Privacy Policy
Version 1.2 — Effective date: September 2026 (supersedes Version 1.1, September 2026, which in turn superseded Version 1.0, April 2026; see Section 8 for the changes each version made).
This Privacy Policy describes how POS System, a service of Ibn Zelt (SSM: 201403253913 / IP0418148-M) ("we", "us", or "our"), collects, uses, and protects the personal data of users of our point-of-sale platform ("the Service"). We are committed to complying with the Personal Data Protection Act 2010 (PDPA) of Malaysia.
1. Data We Collect
Account Information
When you register as a merchant, we collect your name, business name, email address, phone number, and billing details necessary to operate your account and process subscription payments.
Transaction Data
All point-of-sale transactions processed through the Service are stored, including item details, quantities, prices, taxes (SST/GST), payment method, and timestamps. This data is required for e-invoice submission to the Lembaga Hasil Dalam Negeri (LHDN) where applicable.
Buyer Identity Documents (NRIC/Passport)
When a merchant using the Service needs to issue a compliant e-invoice to a buyer who has no Tax Identification Number (TIN) on file, we send that buyer a one-time, secure link asking them to submit their name, Tax Identification Number, and — where the merchant requires it for the invoice — an identity document number (NRIC, passport, business registration number, or army ID). We collect this identity document number solely to populate the buyer identification fields required by LHDN's MyInvois e-invoicing system; it is not used for any other purpose. Submitting this identity document number requires the buyer's explicit, separately recorded consent at the point of submission (see "How We Use Your Data" below) — the merchant cannot submit it on the buyer's behalf.
Payment Information
We never receive or store full payment card numbers. Where a payment is made by card or online banking, it is processed by Chip-In, our payment provider. Payment credentials are entered with Chip-In directly and handled under their systems; we retain only the payment reference and the status they return to us. We use our own Chip-In account for subscription fees paid by merchants to us; each merchant that enables online payment uses their own Chip-In account for payments made by their buyers.
Buyer payments may also be made by bank transfer, in which case they are recorded and approved manually by staff. On this path we retain the payment reference and any notes the payer supplies, together with any payment-proof document they choose to upload. That document is stored as a file in our cloud storage and is reviewed by staff to approve or reject the payment. A payer may request erasure of their personal data, including an uploaded payment-proof document, and we operate a deletion process that removes it upon request (see Section 5, "Your Rights Under PDPA 2010").
Device and Usage Data
We collect browser type, IP address, device identifiers, pages visited, and feature usage patterns to improve the Service and diagnose technical issues. This data is collected via server logs and may include session identifiers.
2. How We Use Your Data
- Providing the Service: Processing orders, generating receipts and e-invoices, and managing your merchant account.
- Billing and subscriptions: Charging subscription fees and issuing invoices for your use of the platform.
- Analytics and improvement: Understanding how merchants use the platform to fix bugs and develop new features.
- Legal compliance: Meeting obligations under Malaysian tax law, including e-invoice submission to LHDN.
- Customer support: Responding to your queries and resolving technical issues.
- Security: Detecting fraudulent activity and protecting against unauthorised access.
- Buyer identity document collection (consent-based): Where a buyer submits an NRIC, passport, business registration number, or army ID via a merchant's e-invoice request link, we process it only for LHDN e-invoice compliance and only after the buyer has ticked a consent checkbox at the point of submission. That submission records the version of this Privacy Policy the buyer consented under and the date and time of consent. The buyer may decline to provide the identity document; doing so may prevent the merchant from issuing a fully compliant e-invoice, but does not affect any other use of the Service.
3. Data Sharing
We share personal data only with the following trusted third parties, and only to the extent necessary:
- Chip-In: The payment provider used on this platform. We use our own Chip-In account to collect subscription fees from merchants. Each merchant that enables online payment for their storefront uses their own Chip-In account to collect from their buyers — those payments are received into that merchant's account, not ours. In both cases Chip-In receives the transaction and payer details necessary to take the payment, and handles payment credentials under their own systems.
- Supabase: Our cloud database and file storage provider, hosting all application data as well as uploaded files such as payment-proof documents. Data is stored in their infrastructure under a data processing agreement.
- LHDN (Lembaga Hasil Dalam Negeri): Malaysian tax authority. Where merchants are required to submit e-invoices, relevant transaction data is transmitted to the MyInvois portal via the LHDN API.
- Cloudflare: CDN and edge infrastructure provider. Request metadata passes through their network.
We do not sell personal data to third parties. We do not share data for advertising purposes.
4. Data Retention
- Transaction data: Retained for a minimum of 7 years in compliance with Section 82 of the Income Tax Act 1967 and Malaysian GST/SST regulations.
- Account data: Retained for as long as your account is active. Upon account deletion, personal identifiers are purged within 30 days, subject to the tax retention requirement above.
- Usage logs: Retained for up to 90 days for security and debugging purposes.
- Payment references, payer notes and payment-proof documents: Treated as transaction data and retained on the same basis as the entry above. A payer may request erasure of a payment-proof document at any time; we will action it unless the record must still be retained under that requirement.
5. Your Rights Under PDPA 2010
As a data subject under the Personal Data Protection Act 2010 (Malaysia), you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete personal data.
- Limit processing: Object to processing of your personal data in certain circumstances.
- Deletion: Request deletion of your personal data where we are not legally required to retain it.
To exercise these rights, use the self-service tools available in your account dashboard, or submit a request to the /api/account endpoint using your authenticated session. You may also contact us at [email protected].
We aim to respond to verified requests within 21 days.
6. Security Measures
We implement the following technical and organisational measures to protect your data:
- AES-GCM encryption for secrets and sensitive configuration values stored at rest.
- TLS/HTTPS enforced for all data in transit.
- Row-Level Security (RLS) on our database ensures each merchant can only access their own data.
- Access to production systems is restricted to authorised personnel only.
- Regular security reviews of API endpoints and authentication flows.
7. Cookies
We use cookies and similar technologies. See our Cookie Policy for full details.
8. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to registered account holders at least 14 days before they take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
Version 1.1 (September 2026): Added the "Buyer Identity Documents (NRIC/Passport)" category under Section 1, the consent-based buyer identity document purpose under Section 2, and Section 10 (Data Protection Officer). No prior data-handling commitment was removed or narrowed.
Version 1.2 (September 2026): Reworded Section 10 (Data Protection Officer) to state that the Data Protection Officer designation is voluntary and to disclaim any claim of registration with, or notification to, the Personal Data Protection Commissioner. No prior data-handling commitment was removed or narrowed.
9. Contact Us
For privacy-related enquiries, data access requests, or complaints, please contact:
Ibn Zelt (SSM: 201403253913 / IP0418148-M)
Email: [email protected]
Address: No. 8, Kampung Tengku Hussien Lama, 30020 Ipoh, Perak, Malaysia
If you are not satisfied with our response, you may lodge a complaint with the Department of Personal Data Protection Malaysia (JPDP) at www.pdp.gov.my.
10. Data Protection Officer
Ibn Zelt has voluntarily designated a Data Protection Officer, identified by role rather than by individual name, to oversee our compliance with this Policy. This designation is made on our own initiative and does not constitute a claim that we are registered with, or have notified, the Personal Data Protection Commissioner as a data user required to appoint a Data Protection Officer under the Personal Data Protection Act 2010 as amended by Act A1354 (2024). Any PDPA enquiry may be directed to the Data Protection Officer at [email protected] (see Section 9).
11. Data Controller and Data Processor Roles
The Service is a multi-tenant platform used by many independent merchants ("tenants") to run their own businesses. Because of this, Ibn Zelt and each tenant hold different roles under the PDPA depending on whose personal data is involved, and the obligations that apply differ accordingly.
Ibn Zelt as data controller. We are the data controller for personal data we collect to operate the Service and our relationship with merchants — this includes your Account Information (name, business name, email, phone number, billing details), Device and Usage Data collected across the platform, and data processed for our own billing, security, and legal compliance purposes as described in Sections 1 and 2.
Tenants as data controller. Each tenant merchant is the data controller for the personal data of their own customers and buyers — including Transaction Data and any Buyer Identity Documents collected through that tenant's e-invoice requests. The tenant determines why and how that data is collected and used (for example, which sales require an e-invoice, and what is printed on a receipt). Ibn Zelt does not decide these purposes on the tenant's behalf.
Ibn Zelt as data processor. For the personal data described in the paragraph above, Ibn Zelt acts as a data processor: we operate the shared infrastructure (database, e-invoice submission, storage) that stores and processes this data on the tenant's instructions, under the technical and organisational measures described in Section 6, and we do not use it for our own independent purposes. A buyer or customer with a query about how a specific tenant uses their data should first contact that tenant; Ibn Zelt remains reachable at the contact details in Section 9 for platform-level enquiries and matters that fall within our role as controller.