Skip to content
Legal

Privacy Policy

Last updated: September 2026

1. Introduction

KINPASS Technology Sdn. Bhd. (Co. No. 202601011901) (“KINPASS”, “we”, “us”) is committed to protecting your personal data in accordance with the Personal Data Protection Act 2010 (PDPA) of Malaysia. This Privacy Policy explains how we collect, use, disclose, and safeguard your information.

2. Information We Collect

Account Information

Name, email address, phone number, and profile information provided during registration.

Children's Information

Child's name, date of birth, identity number (NRIC or passport), medical notes, allergies, and emergency contact details. This information is collected with parental consent and shared with activity providers for safety purposes.

Payment Information

Payment details are processed and stored securely by Stripe. KINPASS does not store credit card numbers or bank account details on our servers.

Usage Data

Booking history, app usage patterns, device information, and location data (with your permission) to improve our services.

3. How We Use Your Information

  • To provide and operate the KINPASS platform
  • To process bookings and payments
  • To share necessary child safety information with activity providers
  • To send booking confirmations, reminders, and service updates
  • To improve our platform and develop new features
  • To comply with legal obligations

4. Children's Data Protection

We take special care with children's data. IC numbers and emergency contact information are encrypted using AES-256-GCM. Access to children's data is restricted to the parent/guardian and the booked activity provider. We obtain explicit parental consent before collecting or processing any child's personal data.

5. Data Sharing

We share your information only with:

  • Activity Partners: Child's name, age, medical notes, and emergency contact for booked classes
  • Payment Processors: Stripe, for processing payments securely
  • Service Providers: Hosting, email, and analytics providers who process data on our behalf
  • Advertising Platforms: Meta (Facebook & Instagram), TikTok and LinkedIn, to measure our advertising — see below
  • Legal Requirements: When required by Malaysian law or regulation

Advertising Measurement (Meta)

If you came to KINPASS by clicking one of our Facebook or Instagram ads, we tell Meta when that click led to an account, a free trial, a subscription or a credit purchase, so we can tell which ads are worth running. This happens in two ways: the Meta Pixel in your browser on kinpass.com (described in our Cookie Policy), and a direct server-to-server report from KINPASS when the action happens in the mobile app, where no browser is involved.

We also run advertising on TikTok and LinkedIn, which use browser tags on kinpass.com in the same way. Those two receive only what happens on the website — we do not send them server-side reports of what you do in the app.

In the server-to-server report we send: your email address and phone number converted into an irreversible scrambled code (a “hash” — Meta can match it to an existing account but cannot read it), a scrambled version of your KINPASS account id, your country, the identifier from the ad you clicked, and what you did (signed up, started a trial, subscribed, or bought credits) with its value in ringgit.

We never send your name, your IC number, your children's information, which activities you view or book, or anything about a specific class. We send nothing at all for parents who did not arrive from a Meta ad, and nothing further once an account is deleted.

Measurement inside the KINPASS app

The KINPASS app also includes the Meta SDK and Google Analytics for Firebase. They tell Meta and Google that the app was installed and opened, and which screens, searches and activity pages you looked at, so those platforms can measure whether their ads brought you here. They receive a random installation id, your scrambled account id and, for Meta, your email address converted on your phone into the same irreversible scrambled code described above — never your name, IC number, children's details or anything about a booking. Google also matches your email on your device only; it never leaves your phone. On iPhone, the app asks for permission before using the advertising identifier (“Ask App Not to Track” keeps it off, and every feature works the same). On Android you can reset or delete the advertising id in your device's Google settings.

To object to this, or to ask us to stop sending your data to Meta, email askme@kinpass.com and we will exclude your account. You can also limit how Meta uses data about you in your Facebook ad preferences.

6. Data Security

We implement industry-standard security measures including encryption at rest and in transit, access controls, and regular security audits. Sensitive data such as children's IC numbers are encrypted with AES-256-GCM.

7. Your Rights

Under the PDPA, you have the right to:

  • Access your personal data held by us
  • Correct inaccurate or incomplete personal data
  • Withdraw consent for data processing
  • Request deletion of your account and associated data

To exercise these rights, contact us at askme@kinpass.com.

8. Data Retention

We retain your personal data for as long as your account is active or as needed to provide services. Upon account deletion, we will remove your personal data within 30 days, except where retention is required by law.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification.

Contact

For privacy-related enquiries, contact our Data Protection Officer at askme@kinpass.com.