We are committed to protecting your personal data and ensuring that your privacy is safeguarded in compliance with the Personal Data Protection Act 2010 (Act 709) of Malaysia. This Privacy Notice outlines how we collect, use, disclose, and protect your personal data when you use our application in connection with your Shopify store.

By using our O2O My-Invois app solution, you agree to the collection and use of your data as outlined in this document. If you do not agree with the terms of this notice, you should not use our app.


1. Data We Collect and How We Use It

As part of our service, we may collect and process the following personal data through the Shopify API. The specific permissions required are as follows:

Permission Description

read_orders

Access to read the details of orders placed in your store.
read_localesAccess human-readable names on your store.
read_customersAccess to read the details of your customers who placed order in your store.
read_productsAccess to read the details of products in your store.
customer_read_ordersAccess to read the details of orders placed in your store in Customer Detail page.
read_locationsAccess to read the details of locations.

These permissions will be used to retrieve data necessary for processing your store’s orders and for providing the requested services. The data obtained from the Shopify API is only used for the intended purpose and is not shared with third parties except as detailed below.


2. Data We Retrieve and Process for the MyInvois

As part of our solution, we will retrieve order data from your Shopify store for the Malaysia MyInvois. The following data are collected from customer request on the e-invoice:

Data Field Description
Order Datetime* The date and time the order was placed.
Order ID* The unique identifier for the order.
Order Total Amount* The total amount of the order, excluding taxes.
Order Discount Amount The discount applied to the order, if any.
Order Tax Amount The tax amount applied to the order.
Order Refunded Amount The amount refunded, if any.
Customer Name
Customer Email
Customer Phone Number
Customer Address
Cart Item
The order information needed to generate MyInvois

3. Data Retention Policy

We do not permanently store the data retrieved from your Shopify store. Any data processed and sent to the LHDN API will be retained only for the necessary and suitable duration.

  • Retention Period: All processed e-invoice request (if any) will be retained in our system for a maximum of 60 days to assist with any queries.
  • After 60 days, all data collected will be deleted from our system.

We will not use or retain your personal data for any other purposes beyond the stated services.


4. Data Sharing and Third-Party Access

We do not share your data with any third parties, except for:

  • The LHDN MyInvois API: The data is sent to the official Malaysia e-invoicing platform in a secure manner to validate the e-invoices.
  • Authorized Personnel: Only those involved in processing your data for the intended purposes (e.g., customer support or technical personnel) have access to the data.

We ensure that all necessary precautions are in place to protect the confidentiality and integrity of your data.


5. Data Protection and Security Measures

We take the protection of your personal data seriously. We implement appropriate technical and organizational measures to safeguard your data, including:

  • Data encryption during transmission.
  • Secure storage practices for any temporary data.
  • Access control mechanisms to restrict unauthorized access.

6. Your Rights

Under the Personal Data Protection Act 2010 (PDPA), you have the right to:

  • Withdraw consent for us to process your data at any time (subject to legal and contractual obligations).

If you wish to withdraw our access, you can uninstall our custom app or let us know to stop our integration. If you have any questions regarding the use of your data, please contact us.


7. Changes to this document

We may update this document from time to time to reflect changes in our data processing practices or legal requirements. We will notify you of any significant changes through our app or by email. Please review this page periodically for updates.


By using our solution, you acknowledge that you have read and understood this document and consent to the collection, use, and sharing of your data as described above.