Privacy Policy
Last updated: 14 March 2026
1. Introduction
Perlu Kopi ("we", "our", or "us") is committed to protecting your personal data in accordance with the Personal Data Protection Act 2010 (PDPA) of Malaysia. This policy explains how we collect, use, and safeguard your information when you use our website and mobile application.
2. Information We Collect
We collect the following types of information:
- Account information: Name, email address, and password when you register.
- Brewing data: Bean collections, brew recipes, brew sessions, ratings, and tasting notes you choose to log.
- Profile information: Username and any optional profile details you provide.
- Usage data: Anonymous analytics data such as pages visited and features used.
3. How We Use Your Information
- To provide and maintain our service, including your personal brewing journal.
- To display your public profile and shared bean collections, if you opt in.
- To improve our platform based on aggregated, anonymised usage patterns.
- To send important service updates (e.g., security notices).
4. Data Sharing
We do not sell your personal data. We may share data only in these circumstances:
- Public profiles: If you enable a public profile, your username and public bean collections are visible to others.
- Service providers: We use third-party services (hosting, error tracking) that process data on our behalf under strict agreements.
- Legal requirements: If required by Malaysian law or legal process.
5. Data Security
We implement appropriate technical and organisational measures to protect your data, including encrypted connections (HTTPS), secure password hashing, and token-based API authentication.
6. Your Rights
Under the PDPA, you have the right to:
- Access your personal data held by us.
- Correct any inaccurate or incomplete data.
- Request deletion of your account and associated data.
- Withdraw consent for optional data processing.
7. Data Retention
We retain your data for as long as your account is active. If you delete your account, we will remove your personal data within 30 days, except where retention is required by law.
8. Cookies & Analytics
We use privacy-friendly analytics that do not use cookies or track personal information. No third-party advertising cookies are used on our platform.
9. Changes to This Policy
We may update this policy from time to time. We will notify registered users of any significant changes via email or in-app notification.
10. Contact Us
If you have questions about this privacy policy or wish to exercise your rights, please contact us at [email protected].