Rujukan Laman

How apk8d Handles Your Personal Data

At apk8d, we are transparent about what personal data we collect from your account, how we use it, and how long we keep it — because your trust…

Data collected only as neededTouch 'n Go & GrabPay transaction privacyYour right to access or delete dataNo third-party selling of your detailsSecure encrypted storage
apk8d How apk8d Handles Your Personal Data
REACH OUR PRIVACY TEAM

Contact Us About Your Data

If you have questions about this policy, want to request a copy of your stored data, or need to ask us to correct or delete information…

Email Privacy Request Send a written data request or correction notice to our dedicated privacy inbox.
Live Chat Support Start a live chat session directly from your account dashboard.
In-Account Support Ticket Log a formal support ticket from the Help section of your account.
DATA HANDLING STANDARDS

Explore How We Protect Account Data

We apply specific technical and procedural controls at every stage of your data lifecycle — from the moment you key in your details at registration through to the point where your account…

Encrypted Data Storage

All account data — including payment identifiers for Touch 'n Go, GrabPay, Boost dan FPX — is stored using AES-256 encryption at rest. Only authorised system processes can read this data, and access is logged with a full audit trail.

Cookie Controls

We use session cookies to keep you logged in securely and analytics cookies to understand how pages are used. You can manage your cookie preferences at any time from the settings panel inside your account without affecting core functions.

Account Security Practices

Your account is protected by hashed passwords and optional two-factor authentication sent to your registered mobile number. We never store your password in plain text, and login attempts from unrecognised devices trigger a verification step automatically.

Data Retention Schedule

We keep your active account data for as long as your account remains open. After closure, we retain only the minimum records required under applicable Malaysian financial regulations, and we delete everything else within 90 days of your account closure date.

Third-Party Data Sharing

We share your data only with payment processors needed to complete your Touch 'n Go, GrabPay, Boost or FPX transactions, and with identity-verification services where local law requires it. We do not sell your data to marketers or data brokers under any circumstances.

Your Right to Request Changes

You may request a full copy of your stored data, ask us to correct inaccurate details, or request deletion of your account and associated records at any time by contacting our privacy team through the channels listed on this page.

Switch Through Your Privacy Policy Questions

These are the questions our account holders ask most often about how we collect, store and handle personal data. If your question is not covered here, open a support ticket from your account and our privacy team will get back to you within two business days.

We collect your name, email address, phone number, and the payment identifiers linked to your chosen method — such as your Touch 'n Go wallet ID or GrabPay reference. We also log device and session data to secure your login.

Payment identifiers from Touch 'n Go, GrabPay, Boost dan FPX are encrypted at rest using AES-256. They are passed to payment processors over TLS-secured connections and are never stored alongside your account password or login credentials.

Yes. Send a data access request to our privacy email or log a support ticket from your account. We will compile and send you a copy of your stored personal data within two business days of verifying your identity.

Contact our privacy team via email or in-account ticket and state that you want your data deleted. We will remove your personal data within 90 days of account closure, keeping only the minimum records required by applicable Malaysian law.

Only with the payment processors needed to complete your transactions and with identity-verification services where local law requires it. We do not sell your information to advertisers, data brokers, or any unrelated third parties.

We delete non-essential personal data within 90 days of account closure. Records required under applicable Malaysian financial regulations are retained only for the duration mandated by those regulations, then permanently deleted.

When you add a new payment method, the new identifiers are encrypted and stored. Old payment identifiers you remove are flagged for deletion and purged from active storage within 30 days unless retained as required by applicable local law.