PRIVACY

Privacy Policy

Effective and Last Updated: 5 August 2026

This Privacy Policy explains how SiniSlot collects, uses, discloses, retains, and protects personal data when businesses use the SiniSlot platform and when customers make bookings or payments. It should be read together with our Terms and Conditions.

SiniSlot is a booking and business-management platform for Malaysian SMEs. This Policy applies to sinislot.shop, SiniSlot dashboards, public booking pages, WhatsApp booking flows, payment-related receipts, customer support, and the SiniSlot chatbot.

For business account, platform billing, support, security, and product-analytics data, SiniSlot determines why and how the data is processed. For customer information submitted to an SME for a booking, the SME also determines how that information is used to provide its services. Customers should read the SME’s own privacy notice and contact that SME first about its use of booking information.

  • Account and business data: name, email address, authentication identifiers, business name, business profile, public username, services, operating hours, staff permissions, subscription tier, and settings.
  • Booking and customer data: customer name, phone or WhatsApp identifiers, appointment date and time, selected services, booking reference, custom-form answers, notes, status, source, and communication language.
  • Booking payment data: amount, currency, payment status, payment method category, refund status, receipt number, Stripe account and transaction references, and timestamps. SiniSlot does not store complete card numbers, card security codes, online-banking passwords, or one-time payment codes.
  • Stripe merchant data: connected-account identifier, onboarding and verification status, enabled payment capabilities, limited balance and payout summaries, payout schedule, and restriction information. Bank-account details and withdrawals remain managed in Stripe.
  • Pitis and subscription data: wallet balance, top-ups, subscription tier, renewal and deduction records, Stripe Checkout references, and transaction status.
  • E-Invoice data: taxpayer identification and registration details, business classification, customer or supplier details, invoice line items, tax values, MyInvois credentials or identifiers, submission status, validation results, and document references where the feature is used.
  • Communications: contact-form submissions, support messages, feedback, chatbot prompts and recent conversation context, and records of booking or notification delivery.
  • Device and usage data: IP-derived security or rate-limit information, browser and device data, page and feature usage, referral source, UTM source, push-subscription details, cookies or similar identifiers, and diagnostic logs.

We collect data directly from users, from SMEs acting for their customers, through public and WhatsApp booking flows, from browsers and devices, and from service providers such as Stripe, Meta WhatsApp, Supabase, Google, and LHDN MyInvois. Please provide only data that is accurate, relevant, and lawful to share.

  • Create and secure accounts, authenticate users, apply staff permissions, and provide subscribed features.
  • Check availability, prevent duplicate bookings, create and manage appointments, and maintain booking records.
  • Create Stripe checkout sessions, verify signed payment events, confirm paid bookings, reconcile payment or refund status, show merchant balances and payouts, and provide private receipts.
  • Operate Pitis Wallet top-ups, subscriptions, plan limits, renewals, and platform billing records.
  • Send WhatsApp messages, dashboard notifications, Web Push notifications, appointment confirmations, reminders, receipts, and operational alerts.
  • Support E-Invoice preparation and transmission when configured by an eligible SME.
  • Answer product questions through the chatbot and respond to support or privacy requests.
  • Measure product and marketing performance, diagnose faults, prevent abuse and fraud, enforce our terms, and protect users, SiniSlot, Stripe, and participating SMEs.
  • Meet accounting, tax, regulatory, dispute-resolution, law-enforcement, and other legal obligations.

Customer booking payments are processed by Stripe as direct charges for the SME’s connected Stripe account. Stripe independently collects payment credentials and may conduct identity, fraud, sanctions, and compliance checks under its own terms and privacy policy. SiniSlot receives transaction status and limited identifiers needed to operate the booking.

A private SiniSlot receipt link can be sent after payment. The link is designed not to expose full payment credentials or public Stripe identifiers, but anyone who obtains the link may be able to view the receipt. Recipients should not publish or forward it unnecessarily.

Stripe merchant balances are separate from the SiniSlot Pitis Wallet. SiniSlot displays limited Stripe balance and payout information but does not use the SiniSlot dashboard to manage bank accounts or initiate merchant withdrawals.

When a user interacts through WhatsApp, Meta and the relevant SME process identifiers, message metadata, form responses, and delivery information. WhatsApp availability and processing are also governed by Meta’s terms and privacy practices.

When the SiniSlot chatbot is used, the submitted prompt and conversation context are sent to Google Gemini to generate a response. Do not enter payment credentials, passwords, identity-document numbers, health details, legal secrets, or other sensitive information in chat. Chatbot responses are automated and may be inaccurate.

Web Push notifications are optional. A browser push subscription contains a delivery endpoint and cryptographic keys. Users can disable notifications in their browser or device settings.

SiniSlot uses necessary browser storage for security, language, session, and product functions. We also record a limited referral source once per browser session and use Google tags for advertising measurement. Google and other providers may use cookies or similar technologies and receive device, page, referral, and interaction information under their own policies.

Users can restrict cookies through browser settings, although disabling necessary storage may affect login, preferences, booking, or dashboard features. Browser privacy controls and advertising settings can also limit some measurement.

  • The SME and its authorized staff, where needed to manage a customer’s booking, service, payment, refund, or E-Invoice.
  • Stripe for customer payments, merchant onboarding, Pitis top-ups, fraud controls, refunds, disputes, balances, and payouts.
  • Supabase for database hosting, authentication, and application services; Google Cloud for application hosting and logs; Google Gemini for chatbot responses; Meta WhatsApp for booking flows and messages; Google for tag measurement; and infrastructure providers for Web Push delivery.
  • LHDN MyInvois or related tax systems when an SME configures and submits an E-Invoice.
  • Professional advisers, insurers, auditors, authorities, courts, law enforcement, or transaction counterparties where reasonably necessary for legal compliance, safety, claims, financing, reorganization, merger, or sale.

SiniSlot does not sell personal data for money. We do not disclose customer lists to unrelated third parties for their independent direct marketing.

Some providers and their infrastructure may process data outside Malaysia. Where personal data is transferred internationally, we take reasonable steps to use reputable providers, contractual protections, access controls, and other safeguards appropriate to the data and service. Provider locations and subprocessors may change over time.

We retain personal data only for as long as reasonably needed for the purposes described in this Policy, the SME’s instructions, account operation, security, dispute handling, and legal, accounting, tax, or regulatory requirements. Different records therefore have different retention periods.

Active account, booking, payment, wallet, subscription, and E-Invoice records may be retained while the account or business relationship continues and afterwards where records are required. Terminal unconfirmed payment-hold personal data is designed to be redacted after 30 days through maintenance. Payment observability records are maintained for 90 days by default. Security, hosting, provider, backup, and transaction records follow their applicable operational and legal schedules.

When data is no longer required, we delete or anonymize it where reasonably practicable. Deletion from backups and third-party systems may occur on their normal cycles, and some records may be preserved where deletion would conflict with legal duties, fraud prevention, payment disputes, or another person’s rights.

We use reasonable administrative and technical safeguards, including access controls, encrypted connections, secrets management, signed webhook verification, rate limits, redaction, restricted financial views, and monitoring. No service is completely secure. Users must protect account credentials, devices, receipt links, and one-time codes and notify us promptly of suspected unauthorized access.

Subject to Malaysian law and any applicable exceptions, individuals may request access to or correction of personal data, withdraw consent where processing relies on consent, ask questions about processing, or request deletion where retention is no longer required. SMEs can update much of their account data in the dashboard. Booking customers should contact the relevant SME first because the SME controls the service relationship and may hold additional records outside SiniSlot.

  • Send privacy requests to support@sinislot.shop with enough information to verify identity and locate the relevant account or booking.
  • Do not send full card details, banking passwords, or one-time codes with a request.
  • We may request verification, clarify the scope, charge a permitted fee, refuse a legally exempt request, or retain records where required by law or a live dispute.
  • Marketing and optional push notifications can be disabled using the unsubscribe method provided or browser/device controls.

SiniSlot business accounts are not intended for persons under 18. An SME that accepts bookings involving children is responsible for obtaining appropriate parent or guardian authority and collecting only necessary information.

We may update this Policy as our services, providers, or laws change. The effective date above identifies the latest version. Material changes may also be communicated through the platform where appropriate.

For privacy questions or requests, use the Contact page or email support@sinislot.shop. For data held by a business in connection with its services, contact that business first.