Privacy Policy
Last updated 17 June 2026
This policy explains what personal data Agedeck collects, why, who we share it with, and the rights you have under Malaysia's Personal Data Protection Act 2010 (the "PDPA").
1. Who we are
Agedeck is a website builder for agents in Malaysia. It is operated by Agedeck based in Malaysia, who is the data controller responsible for your personal data. You can reach us at [email protected].
This policy covers the Agedeck app at agedeck.com — the marketing site, the agent dashboard, and the public agent pages we host.
2. The personal data we collect
When you sign up and build your page, we collect:
- Account data — your email address, and a password (stored only as a secure hash by our authentication provider; we never see it). If you sign in with Google, we receive your email and a Google account identifier.
- Profile & page content you enter — your name, page handle, WhatsApp number, photo, tagline/bio, job title, years of experience, languages, social links, licence details, and the content of your page (services, steps, testimonials, achievements, FAQs, and videos you upload or link).
- Billing data — if you subscribe, your plan, subscription status, renewal date, and the customer/subscription identifiers from our payment processor, Stripe.
- Technical data — basic information your browser sends (such as IP address and device/browser type) needed to serve and secure the site. We do not run analytics or advertising trackers (see our Cookie Policy).
3. What we deliberately do not store
- Card details. Payments are handled entirely by Stripe on their own secure systems. Your full card number never touches our servers.
4. How and why we use your data
We use your data for these purposes, on these legal bases under the PDPA:
- To provide the service — create your account, build and host your public page (performance of our agreement with you).
- To take payment — manage your subscription through Stripe (performance of our agreement; legal obligation for tax records).
- To keep the service secure — prevent abuse, fraud and downtime (our legitimate interest in running a safe service).
- To contact you — service emails such as sign-up confirmation, password resets and billing notices (performance of our agreement).
- Optional analytics — only if you consent (see the Cookie Policy). None are active today.
5. Who we share your data with
We do not sell your data. We share it only with the service providers (data processors) that run, host, secure, store, and communicate through Agedeck, each used strictly to operate the service:
| Provider | What it does | Where data may be processed | Their privacy policy |
|---|---|---|---|
| Supabase | Database, sign-in and file storage (your account + page content) | Outside Malaysia | supabase.com/privacy |
| Stripe | Payment and subscription processing | Outside Malaysia (incl. USA) | stripe.com/privacy |
| Vercel | Website hosting and content delivery | Outside Malaysia (global edge) | vercel.com/legal/privacy-policy |
| Cloudflare | DNS, proxy, CDN, DDoS protection, and R2 object storage for uploaded images and videos | Outside Malaysia (global edge) | cloudflare.com/privacypolicy |
| Resend | Transactional email delivery for account, sign-in, and other service messages | Outside Malaysia (incl. USA) | resend.com/legal/privacy-policy |
| Optional “Sign in with Google” login | Outside Malaysia (incl. USA) | policies.google.com/privacy |
We may also disclose data where the law requires it, or to protect our rights and the safety of others.
6. International transfers
The providers above operate outside Malaysia, including in the United States. Where your data is transferred abroad, we rely on each provider's safeguards (such as standard contractual clauses and their own compliance programmes), consistent with the PDPA and the cross-border transfer guidelines issued under it.
7. How long we keep it
We keep your account and page data for as long as your account is active. If you delete your account, your agent record and page content are removed. We may retain limited records we are legally required to keep (for example, billing records for tax purposes, typically up to seven years).
8. Your rights under the PDPA
You have the right to:
- access the personal data we hold about you, and ask for a copy;
- correct data that is inaccurate or out of date;
- request deletion of your data (you can delete your account from the dashboard);
- request a portable copy of the data you gave us;
- withdraw consent (for example, to optional analytics) at any time; and
- limit or object to certain processing.
Most of these you can do yourself in the dashboard. For anything else, email us at [email protected] and we aim to respond within 21 days.
9. Data-protection contact and breaches
Our contact for data-protection matters is reachable at [email protected]. If a personal data breach occurs that is likely to cause you significant harm, we will notify the Personal Data Protection Commissioner and affected users as required under the PDPA.
10. Children
Agedeck is intended for licensed insurance agents and is not directed at anyone under 18. We do not knowingly collect data from children.
11. Changes to this policy
We may update this policy as the service evolves or the law changes. We will post the updated version here with a new “last updated” date; significant changes will be made clear.