Legal
What QIUBBX promises — modular Legal Centre documents with version control.
Open →TRUST & COMPLIANCE
Terms explain promises. Privacy explains data handling. Compliance ensures systems match the documents. Audit ensures we can prove it.
QIUBBX is committed to applicable privacy, security, payment and platform requirements.
We do not claim “100% compliant.” Control scores are honest. Gaps stay visible as PARTIAL or NEEDS_REVIEW until verified.
93% · Public readiness score
Weighted score of published control objects (PASS / PARTIAL / NEEDS_REVIEW). Not a legal certification.
Every requirement should map: policy → system → API/UI → procedure → evidence.
What QIUBBX promises — modular Legal Centre documents with version control.
Open →What QIUBBX does with data — PDPA notice, retention, age gate, processors, rights.
Open →Access control, encryption in transit, logging, incident response readiness.
Open →Razorpay Curlec, settlement honesty, no unnecessary card storage.
Open →Seller, Rider, QBP, marketplace and food-safety participant rules.
Open →Account deletion, support, monitoring and monthly review cadence.
Open →Control objects, acceptance records, vendor register and evidence vault design.
Open →Priority domain map for marketplace, payment, store review and PDPA ops.
Terms, service-specific terms, policies and versioned publication.
DPO, breach, DPIA, privacy-by-design, cross-border, automated decision/profiling awareness.
Privacy disclosures, in-app privacy access, account deletion, purpose strings.
Data Safety form must match SDK inventory + privacy disclosures + web deletion resource.
Curlec gateway, settlement disclosure, PCI posture (no full PAN/CVV at QIUBBX).
Auth, age gate 18+, verification for Seller/Rider/QBP, deletion workflow.
Inventory, classification, retention owners, consent types, export/correction.
AuthN/Z, least privilege, secrets, logging, monitoring baseline.
Onboarding, documents, food-related requirements, continuous review.
Identity, vehicle/docs, delivery conduct, earnings ledger integrity.
Flat model ethics, certification, KPI, attribution — not MLM.
Food-safety expectations, venue types, prohibited activity.
Cancellation stages, quality issues, chargebacks, consumer fairness.
Detect → contain → assess → notify when required (incl. PDPA DBN).
Control matrix, legal acceptance audit trail, evidence vault design.
Selected P0 control objects. Full internal vault expands in Ops / Admin.
| Control | System | Policy | Evidence | Owner | Status |
|---|---|---|---|---|---|
| LEG-001Legal Centre published Modular legal pages at /legal with TOC UI and version metadata. | Yes | Yes | Yes | Legal / Web | PASS |
| PRIV-001Privacy Policy comprehensive Multi-role privacy with retention table, age gate, named processors. Legal Centre documents are PUBLISHED and in force for Malaysia (versioned). | Yes | Yes | Yes | Privacy | PASS |
| PRIV-002Versioned privacy acceptance Store documentId + version + timestamp + source — not a single accepted boolean. Schema defined in Legal Center acceptance model; product wiring staged. | No | Yes | No | Engineering / Privacy | PARTIAL |
| PRIV-003Master data inventory Role × data × classification inventory published and compared to DB/SDK. Initial architecture inventory live on /trust — must be reconciled to production schema. | Yes | Yes | No | Privacy / Engineering | PARTIAL |
| PRIV-004Vendor & processor register Named production processors with region and purpose (privacy-ops). | Yes | Yes | Yes | Privacy | PASS |
| ACC-001Account deletion (Apple + Play) In-app delete + web resource wired to production request-web API; workflow with retention exceptions. Web: POST /api/auth/deletion/request-web. In-app: AccountDeletionView / AccountDeletionScreen. | Yes | Yes | Yes | Product / Engineering | PASS |
| STORE-001Apple privacy disclosure source matrix Nutrition Labels filled from published SDK + Data Safety matrix on Trust Centre. Console must remain consistent with /trust#data-safety on each release. | Yes | Yes | Yes | Mobile | PASS |
| STORE-002Google Data Safety source matrix Play Data Safety completed from Trust matrix + SDK inventory only. | Yes | Yes | Yes | Mobile | PASS |
| PAY-001Razorpay production model published Public Payments + Payment Terms describe split settlement and fee roles. | Yes | Yes | Yes | Finance / Product | PASS |
| SEC-001Security baseline TLS, hashing, session/auth controls, logging; documented public security layer. | Yes | Yes | Yes | Security / Engineering | PASS |
| SDK-001SDK inventory Named production-wired SDKs with platforms, purpose and data. | Yes | Yes | Yes | Mobile / Privacy | PASS |
| PC-001Privacy Center (public) Public Privacy Center with access, export, consent, deletion entry points. | Yes | Yes | Yes | Privacy / Web | PASS |
| SELL-001Seller Terms & verification frames Seller Terms live; document register/ops monitor for expiry. | Yes | Yes | No | Compliance | PARTIAL |
| RID-001Rider Terms & earnings honesty Rider Terms + QXRider programme honesty (no inventing instant payout). | Yes | Yes | Yes | Compliance / Product | PASS |
| QBP-001QBP ethics & flat model No MLM; 2.5% seller-side; ethics & certification framework published. | Yes | Yes | Yes | QBP Ops | PASS |
| REF-001Refund & cancellation policy Public refund-cancellation legal module. | Yes | Yes | Yes | Legal / Support | PASS |
| INC-001Breach / incident procedure documented Privacy Policy breach flow + PDPA ops DBN guidelines. | Yes | Yes | Yes | Security / Privacy | PASS |
| AUD-001Public control matrix Control objects with status published on Trust Centre. | Yes | Yes | Yes | Compliance | PASS |
| AI-001Adam AI disclosure & human oversight Adam limitations disclosed; high-risk decisions require human review. | Yes | Yes | Yes | Product / Privacy | PASS |
Role × data map for Customer / Seller / Rider / QBP, aligned with Privacy Policy and SDK inventory.
Architecture inventory — not a claim that every field is collected for every user at all times.
| Data | C | S | R | Q | Purpose | Class |
|---|---|---|---|---|---|---|
| Name | ✓ | ✓ | ✓ | ✓ | Identity | PERSONAL |
| ✓ | ✓ | ✓ | ✓ | Communication | PERSONAL | |
| Phone | ✓ | ✓ | ✓ | ✓ | Communication | PERSONAL |
| Address | ✓ | ✓ | ✓ | ✓ | Operations | PERSONAL |
| Location | ✓ | — | ✓ | — | Delivery / discovery | HIGH_SENSITIVITY |
| Orders | ✓ | ✓ | ✓ | — | Transaction | CONFIDENTIAL |
| Payment status | ✓ | ✓ | ✓ | ✓ | Settlement | CONFIDENTIAL |
| Bank details | — | ✓ | ✓ | ✓ | Payout | HIGH_SENSITIVITY |
| Identity docs | — | ✓ | ✓ | ✓ | Verification | HIGH_SENSITIVITY |
| Business docs | — | ✓ | — | — | Compliance | CONFIDENTIAL |
| TIN | — | — | — | ✓ | Tax | HIGH_SENSITIVITY |
| Wallet / earnings | — | — | ✓ | ✓ | Earnings | CONFIDENTIAL |
| Device data | ✓ | ✓ | ✓ | ✓ | Security / ops | PERSONAL |
| Reviews / content | ✓ | ✓ | ✓ | ✓ | Marketplace | PERSONAL |
| AI interactions | ✓ | ✓ | ✓ | ✓ | Adam / AI service | PERSONAL |
| Public menu / business name | — | ✓ | — | — | Catalogue | PUBLIC |
| Provider | Role | Region |
|---|---|---|
| QIUBBX production platform (self-hosted) | Primary application / API controller systems | Singapore (api.qiubbx.com · VPS 84.247.146.47) |
| MongoDB · Redis · Meilisearch (QIUBBX Docker stack) | Primary datastore, cache, search (co-located with API) | Singapore (same VPS / compose as production API) |
| LiveKit (self-hosted SFU) | Arena Live real-time media | Singapore (wss://api.qiubbx.com media stack) |
| Razorpay Curlec | Payment gateway & settlement (payments, Route/payouts as configured) | Malaysia payment rails via Curlec; gateway processing systems operated by Razorpay group (may include India and other provider regions) |
| Google Maps Platform | Geocoding, places, maps, distance for delivery / discovery | Google multi-region cloud (request processed outside Malaysia as Google routes traffic) |
| Google Sign-In · Google Play / Firebase (where enabled) | Auth (Google), push (FCM), Crashlytics diagnostics — not Firebase Analytics / not advertising ID | Google multi-region |
| Apple (Sign in with Apple · App Store · APNs) | iOS auth, distribution, push | Apple multi-region |
| OpenAI (where configured) | AI-assisted features (e.g. Adam / voice transcription paths that use OpenAI) | United States / OpenAI multi-region |
| Anthropic (where configured) | Select AI/verification assistance paths | United States / Anthropic multi-region |
| Twilio (where SMS/voice configured) | SMS / communications | Twilio multi-region |
| Website / static hosting providers | Public marketing & Legal Centre hosting (qiubbx.com) | As deployed (e.g. Contabo / CDN path configured for the site) |
Production-wired libraries only. Use this table when filling Apple Privacy Nutrition and Google Play Data Safety.
| SDK / library | Platforms | Purpose | Data | 3rd party | Required |
|---|---|---|---|---|---|
| Firebase Core Privacy | ios, android | Firebase bootstrap for Crashlytics / FCM | App instance identifiers; crash metadata when Crashlytics enabled | Yes | Yes |
| Firebase Crashlytics Privacy | ios, android | Crash reporting and stability diagnostics | Stack traces, device model/OS, app version; may include breadcrumbs | Yes | Yes |
| Firebase Cloud Messaging (FCM) Privacy | android, backend | Push notifications | FCM device tokens; message delivery metadata | Yes | No |
| Apple Push Notification service (via system) | ios | iOS push delivery | Device push tokens | Yes | No |
| Google Sign-In Privacy | ios, android | OAuth account authentication | Google account ID, name, email (as granted) | Yes | No |
| Sign in with Apple Privacy | ios | iOS OAuth authentication | Apple user ID, email (relay or real as granted) | Yes | No |
| Google Maps SDK / Places / Geocoding Privacy | ios, android, backend | Maps, geocoding, delivery navigation support | Coordinates, addresses, place queries | Yes | Yes |
| Razorpay Curlec checkout Privacy | ios, android, web, backend | Payment authorization and settlement | Order amount, payment status refs; card data via provider PCI environment | Yes | Yes |
| LiveKit (self-hosted SFU) | ios, android, backend | Arena Live real-time media | Live session IDs; audio/video streams while live | No | No |
| Coil (Android image loading) | android | Remote image decode/cache | Image URLs requested by app (processed on device / QIUBBX CDN) | No | Yes |
| URLSession + ImageIO / URLCache (iOS) | ios | API + remote image pipeline | Request URLs, cached image bytes | No | Yes |
| OpenAI API (backend, where configured) Privacy | backend | Adam / voice transcription paths when key present | Prompts and audio/content submitted to those features only | Yes | No |
| Twilio (backend, where configured) Privacy | backend | SMS / messaging OTP | Phone numbers and message metadata when SMS paths enabled | Yes | No |
Source matrix for Play Console and App Store Connect. Console answers must match this table on every release.
| Category | Collect | Share | Optional | Deletion | Purpose | Sources |
|---|---|---|---|---|---|---|
| Name | ✓ | ✓ | — | ✓ | Account management; order fulfilment with Sellers/Riders | QIUBBX API |
| Email address | ✓ | ✓ | — | ✓ | Auth, receipts, support, optional marketing | QIUBBX API, Google Sign-In, Sign in with Apple |
| Phone number | ✓ | ✓ | — | ✓ | Auth/OTP, delivery contact, SMS where enabled | QIUBBX API, Twilio (if enabled) |
| Physical address | ✓ | ✓ | — | ✓ | Delivery address / pickup | QIUBBX API, Google Maps |
| Precise / approximate location | ✓ | ✓ | ✓ | ✓ | Nearby discovery, delivery, Rider assignment | OS location, Google Maps |
| Purchase history / financial info | ✓ | ✓ | — | ✓ | Orders, payments, refunds, settlement | QIUBBX API, Razorpay Curlec |
| Payment info (provider-handled card data) | — | ✓ | — | — | Card PAN/CVV processed by Razorpay PCI — not stored as full card by QIUBBX | Razorpay Curlec |
| Photos / media (user content) | ✓ | — | ✓ | ✓ | Profile, menu, reviews, support attachments | QIUBBX API, Coil / ImageIO |
| App interactions / product interaction | ✓ | — | — | ✓ | Analytics, reliability, product improvement | QIUBBX API, Crashlytics |
| Crash logs | ✓ | ✓ | — | — | Stability diagnostics | Firebase Crashlytics |
| Device or other IDs | ✓ | ✓ | — | ✓ | Push, security, fraud signals | FCM, APNs, QIUBBX API |
| Other user content (reviews, messages, AI prompts) | ✓ | ✓ | ✓ | ✓ | Marketplace, support, Adam AI features when used | QIUBBX API, OpenAI/Anthropic where configured |
Public trust layer for website, policies, SDK/Data Safety matrices and deletion paths. Residual P1 ops items stay listed open.
Public hub for rights, export, consent types and deletion. Full native Privacy Center remains P1.
Collection, use, processors, retention, rights.
Portability request (JSON/CSV) after identity verification.
Separate records — never one accepted=true for everything.
Cookie policy; marketing opt-out via app settings when shipped.
All privacy rights entry points in one place.
Store-facing resource wired to request-web API.
DPO and privacy channel with ticket/reference expected.