Legal
Privacy Policy
Last updated: 26 August 2026
This Privacy Policy explains how EJD Labs Sdn. Bhd. ("we", "us", "PlatePings") collects, uses, discloses, and protects personal data when you use PlatePings websites, apps, push notifications, email alerts, and QR stickers (the "Service"). We process personal data in accordance with Malaysia's Personal Data Protection Act 2010 (PDPA) and related regulations.
1. Who we are
PlatePings is operated by EJD Labs Sdn. Bhd., a company incorporated in Malaysia. For privacy requests, contact us at privacy@platepings.com.
2. Data we collect
Vehicle owners
- Email address (for account login and email backup alerts)
- Optional mobile phone number (if provided for future contact options)
- Vehicle plate number, make, model, nickname, and optional photo
- Shipping address for QR sticker fulfilment
- Notification preferences (quiet hours, mute settings)
- Push subscription endpoints for browser / PWA alerts
- Payment metadata processed by Stripe (we do not store full card numbers)
Scanners (message senders)
- No account is required to send a preset message
- A session fingerprint (hashed) for rate limiting abuse
- Optional approximate location / area label if you share it
- Selected preset message type (no free-form text from scanners)
Technical data
- Device and browser information, IP address, and diagnostic logs
- Cookies and similar technologies needed for authentication and security (see Cookies Policy)
3. How we use data
- Authenticate owners via email and password
- Deliver scanner messages to owners via push notifications (primary) and email when push is not enabled
- Register plates, process payments, and fulfil sticker orders
- Enforce rate limits, prevent spam and abuse, and secure the Service
- Provide account settings, data export, and support
- Comply with legal obligations and resolve disputes
We do not sell personal data. We do not use scanner or owner message content for advertising.
4. Legal bases (PDPA)
We process personal data where one or more of the following apply:
- You have given consent (for example, registering a plate or sharing location)
- Processing is necessary to perform a contract with you (the Service)
- Processing is necessary for our legitimate interests in operating a safe messaging platform, balanced against your rights
- Processing is required to comply with law
5. Sharing with processors
We use trusted providers who process data on our instructions, including:
- Supabase — database, authentication infrastructure, and file storage
- Stripe — payment processing
- Upstash — rate-limit storage
- Resend — email backup alerts when push notifications are not enabled
- Hosting providers (for example Vercel) — application hosting
Some providers may process data outside Malaysia. Where we transfer data internationally, we take reasonable steps to ensure appropriate safeguards consistent with the PDPA.
6. Retention
- Live message threads expire about 2 hours after sending, after which the public reply link stops working
- Operational message logs are retained for about 30 days for abuse prevention and support, then deleted automatically
- Owner account and plate data are kept while the account remains active
- Payment and shipping records are retained as needed for accounting and fulfilment
7. Your rights
Subject to the PDPA, you may request to:
- Access personal data we hold about you
- Correct inaccurate data
- Withdraw consent where processing is consent-based
- Limit or object to certain processing
- Export your data (owners can download an export from Settings)
- Request deletion of your account and associated personal data, subject to legal retention needs
Email privacy@platepings.com. We will respond within a reasonable period as required by law.
8. Children
The Service is intended for users aged 18 and above. We do not knowingly collect personal data from children. If you believe a child has provided data, contact us and we will take appropriate steps.
9. Security
We use industry-standard measures including encrypted transport (HTTPS), access controls, hashed session fingerprints for rate limiting, and least-privilege service credentials. No method of transmission or storage is completely secure; please keep your login device safe.
10. Changes
We may update this policy from time to time. The "Last updated" date will change when we do. Material changes may be notified via the Service or email where appropriate.