Privacy Policy

Last updated: 31 July 2026

Before you run paid traffic: replace every [SQUARE BRACKET] below with your real details (registered business name, SSM number, business address, payment gateway). Meta and Google both check these pages during ad review, and placeholders will fail the check.

This policy explains what personal data we collect through robinooi.com.my and its subdomains (scan.robinooi.com.my, orm.robinooi.com.my, social.robinooi.com.my), why we collect it, and what rights you have over it.

The data controller is [REGISTERED BUSINESS NAME] (SSM registration no. [SSM NUMBER]), of [BUSINESS ADDRESS, MALAYSIA], referred to below as "we" or "us". You can reach us at support@robinooi.com.my.

We process personal data in accordance with the Malaysian Personal Data Protection Act 2010 (PDPA). Where we serve customers in the United Kingdom or the European Economic Area, we also apply UK GDPR / EU GDPR standards.

1. What we collect

CategoryExamplesWhen
Identity & contactName, email address, phone or WhatsApp number, countryWhen you run a scan, opt in to an email list, or buy
Business dataBusiness name, website URL, social profile handles, Google Business Profile listingWhen you submit them to one of our scanning tools
Scan resultsYour Brand Identity Score, pillar sub-scores, and the report generated for youGenerated when you run a scan
Transaction dataOrder reference, product purchased, amount, currency, date, payment statusAt checkout
Usage dataIP address, browser and device type, pages viewed, referring source, timestampsAutomatically, on every visit
Member activityAccess code used, module completion you mark on your own deviceInside the member area

What we do not collect

We never see or store your full card number, CVV or bank credentials. Payments are handled entirely by our payment gateway (see section 3). We do not ask for your national identity card number, and we do not knowingly collect data from anyone under 18.

2. Why we process it, and on what basis

We do not sell your personal data. We do not share it with third parties for their own marketing. We do not run ads on our own site.

3. Who we share it with

We use a small number of processors to run the business. Each one only receives what it needs:

ProcessorPurposeData shared
MailerLiteEmail delivery and list managementName, email, opt-in source, engagement
[PAYMENT GATEWAY — e.g. senangPay / Billplz / Stripe]Taking paymentName, email, billing details, amount. Card data goes directly to them and never reaches us.
VercelWebsite and member-area hostingServer logs, IP address
Third-party data APIsGenerating your scan reportOnly the public business identifiers you submit (website, profile handles, business name)

We may also disclose data where we are legally required to, or to establish or defend a legal claim.

Transfers outside Malaysia

Some processors above store data outside Malaysia. Where that happens we rely on the processor's contractual safeguards and, for UK/EEA customers, on Standard Contractual Clauses or an adequacy decision.

4. How long we keep it

5. Cookies and tracking

We use cookies and similar technologies for three things: keeping the site working (essential), understanding traffic in aggregate (analytics), and measuring ad performance (advertising). Essential cookies cannot be switched off. You can block or delete the rest through your browser settings; the site will still work, but some features may not.

Complete this list with the tools you actually run, before launch — for example Meta Pixel, Google Analytics 4, Google Ads. Listing a tool you do not use, or omitting one you do, both create problems at ad review.

6. Your rights

Under the PDPA you may ask us to:

If you are in the UK or EEA you additionally have rights to erasure, portability and objection.

Email support@robinooi.com.my and we will respond within 21 days. There is no charge. If you are not satisfied with our response, you may complain to the Personal Data Protection Department (JPDP) Malaysia, or to your local supervisory authority.

7. Security

Data is transmitted over TLS, hosting is access-controlled, and processor accounts use multi-factor authentication. Please note that member-area access codes are shared secrets and are not individually authenticated — treat your code as a password, and do not share it.

8. Changes

If we change this policy materially we will update the date at the top and, where the change affects how we use data you have already given us, email you before it takes effect.

9. Contact

[REGISTERED BUSINESS NAME]
[BUSINESS ADDRESS, MALAYSIA]
support@robinooi.com.my