Privacy Policy

Privacy Policy

Effective date: 30 June 2026
Last updated: 30 June 2026


1. Introduction

This Privacy Policy explains how iStamp (“we”, “us”, “our”) collects, uses, discloses, stores, and protects personal data when you use our website, applications, and services (the “Service”).

This Policy applies to:

  • Merchants (business users who register and operate loyalty programs)
  • Merchant Staff (users invited by Merchants)
  • Customers (individuals who join a Merchant’s stamp program)
  • Visitors to our marketing site

Operators:

  • Thinking Studio Sdn. Bhd. (Malaysia) — primary operator for Malaysian Merchants
  • Thinking Studio LLC (State of Delaware, United States) — for non-Malaysia Merchants where applicable

Contact: privacy@thinkingstudio.my


2. Important roles — who is responsible for what?

2.1 iStamp as platform provider

We process data to provide, secure, and improve the Service, bill Merchants, and comply with law.

2.2 Merchants as program operators

When a Customer joins your stamp program, you decide what rewards to offer and how the program runs. For Customer personal data collected for your loyalty program, you are typically the data user / controller under Malaysia’s Personal Data Protection Act 2010 (PDPA) (or equivalent law in your country), and iStamp acts as a service provider / processor processing that data on your instructions via the platform.

Merchants must:

  • Provide Customers with appropriate privacy notice (your program terms may reference data use)
  • Respond to Customer rights requests where you are controller
  • Only collect data you need and use it lawfully
  • Not upload unlawful or excessive personal data into the Service

2.3 Customers

Customers interact with Merchants through iStamp tools. Customers may contact the Merchant for program-specific questions, and iStamp for platform/security issues.


3. Personal data we collect

3.1 Merchant and Staff account data

DataExamplesPurpose
Identity & contactName, email, phone, business name, addressAccount creation, support, billing
AuthenticationHashed password, session tokensLogin security
Role & permissionsOwner, manager, staffAccess control
BillingPlan, payment status, transaction references from payment providersSubscriptions
Usage & logsIP address, device/browser type, timestamps, feature usageSecurity, analytics, troubleshooting

3.2 Customer data (via Merchant programs)

DataExamplesPurpose
Identity & contactName, phone (as submitted at join)Stamp account, recovery, CRM
Program dataStamp balance, earn/redeem history, join dateLoyalty program operation
SecurityAccess token, QR signing secretCard access & dynamic QR
OptionalSecurity icon choice at registrationAccount recovery verification
Merchant notesNotes added by Merchant staff in CRMCustomer relationship management

We do not require Customers to create a password or email for basic stamp card use unless recovery or future features require it.

3.3 Merchant-uploaded content

Promo banners, program terms, marketing copy, and CRM notes may contain personal data if Merchants include it. Merchants are responsible for what they upload.

3.4 Communications

Support emails, feedback, and optional Smart Batch / WhatsApp message content initiated by Merchants (messages are typically composed and sent by Merchants outside or via linked flows — we store templates and segment metadata as configured).

3.5 Cookies and similar technologies

We use cookies and local storage for:

  • Session authentication (Merchants/Staff)
  • Language preference (locale cookie)
  • Security and fraud prevention

See Section 10.


4. How we use personal data

We use personal data to:

  1. Provide the Service — accounts, stamp programs, QR, scan/redemption, CRM
  2. Secure the Service — dynamic QR, cooldowns, access control, audit logs (staff_id on transactions)
  3. Process payments — subscriptions via Billplz (Malaysia) and/or Paddle (international)
  4. Communicate — service notices, billing, security alerts, product updates
  5. Improve the Service — aggregated analytics, debugging, feature development
  6. Comply with law — respond to lawful requests, enforce Terms
  7. Protect rights — fraud investigation, dispute handling

Legal bases (where applicable):

  • Contract — to perform our agreement with Merchants
  • Legitimate interests — security, improvement, fraud prevention (balanced against rights)
  • Consent — where required (e.g. optional marketing if offered)
  • Legal obligation — tax, regulatory, court orders

5. How we share personal data

We do not sell personal data.

We may share data with:

RecipientWhy
Infrastructure providersHosting, database (e.g. Supabase), CDN (e.g. Vercel, Cloudflare)
Payment processorsBillplz, Paddle — billing only
Professional advisersLawyers, accountants — confidentiality obligations
AuthoritiesWhen required by law or to protect rights/safety
Business transfersMerger, acquisition — with notice where required
At Merchant directionStaff users under same Merchant account see Customer data per role permissions

Merchant Staff with appropriate roles can view Customer profiles, stamp history, and notes within that Merchant’s account only (enforced by Row Level Security).


6. International transfers

6.1 Our primary database region is Singapore (ap-southeast-1) via Supabase, which may involve transfer of personal data outside Malaysia or your country.

6.2 We implement appropriate safeguards consistent with applicable law (including PDPA requirements for cross-border transfers where relevant).

6.3 Payment processors may process data in their own regions per their policies.


7. Data retention

CategoryTypical retention
Merchant accountWhile account active + reasonable period after closure
Customer stamp dataWhile Merchant maintains program + period after Merchant deletion/termination as needed for disputes/legal
Transaction logs (earn/redeem)Audit and business records — typically 7 years or as required by law
Billing recordsAs required for tax/accounting (often 7 years in Malaysia)
Server logsLimited rolling period (e.g. 30–90 days) unless needed for security investigation

We may anonymise or aggregate data for analytics and retain anonymised data longer.

Merchants may export Customer data (on eligible plans) before account closure. After termination, deletion timelines apply per contract and law.


8. Security

We implement technical and organisational measures including:

  • Encryption in transit (HTTPS/TLS)
  • Row Level Security (RLS) on database tables — Merchants isolated from each other
  • Dynamic QR with short expiry and HMAC signatures
  • Role-based access for Staff
  • Audit fields on stamp transactions (staff_id, timestamps)
  • Hashed passwords for Merchant accounts (via Supabase Auth)

No system is 100% secure. Report suspected incidents to privacy@thinkingstudio.my promptly.


9. Your rights

9.1 Merchants and Staff

Depending on jurisdiction, you may have rights to access, correct, delete, or restrict processing of your personal data, and to object to certain processing. Contact privacy@thinkingstudio.my. We may verify identity before responding.

9.2 Customers

Contact your Merchant first for stamp balance, program terms, and correction of name/phone in their CRM.

For platform issues (e.g. lost access link, security concern), contact privacy@thinkingstudio.my with Merchant name and phone used at registration. We will coordinate with the Merchant where appropriate.

9.3 Malaysia — PDPA

Malaysian data subjects may have rights under the PDPA 2010, including access and correction. Submit requests to privacy@thinkingstudio.my. We respond within timeframes required by law.

9.4 Withdrawal of consent

Where processing is consent-based, withdrawal may affect ability to use certain features.


10. Cookies and tracking

TypePurpose
EssentialLogin session, security
PreferenceLanguage (locale)
AnalyticsIf enabled in future — we will update this Policy

You can control cookies via browser settings. Blocking essential cookies may break login.

We do not currently use third-party advertising cookies on the Merchant dashboard.


11. Children

The Service is not directed at children under 13 (or under 18 for Merchant accounts). We do not knowingly collect data from children. If you believe we have, contact privacy@thinkingstudio.my for deletion.


12. Merchant obligations summary

If you are a Merchant, you agree to:

  • Have a lawful basis to collect Customer phone/name
  • Not use exported lists for spam without consent
  • Configure retention-appropriate notes in CRM
  • Notify us at privacy@thinkingstudio.my of any personal data breach involving the Service affecting your Customers

13. Changes to this Policy

We may update this Privacy Policy. We will post the new version with an updated effective date and, for material changes, provide notice via email or in-app where appropriate.


14. Contact & data protection enquiries

Privacy emailprivacy@thinkingstudio.my
Supporthello@thinkingstudio.my
Legallegal@thinkingstudio.my
Malaysia entityThinking Studio Sdn. Bhd., [Registered address, Malaysia]
Global entityThinking Studio LLC, [Registered address, United States]

This Privacy Policy should be read together with our Terms of Service and Refund Policy.