Your Privacy Matters
QIUBBX collects the categories described in this Policy to operate a Malaysia Food & Beverage marketplace (including grocery where offered), delivery, Seller tools and related services. We do not sell personal data, we do not use an advertising ID, and we do not operate a first-party product-analytics SDK.
Create and manage your account
Process orders and payments
Facilitate delivery
Connect Customers with Sellers
Support Rider operations
Administer QBP services
Provide Rewards
Keep the app reliable (including crash diagnostics)
Provide Adam / AI-assisted features
Prevent fraud and abuse
Maintain security
Comply with applicable legal obligations
We do not sell your personal data as a product.
Where we share data with Sellers, Riders, payment providers or technology providers, we do so for service operation, security, settlement or legal compliance — not as a data sale product. Details appear in the sections below.
This Privacy Policy is in force. Operational schedule 1.2 (effective notice 2026-08-01). PDPA, retention, age gate (18+) and named processors below follow the QIUBBX PDPA notice, ops framework and production infrastructure.
1. About QIUBBX
QIUBBX Technologies (M) Sdn. Bhd. operates QIUBBX, a digital Food & Beverage marketplace and technology ecosystem.
QIUBBX may connect Customers, Sellers, Riders, QBPs (QIUBBX Business Partners), business partners and service providers through websites, mobile applications, APIs and related systems (together, the “Platform”).
This Privacy Policy explains how QIUBBX handles Personal Data in connection with those services.
2. Scope
This Privacy Policy applies to Personal Data processed in connection with:
Website — qiubbx.com and related QIUBBX web surfaces
Applications — QIUBBX mobile applications
Marketplace — food discovery, ordering, Seller services and related marketplace functions
Delivery — delivery and Rider-related services
Business services — Seller tools, QBA / QBP programme, and operational reporting
Other platform services — Rewards, Pre-Order, RFQ, Adam and other features QIUBBX provides
3. Definitions
Personal DataInformation that identifies or relates to an individual, to the extent defined by applicable law.
CustomerA user who purchases or orders products or services through QIUBBX.
SellerA business that offers food, beverage or related products/services through QIUBBX.
RiderA delivery partner who performs delivery services through QIUBBX-supported workflows.
QBPQIUBBX Business Partner.
PlatformQIUBBX websites, applications, systems, APIs and related services.
Payment ProviderA party that processes payments for QIUBBX. Current payment provider: Razorpay (subject to commercial configuration).
4. Information We Collect — Account
Depending on the features you use, QIUBBX collects:
Full name
Email address
Phone number
Username
Account ID (QIUBBX user ID)
Sign in with Apple identifier and/or Google account identifiers when you use those sign-in methods
Password / credential-related information (hashed or handled via authentication systems — not stored in plain text where QIUBBX controls storage)
Profile information
Account preferences
5. Customer Data
When a Customer uses QIUBBX, related data may include:
Delivery address
Pickup / collection information
Order history
Food preferences where provided
Vouchers
Rewards activity
Reviews
Customer support interactions
Transaction records
6. Seller Data
For Sellers, data may include:
Owner information
Business name
Business registration information
Contact details
Business address
Operating information
Menu and product information
Pricing
Order information
Settlement information
Compliance documentation
Seller operational metrics (orders, fulfilment dashboards — not advertising analytics)
Customer reviews
QBP attribution where applicable
7. Rider Data
Identity
Name
Identity verification information
Phone
Vehicle
Vehicle information
Applicable documentation
Registration information where required
Payment & earnings
Bank / payment information where required for payouts
Earnings
Wallet (where applicable)
Payout records
Delivery operations
Delivery assignments
Pickup / drop-off information
Delivery status
Location information used for assignment, navigation and completion
Proof of delivery where applicable
Safety & support
Incident reports
Disputes
Appeals
Support interactions
8. QBP Data
For QIUBBX Business Partners, data may include:
Name and identity information
TIN (where required)
Phone and email
Malaysian bank information (where required for withdrawals)
QBP UID
Referral / attribution information (including recruitedByAgentId-style fields where used)
Seller portfolio
Training records and certification
KPI and ratings
Wallet, accrual, withdrawal and payout records
Compliance and ethics records
QBP data is used to operate the QBP programme and related wallet / ledger administration.
9. Payment Data
Payment-related information may include:
Transaction ID
Amount and currency
Payment status
Refund status
Payment method indicators
Settlement information
Chargeback information
Razorpay
QIUBBX uses Razorpay Curlec as payment infrastructure for in-app food and grocery checkout (and Razorpay or Stripe on the website for QBA licence payments). Card PAN and CVV are processed by the payment provider under PCI DSS. QIUBBX does not collect or store full card PAN or CVV. QIUBBX retains payment status, gateway references (for example order id / payment id) and settlement metadata as financial records.
Payment Terms → Payments overview →
10. Location Data
Customer
Nearby food and grocery discovery
Delivery address handling
Delivery tracking
Service-area availability
Rider
Assignment
Navigation support
Pickup and delivery completion
Operational tracking while on active delivery workflows
Principle
The mobile apps request When-In-Use location (precise GPS, and coarse/network location when precise is unavailable). QIUBBX does not use background always-on location. Location is used for nearby discovery, quotes, delivery and rider operations — not advertising. OS permission prompts apply.
11. Device & Technical Data
IP address
Device type, OS and app version
Push tokens (FCM on Android, APNs/FCM on iOS) after you sign in, to deliver notifications
Crash logs and diagnostic information via Firebase Crashlytics on release builds — not linked to your QIUBBX user ID
Language and timezone
Log data needed for security and fraud prevention
QIUBBX does not collect an advertising ID and does not ship Firebase Analytics or GoogleAppMeasurement in the mobile apps. Crashlytics is diagnostics only.
12. Usage Data
Searches you submit (including food search and Ask Adam)
Order-flow steps needed to complete checkout and support
Operational server logs for security, fraud prevention and reliability
QIUBBX does not operate a first-party product-analytics or advertising SDK. We do not use usage events to track you across other companies’ apps or websites.
13. Content You Provide
Profile photo
Food, grocery, menu and shop images or videos
Voice and live audio you enable (Ask Adam / search speech, chat, Arena Live, rider walkie-talkie)
Reviews and comments
Messages and support attachments
Business information, listings and programme documents (including QBA onboarding images where you upload them)
Photos and videos you select with the system picker are uploaded to QIUBBX servers so the feature can work (profile, menu, listings, chat, documents). They are not kept only on your device.
14. Customer Support Data
When you contact support, QIUBBX may store:
Conversation and email content
Phone interaction notes where applicable
Complaints
Screenshots and attachments
Transaction references
Resolution information
Purposes include resolving issues, investigating disputes, improving service, preventing abuse and maintaining records.
15. How We Collect Data
Directly from you
Registration, checkout, forms, chat, profile updates and content uploads.
Automatically
Website cookies and server logs for authentication, security and preferences. Mobile apps do not use first-party product analytics. Crash and diagnostic SDKs are described in Device & Technical Data.
From other Platform participants
Order and delivery-related information from Sellers, Riders or other participants as needed to complete a transaction.
From service providers
Payment, verification, infrastructure, messaging, mapping and related providers.
From legal / regulatory sources
Where required or permitted by applicable law.
16. Why We Use Personal Data
Providing the Platform — services you request
Orders — process and manage orders
Delivery — connect orders with delivery operations
Payments — process payment, refund and settlement
Accounts — authentication, verification and account management
Security — fraud, abuse and unauthorised access prevention
Support — answer questions and resolve disputes
Business operations — operational reporting and Platform management (not advertising analytics)
AI features — Adam and other AI-assisted functionality
Rewards — points, rewards and redemption
Compliance — applicable legal and regulatory obligations
17. Adam AI & Automated Processing
Adam is AI-assisted technology within the QIUBBX ecosystem. Adam may help with business insights, recommendations, menu or business analysis, Pre-Order guidance, RFQ assistance, Seller support and operational suggestions.
Adam’s output may be generated using automated systems and may not always be accurate, complete or current. Users must make their own decisions. Adam is not a source of legal, financial, food-safety or regulatory determination.
Where Adam processes Personal Data, it does so only as part of QIUBBX features and operational controls — not as an unrestricted public model training free-for-all. Specific processing purposes follow from the feature you use.
18. Human Decision-Making
AI recommendations do not automatically replace human decision-making unless a specific QIUBBX feature expressly states otherwise.
For example, Adam may suggest actions to a Seller, but the Seller remains responsible for final commercial and food-preparation decisions, subject to applicable terms.
19. How We Share Data
QIUBBX may share Personal Data when needed to provide the service:
Sellers — Customer order information required to fulfil an order
Riders — information required for pickup and delivery
Customers — certain Seller / order information required for the transaction
Payment providers — data required for payment processing
Technology providers — hosting, infrastructure, maps, push, crash diagnostics, communications and security (as service providers for QIUBBX, not as a sale of data for their independent advertising)
Verification providers — identity / business verification where used
Authorities — where required by law or lawful request
20. Seller Data Visibility
Sellers may see Customer information needed to:
Fulfil the order
Contact the Customer regarding the order
Resolve order issues
Sellers must not use Customer data for unauthorised purposes (for example, unsolicited marketing outside Platform rules).
21. Rider Data Visibility
Riders should only receive information necessary to perform delivery, such as:
Pickup details
Destination details
Contact information where required
Order reference
22. QBP Data Visibility
QBPs may see Seller portfolio information needed to perform QBP duties, such as Seller status, performance, compliance status, business information and onboarding progress.
QBPs are not given unrestricted access to all Customer Personal Data on the Platform.
23. Third-Party Service Providers
QIUBBX uses service providers to operate the Platform. Providers should only receive data relevant to the service they deliver, subject to applicable agreements and law. The inventory below reflects production architecture as of the last update of this Policy.
Provider: Role — Processing region — Typical data
QIUBBX production platform (self-hosted): Primary application / API controller systems — Singapore (api.qiubbx.com · VPS 84.247.146.47) — Account, order, profile, ops data stored in QIUBBX databases on the SG stack
MongoDB · Redis · Meilisearch (QIUBBX Docker stack): Primary datastore, cache, search (co-located with API) — Singapore (same VPS / compose as production API) — Application databases and indexes for marketplace features
LiveKit (self-hosted SFU): Arena Live real-time media — Singapore (wss://api.qiubbx.com media stack) — Live session / stream signaling and media while live features are used
Razorpay Curlec: Payment gateway & settlement (payments, Route/payouts as configured) — Malaysia payment rails via Curlec; gateway processing systems operated by Razorpay group (may include India and other provider regions) — Transaction amounts, status, payment method tokens/refs; sensitive card data processed by provider (PCI DSS) — not full PAN/CVV stored by QIUBBX
Google Maps Platform: Geocoding, places, maps, distance for delivery / discovery — Google multi-region cloud (request processed outside Malaysia as Google routes traffic) — Addresses, coordinates and place queries for maps, nearby discovery and delivery. The Maps SDK may process limited technical data for the maps service under Google’s terms — that is not QIUBBX first-party advertising or product analytics.
Google Sign-In · Google Play / Firebase (where enabled): Auth (Google), push (FCM), Crashlytics diagnostics — not Firebase Analytics / not advertising ID — Google multi-region — OAuth identifiers; FCM device tokens after you sign in; crash logs not linked to your QIUBBX user ID
Apple (Sign in with Apple · App Store · APNs): iOS auth, distribution, push — Apple multi-region — Apple identity tokens, device push tokens, store-related metadata
OpenAI (where configured): AI-assisted features (e.g. Adam / voice transcription paths that use OpenAI) — United States / OpenAI multi-region — Prompts and content you submit to AI features; limited operational context needed for the feature — not unrestricted export of all account data
Anthropic (where configured): Select AI/verification assistance paths — United States / Anthropic multi-region — Content submitted to those configured AI workflows only
Twilio (where SMS/voice configured): SMS / communications — Twilio multi-region — Phone numbers and message metadata for OTP / notifications when enabled
Website / static hosting providers: Public marketing & Legal Centre hosting (qiubbx.com) — As deployed (e.g. Contabo / CDN path configured for the site) — Server logs, cookies, contact form enquiries on the public site
Additional subprocessors may be added when product integrations change; material additions will be reflected in a versioned update of this section.
24. Razorpay Curlec
QIUBBX uses Razorpay Curlec for payment processing in Malaysia (FPX, cards, e-wallets and other methods as enabled). Transaction-related data may be processed by Razorpay according to the payment architecture and applicable Razorpay / Curlec terms and privacy practices.
Card data
QIUBBX does not store full card PAN or CVV. Sensitive card credentials are processed by the payment provider under PCI DSS. Payment status, references and settlement metadata may be retained by QIUBBX as financial records.
25. Cross-Border Processing
QIUBBX’s primary marketplace service area is Malaysia, but production systems and some processors operate outside Malaysia.
Primary application data & LiveKit media stack: Singapore (api.qiubbx.com)
Payment (Razorpay Curlec): Malaysia rails with Razorpay group processing (may include India and other provider regions)
Maps, Google Sign-In, Firebase/FCM, Apple services: multi-region provider clouds
AI providers (OpenAI / Anthropic where configured): typically United States / provider multi-region
Twilio (if SMS/voice enabled): multi-region
Under Malaysia’s PDPA (as amended), cross-border transfers rely on appropriate safeguards — including contractual protections, processor diligence and, where required, transfer impact assessment for adequacy / similar protection — so that recipients provide a level of protection consistent with QIUBBX’s obligations.
By using QIUBBX services that require these providers (for example payment, maps, AI features, or cloud-hosted accounts), you acknowledge that Personal Data may be processed in those regions as described above.
26. Data Security
QIUBBX uses reasonable and appropriate security measures to protect data, which may include:
Access control
Authentication
Encryption where appropriate
Logging and monitoring
Security review practices
Incident response processes
No internet service can guarantee absolute security.
27. Account Security
You are responsible for:
Keeping passwords confidential
Protecting OTPs
Securing your devices
Not sharing credentials
Reporting unauthorised access promptly
If you suspect account compromise, contact QIUBBX Support immediately at support@qiubbx.com.
28. Data Retention
QIUBBX keeps Personal Data only as long as needed for the purposes collected, including service delivery, accounting, legal obligations, dispute resolution, fraud prevention, security and compliance. Financial and tax-related transaction records are retained for up to 7 years where applicable (aligned with QIUBBX PDPA Notice and financial archive policy).
Operational schedule 1.2
Last updated 2026-08-19. Periods may be extended under a documented legal hold (dispute, investigation or regulator request).
Data: Purpose — Retention
Account profile: Account management & authentication — Duration of active account; then delete / de-identify within 30 days of completed deletion, except lawful holds below
Orders & delivery records: Transaction history, disputes, refunds — Up to 7 years from order completion (tax / accounting / disputes)
Payments & settlement: Financial records, chargebacks, audit — Up to 7 years from transaction date
Seller compliance docs: Verification, food-safety audit, platform governance — While Seller active + up to 7 years after last regulated activity or contractual need
Rider identity & payout: Delivery ops, earnings, verification — While Rider active + up to 7 years for payment/tax records
QBP wallet / ledger: Accrual, withdrawal, audit — Up to 7 years from last ledger event
Live location (session): Nearby discovery, active delivery tracking — While feature is in use / active delivery; not retained as long-term history after session ends (except incident holds)
Support tickets: Dispute resolution & service quality — Up to 3 years after ticket closed (longer if linked to open legal hold)
Security / access logs: Security, fraud prevention — Typically 12–24 months; extend if investigation or legal hold
Data breach register: PDPA breach notification compliance — Minimum 2 years from notification (PDPA ops framework)
Marketing preferences: Consent & opt-out evidence — While account active + up to 2 years after opt-out/withdrawal for proof of consent state
Privacy acceptance record: Versioned consent / acknowledgment audit — Up to 7 years (aligns with contractual / regulatory evidence)
After the relevant period, data is deleted, anonymised or securely archived in a restricted form. Aggregated analytics that no longer identify you may be kept longer.
29. Marketing & Communication
QIUBBX may send transactional notifications, order updates, payment notifications, security alerts and service announcements.
Marketing communications will be managed according to applicable consent and opt-out requirements. You may opt out of marketing without losing essential transactional communications.
Preference model (product)
In-app preference groups are designed to separate (1) Transactional Notifications from (2) Marketing & Promotions. Exact UI labels may evolve; transactional and security messages may still be required for service safety.
30. Cookies
The public website uses cookies and similar technologies for authentication, security and preferences. Marketing cookies, if used on the website, are described in the Cookies Policy. The QIUBBX mobile apps do not use an advertising ID and do not run first-party product analytics.
31. Children & Age Gate
QIUBBX is a commercial Food & Beverage marketplace for Malaysia. The minimum age to create and use a QIUBBX account is 18 years.
Customer (account holder / purchaser): 18+
Seller: 18+
Rider / QXRider: 18+
QBP (QIUBBX Business Partner): 18+
QIUBBX does not knowingly create accounts for, or market services to, children under 18. A parent or guardian who places an order for a household does so on their own adult account. If we learn we hold an account for someone under 18, we may suspend it and delete or restrict personal data as appropriate.
QIUBBX may request identity or age-related information where required for payment, Seller, Rider or QBP onboarding, fraud prevention or law.
Legal basis for 18+
In Malaysia, the age of majority for contractual capacity is generally 18. QIUBBX is a paid commercial marketplace (orders, payments, Seller/Rider/QBP roles); accounts and age-gated services require users to be 18 or older.
32. User Rights
Subject to applicable law (including Malaysian requirements that apply to QIUBBX), you may have rights to:
Request access
Request correction
Request deletion where applicable
Withdraw applicable consent
Raise privacy concerns
Make data-related enquiries
QIUBBX will process requests according to applicable legal requirements and identity verification needs.
33. Data Access Request
1. Request
2. Identity verification
3. Scope review
4. Data retrieval
5. Response
QIUBBX will not disclose Personal Data to a requester without appropriate identity verification.
34. Data Correction
Where the product allows, update information under Profile → Account Settings.
For data you cannot update yourself, contact the Privacy Team at privacy@qiubbx.com.
35. Data Deletion
You may request account deletion.
1. Account
2. Settings
3. Delete account
4. Verify identity
5. Confirm
6. Deletion processing
Account Deletion Policy → Account deletion page →
36. What May Not Be Deleted Immediately
Some data may need to be retained for legal obligations, accounting, payment records, fraud prevention, disputes, security or regulatory requirements.
Where appropriate and feasible, such data may be retained securely, restricted, anonymised or de-identified rather than deleted immediately.
37. Download My Data
QIUBBX intends to support data export requests as product capability matures:
1. Request
2. Identity verification
3. Prepare export
4. Secure download
5. Expiry
Exports may include categories such as profile, orders, transactions, rewards, support and applicable activity, in formats such as JSON, CSV or PDF depending on data type and product implementation.
Until the in-app export is available, submit requests to privacy@qiubbx.com with enough detail for identity verification and scope.
38. Privacy Request Center (Product Direction)
QIUBBX’s product direction for in-app privacy management includes:
My Data
Download My Data
Correct My Information
Marketing Preferences
Delete My Account
Privacy Requests
Privacy Policy link
This Policy supports that system. Feature availability may roll out in stages across app versions.
39. Data Breach / Incident Response
1. Detect
2. Contain
3. Assess
4. Investigate
5. Remediate
6. Notify where legally required
Notifications to affected parties or authorities will be made when required by applicable law.
40. Fraud & Security Monitoring
QIUBBX may process data to detect fake orders, payment abuse, account takeover, identity abuse, suspicious transactions and platform manipulation. Automated signals may be used for risk detection.
41. Legal & Regulatory Disclosure
Comply with law
Respond to lawful requests
Protect rights
Prevent fraud
Protect safety
Investigate violations of Platform terms
42. Business Transfers
If QIUBBX undergoes a merger, acquisition, restructuring or asset transfer, Personal Data may be transferred as part of that business transaction, subject to applicable law.
43. Links to Third-Party Websites
The Platform may link to external services. QIUBBX is not responsible for privacy practices of third parties that QIUBBX does not control. Read those parties’ privacy policies.
44. Changes to This Privacy Policy
QIUBBX may update this Privacy Policy. Each version should carry Version, Effective Date and Last Updated metadata.
For material changes, QIUBBX may provide notice via app, website, email or in-product notification.
45. Version History
Past versions are not overwritten. Published effective dates follow the PDPA Notice schedule where applicable.
Version: Effective Date — Summary
1.0: 2026-08-01 — Initial comprehensive Privacy Policy structure (multi-role marketplace)
1.1: 2026-08-19 — Filled retention schedule, age gate (18+), named processors & cross-border map from ops infrastructure
46. Consent & Acceptance
At registration or other appropriate moments, QIUBBX may require acknowledgement such as: “I have read and acknowledge the QIUBBX Privacy Policy.”
Acceptance records are designed to store user ID, document ID, version, accepted-at timestamp, IP address, user agent and source — so QIUBBX can show which Privacy Policy version a user accepted at a given time. Exact schema may follow the Legal Center acceptance model.
47. Contact Privacy Team
Privacy Questions?
QIUBBX Technologies (M) Sdn. Bhd.
Data Protection Officer (DPO): dpo@qiubbx.com
Privacy enquiries: privacy@qiubbx.com
General support: support@qiubbx.com
Website: https://qiubbx.com
Privacy enquiries should receive a ticket or reference number so requests can be audited. Do not send unnecessary sensitive credentials by email. Office phone and postal address will be published when confirmed — Adam and staff must not invent unpublished contact details.
Your data. Your choices. Our responsibility.
In-app “Manage Privacy Settings” will surface as the Privacy Center lands in the native apps. Until then, use the contacts and policies above.