Who we are
This Privacy Notice is issued by Yes Can Do Sdn Bhd (registration no. 202101022325 (1422625-W)), doing business as tapow.my ('we', 'us', or 'our'). It describes how we collect, store, use, disclose, and otherwise process ('process') your personal data when you use our services ('Services'), including when you:
- Visit or order through our website and web app at tapow.my and app.tapow.my
- Order, chat, or log in through our WhatsApp assistant on +60 10-282 8258
- Pay a bill through a tapow.my QR code or payment link
- Apply to put your restaurant on tapow.my, or run a venue on our vendor dashboard
tapow.my is a food ordering platform that connects customers with independent restaurants. Restaurants remain the seller of record for the food you order; we facilitate ordering, payment collection, and delivery arrangement on their behalf. For personal data processed through the platform, Yes Can Do Sdn Bhd is the data controller under the Personal Data Protection Act 2010 ('PDPA').
One thing to know as you read this notice: customer accounts are built but not yet switched on, so today everyone orders as a guest. Where this notice describes accounts, logging in with a WhatsApp code, or saving your details for next time, it is telling you how that will work and what we will hold when it opens, not describing something you can use right now.
Questions or concerns? Contact us at hello@tapow.my. If you do not agree with this notice, please do not use the Services.
Language: this notice is currently provided in English. A Bahasa Melayu version is being prepared, as the PDPA requires; until it is published, contact us and we will explain any part of this notice in Bahasa Melayu.
Summary of key points
What we collect. What you'd expect a food ordering platform to need: your name, phone number, delivery address and map pin, your orders, and your messages when you order through WhatsApp. An email address only if you choose to give one. If you run a restaurant on tapow.my, your business registration and bank details too. Full detail in Section 01.
Sensitive data. We never ask for sensitive personal data (health, beliefs, biometrics), and no part of the platform has a field for it. If you volunteer something sensitive in a free-text note or a message, for example a food allergy, we hold it as part of that order or conversation and protect it like the rest of your data. Card numbers go directly to our payment provider and never touch our servers.
Who we share with. Only the service providers that make the platform work: payments, database hosting, AI, delivery, WhatsApp, and address search. They are all named in Section 03. We do not sell your data and we do not run advertising trackers.
Where it lives. Some of our providers process data outside Malaysia. We are honest about that in Section 04.
Your rights. Under the PDPA you can access, correct, and delete your data, withdraw consent, and opt out of marketing. How to do that, and how fast we respond, is in Section 10.
What we collect
When you place an order
- Your name and phone number
- For delivery: your delivery address, including the map pin location you confirm, and any building, unit, or delivery notes you add
- Your order contents, order history, and order status
- An email address, only if you choose to provide one (for example when we offer to save your details after an order)
When you use WhatsApp with us
- Your WhatsApp phone number and profile name
- The content of your messages with our assistant, including orders, questions, and any location pins you share. If you send a photo or a voice note, we store the message record too, though our assistant only reads text and will say so
- Login codes, if you use WhatsApp to sign in to your tapow.my account
When you use voice ordering
If you use the microphone on a venue's menu, your speech is turned into text by your own web browser, and only that text is sent to us to build your order. We never receive or store the audio, we do not build voice profiles, and we do not use your voice to identify you. We do not keep the transcript either: what survives is whatever the order itself records, such as items and any note you added.
One thing worth knowing that is outside our control: most browsers, including Chrome, perform speech recognition on their own servers rather than on your device. If you use voice ordering in such a browser, your speech is processed by your browser's provider (for Chrome, Google) under their privacy terms, before any text reaches us. If you would rather that not happen, type your order instead.
Payment data
Card and e-wallet details are entered directly with our payment provider, Stripe, and are handled and stored by Stripe, not by us. No card number ever reaches our systems. What we store is the payment reference, the amount, the status (paid, refunded, failed), and the transaction record Stripe sends us, which can include the billing details you gave Stripe and the last four digits of a card. Stripe's privacy notice: stripe.com/en-my/privacy.
If you run a restaurant on tapow.my
- Owner and contact details: name, phone number, email, and the phone numbers you authorise to reach your dashboard or receive order alerts
- Business details: SSM registration number and certificate, SST registration number if applicable
- Payout details: bank name, account holder name, account number
- Venue details: address and map pin, storefront photo, menu content and photos
These are collected to verify your business, list your venue, and pay you. Supplying them is a condition of selling on tapow.my; without them we cannot approve an application or make payouts. We are also required by consumer protection regulations to keep records of the businesses selling on the platform.
Collected automatically
Less than you might expect. We run no analytics, no tracking pixels, and no advertising tools, so we do not build a record of the pages you view or a profile of your device.
What does happen is ordinary internet plumbing: our hosting and database providers keep standard server logs of requests made to us, which include IP addresses and timestamps, and we use your IP address momentarily to rate-limit abusive traffic (that counter is held in memory and never stored). Errors are logged so we can fix them.
Received from third parties
We receive delivery status updates and rider details (name, phone number, tracking link) from our courier partner so we can show you where your order is, and payment status events from Stripe so your order and refund status stay accurate.
All personal data you provide must be true, complete, and accurate. Providing someone else's data (for example an alternate recipient's name and address for a delivery) is only allowed if you are authorised to do so.
How we use your data
We process your personal data to:
- Take and fulfil orders. Send your order to the restaurant, print the kitchen ticket, collect payment, arrange delivery, and show you order status.
- Run the WhatsApp assistant. Understand your messages, answer questions, build your order, and send you payment links and confirmations.
- Operate accounts. Log you in via WhatsApp code, keep your saved addresses and order history, and let you manage them.
- Process refunds and resolve problems. Handle cancellations, refunds, and support conversations.
- Onboard and pay vendors. Review applications, verify businesses, list venues, and make weekly payouts.
- Keep the platform safe. Prevent fraud and abuse, secure accounts, and protect the Services.
- Send service communications. Order confirmations, receipts, and notices about changes to our terms or policies.
- Improve the Services. Understand usage and fix what's broken, using aggregated or technical data wherever possible.
- Comply with the law. Tax and accounting record-keeping, consumer protection obligations, and lawful requests from authorities.
We do not use your personal data for third-party advertising, and we only send direct marketing (for example promotions) where the law allows, with a working opt-out every time. See Section 10.
Who we share it with
We share personal data with the following classes of recipients, strictly for the purposes described in this notice:
- The restaurant you order from. Your name, order contents, and for delivery your address and phone number, so they can prepare and hand over your order.
- Payments: Stripe. Processes every card and e-wallet payment, and refunds. (privacy notice) We expect to add Curlec by Razorpay, a Malaysian payment provider, as an additional payment partner; when live, payments routed through Curlec will be subject to its privacy notice.
- Database and backend: Supabase. Hosts our database, where orders, accounts, conversations, and vendor records are stored. (privacy notice)
- AI: Anthropic. Powers our WhatsApp assistant, voice ordering, and vendor dashboard assistant. Your messages or transcribed speech, plus the order context needed to answer, are sent to Anthropic's Claude models to generate responses. (privacy notice)
- Delivery: Delyva. Receives your name, phone number, delivery address, and pin so a rider can be dispatched to you. (privacy notice)
- WhatsApp: Meta. Our WhatsApp assistant runs on the WhatsApp Business Platform, so your messages to and from us transit Meta's systems under WhatsApp's own terms and privacy policy. (privacy notice)
- Address search: Google. When you type or pin an address, the text and coordinates are sent to Google's Places services to find and label the location. Separately, if you use voice ordering in a browser that performs speech recognition on its own servers (Chrome does), your speech reaches that browser's provider before any text reaches us. (privacy notice)
- Hosting: DigitalOcean. Hosts the web app and this site, and as such sees standard technical logs. (privacy notice)
- Order notifications: n8n. Where a venue's order alerts are routed through our automation service, the order details needed to raise that alert, including your name, phone number, and delivery address, pass through it. (privacy notice)
A few parts of the Services load from other companies' servers as your page renders. These receive your IP address and the page you are on, because that is how a web request works, but they receive no order or account information: OpenStreetMap for the map tiles behind our address picker (so the area you are pinning is visible to them), rsms.me for the app's typeface, Google Fonts for this legal site's typefaces, and Unsplash for some venue photos.
Beyond these: we may disclose personal data if required by law or a competent authority; and if the business is ever merged, sold, or restructured, personal data may transfer as part of that transaction, under this notice's protections.
We do not sell personal data. We do not share it with advertisers or data brokers.
Where your data lives
We operate from Malaysia, and some of the service providers named in Section 03 store or process data on servers outside Malaysia (including in the United States, Singapore, and other regions where those providers operate). This means your personal data may be transferred outside Malaysia.
Where that happens, we rely on the grounds permitted by section 129 of the PDPA (as amended): the transfer is necessary to perform our contract with you (for example, processing your payment), or we have taken reasonable precautions and exercised due diligence, including contractual data protection commitments with each provider. Each provider named in Section 03 is bound by its own published data processing terms, and by the PDPA's direct obligations on data processors where applicable.
Cookies & local storage
The Services use browser storage (localStorage and similar) to make things work: your cart, your saved preferences (like delivery or pickup mode), your session when you log in, and device-side copies of things like addresses. Most of this stays on your device and is not a tracking technology.
We use cookies and similar technologies only for essential purposes such as security and keeping you signed in. We do not use third-party advertising cookies, tracking pixels, or ad networks on the Services.
You can clear your browser storage at any time; doing so signs you out and empties device-side data like your cart. Payment pages served by Stripe may set their own cookies for fraud prevention, under Stripe's notice.
AI features
Parts of the Services are powered by artificial intelligence, provided by Anthropic (Claude models):
- The WhatsApp ordering assistant. Your messages, and the venue and order context needed to answer them, are sent to Anthropic to generate the assistant's replies.
- Voice ordering on venue menus. Your speech is transcribed in your browser; the transcribed text is processed the same way.
- Vendor dashboard assistant. Operators can manage their venue conversationally; their messages and venue data are processed the same way.
Three commitments about how we've built these features:
- The AI never decides what you pay for an order. Every item price is computed by our servers from the venue's menu, and order totals are recalculated and verified server-side before any payment link is issued. The assistant has no way to name a price. (The one place an amount is typed rather than calculated is a venue asking our vendor assistant to raise a scan-to-pay bill for a walk-in customer, where the amount is the venue's own instruction and you see it before you pay.)
- The AI never takes money from you. Payments happen only when you open a payment page and complete it yourself, and refunds are handled by our systems and our team, never by the assistant.
- AI output can be wrong. If the assistant says something inconsistent with the priced order summary you're shown before paying, the summary is authoritative. See our Terms.
We use Anthropic under its commercial terms. If you'd rather not interact with AI features, you can order through the web app and reach a human through our support channels (contact page).
How long we keep it
We keep personal data only as long as needed for the purposes in this notice. We would rather tell you plainly which of these are automatic today and which we do on request, than imply more machinery than we have:
- Order and payment records: retained for up to 7 years, because Malaysian tax and accounting law requires it.
- Login codes: expire within minutes and are automatically deleted within 24 hours. This one runs on a scheduled job.
- WhatsApp conversations: kept while they are useful for running the assistant, answering support questions, and resolving disputes. We do not yet run an automatic deletion schedule for them, so today they persist until we clear them. You can ask us to delete your conversation at any time and we will.
- Account data (saved addresses, profile): kept while your account is in use. There is no self-serve delete button yet, so account deletion is something you ask us for, by email or WhatsApp, and we do it by hand, keeping only what the order-record retention above requires. We do not currently run an automatic sweep for dormant accounts.
- Vendor records: business and transaction records are kept for at least 3 years after a venue leaves the platform, as consumer protection regulations require, and up to 7 years where tax law applies.
Building the missing automatic deletion is work we intend to do, and this section will be updated when it lands rather than before. Where immediate deletion is not possible (for example, database backups), data is isolated from further use until it can be deleted.
How we keep it safe
We take reasonable technical and organisational measures appropriate to the data we hold: encrypted connections (HTTPS) across all Services, database access restricted by row-level security and least-privilege server roles so that tables holding personal data cannot be read by the app's public key at all, session tokens stored hashed, single-use time-limited login links and login codes, and payment card data handled exclusively by Stripe so it never reaches our infrastructure. The one exception to hashed-at-rest is a brief step during WhatsApp login, where a freshly minted session token is held in readable form only until the browser that started the login collects it.
No electronic transmission or storage is guaranteed to be 100% secure, and we cannot promise that unauthorised third parties will never defeat our security. What we can promise is the breach response in Section 11.
Minors
The Services are intended for users aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe we hold data on a person under 18, contact us at hello@tapow.my and we will delete it.
Your rights under the PDPA
Under the PDPA (including the 2024 amendments) you have the right to:
- Access the personal data we hold about you. We respond within 21 days of a verified request; if we need longer, the PDPA allows one extension of up to 14 days and we will tell you why. A small fee may apply as permitted by the PDPA.
- Correct data that is inaccurate, incomplete, or out of date. Same timelines as access.
- Withdraw consent to processing at any time by written notice, after which we stop the processing concerned. This may mean we can no longer provide parts of the Services (for example, we cannot deliver without an address).
- Stop direct marketing. Tell us once and promotional messages stop; order and service messages continue.
- Prevent processing likely to cause damage or distress, as provided by section 42 of the PDPA.
- Data portability. Ask us to transmit your data (such as your profile and order history) to you or another provider in a machine-readable format, where technically feasible.
- Delete your account and data. Ask us and we deactivate the account and delete personal data not subject to the retention periods in Section 07. This is handled by a person rather than a button today, so allow us the response times below.
How to make a request
Email hello@tapow.my or message our WhatsApp line with the words 'data request' and what you want. We will verify you control the phone number or email on the record before acting, and confirm in writing when done.
If you are unsatisfied with how we handle your personal data, you may complain to the Personal Data Protection Commissioner of Malaysia (pdp.gov.my). We'd appreciate the chance to fix it first.
If something goes wrong
If a personal data breach occurs that causes or is likely to cause significant harm, we will notify the Personal Data Protection Commissioner as soon as practicable and within 72 hours, and notify affected users without unnecessary delay and within 7 days of notifying the Commissioner, in each case as required by section 12B of the PDPA. We maintain an internal register of data breaches, including those below the notification threshold.
Updates to this notice
We may update this notice as the Services and the law evolve. The 'Last updated' date at the top changes with every revision. If we make material changes, we will notify you before they take effect, by a prominent notice on the Services or a direct message (WhatsApp or email).
How to contact us
For anything in this notice, including data protection inquiries and complaints (the contact point required by the PDPA's Notice and Choice Principle):
Taman Danau Desa, Kuala Lumpur 58100, Malaysia