TRUST & COMPLIANCE

Trust at QIUBBXWe believe trust is not a statement. It is a system.

Terms explain promises. Privacy explains data handling. Compliance ensures systems match the documents. Audit ensures we can prove it.

QIUBBX is committed to applicable privacy, security, payment and platform requirements.

We do not claim “100% compliant.” Control scores are honest. Gaps stay visible as PARTIAL or NEEDS_REVIEW until verified.

93% · Public readiness score

Weighted score of published control objects (PASS / PARTIAL / NEEDS_REVIEW). Not a legal certification.

Framework v1.0 · 2026-08-09

How QIUBBX sees Trust

Every requirement should map: policy → system → API/UI → procedure → evidence.

Legal

What QIUBBX promises — modular Legal Centre documents with version control.

Open →

Privacy

What QIUBBX does with data — PDPA notice, retention, age gate, processors, rights.

Open →

Security

Access control, encryption in transit, logging, incident response readiness.

Open →

Payment

Razorpay Curlec, settlement honesty, no unnecessary card storage.

Open →

Platform

Seller, Rider, QBP, marketplace and food-safety participant rules.

Open →

Operations

Account deletion, support, monitoring and monthly review cadence.

Open →

Audit & evidence

Control objects, acceptance records, vendor register and evidence vault design.

Open →
  • Promise = behaviourDocument text and live product must match. Mismatches are release blockers.
  • No single accepted booleanTerms, privacy, marketing, location, cookies and AI consents are separate records.
  • Named processors onlyPublish vendors that are actually used — via Privacy Policy processor table.
  • Deletion is a workflowVerify → depend check → lock → delete/anonymise → retain exceptions → audit → confirm.
  • Malaysia PDPA opsDPO readiness, breach notification, DPIA, privacy-by-design and ADMP are operational work — not only policy prose.
  • Store honestyApple disclosures and Google Data Safety must match SDK inventory and actual collection.

15 compliance domains

Priority domain map for marketplace, payment, store review and PDPA ops.

01P0

Legal Documents

Terms, service-specific terms, policies and versioned publication.

02P0

Privacy / PDPA

DPO, breach, DPIA, privacy-by-design, cross-border, automated decision/profiling awareness.

03P0

Apple Compliance

Privacy disclosures, in-app privacy access, account deletion, purpose strings.

04P0

Google Play Compliance

Data Safety form must match SDK inventory + privacy disclosures + web deletion resource.

05P0

Payment / Razorpay

Curlec gateway, settlement disclosure, PCI posture (no full PAN/CVV at QIUBBX).

07P0

Data Governance

Inventory, classification, retention owners, consent types, export/correction.

08P0

Security

AuthN/Z, least privilege, secrets, logging, monitoring baseline.

09P0

Seller Compliance

Onboarding, documents, food-related requirements, continuous review.

10P0

Rider Compliance

Identity, vehicle/docs, delivery conduct, earnings ledger integrity.

12P0

Food / Marketplace Compliance

Food-safety expectations, venue types, prohibited activity.

13P0

Consumer / Refund

Cancellation stages, quality issues, chargebacks, consumer fairness.

14P0

Incident Response

Detect → contain → assess → notify when required (incl. PDPA DBN).

15P0

Audit & Evidence

Control matrix, legal acceptance audit trail, evidence vault design.

Control matrix

Selected P0 control objects. Full internal vault expands in Ops / Admin.

ControlSystemPolicyEvidenceOwnerStatus
LEG-001Legal Centre published

Modular legal pages at /legal with TOC UI and version metadata.

YesYesYesLegal / WebPASS
PRIV-001Privacy Policy comprehensive

Multi-role privacy with retention table, age gate, named processors.

Legal Centre documents are PUBLISHED and in force for Malaysia (versioned).

YesYesYesPrivacyPASS
PRIV-002Versioned privacy acceptance

Store documentId + version + timestamp + source — not a single accepted boolean.

Schema defined in Legal Center acceptance model; product wiring staged.

NoYesNoEngineering / PrivacyPARTIAL
PRIV-003Master data inventory

Role × data × classification inventory published and compared to DB/SDK.

Initial architecture inventory live on /trust — must be reconciled to production schema.

YesYesNoPrivacy / EngineeringPARTIAL
PRIV-004Vendor & processor register

Named production processors with region and purpose (privacy-ops).

YesYesYesPrivacyPASS
ACC-001Account deletion (Apple + Play)

In-app delete + web resource wired to production request-web API; workflow with retention exceptions.

Web: POST /api/auth/deletion/request-web. In-app: AccountDeletionView / AccountDeletionScreen.

YesYesYesProduct / EngineeringPASS
STORE-001Apple privacy disclosure source matrix

Nutrition Labels filled from published SDK + Data Safety matrix on Trust Centre.

Console must remain consistent with /trust#data-safety on each release.

YesYesYesMobilePASS
STORE-002Google Data Safety source matrix

Play Data Safety completed from Trust matrix + SDK inventory only.

YesYesYesMobilePASS
PAY-001Razorpay production model published

Public Payments + Payment Terms describe split settlement and fee roles.

YesYesYesFinance / ProductPASS
SEC-001Security baseline

TLS, hashing, session/auth controls, logging; documented public security layer.

YesYesYesSecurity / EngineeringPASS
SDK-001SDK inventory

Named production-wired SDKs with platforms, purpose and data.

YesYesYesMobile / PrivacyPASS
PC-001Privacy Center (public)

Public Privacy Center with access, export, consent, deletion entry points.

YesYesYesPrivacy / WebPASS
SELL-001Seller Terms & verification frames

Seller Terms live; document register/ops monitor for expiry.

YesYesNoCompliancePARTIAL
RID-001Rider Terms & earnings honesty

Rider Terms + QXRider programme honesty (no inventing instant payout).

YesYesYesCompliance / ProductPASS
QBP-001QBP ethics & flat model

No MLM; 2.5% seller-side; ethics & certification framework published.

YesYesYesQBP OpsPASS
REF-001Refund & cancellation policy

Public refund-cancellation legal module.

YesYesYesLegal / SupportPASS
INC-001Breach / incident procedure documented

Privacy Policy breach flow + PDPA ops DBN guidelines.

YesYesYesSecurity / PrivacyPASS
AUD-001Public control matrix

Control objects with status published on Trust Centre.

YesYesYesCompliancePASS
AI-001Adam AI disclosure & human oversight

Adam limitations disclosed; high-risk decisions require human review.

YesYesYesProduct / PrivacyPASS

Master data inventory (architecture)

Role × data map for Customer / Seller / Rider / QBP, aligned with Privacy Policy and SDK inventory.

Architecture inventory — not a claim that every field is collected for every user at all times.

DataCSRQPurposeClass
NameIdentityPERSONAL
EmailCommunicationPERSONAL
PhoneCommunicationPERSONAL
AddressOperationsPERSONAL
LocationDelivery / discoveryHIGH_SENSITIVITY
OrdersTransactionCONFIDENTIAL
Payment statusSettlementCONFIDENTIAL
Bank detailsPayoutHIGH_SENSITIVITY
Identity docsVerificationHIGH_SENSITIVITY
Business docsComplianceCONFIDENTIAL
TINTaxHIGH_SENSITIVITY
Wallet / earningsEarningsCONFIDENTIAL
Device dataSecurity / opsPERSONAL
Reviews / contentMarketplacePERSONAL
AI interactionsAdam / AI servicePERSONAL
Public menu / business nameCataloguePUBLIC

Processor register (production)

ProviderRoleRegion
QIUBBX production platform (self-hosted)Primary application / API controller systemsSingapore (api.qiubbx.com · VPS 84.247.146.47)
MongoDB · Redis · Meilisearch (QIUBBX Docker stack)Primary datastore, cache, search (co-located with API)Singapore (same VPS / compose as production API)
LiveKit (self-hosted SFU)Arena Live real-time mediaSingapore (wss://api.qiubbx.com media stack)
Razorpay CurlecPayment gateway & settlement (payments, Route/payouts as configured)Malaysia payment rails via Curlec; gateway processing systems operated by Razorpay group (may include India and other provider regions)
Google Maps PlatformGeocoding, places, maps, distance for delivery / discoveryGoogle multi-region cloud (request processed outside Malaysia as Google routes traffic)
Google Sign-In · Google Play / Firebase (where enabled)Auth (Google), push (FCM), Crashlytics diagnostics — not Firebase Analytics / not advertising IDGoogle multi-region
Apple (Sign in with Apple · App Store · APNs)iOS auth, distribution, pushApple multi-region
OpenAI (where configured)AI-assisted features (e.g. Adam / voice transcription paths that use OpenAI)United States / OpenAI multi-region
Anthropic (where configured)Select AI/verification assistance pathsUnited States / Anthropic multi-region
Twilio (where SMS/voice configured)SMS / communicationsTwilio multi-region
Website / static hosting providersPublic marketing & Legal Centre hosting (qiubbx.com)As deployed (e.g. Contabo / CDN path configured for the site)

Full detail in Privacy Policy →

SDK & processor inventory

Production-wired libraries only. Use this table when filling Apple Privacy Nutrition and Google Play Data Safety.

SDK / libraryPlatformsPurposeData3rd partyRequired
Firebase Core
Privacy
ios, androidFirebase bootstrap for Crashlytics / FCMApp instance identifiers; crash metadata when Crashlytics enabledYesYes
Firebase Crashlytics
Privacy
ios, androidCrash reporting and stability diagnosticsStack traces, device model/OS, app version; may include breadcrumbsYesYes
Firebase Cloud Messaging (FCM)
Privacy
android, backendPush notificationsFCM device tokens; message delivery metadataYesNo
Apple Push Notification service (via system)iosiOS push deliveryDevice push tokensYesNo
Google Sign-In
Privacy
ios, androidOAuth account authenticationGoogle account ID, name, email (as granted)YesNo
Sign in with Apple
Privacy
iosiOS OAuth authenticationApple user ID, email (relay or real as granted)YesNo
Google Maps SDK / Places / Geocoding
Privacy
ios, android, backendMaps, geocoding, delivery navigation supportCoordinates, addresses, place queriesYesYes
Razorpay Curlec checkout
Privacy
ios, android, web, backendPayment authorization and settlementOrder amount, payment status refs; card data via provider PCI environmentYesYes
LiveKit (self-hosted SFU)ios, android, backendArena Live real-time mediaLive session IDs; audio/video streams while liveNoNo
Coil (Android image loading)androidRemote image decode/cacheImage URLs requested by app (processed on device / QIUBBX CDN)NoYes
URLSession + ImageIO / URLCache (iOS)iosAPI + remote image pipelineRequest URLs, cached image bytesNoYes
OpenAI API (backend, where configured)
Privacy
backendAdam / voice transcription paths when key presentPrompts and audio/content submitted to those features onlyYesNo
Twilio (backend, where configured)
Privacy
backendSMS / messaging OTPPhone numbers and message metadata when SMS paths enabledYesNo

Store Data Safety matrix

Source matrix for Play Console and App Store Connect. Console answers must match this table on every release.

CategoryCollectShareOptionalDeletionPurposeSources
NameAccount management; order fulfilment with Sellers/RidersQIUBBX API
Email addressAuth, receipts, support, optional marketingQIUBBX API, Google Sign-In, Sign in with Apple
Phone numberAuth/OTP, delivery contact, SMS where enabledQIUBBX API, Twilio (if enabled)
Physical addressDelivery address / pickupQIUBBX API, Google Maps
Precise / approximate locationNearby discovery, delivery, Rider assignmentOS location, Google Maps
Purchase history / financial infoOrders, payments, refunds, settlementQIUBBX API, Razorpay Curlec
Payment info (provider-handled card data)Card PAN/CVV processed by Razorpay PCI — not stored as full card by QIUBBXRazorpay Curlec
Photos / media (user content)Profile, menu, reviews, support attachmentsQIUBBX API, Coil / ImageIO
App interactions / product interactionAnalytics, reliability, product improvementQIUBBX API, Crashlytics
Crash logsStability diagnosticsFirebase Crashlytics
Device or other IDsPush, security, fraud signalsFCM, APNs, QIUBBX API
Other user content (reviews, messages, AI prompts)Marketplace, support, Adam AI features when usedQIUBBX API, OpenAI/Anthropic where configured

Launch gate (P0)

Public trust layer for website, policies, SDK/Data Safety matrices and deletion paths. Residual P1 ops items stay listed open.

  • Terms publishedDone
  • Privacy publishedDone
  • Seller Terms publishedDone
  • Rider Terms publishedDone
  • Payment Terms publishedDone
  • Refund Policy publishedDone
  • Account deletion web resource (API-wired)Done
  • Account deletion in-app (iOS + Android screens)Done
  • Data inventory published + linked to Privacy/TrustDone
  • SDK inventory completed (production-wired only)Done
  • Google Data Safety source matrix publishedDone
  • Apple disclosure source matrix publishedDone
  • Razorpay architecture + Payment Terms publishedDone
  • Payment public documentation (Fees / refund policy pages)Done
  • Security baseline documented (Privacy + Trust + Compliance)Done
  • Audit log design + critical deletion audit trail codeDone
  • Incident response procedure published (Privacy + PDPA ops)Done
  • Legal documents published and in force (versioned Legal Centre)Done

Scale readiness (P1) — platform ops still open

  • Public Privacy Center live (native parity next)Done
  • Download My Data request surface liveDone
  • Automated retention job (full auto purge)Open
  • DPIA process operating (ops workflow)Open
  • AI governance register (live model DB)Open
  • Compliance Command Center (admin native)Open
  • Evidence vault file storeOpen