LAST UPDATED 24 AUGUST 2026
Privacy policy
CollectLah runs digital loyalty cards for local businesses. This explains what personal data we hold, why we hold it, and what you can ask us to do with it.
Who is responsible for your data
CollectLah is operated in Malaysia.
When you join a loyalty program, there are two parties involved. The business you joined — the cafe or restaurant whose card you signed up for — decides what to collect and why; under the Personal Data Protection Act 2010 (PDPA) they are the data controller. CollectLah stores and processes those operational records on their instructions as their data processor. If you separately choose personalised offers from CollectLah, CollectLah is also responsible for the limited marketing profile described below.
What we collect
- What you give us when you join: your name, verified mobile number, and an optional email address.
- Business records: purchases, appointments and, when needed to fulfil an order, a delivery address. These stay in that business's protected workspace.
- Your loyalty activity: stamps and points earned, rewards unlocked and redeemed, which outlet you visited, and when.
- Your consent choices: whether you accepted the program terms, and whether you opted in to marketing messages, each recorded with a timestamp.
- Basic technical data: your IP address at sign-up, used to limit automated abuse of public join links.
We do not collect payment card details. We do not track you across other websites.
Why we use it
- To create and run your loyalty card, including the pass stored in Apple Wallet.
- To keep your stamp and point balances accurate, and to let staff verify a reward at the counter.
- To show the business aggregate reporting about visits and returning customers.
- To send personalised offers from the business and CollectLah only if you opted in. You can change the channels or opt out from your web card without affecting your loyalty balance.
- To create pseudonymous product, visit and feature-usage events for aggregate reporting and future service improvement. These events do not contain your name, phone number, email or delivery address.
- To protect the service from fraudulent or automated sign-ups.
Who we share it with
Your data is visible to the business whose program you joined and to their staff members. Beyond that, we share it only with the service providers needed to run CollectLah: our hosting and database provider, our wallet pass provider, our messaging provider for the SMS or email you opted in to, and our payment provider where a business pays for its subscription. Each acts on our instructions and may not use your data for their own purposes.
We do not sell your personal data, and we do not share it with advertisers.
How long we keep it
We keep identifiable loyalty and marketing records while they are needed for the stated purpose and for up to 24 months after your last recorded engagement, after which they are deleted or anonymised unless a legal or accounting obligation requires longer retention. Consent records and security logs may be kept longer where needed to show that we handled your choices correctly. Pseudonymous aggregate events may be retained for longer because they do not directly identify you.
Your rights
Under the PDPA you may ask us to:
- Access the personal data we hold about you, and receive a copy of it.
- Correct anything that is inaccurate or out of date.
- Withdraw consent to marketing messages, or to the program entirely.
- Delete your data. We anonymise your record rather than removing transaction history outright, so the business's past sales reporting stays intact while nothing remains that identifies you.
Contact the business whose program you joined and we will respond within 21 days. There is no charge for a reasonable request.
How we protect it
Data is transmitted over encrypted connections and stored on managed infrastructure with access restricted to the business's own staff and the operator. Staff access is role-based, and changes to customer records are written to an append-only audit log. No system is perfectly secure; if a breach affects your data we will tell you and the relevant authority without undue delay.
Changes to this policy
If we make a material change we will update the date at the top of this page. Where the change affects how we use data you already gave us, we will ask the business to notify you.