Privacy Policy

Last updated: 21 September 2026

1. Introduction

This Privacy Policy explains how Setia Rewards collects, uses, and protects information shared by Merchants and their customers while using our platform.

2. Data We Collect

We collect: (a) Merchant business and staff account information (name, email, phone number, encrypted password); (b) customer names and phone numbers registered via outlet QR scans; and (c) stamp transaction and reward redemption records.

3. How We Use Data

Data is used solely to operate the core functions of the Service — verifying account identity, tracking stamp card progress, issuing and redeeming vouchers, and helping Merchants understand their customers' visit patterns.

4. Data Sharing

We do not sell or share your data with third parties for marketing purposes. When payment integration (e.g. AffinPay) is enabled in the future, payment information will be processed directly by that gateway provider under their own privacy policy.

5. Cookies

We use a session cookie to maintain login state, and one convenience cookie (last phone number used) to speed up the customer stamp check-in process. No third-party advertising tracking cookies are used.

6. Data Security

Passwords are stored in encrypted hashed form. Access to Merchant data is restricted by role-based access so staff can only access the functions they are permitted to use.

7. Data Retention

Data is retained for as long as the Merchant account remains active. Merchants may request data deletion by emailing us, subject to record-keeping requirements for audit or legal purposes.

8. Your Rights

You have the right to request access to, correction of, or deletion of your personal information. Please contact us via our Contact Us page to make such a request.

9. Changes to This Policy

This Privacy Policy may be updated from time to time. The "Last updated" date above reflects the current version of this policy.

Have questions about this policy? Contact us at Contact Us.
BM EN