Privacy Policy
Privacy Policy
Effective date: 30 June 2026
Last updated: 30 June 2026
1. Introduction
This Privacy Policy explains how iStamp (“we”, “us”, “our”) collects, uses, discloses, stores, and protects personal data when you use our website, applications, and services (the “Service”).
This Policy applies to:
- Merchants (business users who register and operate loyalty programs)
- Merchant Staff (users invited by Merchants)
- Customers (individuals who join a Merchant’s stamp program)
- Visitors to our marketing site
Operators:
- Thinking Studio Sdn. Bhd. (Malaysia) — primary operator for Malaysian Merchants
- Thinking Studio LLC (State of Delaware, United States) — for non-Malaysia Merchants where applicable
Contact: privacy@thinkingstudio.my
2. Important roles — who is responsible for what?
2.1 iStamp as platform provider
We process data to provide, secure, and improve the Service, bill Merchants, and comply with law.
2.2 Merchants as program operators
When a Customer joins your stamp program, you decide what rewards to offer and how the program runs. For Customer personal data collected for your loyalty program, you are typically the data user / controller under Malaysia’s Personal Data Protection Act 2010 (PDPA) (or equivalent law in your country), and iStamp acts as a service provider / processor processing that data on your instructions via the platform.
Merchants must:
- Provide Customers with appropriate privacy notice (your program terms may reference data use)
- Respond to Customer rights requests where you are controller
- Only collect data you need and use it lawfully
- Not upload unlawful or excessive personal data into the Service
2.3 Customers
Customers interact with Merchants through iStamp tools. Customers may contact the Merchant for program-specific questions, and iStamp for platform/security issues.
3. Personal data we collect
3.1 Merchant and Staff account data
| Data | Examples | Purpose |
|---|---|---|
| Identity & contact | Name, email, phone, business name, address | Account creation, support, billing |
| Authentication | Hashed password, session tokens | Login security |
| Role & permissions | Owner, manager, staff | Access control |
| Billing | Plan, payment status, transaction references from payment providers | Subscriptions |
| Usage & logs | IP address, device/browser type, timestamps, feature usage | Security, analytics, troubleshooting |
3.2 Customer data (via Merchant programs)
| Data | Examples | Purpose |
|---|---|---|
| Identity & contact | Name, phone (as submitted at join) | Stamp account, recovery, CRM |
| Program data | Stamp balance, earn/redeem history, join date | Loyalty program operation |
| Security | Access token, QR signing secret | Card access & dynamic QR |
| Optional | Security icon choice at registration | Account recovery verification |
| Merchant notes | Notes added by Merchant staff in CRM | Customer relationship management |
We do not require Customers to create a password or email for basic stamp card use unless recovery or future features require it.
3.3 Merchant-uploaded content
Promo banners, program terms, marketing copy, and CRM notes may contain personal data if Merchants include it. Merchants are responsible for what they upload.
3.4 Communications
Support emails, feedback, and optional Smart Batch / WhatsApp message content initiated by Merchants (messages are typically composed and sent by Merchants outside or via linked flows — we store templates and segment metadata as configured).
3.5 Cookies and similar technologies
We use cookies and local storage for:
- Session authentication (Merchants/Staff)
- Language preference (
localecookie) - Security and fraud prevention
See Section 10.
4. How we use personal data
We use personal data to:
- Provide the Service — accounts, stamp programs, QR, scan/redemption, CRM
- Secure the Service — dynamic QR, cooldowns, access control, audit logs (
staff_idon transactions) - Process payments — subscriptions via Billplz (Malaysia) and/or Paddle (international)
- Communicate — service notices, billing, security alerts, product updates
- Improve the Service — aggregated analytics, debugging, feature development
- Comply with law — respond to lawful requests, enforce Terms
- Protect rights — fraud investigation, dispute handling
Legal bases (where applicable):
- Contract — to perform our agreement with Merchants
- Legitimate interests — security, improvement, fraud prevention (balanced against rights)
- Consent — where required (e.g. optional marketing if offered)
- Legal obligation — tax, regulatory, court orders
5. How we share personal data
We do not sell personal data.
We may share data with:
| Recipient | Why |
|---|---|
| Infrastructure providers | Hosting, database (e.g. Supabase), CDN (e.g. Vercel, Cloudflare) |
| Payment processors | Billplz, Paddle — billing only |
| Professional advisers | Lawyers, accountants — confidentiality obligations |
| Authorities | When required by law or to protect rights/safety |
| Business transfers | Merger, acquisition — with notice where required |
| At Merchant direction | Staff users under same Merchant account see Customer data per role permissions |
Merchant Staff with appropriate roles can view Customer profiles, stamp history, and notes within that Merchant’s account only (enforced by Row Level Security).
6. International transfers
6.1 Our primary database region is Singapore (ap-southeast-1) via Supabase, which may involve transfer of personal data outside Malaysia or your country.
6.2 We implement appropriate safeguards consistent with applicable law (including PDPA requirements for cross-border transfers where relevant).
6.3 Payment processors may process data in their own regions per their policies.
7. Data retention
| Category | Typical retention |
|---|---|
| Merchant account | While account active + reasonable period after closure |
| Customer stamp data | While Merchant maintains program + period after Merchant deletion/termination as needed for disputes/legal |
| Transaction logs (earn/redeem) | Audit and business records — typically 7 years or as required by law |
| Billing records | As required for tax/accounting (often 7 years in Malaysia) |
| Server logs | Limited rolling period (e.g. 30–90 days) unless needed for security investigation |
We may anonymise or aggregate data for analytics and retain anonymised data longer.
Merchants may export Customer data (on eligible plans) before account closure. After termination, deletion timelines apply per contract and law.
8. Security
We implement technical and organisational measures including:
- Encryption in transit (HTTPS/TLS)
- Row Level Security (RLS) on database tables — Merchants isolated from each other
- Dynamic QR with short expiry and HMAC signatures
- Role-based access for Staff
- Audit fields on stamp transactions (
staff_id, timestamps) - Hashed passwords for Merchant accounts (via Supabase Auth)
No system is 100% secure. Report suspected incidents to privacy@thinkingstudio.my promptly.
9. Your rights
9.1 Merchants and Staff
Depending on jurisdiction, you may have rights to access, correct, delete, or restrict processing of your personal data, and to object to certain processing. Contact privacy@thinkingstudio.my. We may verify identity before responding.
9.2 Customers
Contact your Merchant first for stamp balance, program terms, and correction of name/phone in their CRM.
For platform issues (e.g. lost access link, security concern), contact privacy@thinkingstudio.my with Merchant name and phone used at registration. We will coordinate with the Merchant where appropriate.
9.3 Malaysia — PDPA
Malaysian data subjects may have rights under the PDPA 2010, including access and correction. Submit requests to privacy@thinkingstudio.my. We respond within timeframes required by law.
9.4 Withdrawal of consent
Where processing is consent-based, withdrawal may affect ability to use certain features.
10. Cookies and tracking
| Type | Purpose |
|---|---|
| Essential | Login session, security |
| Preference | Language (locale) |
| Analytics | If enabled in future — we will update this Policy |
You can control cookies via browser settings. Blocking essential cookies may break login.
We do not currently use third-party advertising cookies on the Merchant dashboard.
11. Children
The Service is not directed at children under 13 (or under 18 for Merchant accounts). We do not knowingly collect data from children. If you believe we have, contact privacy@thinkingstudio.my for deletion.
12. Merchant obligations summary
If you are a Merchant, you agree to:
- Have a lawful basis to collect Customer phone/name
- Not use exported lists for spam without consent
- Configure retention-appropriate notes in CRM
- Notify us at privacy@thinkingstudio.my of any personal data breach involving the Service affecting your Customers
13. Changes to this Policy
We may update this Privacy Policy. We will post the new version with an updated effective date and, for material changes, provide notice via email or in-app where appropriate.
14. Contact & data protection enquiries
| Privacy email | privacy@thinkingstudio.my |
| Support | hello@thinkingstudio.my |
| Legal | legal@thinkingstudio.my |
| Malaysia entity | Thinking Studio Sdn. Bhd., [Registered address, Malaysia] |
| Global entity | Thinking Studio LLC, [Registered address, United States] |
This Privacy Policy should be read together with our Terms of Service and Refund Policy.