1. Our commitment to your customers' data
- We do not sell or rent personal data.
- We do not share customer names, email addresses, telephone numbers or postal addresses with other merchants.
- We do not use a merchant's customer contact details for unrelated ROAS.my direct marketing.
- We do not combine customer lists from different merchants to create a shared marketing audience.
- A merchant's page will not be made available as a reusable Public Library template without that merchant's clear action or permission.
2. About this policy
This Policy explains how ROAS.my, operated by Scale Sparks Solution, collects, uses, stores and protects data when you use our website, dashboard, sales pages, checkout and related services. Your use of ROAS.my is also governed by our Terms of Service.
3. Data we collect
- Account and business data: your name, email address, Google profile, properties, domains, settings and subscription information.
- Merchant content: sales pages, products, prices, media, checkout configuration, integrations and other materials you upload or publish.
- Merchant customer data: names, email addresses, telephone numbers, delivery or billing addresses, dates of birth or other checkout answers requested by the merchant, products, order values and statuses, and delivery information.
- Payment data: transaction identifiers, payment status, subscription plan and billing history. Payment providers process card details, and ROAS.my does not store complete card numbers.
- Usage and technical data: IP address, device and browser type, pages viewed, traffic source, UTM parameters, first-party sessions and events, access times, security logs and system performance information.
- Communications: support requests, feedback and information submitted through programme forms or other communications with us.
4. How we use data
We process data as reasonably necessary to:
- provide, operate, support and protect the Service;
- receive orders, calculate analytics and carry out merchant instructions;
- manage accounts, subscriptions, billing, transactional messages and support;
- prevent fraud, abuse, disruption and security incidents;
- understand the use and performance of the Service, conduct internal analysis, and improve our features, workflows and user experience; and
- produce aggregated or de-identified statistics, trends and benchmarks that do not identify a merchant's customer to external parties.
Authorised personnel may access data where reasonably necessary for operations, support, security, compliance and service improvement. Such access is subject to internal controls.
5. When data is shared
Data may be shared only where necessary with:
- the merchant receiving an order and authorised users of the relevant account;
- hosting, storage, email, monitoring, payment and infrastructure providers that help us operate the Service;
- payment gateways, advertising platforms, order management systems, webhooks or other integrations selected and configured by the merchant;
- professional advisers, law enforcement, regulators or public authorities where disclosure is required or permitted by law; and
- a party involved in a merger, acquisition or transfer of the ROAS.my business or assets, subject to appropriate safeguards.
Some providers may process data outside Malaysia. We select appropriate providers and take reasonable steps to safeguard data during such processing.
6. The roles of merchants and ROAS.my
For customer data collected through a merchant's sales page or checkout, the merchant decides what data is required and why it is used. The merchant is responsible for providing appropriate notices, obtaining consent where required and complying with applicable law. ROAS.my processes that data on the merchant's behalf to provide the Service and carry out the merchant's settings or instructions.
For account, billing, security and platform usage data, ROAS.my determines the processing reasonably required to operate the Service.
7. Cookies and first-party tracking
ROAS.my uses cookies or first-party identifiers for login sessions, security, user preferences, visit measurement and attribution. Merchants may also enable third-party analytics or advertising integrations on their properties. Those third parties process data under their own policies.
8. Retention and security
We use access controls, account isolation, encrypted connections, backups and monitoring to reduce the risk of loss, misuse or unauthorised access. No system can be guaranteed completely secure, but we apply reasonable technical and organisational safeguards.
We retain data while an account is active and afterwards only for as long as reasonably necessary to provide the Service, resolve disputes, prevent abuse, comply with legal obligations or complete a deletion request. Backup copies may take a reasonable period to expire under our retention cycle.
9. Your rights and choices
Subject to applicable law, you may request access to or correction of your personal data, withdraw certain consent, object to direct marketing or request deletion. A merchant is responsible for handling requests from its customers and may contact us when technical assistance is required.
Send a request to [email protected]. We may verify the identity and authority of the requester before acting on a request.
10. Changes and contact
We may update this Policy when the Service or applicable law changes. Where reasonable, material changes will be communicated through the platform, by email or through another appropriate notice before they take effect.
Privacy enquiries may be sent to Scale Sparks Solution at [email protected].