Privacy Policy

Last updated: July 2026

1. Introduction

Phi Software Sdn Bhd (Registration No. 202401040912) ("we," "our," or "us") operates the FeeCollec platform ("the Service"). This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you use our website and services.

We are committed to protecting your privacy in compliance with the Malaysian Personal Data Protection Act 2010 (PDPA) and applicable international data protection standards.

2. What Data We Collect

2.1 Account Data

  • Email address (required for registration and login)
  • Name and company name (provided during onboarding)
  • Account activity log (login timestamps, IP addresses)

2.2 Customer Data (uploaded by you)

When you use the Service to send bills, you upload data about your customers, including:

  • Customer name, email address, and phone number
  • Billing details: account number, invoice date, current amount, overdue amount
  • Payment status and transaction history
  • Payment proof images (receipts, screenshots) submitted by payers

Important: You are responsible for obtaining necessary consent from your customers before uploading their data to our platform.

2.3 Payer Data

When a customer completes a payment via the gateway, we receive from the gateway callback only:

  • Payment gateway transaction ID and payment status (paid/pending/failed)
  • The payment reference code
  • Uploaded payment proof images (if submitted via our platform)

Note: We do not collect, process, or store credit card numbers, bank account details, or any sensitive financial credentials. All payment data is handled directly between the payer and the client's own third-party payment gateway account. Our platform never touches or handles the funds — we only receive transaction status updates from the gateway to update the collection record.

2.4 Technical Data

  • IP address, browser type, device information
  • Pages visited and time spent on the site
  • Referral source and interaction data

2.5 Communications

  • Email correspondence with our support team
  • WhatsApp messages sent through the platform are processed via Meta's WhatsApp Business API and subject to Meta's privacy policy

3. How We Use Your Data

We use collected data for the following purposes:

  • Service Delivery: Process CSV uploads, send WhatsApp/email notifications, generate payment links that redirect to the client's gateway, and monitor payment status via gateway callback
  • Authentication: Verify identity and authorize access to the platform
  • Customer Support: Respond to inquiries and troubleshoot issues
  • Analytics: Improve platform performance and user experience
  • Compliance: Meet legal and regulatory obligations under Malaysian law
  • Billing: Process subscription payments and credit top-ups

4. Legal Basis for Processing (PDPA)

Under the PDPA, we process personal data based on the following grounds:

  • Consent: You have provided explicit consent for the specific purpose (e.g., account registration, data upload)
  • Contractual Necessity: Processing is necessary to fulfill our service agreement with you
  • Legal Obligation: Processing is required to comply with applicable laws
  • Legitimate Interest: Processing for analytics, security, and platform improvement, balanced against your privacy rights

5. Data Sharing & Disclosure

We do not sell, trade, or rent your personal data. We may share data only in the following circumstances:

5.1 Service Providers

  • Amazon Web Services (AWS SES) — email delivery
  • Meta (WhatsApp Business API) — WhatsApp message delivery
  • Payment Gateways (Billplz, Stripe, PayPal, DuitNow, Xendit) — we query their APIs solely to check and update payment status. No payment data (credit card numbers, banking details) passes through or is stored on our platform. All fund transactions occur directly between the payer and the client's gateway account
  • GitHub — source code hosting and CI/CD

5.2 Legal Requirements

  • When required by law, court order, or regulatory authority
  • To protect our rights, property, or safety
  • To investigate suspected violations of our Terms

5.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of the transaction. We will notify you of any such change.

6. Data Storage & Security

Storage Location: Data is stored on servers located in Malaysia (OVHcloud). Email notifications are sent through AWS SES.

No Payment Data Storage: We do not store credit card numbers, bank account details, or any sensitive financial credentials on our servers. Payment gateway API keys are encrypted at rest and used solely for payment status lookup. We never handle, process, or hold funds. All payment transactions occur directly between the payer and the client's own payment gateway account. Chargebacks, refunds, and disputes are handled entirely between the client, their gateway provider, and the payer.

Encryption:

  • Data in transit: TLS 1.2+ for all API and web traffic
  • Data at rest: SQLite databases with file-level permissions
  • Passwords: Salted SHA-256 hashing
  • API tokens: HMAC-signed

Access Control: Per-tenant database isolation ensures your data is not accessible by other tenants. Access to servers is restricted to authorized personnel via SSH key authentication.

Backups: We recommend maintaining your own backups of uploaded CSV data. We do not guarantee point-in-time recovery.

7. Data Retention

  • Account data: Retained for the duration of your account plus 30 days after termination
  • Customer data: Retained until you delete it or your account is terminated
  • Payment transactions: Retained for 7 years for tax and legal compliance
  • Technical logs: Retained for 90 days

8. Your Rights (PDPA)

Under the Malaysian Personal Data Protection Act 2010, you have the following rights:

  • Right of Access: Request a copy of your personal data we hold
  • Right of Correction: Request correction of inaccurate data
  • Right of Withdrawal: Withdraw consent for processing at any time
  • Right of Deletion: Request deletion of your data (subject to legal retention requirements)
  • Right to Limit Processing: Restrict how we use your data
  • Right to Data Portability: Request your data in a structured, machine-readable format

To exercise any of these rights, contact us at [email protected]. We will respond within 21 days as required by the PDPA.

9. Cookies

We use essential cookies for authentication and session management. We do not use tracking cookies or third-party analytics cookies. You may configure your browser to refuse cookies, but this may affect platform functionality.

10. Children's Privacy

The Service is intended for business use and is not directed at individuals under the age of 18. We do not knowingly collect data from minors. If you believe a minor has provided us with personal data, please contact us.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. For material changes, we will notify you via email or platform notification.

12. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your data, please contact our Data Protection Officer:

Email: [email protected]
Business Address: Phi Software Sdn Bhd, Malaysia
Website: www.phisoft.my

If you are not satisfied with our response, you have the right to lodge a complaint with the Department of Personal Data Protection Malaysia (JPDP).