Legal  /  Document 02 of 04

Privacy Policy

What personal data we collect when you use tapow.my, why we collect it, who we share it with, and the rights you have over it under Malaysia's Personal Data Protection Act 2010.

In effect Last updated  11 August 2026 Jurisdiction  Malaysia Reading time  ~14 min
Preamble

Who we are

In plain English We're Yes Can Do Sdn Bhd, the company behind tapow.my. This notice tells you what we do with your data, and what we don't.

This Privacy Notice is issued by Yes Can Do Sdn Bhd (registration no. 202101022325 (1422625-W)), doing business as tapow.my ('we', 'us', or 'our'). It describes how we collect, store, use, disclose, and otherwise process ('process') your personal data when you use our services ('Services'), including when you:

  • Visit or order through our website and web app at tapow.my and app.tapow.my
  • Order, chat, or log in through our WhatsApp assistant on +60 10-282 8258
  • Pay a bill through a tapow.my QR code or payment link
  • Apply to put your restaurant on tapow.my, or run a venue on our vendor dashboard

tapow.my is a food ordering platform that connects customers with independent restaurants. Restaurants remain the seller of record for the food you order; we facilitate ordering, payment collection, and delivery arrangement on their behalf. For personal data processed through the platform, Yes Can Do Sdn Bhd is the data controller under the Personal Data Protection Act 2010 ('PDPA').

One thing to know as you read this notice: customer accounts are built but not yet switched on, so today everyone orders as a guest. Where this notice describes accounts, logging in with a WhatsApp code, or saving your details for next time, it is telling you how that will work and what we will hold when it opens, not describing something you can use right now.

Questions or concerns? Contact us at hello@tapow.my. If you do not agree with this notice, please do not use the Services.

Language: this notice is currently provided in English. A Bahasa Melayu version is being prepared, as the PDPA requires; until it is published, contact us and we will explain any part of this notice in Bahasa Melayu.

Summary

Summary of key points

In plain English The short version. Every claim here has a fuller section below.

What we collect. What you'd expect a food ordering platform to need: your name, phone number, delivery address and map pin, your orders, and your messages when you order through WhatsApp. An email address only if you choose to give one. If you run a restaurant on tapow.my, your business registration and bank details too. Full detail in Section 01.

Sensitive data. We never ask for sensitive personal data (health, beliefs, biometrics), and no part of the platform has a field for it. If you volunteer something sensitive in a free-text note or a message, for example a food allergy, we hold it as part of that order or conversation and protect it like the rest of your data. Card numbers go directly to our payment provider and never touch our servers.

Who we share with. Only the service providers that make the platform work: payments, database hosting, AI, delivery, WhatsApp, and address search. They are all named in Section 03. We do not sell your data and we do not run advertising trackers.

Where it lives. Some of our providers process data outside Malaysia. We are honest about that in Section 04.

Your rights. Under the PDPA you can access, correct, and delete your data, withdraw consent, and opt out of marketing. How to do that, and how fast we respond, is in Section 10.

Section 01

What we collect

In plain English Your name, number, and address when you order. Your messages when you order on WhatsApp. Card details go straight to Stripe; we never see them. Restaurant owners also give us business and bank details.

When you place an order

  • Your name and phone number
  • For delivery: your delivery address, including the map pin location you confirm, and any building, unit, or delivery notes you add
  • Your order contents, order history, and order status
  • An email address, only if you choose to provide one (for example when we offer to save your details after an order)

When you use WhatsApp with us

  • Your WhatsApp phone number and profile name
  • The content of your messages with our assistant, including orders, questions, and any location pins you share. If you send a photo or a voice note, we store the message record too, though our assistant only reads text and will say so
  • Login codes, if you use WhatsApp to sign in to your tapow.my account

When you use voice ordering

If you use the microphone on a venue's menu, your speech is turned into text by your own web browser, and only that text is sent to us to build your order. We never receive or store the audio, we do not build voice profiles, and we do not use your voice to identify you. We do not keep the transcript either: what survives is whatever the order itself records, such as items and any note you added.

One thing worth knowing that is outside our control: most browsers, including Chrome, perform speech recognition on their own servers rather than on your device. If you use voice ordering in such a browser, your speech is processed by your browser's provider (for Chrome, Google) under their privacy terms, before any text reaches us. If you would rather that not happen, type your order instead.

Payment data

Card and e-wallet details are entered directly with our payment provider, Stripe, and are handled and stored by Stripe, not by us. No card number ever reaches our systems. What we store is the payment reference, the amount, the status (paid, refunded, failed), and the transaction record Stripe sends us, which can include the billing details you gave Stripe and the last four digits of a card. Stripe's privacy notice: stripe.com/en-my/privacy.

If you run a restaurant on tapow.my

  • Owner and contact details: name, phone number, email, and the phone numbers you authorise to reach your dashboard or receive order alerts
  • Business details: SSM registration number and certificate, SST registration number if applicable
  • Payout details: bank name, account holder name, account number
  • Venue details: address and map pin, storefront photo, menu content and photos

These are collected to verify your business, list your venue, and pay you. Supplying them is a condition of selling on tapow.my; without them we cannot approve an application or make payouts. We are also required by consumer protection regulations to keep records of the businesses selling on the platform.

Collected automatically

Less than you might expect. We run no analytics, no tracking pixels, and no advertising tools, so we do not build a record of the pages you view or a profile of your device.

What does happen is ordinary internet plumbing: our hosting and database providers keep standard server logs of requests made to us, which include IP addresses and timestamps, and we use your IP address momentarily to rate-limit abusive traffic (that counter is held in memory and never stored). Errors are logged so we can fix them.

Received from third parties

We receive delivery status updates and rider details (name, phone number, tracking link) from our courier partner so we can show you where your order is, and payment status events from Stripe so your order and refund status stay accurate.

All personal data you provide must be true, complete, and accurate. Providing someone else's data (for example an alternate recipient's name and address for a delivery) is only allowed if you are authorised to do so.

Section 02

How we use your data

In plain English To get your order cooked, paid for, and to your hands; to run your account; to keep the platform safe; and to meet our legal obligations. Nothing more clever than that.

We process your personal data to:

  • Take and fulfil orders. Send your order to the restaurant, print the kitchen ticket, collect payment, arrange delivery, and show you order status.
  • Run the WhatsApp assistant. Understand your messages, answer questions, build your order, and send you payment links and confirmations.
  • Operate accounts. Log you in via WhatsApp code, keep your saved addresses and order history, and let you manage them.
  • Process refunds and resolve problems. Handle cancellations, refunds, and support conversations.
  • Onboard and pay vendors. Review applications, verify businesses, list venues, and make weekly payouts.
  • Keep the platform safe. Prevent fraud and abuse, secure accounts, and protect the Services.
  • Send service communications. Order confirmations, receipts, and notices about changes to our terms or policies.
  • Improve the Services. Understand usage and fix what's broken, using aggregated or technical data wherever possible.
  • Comply with the law. Tax and accounting record-keeping, consumer protection obligations, and lawful requests from authorities.

We do not use your personal data for third-party advertising, and we only send direct marketing (for example promotions) where the law allows, with a working opt-out every time. See Section 10.

Section 03

Who we share it with

In plain English Only the services that make tapow.my work, and they're all named here. We don't sell your data and there are no ad networks on the platform.

We share personal data with the following classes of recipients, strictly for the purposes described in this notice:

  • The restaurant you order from. Your name, order contents, and for delivery your address and phone number, so they can prepare and hand over your order.
  • Payments: Stripe. Processes every card and e-wallet payment, and refunds. (privacy notice) We expect to add Curlec by Razorpay, a Malaysian payment provider, as an additional payment partner; when live, payments routed through Curlec will be subject to its privacy notice.
  • Database and backend: Supabase. Hosts our database, where orders, accounts, conversations, and vendor records are stored. (privacy notice)
  • AI: Anthropic. Powers our WhatsApp assistant, voice ordering, and vendor dashboard assistant. Your messages or transcribed speech, plus the order context needed to answer, are sent to Anthropic's Claude models to generate responses. (privacy notice)
  • Delivery: Delyva. Receives your name, phone number, delivery address, and pin so a rider can be dispatched to you. (privacy notice)
  • WhatsApp: Meta. Our WhatsApp assistant runs on the WhatsApp Business Platform, so your messages to and from us transit Meta's systems under WhatsApp's own terms and privacy policy. (privacy notice)
  • Address search: Google. When you type or pin an address, the text and coordinates are sent to Google's Places services to find and label the location. Separately, if you use voice ordering in a browser that performs speech recognition on its own servers (Chrome does), your speech reaches that browser's provider before any text reaches us. (privacy notice)
  • Hosting: DigitalOcean. Hosts the web app and this site, and as such sees standard technical logs. (privacy notice)
  • Order notifications: n8n. Where a venue's order alerts are routed through our automation service, the order details needed to raise that alert, including your name, phone number, and delivery address, pass through it. (privacy notice)

A few parts of the Services load from other companies' servers as your page renders. These receive your IP address and the page you are on, because that is how a web request works, but they receive no order or account information: OpenStreetMap for the map tiles behind our address picker (so the area you are pinning is visible to them), rsms.me for the app's typeface, Google Fonts for this legal site's typefaces, and Unsplash for some venue photos.

Beyond these: we may disclose personal data if required by law or a competent authority; and if the business is ever merged, sold, or restructured, personal data may transfer as part of that transaction, under this notice's protections.

We do not sell personal data. We do not share it with advertisers or data brokers.

Section 04

Where your data lives

In plain English tapow.my is run from Malaysia, but some of our providers process data overseas. That's normal for internet services; here's how we keep it protected.

We operate from Malaysia, and some of the service providers named in Section 03 store or process data on servers outside Malaysia (including in the United States, Singapore, and other regions where those providers operate). This means your personal data may be transferred outside Malaysia.

Where that happens, we rely on the grounds permitted by section 129 of the PDPA (as amended): the transfer is necessary to perform our contract with you (for example, processing your payment), or we have taken reasonable precautions and exercised due diligence, including contractual data protection commitments with each provider. Each provider named in Section 03 is bound by its own published data processing terms, and by the PDPA's direct obligations on data processors where applicable.

Section 05

Cookies & local storage

In plain English We use your browser's storage to remember your cart, addresses, and preferences on your own device. No advertising trackers, no third-party analytics pixels.

The Services use browser storage (localStorage and similar) to make things work: your cart, your saved preferences (like delivery or pickup mode), your session when you log in, and device-side copies of things like addresses. Most of this stays on your device and is not a tracking technology.

We use cookies and similar technologies only for essential purposes such as security and keeping you signed in. We do not use third-party advertising cookies, tracking pixels, or ad networks on the Services.

You can clear your browser storage at any time; doing so signs you out and empties device-side data like your cart. Payment pages served by Stripe may set their own cookies for fraud prevention, under Stripe's notice.

Section 06

AI features

In plain English Our WhatsApp assistant and voice ordering run on Anthropic's Claude. Your messages are sent to Anthropic so the assistant can reply. The AI never sets prices, and money only moves when you tap a payment link yourself.

Parts of the Services are powered by artificial intelligence, provided by Anthropic (Claude models):

  • The WhatsApp ordering assistant. Your messages, and the venue and order context needed to answer them, are sent to Anthropic to generate the assistant's replies.
  • Voice ordering on venue menus. Your speech is transcribed in your browser; the transcribed text is processed the same way.
  • Vendor dashboard assistant. Operators can manage their venue conversationally; their messages and venue data are processed the same way.

Three commitments about how we've built these features:

  • The AI never decides what you pay for an order. Every item price is computed by our servers from the venue's menu, and order totals are recalculated and verified server-side before any payment link is issued. The assistant has no way to name a price. (The one place an amount is typed rather than calculated is a venue asking our vendor assistant to raise a scan-to-pay bill for a walk-in customer, where the amount is the venue's own instruction and you see it before you pay.)
  • The AI never takes money from you. Payments happen only when you open a payment page and complete it yourself, and refunds are handled by our systems and our team, never by the assistant.
  • AI output can be wrong. If the assistant says something inconsistent with the priced order summary you're shown before paying, the summary is authoritative. See our Terms.

We use Anthropic under its commercial terms. If you'd rather not interact with AI features, you can order through the web app and reach a human through our support channels (contact page).

Section 07

How long we keep it

In plain English Order and payment records stay as long as tax law requires. Chats, addresses, and accounts don't need to live that long, and we clean up data we no longer need.

We keep personal data only as long as needed for the purposes in this notice. We would rather tell you plainly which of these are automatic today and which we do on request, than imply more machinery than we have:

  • Order and payment records: retained for up to 7 years, because Malaysian tax and accounting law requires it.
  • Login codes: expire within minutes and are automatically deleted within 24 hours. This one runs on a scheduled job.
  • WhatsApp conversations: kept while they are useful for running the assistant, answering support questions, and resolving disputes. We do not yet run an automatic deletion schedule for them, so today they persist until we clear them. You can ask us to delete your conversation at any time and we will.
  • Account data (saved addresses, profile): kept while your account is in use. There is no self-serve delete button yet, so account deletion is something you ask us for, by email or WhatsApp, and we do it by hand, keeping only what the order-record retention above requires. We do not currently run an automatic sweep for dormant accounts.
  • Vendor records: business and transaction records are kept for at least 3 years after a venue leaves the platform, as consumer protection regulations require, and up to 7 years where tax law applies.

Building the missing automatic deletion is work we intend to do, and this section will be updated when it lands rather than before. Where immediate deletion is not possible (for example, database backups), data is isolated from further use until it can be deleted.

Section 08

How we keep it safe

In plain English Encryption in transit, locked-down database access, and card details that never touch our servers. No system is 100% bulletproof, and we'll be straight with you about that.

We take reasonable technical and organisational measures appropriate to the data we hold: encrypted connections (HTTPS) across all Services, database access restricted by row-level security and least-privilege server roles so that tables holding personal data cannot be read by the app's public key at all, session tokens stored hashed, single-use time-limited login links and login codes, and payment card data handled exclusively by Stripe so it never reaches our infrastructure. The one exception to hashed-at-rest is a brief step during WhatsApp login, where a freshly minted session token is held in readable form only until the browser that started the login collects it.

No electronic transmission or storage is guaranteed to be 100% secure, and we cannot promise that unauthorised third parties will never defeat our security. What we can promise is the breach response in Section 11.

Section 09

Minors

In plain English tapow.my is for users 18 and over. If we learn we hold data on someone under 18, we delete it.

The Services are intended for users aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe we hold data on a person under 18, contact us at hello@tapow.my and we will delete it.

Section 10

Your rights under the PDPA

In plain English See your data, fix it, delete it, take it with you, or tell us to stop. Message or email us and we'll handle it within the legal timelines.

Under the PDPA (including the 2024 amendments) you have the right to:

  • Access the personal data we hold about you. We respond within 21 days of a verified request; if we need longer, the PDPA allows one extension of up to 14 days and we will tell you why. A small fee may apply as permitted by the PDPA.
  • Correct data that is inaccurate, incomplete, or out of date. Same timelines as access.
  • Withdraw consent to processing at any time by written notice, after which we stop the processing concerned. This may mean we can no longer provide parts of the Services (for example, we cannot deliver without an address).
  • Stop direct marketing. Tell us once and promotional messages stop; order and service messages continue.
  • Prevent processing likely to cause damage or distress, as provided by section 42 of the PDPA.
  • Data portability. Ask us to transmit your data (such as your profile and order history) to you or another provider in a machine-readable format, where technically feasible.
  • Delete your account and data. Ask us and we deactivate the account and delete personal data not subject to the retention periods in Section 07. This is handled by a person rather than a button today, so allow us the response times below.

How to make a request

Email hello@tapow.my or message our WhatsApp line with the words 'data request' and what you want. We will verify you control the phone number or email on the record before acting, and confirm in writing when done.

If you are unsatisfied with how we handle your personal data, you may complain to the Personal Data Protection Commissioner of Malaysia (pdp.gov.my). We'd appreciate the chance to fix it first.

Section 11

If something goes wrong

In plain English If a data breach happens that could seriously harm you, we notify the regulator within 72 hours and tell you directly within 7 days after. No burying it.

If a personal data breach occurs that causes or is likely to cause significant harm, we will notify the Personal Data Protection Commissioner as soon as practicable and within 72 hours, and notify affected users without unnecessary delay and within 7 days of notifying the Commissioner, in each case as required by section 12B of the PDPA. We maintain an internal register of data breaches, including those below the notification threshold.

Section 12

Updates to this notice

In plain English We update this from time to time. Material changes get a heads-up before they take effect.

We may update this notice as the Services and the law evolve. The 'Last updated' date at the top changes with every revision. If we make material changes, we will notify you before they take effect, by a prominent notice on the Services or a direct message (WhatsApp or email).

Section 13

How to contact us

In plain English Easiest way: WhatsApp us, or email hello@tapow.my. Mail also works if you prefer paper.

For anything in this notice, including data protection inquiries and complaints (the contact point required by the PDPA's Notice and Choice Principle):

Reach the team
Yes Can Do Sdn Bhd
WhatsApp
Registration no.
202101022325 (1422625-W)
Registered address
7-2, Plaza Danau 2, Jalan 2/109f,
Taman Danau Desa, Kuala Lumpur 58100, Malaysia