Legal

Privacy Policy

This policy explains what personal data O2O eCommerce Sdn Bhd collects when you use the O2O Commerce platform, why we collect it, who we share it with, and the control you have over it.

Last updated

1Who we are

O2O Commerce is a multi-tenant ecommerce platform operated by O2O eCommerce Sdn Bhd (Company No. 202101009872 / 1410171-U), a company incorporated in Malaysia with its registered office at Unit B-01-3A, 3 Two Square, No. 2, Jalan 19/1, Section 19, 46300 Petaling Jaya, Selangor, Malaysia.

In this policy, “we”, “us” and “O2O” mean O2O eCommerce Sdn Bhd. “You” means a merchant, a member of a merchant’s staff, or anyone else who signs in to the platform. We are the data controller for the account data described below. We process this data in accordance with the Malaysian Personal Data Protection Act 2010 (PDPA).

2Data we collect

We collect only what the platform needs in order to work:

  • Account details — your name, email address, phone number, password (stored only as a salted hash), store name, and the role assigned to you within a store.
  • Business details — your store’s trading name, address, business registration and tax identifiers, currency, and payout or bank details where you enable payments.
  • Usage data — pages visited inside the admin portal, actions taken, feature usage, and audit entries recording who changed what and when.
  • Technical data — IP address, browser type and version, device type, operating system, language, and timestamps.
  • Support correspondence — messages, attachments, and contact details you send us when you ask for help.
  • Billing data — subscription plan, invoices, and payment status. Card numbers are handled by our payment providers and never stored on our servers.

We do not ask for and do not want sensitive personal data such as health information, political opinions, or religious beliefs. Please do not send it to us.

3Google sign-in

You may choose to sign in to O2O Commerce with your Google account instead of a password. When you do, Google asks for your permission before sharing anything, and we receive only the following from your Google profile:

  • Your email address and whether Google has verified it (openid, userinfo.email).
  • Your basic profile information — name and profile picture (userinfo.profile).

What we do not do with your Google data

We use your Google email address for one purpose only: to match you to an existing O2O Commerce account and sign you in. We do not use it for advertising, we do not sell it, we do not transfer it to third parties except as described in this policy, and we do not use it to train any artificial intelligence or machine-learning model.

We request no other Google scopes for sign-in. We cannot read your Gmail, your Drive files, your Contacts, or your Calendar, and we never ask for that access.

We do not store a Google refresh token for sign-in. The authorisation code Google returns is exchanged once, server-to-server, for your verified email address and then discarded. You can revoke our access at any time from your Google Account permissions page; doing so stops Google sign-in but does not delete your O2O Commerce account.

O2O Commerce’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Separately, if you install our Google Shopping integration, you authorise O2O Commerce against a Google Merchant Center account that you own. That connection is made by you, per store, and can be revoked by you at any time without affecting the rest of your account. It is used solely to publish your own product catalogue to your own Merchant Center account.

4How we use data

We use personal data to:

  • Create and authenticate your account, and keep your session secure.
  • Provide the platform — your storefront, orders, products, customers, and reports.
  • Send service messages such as password resets, verification emails, invoices, security alerts, and changes to these policies.
  • Provide customer support and investigate issues you report.
  • Detect, prevent, and investigate fraud, abuse, and security incidents.
  • Measure and improve platform performance, reliability, and features, using aggregated or anonymised data wherever it will do.
  • Meet our legal, tax, and regulatory obligations.

We send marketing email about O2O products only where you have opted in or where we are otherwise permitted to. Every marketing email carries an unsubscribe link, and unsubscribing never affects service messages you need in order to run your store.

5Your shoppers' data

When you run a store on O2O Commerce, your customers give you their personal data — names, delivery addresses, contact details, and order history. For that data, you are the data controller and we are your data processor. We hold and process it on your instructions so that your store can function.

  • We do not use your customers' data for our own purposes, and we do not sell it.
  • We do not contact your customers on our own behalf.
  • Each store's data is isolated from every other store on the platform at the database level.
  • You remain responsible for having a lawful basis to collect your customers' data and for publishing your own store's privacy notice.

6Cookies and logs

We use cookies and similar technologies. The ones we set fall into two groups:

  • Strictly necessary — your signed-in session, the OAuth state token that protects the Google sign-in flow against cross-site request forgery, and security preferences. The platform cannot work without these.
  • Functional and analytics — remembering interface preferences, and measuring which features are used so we can improve them.

Session cookies are deleted when you sign out or close your browser. Persistent cookies remain until they expire or you clear them. You can block cookies in your browser settings, but blocking the strictly necessary ones will prevent you from signing in.

Our servers also keep standard log files recording IP address, browser type, referring pages, and timestamps. We use these for security monitoring, abuse investigation, and diagnosing faults.

7Sharing and disclosure

We do not sell personal data. We share it only in these situations:

  • Service providers — hosting, email delivery, payment gateways, SMS and messaging providers, error monitoring, and analytics. They act on our instructions, under contract, and may use the data only to provide their service to us.
  • Integrations you enable — where you connect a shipping carrier, payment gateway, marketplace, or channel such as Google Merchant Center, the data required for that integration is sent to it at your direction.
  • Legal requirements — where we are required to disclose by law, court order, or a lawful request from a public authority, or where disclosure is necessary to protect our rights, safety, or property.
  • Business transfers — if O2O eCommerce Sdn Bhd is involved in a merger, acquisition, or sale of assets, data may transfer to the acquiring party. We will notify you before your data becomes subject to a different privacy policy.

We may publish aggregated, anonymised statistics about platform usage that cannot identify you or any individual.

8Storage and security

Platform data is hosted on servers operated by our infrastructure providers. Data may be stored or processed in Malaysia and in other countries where our providers operate; where data leaves Malaysia we take steps to ensure it receives a comparable standard of protection.

  • All traffic to the platform is encrypted in transit using TLS.
  • Passwords are stored only as salted hashes and are never recoverable in plain text.
  • Access to production systems is restricted to authorised personnel and logged.
  • Every store's records are isolated by row-level security so one merchant cannot read another merchant's data.
  • Administrative actions inside a store are written to an audit trail.

No system is perfectly secure. You are responsible for keeping your password confidential, enabling the security options we offer, signing out of shared devices, and telling us promptly at support@o2o.my if you suspect unauthorised access to your account.

9Retention and deletion

We keep personal data for as long as your account is active, and afterwards only as long as we need it for the purposes described in this policy or to meet a legal obligation.

  • Account and store data is retained for 30 days after your subscription ends, so that you can reactivate or export it. After that window it is scheduled for deletion.
  • Invoices and financial records are retained for the period required by Malaysian tax and accounting law.
  • Security and audit logs are retained on a rolling basis for abuse and incident investigation.
  • Backups are cycled on a fixed schedule; deleted data persists in backups until those backups expire.

To request deletion of your account and personal data, email admin@o2o.my from the address on the account. We will confirm the request before acting on it, because deletion cannot be undone.

10Your rights

Under the PDPA and comparable laws, you may ask us to:

  • Access the personal data we hold about you, and receive a copy of it.
  • Correct data that is inaccurate, incomplete, or out of date.
  • Delete data where we no longer have a reason to keep it.
  • Limit or object to certain processing, including direct marketing.
  • Withdraw a consent you previously gave, without affecting processing already carried out.

Send requests to admin@o2o.my. We will respond within the time the law allows, and we may ask you to verify your identity first. If a request concerns data we hold on behalf of a merchant — for example your order history with a store on our platform — we will refer you to that merchant, who controls it.

11Third-party services

The platform links to and integrates with services we do not operate, including payment gateways, shipping carriers, marketplaces, and Google. Their handling of your data is governed by their own privacy policies, not this one. We encourage you to read them before connecting a service.

12Children

O2O Commerce is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.

13Changes to this policy

We may update this policy as the platform changes or the law requires. The date at the top of this page always reflects the current version. Where a change materially affects your rights, we will notify account holders by email or through the admin portal before it takes effect. Continuing to use the platform after that date means you accept the updated policy.

14Contact us

For any question about this policy, or to exercise a right described in it:

O2O eCommerce Sdn Bhd

Privacy enquiries: admin@o2o.my
Support: support@o2o.my
Phone: +603 7620 7020 (10:00–19:00 MYT, Monday to Friday)
Unit B-01-3A, 3 Two Square, No. 2, Jalan 19/1, Section 19, 46300 Petaling Jaya, Selangor, Malaysia

O2O eCommerce Sdn Bhd (202101009872 / 1410171-U)
Unit B-01-3A, 3 Two Square, No. 2, Jalan 19/1, Section 19, 46300 Petaling Jaya, Selangor, Malaysia