01 Privacy & DataFramework6 min readLast updated 2026-08-09

Privacy & Data Protection

Your data, your rights, our responsibility — processed only for disclosed purposes.

QIUBBX processes personal data in connection with commercial platform operations. Malaysia’s PDPA framework (and related JPDP guidance on DPO, breach notification, DPIA, by-design, automated decisions and cross-border transfer) informs how we design this public and technical layer.

Why we process data

  • Account management
  • Order processing
  • Delivery
  • Payment
  • Customer support
  • Merchant and rider operations
  • Fraud prevention and security
  • Analytics and platform integrity
  • AI / business intelligence (where permitted)
  • Legal and regulatory obligations

Inventory first

A living data inventory (identity, contact, location, payment references, vehicle, business, order, device, behaviour, AI metrics) must be audited against real databases and SDKs before finalising public tables. Do not treat marketing lists as legal inventory.

Classification (engineering)

  • PUBLIC
  • INTERNAL
  • CONFIDENTIAL
  • PERSONAL
  • SENSITIVE
  • FINANCIAL
  • SECURITY-CRITICAL

Example: restaurant display name may be PUBLIC; customer phone is PERSONAL; bank account is FINANCIAL; identity documents and payment credentials are restricted/security-critical.

DPO

DPO details are only published after a real appointment when triggers under applicable guidance are met. We do not place placeholder personal names as DPO on this site.
Formal policySee Privacy Policy (versioned) and Data Rights for subject requests.
Important: The information in this Compliance Centre explains QIUBBX policies, controls and operational approach. It does not constitute legal advice. Requirements may change and may vary by jurisdiction, service, transaction type and circumstances. Formal legal documents and applicable laws govern if there is any inconsistency.
Back to Compliance