OrderLah Privacy Notice (Malaysia)
Draft wording — pending legal review. This document has been published by OrderLah so that it applies, and has not yet been reviewed by a qualified lawyer in this jurisdiction.
- Issued by
- OrderLah MY
OrderLah Privacy Notice — Malaysia
This Notice explains what personal data OrderLah MY collects when you use OrderLah, why, and what you can ask us to do about it. It is written to be read, not to be survived.
It is separate from our Merchant Terms of Service. Accepting the Terms is a contract; this Notice tells you what we do with personal data, and we ask you to acknowledge that you have been given it.
1. Who we are
OrderLah MY is the OrderLah company responsible for personal data collected in Malaysia. Our registered name, business registration number, registered address and contact addresses are shown with this Notice wherever it is displayed.
2. Who this Notice is for
- merchant owners, directors and authorised representatives;
- merchant administrators, managers and staff who use OrderLah;
- people whose contact details a merchant gives us as a support or billing
contact;
- visitors to our websites and people who request a demonstration;
- customers who order from a merchant through an OrderLah QR or browser
ordering page, for the limited data described in section 6.
3. What we collect
Account and business information. Your name, email address and telephone number; your business name, registration details, country, currency and time zone; your outlets, their names, addresses and settings; the roles and access you give your team.
Sign-in and security information. A hashed password, or — if you sign in with Google — the fact that a Google account with a verified email address is linked to yours and Google's own stable identifier for it. We never receive your Google password. Session identifiers, sign-in and sign-out events, password reset and email verification events, and the IP address a request came from.
Device information. For each device paired to a Hub: an identifier we issue, what it is for (counter, kitchen, display), its name, when it last connected, and the credential's own fingerprint. We do not collect a device's phone number, IMEI, advertising identifier or location.
Operational data from your shop. Orders, items, tables, prices, discounts, payment status, staff actions and timestamps. Most of this stays on your own Hub; what reaches us is described in section 5.
Billing information. What you bought, when, in what currency, the invoices we issued, and the payment reference and status our provider returned. For a payment taken through your own provider account we also store what a receipt and a reconciliation need: the card brand and its last four digits, the wallet or bank used, the country of issue, the authorisation code, and the name the payer gave the provider. We do not receive or store a full card number or a security code.
Support and communications. What you write to us, and what we write back.
Diagnostics and security logs. Error reports, request logs, rate-limit and authentication events. Values that look like secrets or payment credentials are redacted before anything is written down.
4. What we do with it
To create and run your account; to authenticate you and your devices; to pair devices to a Hub; to provision and configure outlets; to deliver orders between your own devices and to your kitchen; to manage licences and trials; to bill you and issue invoices; to record payment status; to provide support; to detect, investigate and prevent fraud, abuse and security incidents; to keep the service reliable and to diagnose faults; to back up and restore data where you have enabled backup; to produce the reports you ask for; to tell you things you need to know about your account, your licence and your security; and to meet our legal and tax obligations.
We rely on the need to perform our contract with you, our legitimate interest in running and securing the service, your consent where we ask for it, and our legal obligations — as the PDPA and the other laws that apply to us require.
5. Where your data actually lives
This matters more in OrderLah than in most software, so it is set out plainly.
On your Hub. Your menu, orders, tables, staff records, print queue and daily takings are held on the device in your shop. That is where the shop reads and writes them, and it is why the shop keeps working with the internet unplugged.
Through the relay. If you use the portal or reach your shop from outside its own network, requests pass through our relay. The relay forwards them; it caches some public pages for speed and does not keep your order history.
In our cloud. Your account, business, outlet, device, licence, invoice, payment reference, marketing-consent and audit records are held in our database.
In our own backups of that database. We take an encrypted copy of it daily, kept on our own servers for a bounded period so that we can restore the service after a failure. It holds the same records as the database and nothing more, it is not your Hub's backup, and it is not something you can ask us to restore a single record from.
In your own backups. A backup is a file your Hub writes, to a destination you choose, so that you can restore from it. It is a checksummed JSON file and it is not encrypted, so keep it somewhere you would keep your own accounts. OrderLah keeps no copy of it, and the only housekeeping is on your own device: the Hub keeps the most recent files and deletes older ones.
6. Your customers' information
When a customer orders from you through OrderLah, the order is yours. The information in it — what was ordered, at what table, any note they typed — is your business's record, held on your Hub and handled by you. We process it only to deliver the service to you.
Our customer ordering page deliberately holds as little as possible. It does not ask a diner for a name, an email address, a phone number or an account. A basket is kept in the browser's own storage, keyed to that browser's session, and never sent to us for any purpose other than placing the order with you. An e-receipt is reachable only by the person holding the link, is served with instructions not to cache it, and carries no marketing.
Where you collect more from your customers — a loyalty membership, a delivery address, a phone number for collection — that is your collection, under your own privacy obligations to them. We are not responsible for what you tell your customers about it, and we do not act as their point of contact.
7. Who we share it with
We share personal data only with:
- payment providers, so that a payment can be taken and reconciled;
- hosting and infrastructure providers, who run the servers, network and
storage our cloud services sit on;
- email delivery providers, for the messages we send you;
- connected ordering platforms, where you have connected one, limited to what
is needed to receive that platform's orders;
- professional advisers, auditors and regulators, where we are required or
properly asked;
- a buyer or successor, if the business is sold or reorganised, under the
same protections.
OrderLah does not sell personal information, and we do not share it with advertising networks. Our advertising integrations are switched off unless an operator supplies credentials for one, and no deployment that has not done so has ever sent anybody's data anywhere.
8. Where it is processed
Our servers and our providers are not necessarily in your country. Personal data may be processed in another country, including for hosting, email delivery, and payment processing. Where it is, we take steps to see that it remains protected to a standard consistent with the Personal Data Protection Act 2010 of Malaysia (PDPA). We do not claim that all data stays physically within Malaysia, because it does not.
9. How long we keep it
For as long as we need it: while your account is open, and after that for as long as we must keep the record. In practice that means accounting and tax records for the period the law requires, invoices and credit notes for the same period, security and audit logs for as long as they are useful for investigating an incident, support correspondence while it is relevant, and backups until they age out of their own retention. Where we no longer need something, we delete it or put it beyond use.
10. How we protect it
Access to production systems is restricted to the people who need it, and is authenticated and logged. Credentials are stored hashed or encrypted, never in the clear. Traffic between your devices and our servers is encrypted in transit. A device's credential is stored in the platform's own secure storage, and revoking a device cuts its live connection as well as its future access. Values that look like secrets are redacted before they are logged.
No system is perfectly secure and we do not claim to be. We do not hold any security certification, and this Notice does not assert one.
11. Your choices and rights
Under the PDPA you may ask us for access to the personal data we hold about you, and you may ask us to correct it where it is wrong, incomplete, misleading or out of date. You can also update most of your own account and business details yourself in the Merchant Portal, ask us to close your account, and withdraw consent where we relied on it — including for marketing messages, which you can switch off without losing the operational, security and billing messages you need.
Write to the privacy or legal address shown with this Notice. We will respond within the time the law allows. If you are not satisfied, you may complain to the Personal Data Protection Commissioner of Malaysia.
12. Cookies and local storage
Our portals use browser storage for a small number of things and no more: a session cookie so you stay signed in, a token that protects forms against cross-site submission, and local storage for your own display preferences — the outlet you last looked at, the period you last chose. The customer ordering page uses the browser's own session storage for the basket and the browser session it belongs to.
We do not use advertising cookies and we do not run third-party analytics on the portals or on the customer ordering page. That is why you are not being asked to dismiss a cookie banner.
13. Children
OrderLah's merchant and administration products are for businesses and their authorised staff, and are not directed at children. A customer ordering page is a menu on a restaurant table and may be used by a family; it asks for no personal details and creates no account.
14. Changes to this Notice
We may publish a new version. Where a change is significant we will tell you, and where the law requires your consent for something new we will ask for it rather than assume it. Every version we have published stays available, with the date it took effect, so you can see what applied when.
15. Contact
Contact details for the responsible company are shown with this Notice. Use the privacy or legal address for anything in this document.