Reference

Legal Framework Built for Your Account Security

We keep your account data, payment records and personal information under strict handling rules. Every Touch 'n Go eWallet, Boost and GrabPay transaction you make is logged, encrypted and stored according to the data-protection standards that apply in eligible Malaysia regions.

Data encrypted at restPayment logs retained securelyAccount access controlled by youRegional law complianceClear contact paths for rights requests
jommenang88 Legal Framework Built for Your Account Security
POLICY CONTACT

Reach Us for Rights Requests and Data Questions

If you want to see what account data we hold, correct a detail, or ask how your Touch 'n Go eWallet deposits are logged, open a ticket through live chat or email our support line with your registered address. We respond to data-access and correction requests within the timeframe set by the applicable regional rules, and we walk you through each step so you know exactly what records exist and how to update or remove them.

Live chat Open the chat widget from any lobby page, state that your question is about data or legal policy, and our agent will route your request to the compliance queue for a detailed reply within the same session or via follow-up email.
Email support Send your rights request to our support address, include your registered email and account username, and describe what you need — data copy, correction, deletion or an explanation of how we handle Boost and GrabPay transaction logs.
Account settings panel Log in, navigate to settings, then privacy preferences to toggle marketing emails, download your recent activity summary, or submit a formal data-access request that triggers our internal review and response process.
SECURITY PRACTICE

Data Handling, Retention and Account Protection Steps

We encrypt account credentials and payment details at rest and in transit, log every Touch 'n Go eWallet, Boost and GrabPay transaction with a timestamp and unique reference, and require SMS or email verification before processing withdrawals. Session cookies expire after inactivity so no one can hijack your Live Blackjack or Football Sportsbook session if you step away from your device. We retain payment and login records for the period mandated by regional financial rules, then move older data to secure archive or delete it once the retention window closes.

Encryption standard

All account data, from your email address to your DuitNow transfer history, is encrypted using industry-standard algorithms, so even if storage logs are intercepted they remain unreadable without the decryption keys we hold in separate secure vaults.

Cookie scope and lifespan

Session cookies keep you logged in across the slot lobby, live tables and sportsbook for the duration of your visit; they expire after thirty minutes of inactivity, and preference cookies remember your language and layout choices without storing sensitive account identifiers.

Payment log retention

We keep Touch 'n Go eWallet, Boost, GrabPay and FPX transaction records for the minimum period required by financial regulations in each supported Malaysia region, then archive or purge them according to documented schedules you can request through the support paths above.

Rights request process

Submit a data-access, correction or deletion request via live chat or email support; we verify your identity with the registered email and account username, then deliver a structured report or execute the change within the timeframe set by applicable regional law.

Common Questions About Data, Privacy and Account Rights

We collect your email, mobile number for OTP verification, payment identifiers for Touch 'n Go eWallet, Boost or GrabPay deposits, device type and IP address to secure your session, and login timestamps to monitor unusual activity and prevent unauthorized access.

We retain transaction logs for the period mandated by financial regulations in the supported Malaysia regions where you hold an account, typically several years, then archive or delete them once the retention window closes and no active dispute or audit requires the record.

Yes. Contact our support team via live chat or email with your registered address and account username, and we will compile a structured report of your account profile, payment history, session logs and preference settings within the regional timeframe for data-access requests.

We share transaction data only with our payment processors to clear Touch 'n Go eWallet, Boost and GrabPay deposits and verify withdrawals. We do not sell contact lists or account history to marketers, and we do not pass your data to third-party advertisers outside the platform.

Log into your account, open settings, navigate to privacy or communication preferences, and toggle the marketing-email switch off. The change takes effect immediately, and you will still receive transactional messages about deposits, withdrawals and account-security alerts.

We mark your account as closed, stop all marketing communication, and retain your payment and session logs for the minimum period required by financial and anti-fraud rules. After that window, we archive or delete the data according to our documented retention schedule.
Reference

Legal

Service availability depends on eligible regions and local law. Users should check local rules before opening an account.

Access may be available only where local law permits.