Legal
Privacy Policy
This Privacy Policy and Personal Data Protection Notice explains how Platehaus Sdn. Bhd. (SSM 202501045049), the operator and data controller for Platehaus MyQR / MyQRContact, collects, uses, discloses, stores, protects, transfers, and retains personal data when you buy, activate, install, scan, access, or use MyQR.
It should be read together with the Platehaus MyQR Terms of Service. For any privacy question or data subject request, contact support@platehaus.my.
1. Scope and roles
1.1 This Privacy Policy explains how Platehaus collects, uses, discloses, stores, protects, transfers, and retains personal data when you buy, activate, install, scan, access, or use Platehaus MyQR, including physical QR windshield stickers and activation codes; MyQRContact scan and owner-contact flows; Car Dashboards and vehicle records; dashboard invitations and access requests; Telegram bot setup, test alerts, and contact alerts; and reports, support requests, emails, APIs, and related websites.
1.2 This policy applies to Owners, Scanners, Authorized Users, access requesters, invited users, fleet users, business customers, administrators, support users, emergency contacts, and anyone else whose personal data is processed through MyQR.
1.3 Platehaus Sdn. Bhd. is the data controller for personal data that Platehaus decides how and why to process for MyQR. Service providers that process personal data on our behalf act as processors or service providers, depending on the context.
1.4 Owners, Business Customers, fleet operators, employers, property managers, parking operators, and other users may also be responsible for their own collection, disclosure, upload, access approval, and use of third-party personal data through MyQR. You must not provide another person’s personal data unless you have a lawful basis, authority, consent, or legitimate reason to do so.
1.5 This policy should be read with the Platehaus MyQR Terms of Service.
2. Malaysian Personal Data Protection Notice
2.1 This policy is intended to operate as a personal data protection notice for MyQR. We process personal data in line with Malaysia’s Personal Data Protection Act 2010, as amended from time to time, including the principles of consent, notice and choice, disclosure, security, retention, data integrity, and access.
2.2 Where required, this notice should be made available in both English and Bahasa Malaysia. If there is any inconsistency between language versions, the English version applies unless applicable law requires otherwise.
2.3 Where applicable, we will update this policy, our privacy practices, and related notices to reflect Malaysian requirements on data controllers, data processors, data protection officers, data breach notification, data portability, cross-border transfers, security standards, registration, and other obligations.
3. Personal data we collect
3.1 Account and profile data
We may collect user ID; name; email address; phone number; username; authentication and login metadata; account status; support history; role and permission data; and profile snapshots used for invitations, approvals, reports, safety, and audit records.
3.2 Purchase, Sticker, and activation data
We may collect purchase and delivery information for the physical Sticker; Activation Code; code status, generation date, activation date, disabled status, and related user ID; number plate entered during activation; activated plate display, prefix, number, suffix, and system plate ID; vehicle nickname or related voluntary labels; date and time of activation; and consent timestamp and consent-version records.
3.3 Scanner and Contact Event data
When someone scans a Sticker, enters a plate, or tries to contact an Owner, we may collect the entered number plate; whether the entered plate matched an activated plate; Contact Event ID; selected contact reason and method; Contact Event status and timestamps; logged-in user ID (if the Scanner is logged in); Privacy Policy and Terms consent timestamps and versions; IP address; user agent; referrer; approximate location from network or hosting headers (such as country, region, city, latitude, longitude, and timezone where available); request and network security metadata (such as request IDs, route path, search parameter names without their values, host/origin, hosting edge IDs, proxy forwarding headers, IP source, hashed IP identifier, network ASN or organization where available, and Cloudflare or hosting request identifiers where available); scan session and source attribution metadata (such as per-tab scan session ID, session sequence, entry page, referrer page, QR/sticker/source parameters, UTM parameters, advertising click IDs where present, active element context, navigation timing, and page visibility state); browser and device metadata (such as accept-language, client hints, platform, mobile indicator, timezone, timezone offset, viewport size, screen size, color depth, touch capability, hardware concurrency, approximate network connection information, cookie/storage capability, secure-context status, and other client-submitted browser metadata); security correlation identifiers (such as salted hashes generated from IP address and selected browser/device metadata for abuse detection); privacy and browser preference signals where available (such as Do Not Track and Global Privacy Control); lookup metadata (such as match status, visual alias match, and ambiguous match count); action traces for reason selection, contact-method selection, direct contact redirect, and Telegram alert requests; direct contact redirect timestamps; Telegram delivery status, message ID, failure status, and error metadata; and report data if the Contact Event is reported.
3.4 Owner, driver, and emergency contact setup data
For contact setup, we may collect owner or driver name; phone country calling code, national number, and E.164 phone number; preferred contact methods (such as phone call, WhatsApp, or Telegram); emergency contact name, country calling code, national number, and E.164 phone number; setup completion date; created-by and updated-by user IDs; and Telegram status.
3.5 Telegram bot data
If you connect Telegram, we may collect Telegram chat ID, user ID, username, first name and last name; connection status; notification-understanding timestamp; connection timestamp; notification-confirmation timestamp; test-alert sent timestamp; last delivery error and error timestamp; Telegram connect token hash, token expiry, and consumption timestamp; Telegram message IDs; alert payloads and delivery status; and webhook and bot interaction metadata needed to operate the bot securely.
3.6 Car Dashboard Records
If you add vehicle records, we may collect the number plate linked to the Dashboard; record type (such as road tax, insurance, service, oil and fluids, tyres and wheels, battery, brakes, air conditioning, repairs, accident claims, mileage, accessories, or notes); title; data fields entered; notes; dates, date ranges, and date-known type; reminder preferences, intervals, and next reminder date; creation and update timestamps; and user actions related to creating, editing, or deleting records.
3.7 Attachments and files
If you upload documents or images to vehicle records, we may collect file name, file size, MIME type, file storage path, upload timestamp, private signed URL generation metadata, and the image or PDF content you upload (such as receipts, service records, insurance documents, road-tax documents, photos, or other vehicle documents). You should avoid uploading unnecessary personal data, identity documents, payment details, passwords, sensitive personal data, or third-party data. Redact information that is not needed for your vehicle record.
3.8 Invitations, access requests, and Dashboard access data
We may collect invited email address; invited role; invitation token and status; inviter user ID; accepted-by user ID and accepted timestamp; requester user ID and profile snapshot; access request status; approval token; approver user ID and approval timestamp; Dashboard role (such as owner, editor, viewer, or administrator); access status; and access removal records.
3.9 Reports, support, abuse, and admin data
We may collect report reason text; reported Contact Event details; reporting user ID; admin review data; email and support communications; safety, abuse, fraud, security, and enforcement notes; error logs and diagnostics; and operational records needed to investigate or respond to incidents.
3.10 Cookies, analytics, and site data
MyQR may use cookies, local storage, analytics, security tools, hosting logs, and similar technologies. These may process page views, event data, IP address, user agent, referrer, device information, session data, and similar usage data. If site-wide Platehaus analytics tools are active on MyQR pages, their data processing is also described in the general Platehaus Privacy Policy and Cookie Policy, unless a MyQR-specific notice says otherwise.
4. Sources of personal data
We collect personal data directly from you when you buy, activate, enter a plate, choose a contact reason, choose a contact method, set up contact details, connect Telegram, upload records, invite users, request access, report events, or contact support; automatically from your browser, device, network, and request headers; from authentication, hosting, database, storage, email, Telegram, analytics, and security providers; from other users, such as Owners inviting you, access requesters sending profile snapshots, or Owners adding emergency contact details; and from administrative review, abuse reports, and support investigations.
5. Purposes of processing
We process personal data to sell, deliver, replace, support, and manage MyQR Stickers; activate number plates and prevent duplicate or unauthorized activation; connect a scanned number plate to the correct Dashboard; create and manage Contact Events; let Scanners choose a reason to contact an Owner; provide enabled contact methods, such as phone call, WhatsApp, and Telegram; send Telegram setup test alerts and contact alerts; confirm that Telegram notifications were understood and tested during setup; maintain Dashboard records, reminders, and attachments; provide private file storage and signed attachment links; manage Owners, editors, viewers, invitations, and access requests; notify Owners about access requests and invitations; detect, prevent, investigate, and respond to harassment, scams, stalking, baiting, spam, false reports, scraping, fraud, unauthorized access, security incidents, and other abuse; maintain consent, audit, security, and evidential logs; provide customer support; debug, secure, monitor, improve, and operate the Service; comply with law, regulations, court orders, authority requests, accounting, audit, and legal obligations; enforce the MyQR Terms of Service; protect the rights, safety, property, and legitimate interests of Platehaus, users, vehicle owners, drivers, Scanners, and the public; and send service notices and, where permitted, marketing or product communications with opt-out choices.
We do not sell your personal data.
6. Consent, necessity, and required data
6.1 We process personal data where you consent, where processing is necessary or directly related to providing MyQR, where processing is necessary for legal claims, investigation, safety, compliance, or protection of rights, or where applicable Malaysian law otherwise permits.
6.2 Some data is required to provide MyQR. For example, a number plate and Activation Code are required to activate a Sticker; consent records are required before activation, contact flows, direct contact disclosure, or access requests; phone details are required if you enable phone or WhatsApp contact; Telegram identifiers are required if you enable Telegram alerts; contact reason and Contact Event data are required to notify an Owner; Dashboard access data is required to manage roles and permissions; and security metadata is required to detect abuse, scraping, unauthorized access, fraud, and attacks.
6.3 If you do not provide required data, you may not be able to activate a Sticker, contact an Owner, receive alerts, save setup, invite users, request access, or use certain features.
6.4 Some data is optional, such as certain Dashboard Records, notes, attachments, reminders, and contact methods. If you choose to provide optional data, we process it under this policy.
6.5 Where processing is based on consent and you withdraw consent, we will stop the relevant processing where required by law, but this may affect your ability to use the Service. We may still process data where another legal basis or statutory exception applies, including for security, legal claims, compliance, audit, dispute, abuse prevention, or evidence.
7. Data about other people
7.1 You must not provide another person’s personal data unless you have a lawful basis, authority, consent, or legitimate reason to do so.
7.2 If you add emergency contact details, employee contact details, fleet contact details, family contact details, driver details, or third-party documents, you are responsible for informing those people where required and ensuring that the information is accurate and appropriate for MyQR.
7.3 Do not upload unnecessary third-party personal data, identity documents, payment credentials, medical information, biometric data, children’s data, or sensitive information. Redact unnecessary information before uploading vehicle documents.
8. Who can see or receive data
8.1 Owners and Authorized Users
Owners and Authorized Users with Dashboard access may see Dashboard data for the relevant number plate, depending on role and product configuration. This may include Records, attachments, Contact Events, approximate location data, metadata, reports, access users, invitations, and access requests.
8.2 Scanners
Scanners may see only the contact flow and feedback needed to complete the scan and selected contact method. If phone call or WhatsApp is enabled, a logged-in Scanner may be redirected to the Owner’s phone number or WhatsApp link. If Telegram is enabled, the Scanner does not receive the Owner’s phone number through the Telegram contact flow.
8.3 Invited users and access requesters
Invited users may see invitation details needed to accept access. Owners and eligible Authorized Users may see access request details, including requester profile snapshots and request status.
8.4 Service providers
We may disclose personal data to service providers that help us operate MyQR, including providers for hosting and serverless functions; database, authentication, and storage; email delivery; Telegram bot messaging; analytics and performance monitoring; security, abuse prevention, logging, and error monitoring; customer support; payment, delivery, and order administration for physical Stickers; and professional services such as legal, accounting, audit, insurance, and corporate advisers. Service providers may process data in Malaysia or other countries, depending on their infrastructure. We use reasonable contractual, technical, and organizational controls appropriate to the provider and processing risk.
8.5 Authorities, safety, legal claims, and business transfers
We may disclose data if we believe disclosure is reasonably necessary to comply with law, court orders, regulator requests, police requests, or legal process; prevent or investigate harassment, stalking, scams, threats, crime, abuse, security incidents, or fraud; protect life, safety, property, legal rights, or public interest; enforce our Terms; respond to disputes, insurance matters, or legal claims; or support a merger, acquisition, financing, restructuring, sale of assets, or transfer of the MyQR business, subject to appropriate confidentiality and continuity protections.
9. Direct phone, WhatsApp, and Telegram visibility
9.1 If you enable direct phone call or WhatsApp, your phone number may be disclosed through the contact flow to a Scanner and to the relevant third-party app, browser, device, telecommunications network, or service provider.
9.2 If you enable Telegram, Telegram will process your Telegram account and chat data according to Telegram’s own terms and policies. The Telegram flow is designed not to reveal your phone number to the Scanner through MyQR, but Telegram delivery and Telegram’s own processing are outside Platehaus’s full control.
9.3 We may use confirmation prompts, warnings, test alerts, and consent-version records to show that contact-method visibility and notification limitations were explained.
10. Cross-border transfers
10.1 MyQR uses cloud, hosting, messaging, database, storage, email, analytics, security, payment, logistics, and support providers that may process or access data outside Malaysia.
10.2 Where personal data is transferred outside Malaysia, we will take reasonable steps intended to protect the data in line with Malaysian personal data protection requirements. These may include giving notice of the transfer and its purposes; relying on consent where required or appropriate; relying on transfer necessity for the Service where applicable; assessing whether the receiving jurisdiction or recipient provides appropriate protection; taking reasonable precautions and exercising due diligence before and during transfers; using contracts with processors and service providers that address security, confidentiality, permitted use, and return/deletion where appropriate; limiting data transferred to what is necessary; and keeping appropriate transfer records.
10.3 Third-party services such as Telegram, WhatsApp, hosting providers, analytics providers, payment providers, logistics providers, and email providers may operate globally and may be subject to their own terms, policies, and legal requirements.
11. Security
11.1 We use administrative, technical, and organizational safeguards intended to protect personal data. Current product controls include account-based authentication for Dashboard access; role-based Dashboard access for owners, editors, viewers, and administrators; database row-level security policies; service-role restricted server operations; private file storage for attachments; short-lived signed URLs for Dashboard attachments; attachment size limits; image and PDF attachment restrictions; SVG upload blocking; token-based invitations and access approvals; hashed Telegram connect tokens; Telegram webhook secret verification; Telegram notification test and confirmation steps; bot verification on public contact entry points; scan, lookup, direct-contact, and Telegram alert rate limits; safety warnings in scanner and owner-facing contact flows; consent-version records; contact-event reporting workflows; audit logs for sensitive actions; and incident review and support escalation workflows.
11.2 No method of transmission or storage is completely secure. We cannot guarantee that unauthorized access, loss, misuse, or security incidents will never occur.
11.3 You are responsible for keeping your account, phone, email, Telegram account, device, passwords, and Dashboard invitations secure.
12. Data breach handling
12.1 If we believe a personal data breach has occurred, we will assess the incident, take reasonable containment and remediation steps, and notify the Malaysian Personal Data Protection Commissioner and/or affected data subjects where required by law.
12.2 Where a personal data breach must be notified to the Commissioner, we will make the required notification as soon as practicable and within the applicable statutory or regulatory timeframe.
12.3 Where affected data subjects must be notified, we will make the required notification without unnecessary delay and within the applicable statutory or regulatory timeframe.
12.4 We may provide information in phases where permitted, document reasons for any delay, and take steps such as credential resets, access restrictions, contact-method disablement, system isolation, forensic review, service-provider escalation, and user warnings.
12.5 We may ask for additional information to verify identity, secure an account, investigate suspicious activity, or reduce risk.
13. Retention
13.1 We keep personal data only as long as reasonably necessary for the purposes described in this policy, unless a longer period is required or permitted for legal, audit, accounting, tax, security, fraud prevention, dispute, evidence, abuse-prevention, service-continuity, backup, or enforcement reasons.
13.2 Our intended retention approach is:
- Account and profile data — while the account is active, then up to 7 years where needed for legal, dispute, abuse, tax, audit, or operational records.
- Physical Sticker purchase and delivery records — up to 7 years or longer if required by law, tax, accounting, dispute, or warranty needs.
- Activation Code and number plate activation records — for the life of the activated Sticker/Dashboard, then up to 7 years where needed for legal, abuse, support, or audit records.
- Owner, driver, emergency contact, and preferred contact settings — while the Dashboard is active or until updated/deleted, subject to backups and legal retention.
- Contact Events that result in contact attempts — usually up to 24 months for safety, abuse prevention, reports, audit, support, legal claims, and product integrity, unless longer retention is needed.
- Scan and lookup security metadata without a completed contact event — usually 90 to 365 days, unless linked to abuse, reports, fraud, security, disputes, or legal needs.
- Telegram connect tokens — active for a short setup period; expired or consumed tokens may be retained as security/audit records.
- Telegram connections and alert logs — while Telegram is connected and as needed for delivery audit, support, abuse prevention, and legal records.
- Dashboard Records and attachments — until deleted by an authorized user or Dashboard closure, subject to backups and legal retention.
- Invitations and access requests — while pending/active and as needed for audit, support, abuse prevention, and legal records.
- Reports and abuse records — as long as needed to investigate, enforce, prevent repeated abuse, protect legal rights, and assist lawful requests; serious cases may be retained up to 7 years or longer where required.
- Server, security, and diagnostic logs — usually 90 to 365 days, unless longer retention is needed for security, fraud, legal, or operational reasons.
- Consent records and legal version history — as long as needed to prove acceptance, consent, notice, compliance, legal claims, and dispute handling.
- Backups — retained on rolling backup cycles according to provider and operational settings.
13.3 When personal data is no longer required, we will take reasonable steps to delete, destroy, anonymize, or restrict it, subject to technical feasibility, backup cycles, and legal needs.
14. Your choices
You may choose whether to activate a Sticker; which contact methods to enable, subject to setup requirements; whether to enable phone, WhatsApp, Telegram, or none of them; whether to upload optional Records or attachments; who to invite or approve for Dashboard access; whether to disconnect or disable Telegram; whether to report suspicious Contact Events; whether to receive optional marketing where applicable; and whether to request deletion, correction, access, withdrawal, restriction, or export, subject to verification and legal limits.
If you enable direct phone call or WhatsApp, your phone number may be disclosed through those contact flows. If you enable Telegram, Telegram will process your Telegram account and chat data according to Telegram’s own terms and policies.
15. Your rights
15.1 Subject to Malaysian law and verification of your identity, you may request access to personal data we hold about you; correction of inaccurate, incomplete, misleading, or outdated personal data; withdrawal of consent where processing is based on consent; limitation, cessation, or non-commencement of certain processing where applicable; prevention of processing that is likely to cause damage or distress where applicable; prevention of processing for direct marketing; deletion of data where retention is no longer required and deletion is legally and technically feasible; a copy or export of certain data where technically feasible, including data portability where applicable; and information about our data practices.
15.2 We may refuse or limit a request where permitted by law, including where needed for legal claims, safety, fraud prevention, abuse investigation, security, other users’ rights, confidential information, backups, technical infeasibility, or compliance obligations.
15.3 We may charge any fee permitted by law for data-access requests and may require information reasonably necessary to verify your identity and locate the relevant data.
15.4 To make a request, contact support@platehaus.my.
16. Cookies, analytics, and tracking preferences
16.1 MyQR may use cookies, local storage, session storage, analytics tools, security tools, hosting logs, and similar technologies for login, security, abuse prevention, rate limiting, analytics, debugging, product improvement, and service operation.
16.2 You may adjust browser settings to block or clear cookies. Some features may not work properly if cookies, local storage, scripts, or security tools are blocked.
16.3 We may receive browser privacy signals such as Do Not Track or Global Privacy Control where available. Not all signals are standardized or technically actionable for every function. We will handle legally required opt-outs and consent choices through available product or support mechanisms.
17. Marketing and service messages
17.1 We may send service messages, safety messages, security alerts, legal notices, support replies, activation messages, Telegram setup messages, contact alerts, and product-operation communications. These are part of the Service and may not be fully optional.
17.2 We may send optional marketing or product updates where permitted by law. You may opt out of direct marketing using the unsubscribe method in the message or by contacting support@platehaus.my.
17.3 Opting out of marketing does not stop service, safety, support, legal, security, or transactional messages.
18. Children and minors
18.1 MyQR accounts, activation, purchase, and Dashboard management are not intended for persons under 18.
18.2 A minor may use the public scan flow only with appropriate authority or where reasonably necessary for a genuine vehicle-related safety or contact issue.
18.3 If we discover that a minor has used the Service without appropriate authority, we may delete or restrict the data and account where appropriate.
18.4 Owners must avoid uploading personal data about children unless strictly necessary and lawful.
19. Sensitive personal data
19.1 Do not upload sensitive personal data unless it is strictly necessary and you have a lawful basis or express consent where required. This includes identity documents, health information, biometric data, financial account credentials, passwords, criminal allegations, religious or political information, or other highly sensitive information.
19.2 If you upload vehicle documents, review and redact unnecessary personal data before uploading.
19.3 If we identify sensitive personal data that appears unnecessary, unsafe, unlawful, or excessive, we may restrict, remove, or ask you to redact it.
20. Accuracy
20.1 You are responsible for keeping your account, phone number, Telegram connection, emergency contact details, number plate, and Dashboard Records accurate and current.
20.2 We may ask you to confirm, correct, or verify information if it appears inaccurate, unsafe, incomplete, or disputed.
20.3 If you believe personal data shown in MyQR is inaccurate or has been linked to the wrong number plate or account, contact support@platehaus.my promptly.
21. Data Protection Officer and privacy lead
21.1 For privacy questions and data subject requests, contact support@platehaus.my.
21.2 If Platehaus is required by law to appoint or register a Data Protection Officer for MyQR, or if Platehaus voluntarily appoints one, Platehaus will maintain and publish the required business contact details through this page, another privacy page, or another appropriate notice.
22. Third-party links and apps
22.1 MyQR may link to or interact with third-party services such as Telegram, WhatsApp, phone dialer apps, email providers, browsers, maps, payment providers, delivery providers, analytics providers, cloud providers, or external websites.
22.2 Those third parties have their own privacy practices. We are not responsible for their policies, security, availability, or processing except where applicable law says otherwise.
23. Changes to this policy
23.1 We may update this Privacy Policy from time to time.
23.2 If changes materially affect how we process personal data, we will use reasonable efforts to notify users by website notice, in-app notice, consent prompt, email, or another reasonable method.
23.3 Where required, we may request fresh consent and update the consent-version identifiers stored by the Service.
24. Contact and complaints
For privacy questions, access or correction requests, withdrawal requests, deletion requests, data-portability requests, safety reports, or data complaints:
Email: support@platehaus.my
Operator: Platehaus Sdn. Bhd. (SSM: 202501045049)
Registered Address: CT-06-21 Subang Square Corporate Tower, Jalan SS15/4G, SS15, 47500 Subang Jaya, Selangor, Malaysia
You may also have the right to complain to the Malaysian Personal Data Protection Commissioner where applicable.