Privacy Policy
Last updated: 13 September 2026
This Privacy Policy explains how Ideal Link Solutions (Company No. 200703103919 / 001690762-V), trading as LoyaltyPoint ("LoyaltyPoint", "we", "us", "our"), collects, uses, discloses and protects personal data. We are committed to handling personal data in accordance with Malaysia's Personal Data Protection Act 2010 (PDPA) and its subsequent amendments.
This policy applies to our website loyalty2u.com and to the LoyaltyPoint loyalty platform (the "Service"). By using the Service or providing us with personal data, you agree to the practices described here.
1. Who this policy covers
- Retailers / merchants who register for and use LoyaltyPoint, and their staff.
- Partners who refer retailers to us.
- Website visitors.
- End customers of our retailers, whose data is processed on behalf of the retailer (see section 6).
2. Personal data we collect
From retailers, partners and their staff
- Business name, contact name, email address and phone number.
- Login credentials (passwords are stored in encrypted / hashed form).
- Outlet details and loyalty programme settings.
- Billing and payment reference information for subscriptions.
From website visitors
- Information you submit through forms (e.g. enquiries, partner applications).
- Technical data such as IP address, browser type and usage data collected via cookies and similar technologies (see section 7).
3. How we use personal data
- To create and administer your account and provide the Service.
- To process subscriptions, trials, invoices and payments.
- To provide customer support and respond to enquiries.
- To send service-related communications (e.g. account, billing and security notices).
- To improve, secure and develop the Service.
- To comply with legal, tax and regulatory obligations.
- To send marketing communications where you have consented; you may opt out at any time.
4. Legal basis for processing
- Consent — where you have agreed to a specific use, such as marketing.
- Performance of a contract — to deliver the Service you signed up for.
- Legal obligation — to meet accounting, tax and other statutory requirements.
- Legitimate interests — to operate, secure and improve our business, balanced against your rights.
5. Disclosure of personal data
We do not sell your personal data. We may share it only with:
- Service providers that help us run the Service — for example hosting, email delivery, messaging (e.g. WhatsApp), and payment processing — under confidentiality and data-protection obligations.
- Professional advisers and authorities where required by law or to protect our legal rights.
- A successor entity in the event of a merger, acquisition or business transfer.
6. End-customer data (our role as data processor)
When a retailer uses LoyaltyPoint to run their loyalty programme, the retailer collects personal data from their own customers (such as name, phone number, email and birthday). For that data, the retailer is the data controller and LoyaltyPoint acts as a data processor, processing it only to provide the Service on the retailer's instructions.
Retailers are responsible for obtaining valid consent from their customers and for providing their own privacy notice. LoyaltyPoint provides a ready-made customer privacy notice and a consent step to help retailers meet this obligation.
7. Cookies
Our website uses cookies and similar technologies for essential functionality, to remember preferences (such as your chosen language), and to understand how the site is used. You can control cookies through your browser settings; disabling some cookies may affect how the site works.
8. Data retention
We keep personal data for as long as your account is active and as needed to provide the Service. After account closure we retain data only as long as necessary for legitimate business and legal purposes. Financial and transaction records may be retained for up to 7 years to meet accounting and tax requirements.
9. Data security
We apply reasonable technical and organisational measures to protect personal data against unauthorised access, loss, misuse or alteration, including encrypted connections (HTTPS), access controls and secure hosting. No system is completely secure, but we work to protect your data and to address any incidents promptly.
10. International transfers
Where personal data is stored or processed outside Malaysia by our service providers, we take steps to ensure it receives a comparable level of protection as required under the PDPA.
11. Your rights under the PDPA
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to correct inaccurate or incomplete data.
- Withdraw consent — withdraw consent for uses that rely on it, such as marketing.
- Limit processing — request that we limit certain processing.
- Deletion — request deletion of your data, subject to our legal retention obligations.
To exercise these rights, contact us using the details below. End customers of a retailer should contact that retailer directly, as the controller of their data.
12. Changes to this policy
We may update this Privacy Policy from time to time. The latest version will always be available on this page, with the "Last updated" date revised accordingly.
13. Contact us