Legal
Privacy notice
How GoKedai handles personal data, written under the Personal Data Protection Act 2010 (Act 709).
Last updated 21 September 2026
Who is responsible for what
GoKedai is two things at once, and the difference decides who you ask about your data.
- For a merchant
- When you open a kedai, GoKedai is the data controller for your own account: your name, email, phone and the details of your shop.
- For a buyer
- When you buy from a kedai, the merchant running that kedai is the data controller. They decide what to collect and why. GoKedai only processes it on their instructions, as their data processor, and does not sell it, rent it, or use it to market anything to you.
So if you bought something and want your details corrected or removed, ask the kedai you bought from first. Their support address is on your receipt. If they cannot be reached, write to us and we will help.
What is collected
If you open a kedai
- Your name, email address and password, which is stored only as a hash and can never be read back.
- Your kedai: its name, web address, tagline, support email and phone number.
- Bank name, account name and account number, if you give them to be paid a referral reward.
- Your payment gateway credentials, encrypted before they are stored and never shown again after you save them.
- The date you signed up and the last time you signed in.
If you buy from a kedai
- Your name, email address and phone number, as entered on the order form.
- What you ordered, how much it came to, which payment method you chose, and whether it was paid.
- The order number, which is the only thing that opens your receipt.
If you sell as an agent
- Your name, email, phone and password hash.
- Your referral code, the sales credited to it and the commission owed.
- Bank details, if you give them so the merchant can pay you.
What is never collected
Card numbers, CVVs, online banking passwords and TAC codes are never seen by GoKedai. Payment happens on the gateway's own page, and nothing about the instrument comes back to us except whether it succeeded.
Why it is used
- To take an order, send the receipt, and show the merchant what was sold.
- To chase an order that was started and never paid, if the merchant switched that on.
- To work out what an agent is owed.
- To keep the account secure, and to investigate abuse.
- To meet tax and accounting obligations.
Nothing here is used for advertising by GoKedai, and personal data is never sold.
How long it is kept
- Order and payment records are kept for seven years, which is what the tax law requires.
- A merchant's account and kedai are kept while the account is open.
- A buyer's record is kept by the kedai that took the order, for as long as that kedai keeps it.
- Failed background jobs and server logs are pruned within a week.
How it is protected
- Everything travels over HTTPS.
- Passwords are hashed, never stored as text, and cannot be recovered — only reset.
- Payment gateway secrets are encrypted at rest and shown masked after saving.
- Each kedai is separated in the database, so one merchant cannot read another's orders, buyers or agents.
- A receipt is reachable only by its order number, which carries enough randomness that guessing is not practical, and the page is rate limited.
No system is perfect. If you believe something has gone wrong, tell us and we will investigate.
Who else sees it
Three companies, each for one job, and only what that job needs.
- CHIP
- The payment gateway (chip-in.asia). Receives the buyer's name, email and the amount so the payment can be taken. Each merchant uses their own CHIP account, and the money goes to their bank, not ours.
- Resend
- Sends the receipts, invoices and reminders. Receives the recipient address and the contents of the message.
- Meta
- Only if a merchant turns on the Conversions API for one of their forms. It sends the buyer's email, phone and name as irreversible SHA-256 hashes, never as readable text, so the merchant can measure their own advertising. Off unless switched on.
Data may also be disclosed where the law requires it, or to protect someone from harm or fraud. Some of these providers operate outside Malaysia, so data may be processed abroad under contractual protections.
Cookies
Four, none of them for advertising, and none shared with anyone.
- Session cookie
- Keeps you signed in. Deleted when you sign out.
- gk_lang
- Remembers whether you chose English or Bahasa Melayu. Kept for a year.
- gk_ref
- Remembers which agent's link you arrived through, so their sale is credited. Kept for 30 days.
- gk_invite
- Remembers which merchant invited you to open a kedai. Kept for 30 days.
Your rights
Under the Act you may:
- Ask what personal data is held about you, and get a copy.
- Ask for it to be corrected if it is wrong or out of date.
- Withdraw consent, or ask that processing stop, understanding that some of it is needed to keep an order or an account working.
- Ask that it not be used for direct marketing.
- Ask for a copy in a form you can take elsewhere, where the data was given by you and is held electronically.
Write to hello@gokedai.com. We answer within 21 days. If your request is about something you bought, tell us which kedai — they hold that record and we act on their instructions.
Changes
When this notice changes, the date at the top changes with it. Where a change materially affects how personal data is used, merchants will be told by email before it takes effect.