Privacy Policy
Last updated: August 2026
Nightlife Connect ("the Platform"), operated by UMENDRAN A/L MUNIANDY (SSM Registration: 202603216147 (003879689-T)), is committed to protecting your personal data in accordance with Malaysia's Personal Data Protection Act 2010 (PDPA). This Privacy Policy explains what data we collect, how we use it, and your rights. By using the Platform, you acknowledge that you have read and understood this Privacy Policy.
1. Information We Collect
We collect various categories of personal data to provide and improve Nightlife Connect. The specific data we collect depends on how you interact with our Platform:
Account Data — When you register an account, we collect your full name, email address (verified via email confirmation link), and password (stored as a bcrypt hash with 12 rounds of salting). If you choose to provide it, we also collect your date of birth (used for birthday promotions and can be verified via identity document), gender (used for ladies-night and similar promotions), phone number (optional for customers, required for venue owners — verified via SMS one-time password), avatar image (user-uploaded), and bio.
Identity Data — If you participate in identity-gated promotions or apply as a venue owner, we collect identity documents such as your Malaysian IC, passport, or driving licence. Venue owners must also provide their business name, SSM registration number, and business registration document. These documents are stored in secure private storage and are reviewed manually for verification purposes only. We do not extract or store national ID numbers as structured data.
Financial Data — We collect your wallet balance and transaction history, billing name and address (if provided for invoicing), and payment method tokens. Card numbers are never stored on our servers — all payment card data is tokenised and handled exclusively by our payment processor, Xendit. We retain only the Xendit token ID, card brand, last four digits, and expiry date for your reference.
Usage Data — We collect information about how you interact with the Platform, including pages visited, features used, booking and reservation history, QR code scan history, and AI chat queries (if you are signed in, your queries are stored to maintain conversation context).
Device & Technical Data — We collect your IP address, device type and model, operating system, browser type, and geolocation data (only if you grant permission, used for nearby venue discovery). This data is also used for security monitoring, rate limiting, and fraud prevention.
2. How We Collect Information
Directly from you — When you create an account, update your profile, make a booking, contact support, upload documents, or communicate with us through the Platform or email.
Automatically — Through cookies, server logs, and similar technologies when you use the Platform. This includes your IP address, device information, browsing activity, and geolocation data (if permitted). See Section 5 for details on our use of cookies.
From third parties — When you sign in using an OAuth provider (Google, Facebook, Apple, or Microsoft), we receive basic profile information from that provider (name, email, and profile picture) as authorised by you. We also receive payment confirmation data from Xendit when you complete a transaction, and SMS verification confirmations from Twilio when you verify your phone number.
3. How We Use Your Data
We use your personal data for the following specific purposes:
Authentication & account management — To create and secure your account, verify your identity via email or SMS, manage your profile, and support OAuth sign-in through third-party providers.
Bookings & reservations — To process venue bookings, generate QR codes for check-in, communicate booking confirmations and reminders, and manage cancellations.
Payments & wallet — To process transactions, maintain your wallet balance, issue refunds as wallet credits, and generate invoices where requested.
Communication — To send you transactional emails (booking confirmations, account verification, password resets), and, where you have opted in, promotional communications about events, offers, and features.
Promotions & personalisation — To deliver personalised promotions such as birthday offers (using your date of birth) and ladies-night deals (using your gender), and to power the AI chat assistant with context from your previous queries.
Fraud prevention & security — To detect and prevent fraudulent activity, enforce rate limits, monitor for abuse, and protect the security of our Platform and users.
Analytics & improvement — To understand how users interact with the Platform, identify trends, debug issues, and develop new features and improvements.
Legal compliance — To comply with applicable laws, regulations, and legal processes in Malaysia.
4. Legal Basis for Processing
Under Malaysia's Personal Data Protection Act 2010 (PDPA), we process your personal data on the following legal bases:
Consent — Where you have given us explicit consent to process your data for a specific purpose, such as receiving marketing communications, sharing your location for venue discovery, or providing identity documents for verification. You may withdraw your consent at any time (see Section 10).
Contract — Where processing is necessary for the performance of a contract to which you are a party — specifically, the Terms and Conditions governing your use of Nightlife Connect. This includes processing required to facilitate bookings, process payments, and manage your account.
Legitimate interest — Where processing is necessary for our legitimate interests (or those of a third party), provided your rights and interests do not override those interests. This includes fraud prevention, Platform security, analytics for service improvement, and enforcing our Terms and Conditions.
Legal obligation — Where we are required to process data to comply with Malaysian law, such as retaining transaction records for tax or regulatory purposes.
5. Cookies & Tracking
We use cookies and similar tracking technologies on our Platform. Cookies are categorised as follows:
Essential cookies — Required for core Platform functionality, including authentication sessions, security tokens, and CSRF protection. These cannot be disabled.
Functional cookies — Remember your preferences, such as cookie consent choices and display settings, to enhance your experience.
Analytics cookies — Help us understand how users navigate and interact with the Platform, which pages are most popular, and where errors occur. This data is aggregated and does not identify individual users.
Third-party cookies — Our integrated third-party services set their own cookies: Google reCAPTCHA (bot prevention), Google Maps (venue location display), and OAuth identity providers (Google, Facebook, Apple, Microsoft for sign-in). These third parties are responsible for their own cookie practices.
You can manage your cookie preferences through our cookie consent banner displayed on your first visit. Rejecting non-essential cookies will not affect core browsing functionality, but may disable OAuth sign-in and CAPTCHA verification features.
6. Third-Party Services
We integrate with the following third-party service providers to operate the Platform:
Xendit — Payment processing. Xendit handles all payment card data and processes transactions on our behalf. Card numbers are never transmitted to or stored on our servers. Xendit operates under its own privacy policy and is PCI DSS compliant.
Google Maps & reCAPTCHA — Google Maps is used to display venue locations. Google reCAPTCHA is used to prevent automated abuse of forms and authentication flows.
OAuth Providers — Google, Facebook, Apple, and Microsoft are used for single sign-on authentication. When you use OAuth sign-in, these providers share your name, email, and profile picture with us as authorised by you during the sign-in flow.
Twilio — SMS delivery for phone number verification via one-time password (OTP). Twilio processes your phone number solely to deliver the verification message.
Firebase (Google) — Used for push notification delivery to your device. Firebase receives your device token to deliver notifications you have opted into.
Each third-party service provider operates under its own privacy policy. We encourage you to review their policies for details on how they handle your data.
7. Data Sharing
We do not sell your personal data to anyone. Your information is shared only in the following limited circumstances:
Payment processor — Transaction data is shared with Xendit to process payments. Xendit does not share your full card details with us.
Venue owners — When you make a booking at a venue, the venue owner receives the information necessary to fulfil your reservation, including your name and booking details. Venue owners are independent data controllers for information they receive and may have their own privacy practices.
Service providers — We share data with our technical service providers (as listed in Section 6) solely to the extent necessary for them to provide their services to us.
Legal requirements — We may disclose your data if required to do so by law, court order, or request of a competent authority, including compliance with a lawful request from Malaysian law enforcement or regulatory bodies.
Platform protection — We may share data where necessary to enforce our Terms and Conditions, protect the rights and safety of Nightlife Connect, our users, or the public, or to detect and prevent fraud or security threats.
8. Data Retention
Active accounts — We retain your personal data for as long as your account is active and you continue to use the Platform.
Account deletion — When you request account deletion, we will remove or anonymise your personal data within 30 days of receiving your request. Some data may be retained longer where required by law or for legitimate business purposes, such as fraud prevention or financial record-keeping.
Transaction records — Booking and payment transaction records are retained for a minimum period as required by Malaysian tax and financial regulations, even after account deletion.
Identity documents — Uploaded identity and business registration documents are retained only for as long as necessary to complete verification. Once verified, documents are retained in secure storage only for as long as your account remains active and are deleted upon account deletion.
AI chat queries — Conversations with the AI chat assistant are retained while your account is active to maintain conversation context and are deleted upon account deletion.
Device & security data — IP addresses and device information used for security monitoring are retained for a limited period appropriate to the security purpose and are periodically purged.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction:
Encryption in transit — All data transmitted between your device and our servers is encrypted using TLS (HTTPS).
Password hashing — Your password is hashed using bcrypt with 12 rounds of salting before storage. We never store or have access to your plaintext password.
Access controls — Access to personal data is restricted to authorised personnel on a need-to-know basis. Administrative access to production systems is logged and audited.
Private document storage — Identity and business registration documents are stored in private storage directories (private/uploads/) that are not publicly accessible.
Payment security — All payment card data is handled exclusively by Xendit, a PCI DSS-compliant payment processor. We do not store, process, or transmit card numbers on our servers.
While we take reasonable precautions, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security, but we promptly investigate and respond to any security incidents.
10. Your Rights Under Malaysian PDPA
Under Malaysia's Personal Data Protection Act 2010 (PDPA), you have the following rights regarding your personal data:
Right of access — You have the right to request access to the personal data we hold about you. We will respond to your request within the timeframe prescribed by the PDPA.
Right to correction — You have the right to request the correction of any personal data that is inaccurate, incomplete, or misleading. You can update most information directly through your account settings.
Right to withdraw consent — You have the right to withdraw your consent to the processing of your personal data at any time, subject to legal or contractual restrictions. Withdrawal of consent may affect our ability to provide certain services to you (e.g., withdrawing consent for email communication means we cannot send you booking confirmations).
Right to data portability — Where technically feasible, you may request a copy of your personal data in a structured, commonly used, and machine-readable format.
Right to complain — If you believe your personal data has been misused or your rights under the PDPA have been infringed, you have the right to lodge a complaint with the Personal Data Protection Department (PDPD) of Malaysia.
To exercise any of these rights, please contact us at privacy@nightlifeconnect.com. We may need to verify your identity before processing your request.
11. Identity Documents
When you choose to upload identity documents (IC, passport, or driving licence) or business registration documents for verification purposes, we handle them with enhanced security measures:
Documents are stored in private, access-controlled storage and are not publicly visible or accessible to other users.
Documents are reviewed manually by authorised personnel solely for the purpose of verifying your identity or business registration.
We do not extract or store national identification numbers as structured or searchable data fields. Documents are retained in their original uploaded form only.
Uploaded documents are deleted upon account deletion or when they are no longer required for the purpose for which they were collected.
Venue owners must provide valid business registration documents to be approved on the Platform. Customers may optionally provide identity documents to unlock identity-gated promotions.
12. AI Chat Data
If you are signed in when using our AI chat feature, your chat queries and the AI's responses are stored and associated with your account. This data is used to:
Maintain conversation context, allowing the AI to reference previous interactions within the same session or across sessions.
Improve the quality and relevance of AI responses over time.
Chat data is treated as personal data under this Privacy Policy and is subject to the same retention, security, and deletion practices described in this document.
If you are not signed in, AI chat queries are processed but not associated with any personal identifier.
13. International Data Transfers
Your data is primarily stored and processed in Malaysia. However, some of our third-party service providers may process data outside of Malaysia:
Xendit processes payment data across its infrastructure in Southeast Asia.
Google (Firebase, reCAPTCHA, Maps) may process data on servers located in various countries.
Twilio may process SMS delivery data on servers outside Malaysia.
Where your data is transferred or processed outside Malaysia, we ensure that appropriate safeguards are in place to protect your data in accordance with the PDPA.
14. Data Breach Notification
In the unlikely event of a personal data breach that is likely to result in significant harm to you, we will:
Notify the Personal Data Protection Commissioner (PDPD) of Malaysia as required under the PDPA.
Notify affected individuals as soon as practicable, providing information about the nature of the breach and the steps we are taking in response.
Take immediate steps to contain and mitigate the breach, including securing affected systems and reviewing our security practices.
A personal data breach includes any unauthorised access, collection, use, disclosure, or loss of personal data that we hold.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
Material changes to this Privacy Policy will be communicated via email to the address associated with your account or through a prominent notice displayed on the Platform.
Your continued use of the Platform after any changes take effect constitutes your acceptance of the updated Privacy Policy. If you do not agree to the revised policy, you should stop using the Platform and may request account deletion.
We encourage you to review this page periodically for the latest information about our privacy practices.
16. Contact Us
For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact our Data Protection contact:
Email: privacy@nightlifeconnect.com
Postal address: Nightlife Connect, Attn: Privacy Officer, Kuala Lumpur, Malaysia
You may also lodge a complaint with the Personal Data Protection Department (PDPD) of Malaysia if you believe your data protection rights have been infringed.
Nightlife Connect is operated by UMENDRAN A/L MUNIANDY. SSM Registration: 202603216147 (003879689-T). Registered in Malaysia.
This Privacy Policy applies to Nightlife Connect and its associated subdomains. We reserve the right to update this policy at any time. Material changes will be notified via email or a prominent notice on our platform. privacy@nightlifeconnect.com