Rujukan Laman

Privacy Policy — How We Handle Your Account Data

We collect the information you share when opening your account — email, payment details for Touch 'n Go, GrabPay, Boost dan FPX, and wallet activity — so we…

Data collection explainedYour access rightsRetention periodsContact paths openJurisdiction-aware handling
ncr888 Privacy Policy — How We Handle Your Account Data
PRIVACY ENQUIRIES

Reach Us About Data Requests or Privacy Concerns

If you want to see what data we hold, correct an error in your profile, or request deletion after closing your account, contact us through any of the channels below. Our data-protection contact reviews every request within five business days and confirms the next steps. Malaysia-hours email responses typically arrive within one working day.

Team online

Live Chat

Open the lobby chat widget and choose the privacy-request option from the menu. An agent will guide you through identity verification and log your request. Most profile corrections happen in real time; deletion and export requests move to our data team and you'll receive a confirmation email with the timeline.

Email Contact

Send your data request to the privacy address listed in your account footer. Include your registered email and account username so we can verify ownership. We reply within one business day to confirm receipt, then complete access requests in five days and deletion requests in thirty days after account closure.

Account Settings

Log in and visit the privacy section under account settings to download a copy of your profile data, transaction history and session logs in JSON format. The export runs immediately for accounts with under five thousand transactions; larger accounts receive the file by email within two hours.

DATA PROTECTION

How We Secure, Retain and Control Your Information

We encrypt payment credentials at rest using AES-256 and transmit all login and transaction data over TLS.

Encryption Standard

We apply AES-256 encryption to stored payment identifiers and TLS 1.3 to every connection between your browser and our servers. Passwords are hashed with bcrypt before storage so even our database administrators cannot read them. Session cookies are marked secure and httpOnly to block script-based theft.

Access Controls

Support staff see your username, email, balance and recent transactions but not your payment credentials or hashed password. Only the payment-processing service receives the Touch 'n Go, GrabPay, Boost or FPX identifier you provide, and only when you initiate a deposit or withdrawal. No marketing or analytics partner receives personally identifiable data.

Session Security

Your login token expires after two hours of inactivity or immediately when you sign out. If you reset your password or request a security lock every existing session ends at once. We log sign-in IP addresses so you can review recent access from your account page and spot unauthorized attempts.

Retention Rules

Transaction records stay in our archive for seven years to meet financial record-keeping law. Profile data remains active while your account is open. After you close your account and request deletion we anonymize your email, username and preferences within thirty days, keeping only the ledger entries required by regulation.

Cookie Policy

Essential cookies store your session token and language choice; they're required for login and lobby navigation. Analytics cookies count page visits and measure load times so we can fix slow screens; you can disable them in your browser without losing platform functionality. We do not use third-party advertising cookies.

Request a Change

Log in and visit account settings to update your email, display name or notification preferences yourself. To request a full data export, correction of an error, or account deletion contact live chat or send an email to the privacy address in your footer. We verify ownership and confirm next steps within one business day.

Common Questions About Your Data and Privacy Rights

Below are the questions we hear most about data collection, retention and your control over what we store. If your question isn't covered here, reach us through live chat or the privacy email in your account footer.

We ask for your email, a password, a display username and your chosen payment method — Touch 'n Go, GrabPay, Boost or FPX account details. Every transaction generates a record with timestamp, amount and wallet balance. We also log your IP address and device type to detect unusual sign-ins and keep your account secure.

We do not sell your data. We share payment credentials only with the processor handling your deposit or withdrawal, passing the minimum fields needed to clear that transaction. If a regulator or financial authority requires records for compliance we provide them within the legal scope. No marketing or analytics partner receives personally identifiable information.

Transaction records stay in our archive for seven years from the transaction date to meet financial record-keeping law. Profile data — email, username, preferences — remains active while your account is open. After you close your account and request deletion we anonymize profile fields within thirty days, retaining only the ledger entries required by regulation.

Yes. Log in and visit the privacy section under account settings to export your profile data, transaction history and session logs in JSON format. The file generates immediately for most accounts; if you have more than five thousand transactions the export runs in the background and arrives by email within two hours.

You can update your email, display name and notification preferences yourself in account settings. To request deletion after closing your account contact live chat or email the privacy address listed in your footer. We verify ownership and confirm the next steps within one business day; deletion completes within thirty days.

Essential cookies store your session token and language choice so the lobby recognizes you and displays the right interface; they're required for login. Analytics cookies measure page load times and count visits so we can fix slow screens; you can disable them in your browser and still use the platform. We do not deploy third-party advertising cookies.

We encrypt stored payment identifiers with AES-256 and transmit all data over TLS 1.3. Passwords are hashed with bcrypt so even database administrators cannot read them. Session tokens expire after two hours of inactivity and every password reset invalidates old tokens immediately, blocking unauthorized access if your session was compromised.