Privacy Policy

Your privacy is our foundation. Learn how PayPing MY protects your financial data with our privacy-first architecture.

Our Privacy Commitment

At PayPing MY, privacy isn't just a feature—it's the foundation of our entire architecture. We've built our app from the ground up to ensure your financial data stays where it belongs: on your device, under your control.

🔒 Privacy-First Architecture

Your financial transaction data is NEVER stored in the cloud. All transaction amounts, balances, and financial details are stored locally on your device only. Our cloud infrastructure handles notification delivery but never permanently stores your financial information.

1. Information We Collect

1.1 Data Stored Locally on Your Device

The following data is stored ONLY on your device using encrypted local storage (AsyncStorage):

Important: This data NEVER leaves your device. It is not backed up to the cloud, not synchronized with our servers, and not accessible to PayPing MY or any third parties.

1.2 Data Stored in Our Cloud Database (Supabase)

We only store the minimum information necessary for app functionality:

What we DON'T store in the cloud: Transaction amounts, balances, transaction types, or any financial details from your notifications.

1.3 Data That Passes Through (But Is Not Stored)

When sharing notifications across devices, the following data passes through our AWS infrastructure but is NOT permanently stored:

This data is transmitted through AWS API Gateway and SQS queue for delivery to Firebase Cloud Messaging, then immediately deleted. It exists in our infrastructure for seconds only, not permanently.

2. How We Use Your Information

2.1 Local Device Processing

2.2 Cloud Services

2.3 What We DON'T Do

3. Data Sharing and Third-Party Services

3.1 Third-Party Service Providers

We use the following trusted third-party services, each with their own privacy policies:

Service Purpose Data Shared
Supabase (PostgreSQL) User authentication, preferences, device tokens Email, name, user ID, FCM tokens, preferences
Firebase Cloud Messaging (FCM) Push notifications to paired devices Device tokens, notification content (ephemeral)
AWS (API Gateway, SQS, Lambda) Notification routing and delivery Notification content (ephemeral, not stored)
Google Sign-In (Optional) OAuth authentication Email, name, profile picture (if you choose Google Sign-In)

3.2 No Advertising or Analytics

PayPing MY does NOT use:

3.3 User-Initiated Exports

If you choose to use optional export features (Pro plan):

These features are opt-in and under your full control.

4. Data Security

4.1 Technical Security Measures

4.2 Infrastructure Security

4.3 Access Controls

5. Data Retention and Deletion

5.1 Local Device Data

You can manually clear your local transaction history at any time from Settings.

5.2 Cloud Data

5.3 Account Deletion

You can request account deletion at any time:

6. Your Rights (PDPA Compliance)

Under Malaysia's Personal Data Protection Act 2010 (PDPA), you have the following rights:

6.1 Right to Access

6.2 Right to Correction

6.3 Right to Erasure

6.4 Right to Data Portability

6.5 Right to Withdraw Consent

To exercise any of these rights, contact us at privacy@payping.my

7. Children's Privacy

PayPing MY is not intended for use by children under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately so we can delete it.

8. International Data Transfers

Your data is stored and processed in:

We do not transfer data outside of Southeast Asia. All service providers comply with international data protection standards.

9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

We will notify you of material changes by:

Continued use of PayPing MY after changes constitutes acceptance of the updated policy.

10. Contact Us

Privacy Questions or Concerns?

We're committed to transparency and protecting your privacy. If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data:

Email: privacy@payping.my
Data Protection Officer: dpo@payping.my
General Support: support@payping.my

Mailing Address:
PayPing MY
[Address to be added]
Malaysia

We will respond to all privacy requests within 30 days as required by PDPA.

11. Compliance and Certifications

PayPing MY is committed to compliance with:

Last Updated: January 15, 2025

Effective Date: January 15, 2025

Version: 1.0