarik balik persetujuan;
- menghalang pemprosesan yang mungkin menyebabkan kerosakan atau distres, dan pemasaran langsung;
- meminta pemindahan data (portabiliti), jika diperuntukkan oleh undang-undang;
- memadam akaun anda pada bila-bila masa di Tetapan.
Hantar permintaan ke sales@bbjcreative.com dengan subjek "Permintaan Privasi". Kami akan menjawab dalam tempoh 21 hari. Anda juga boleh membuat aduan kepada Jabatan Perlindungan Data Peribadi Malaysia.
Hubungi kami
BBJCreative LLP, [alamat perniagaan berdaftar], Malaysia. E-mel: sales@bbjcreative.com.
Sekiranya terdapat percanggahan antara versi Bahasa Inggeris dan Bahasa Malaysia, versi Bahasa Inggeris akan diguna pakai setakat yang dibenarkan oleh undang-undang.