1. What data we collect
When you use FO2U (operated by FO2U Marketplace Sdn Bhd, "we", "us"), we collect:
- Account data — name, email, password (hashed), role (buyer/seller/admin), preferred language.
- Order data — items ordered, quantities, prices, payment method, status, tracking number.
- Address data — recipient name, phone, delivery address, district, city, country.
- Seller data (if you register as a seller) — shop name, business registration, factory location, product listings.
- Communication data — messages you send us via email, WhatsApp, or in-app support.
- Technical data — IP address, browser type, device, pages visited, referring URL.
We do not store full credit-card numbers. Card payments are processed by PCI-DSS compliant payment processors.
2. How we use your data
We use your data to:
- Operate the marketplace — create your account, process orders, arrange delivery.
- Communicate — send order confirmations, shipping updates, password resets, and support replies.
- Protect against fraud and abuse — detect scam patterns, suspicious payments, and policy violations.
- Comply with legal obligations — including tax, accounting, and law-enforcement requests.
- Improve the service — anonymous analytics to understand how the platform is used.
4. How long we keep data
Account and order records are retained for as long as your account is active, plus seven years thereafter to meet Malaysian tax and accounting record-keeping obligations. After that period, records are anonymised or deleted. You can request deletion of your account at any time (see section 5).
5. Your rights under PDPA
Under Malaysia's Personal Data Protection Act 2010, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Withdraw consent to processing (with limits — we may still need data to fulfil active orders or meet legal obligations).
- Request deletion of your account.
- Limit the processing of your data in certain circumstances.
- Lodge a complaint with the Personal Data Protection Commissioner.
See our PDPA Compliance page for the detailed procedure.
6. Security
We use industry-standard safeguards including SSL/TLS in transit, hashed passwords (bcrypt), least-privilege database access, regular backups, and PCI-DSS-compliant payment processors. No system is 100% secure — we will notify affected users without undue delay if a breach occurs that materially affects their personal data.
8. Contact the Data Protection Officer
For any privacy question or to exercise a PDPA right, contact:
Data Protection Officer
FO2U Marketplace Sdn Bhd
Email: privacy@fo2u.com
WhatsApp: +60 12-345 6789