Legal
Privacy notice
How GoKedai handles personal data, written under the Personal Data Protection Act 2010 (Act 709).
Last updated 26 September 2026
Who is responsible for what
GoKedai is two things at once, and the difference decides who you ask about your data.
- For a merchant
- When you open a kedai, GoKedai is the data controller for your own account: your name, email, phone and the details of your shop.
- For a buyer
- When you buy from a kedai, the merchant running that kedai is the data controller. They decide what to collect and why. GoKedai only processes it on their instructions, as their data processor, and does not sell it, rent it, or use it to market anything to you.
So if you bought something and want your details corrected or removed, ask the kedai you bought from first. Their support address is on your receipt. If they cannot be reached, write to us and we will help.
What is collected
If you open a kedai
- Your name, email address and password, which is stored only as a hash and can never be read back.
- Your kedai: its name, web address, tagline, support email and phone number.
- Bank name, account name and account number, if you give them to be paid a referral reward.
- Your payment gateway credentials, encrypted before they are stored and never shown again after you save them.
- The date you signed up and the last time you signed in.
If you buy from a kedai
- Your name, email address and phone number, as entered on the order form.
- What you ordered, how much it came to, which payment method you chose, and whether it was paid.
- The order number, which is the only thing that opens your receipt.
- The payment slip, if you paid by bank transfer and uploaded a screenshot or photo of it. It is stored privately and only that kedai can open it.
If you sell as an agent
- Your name, email, phone and password hash.
- Your referral code, the sales credited to it and the commission owed.
- Bank details, if you give them so the merchant can pay you.
If you open any page
- Your IP address and your browser's user agent, which every web server receives. They are kept in the session record and the server logs and, only when a merchant has switched on Meta's Conversions API for their form, sent to Meta with the order event.
What is never collected
Card numbers, CVVs, online banking passwords and TAC codes are never seen by GoKedai. Payment happens on the gateway's own page, and nothing about the instrument comes back to us except whether it succeeded.
Why it is used
- To take an order, send the receipt, and show the merchant what was sold.
- To chase an order that was started and never paid, if the merchant switched that on.
- To work out what an agent is owed.
- To keep the account secure, and to investigate abuse.
- To meet tax and accounting obligations.
Nothing here is used for advertising by GoKedai, and personal data is never sold.
How long it is kept
- Order and payment records are kept for seven years, which is what the tax law requires.
- A merchant's account and kedai are kept while the account is open.
- A buyer's record is kept by the kedai that took the order, for as long as that kedai keeps it.
- Failed background jobs and server logs are pruned within a week.
How it is protected
- Everything travels over HTTPS.
- Passwords are hashed, never stored as text, and cannot be recovered — only reset.
- Payment gateway secrets are encrypted at rest and shown masked after saving.
- Each kedai is separated in the database, so one merchant cannot read another's orders, buyers or agents.
- A receipt is reachable only by its order number, which carries enough randomness that guessing is not practical, and the page is rate limited.
No system is perfect. If you believe something has gone wrong, tell us and we will investigate.
Who else sees it
Four companies, each for one job, and only what that job needs.
- CHIP
- The payment gateway (chip-in.asia). Receives the buyer's name, email and the amount so the payment can be taken. Each merchant uses their own CHIP account, and the money goes to their bank, not ours.
- Resend
- Sends the receipts, invoices and reminders. Receives the recipient address and the contents of the message.
- Meta
- Only if a merchant turns on the Conversions API for one of their forms. It sends the buyer's email, phone and name as irreversible SHA-256 hashes, never as readable text, so the merchant can measure their own advertising. The same merchant can also put the Meta Pixel on their order form pages, which lets Meta see the visit from your browser. Both are off unless the merchant switches them on.
- Google Analytics (Google LLC), on GoKedai's own public pages only: the home page and this notice. It receives how the page was used, your device and browser, and your IP address, so we can see how many people visit and where they come from. It does not run on kedai pages, receipts or the merchant console.
Data may also be disclosed where the law requires it, or to protect someone from harm or fraud. Some of these providers operate outside Malaysia, so data may be processed abroad under contractual protections.
Cookies
The first two are set for every visitor, signed in or not, because the site cannot work safely without them. The analytics and advertising cookies come from Google and Meta, and only on the pages named below.
- Session cookie (gokedai-session)
- Holds your visit together and, if you sign in, keeps you signed in. Set for every visitor, including people who never sign in. It expires with the session: two hours after your last page, or when you sign out.
- XSRF-TOKEN
- A random value that proves a form was sent from this site and not from somewhere pretending to be it. Set for every visitor, and expires with the session cookie.
- gk_lang
- Remembers whether you chose English or Bahasa Melayu. Kept for a year.
- gk_ref
- Remembers which agent's link you arrived through, so their sale is credited. Kept for 30 days.
- gk_invite
- Remembers which merchant invited you to open a kedai. Kept for 30 days.
- _ga and _ga_*
- Google Analytics, on the GoKedai home page and this notice only. Tells one visitor from another so visits can be counted. Kept for up to two years.
- _fbp
- The Meta Pixel, set on a kedai's order form pages only when that merchant has switched the pixel on. Lets Meta connect the visit to the merchant's adverts. Kept for 90 days. The pixel does not run on receipts.
Your rights
Under the Act you may:
- Ask what personal data is held about you, and get a copy.
- Ask for it to be corrected if it is wrong or out of date.
- Withdraw consent, or ask that processing stop, understanding that some of it is needed to keep an order or an account working.
- Ask that it not be used for direct marketing.
- Ask for a copy in a form you can take elsewhere, where the data was given by you and is held electronically.
Write to hello@gokedai.com. We answer within 21 days. If your request is about something you bought, tell us which kedai — they hold that record and we act on their instructions.
Changes
When this notice changes, the date at the top changes with it. Where a change materially affects how personal data is used, merchants will be told by email before it takes effect.