Rujukan Laman

How now32 Handles Your Personal Data

This Privacy Policy sets out exactly what personal data now32 collects from you, how we use it, how long we keep it, and who we may share it…

Data collected only for stated purposesTouch 'n Go, GrabPay, Boost dan FPX payment data securedYour rights to access and correct your dataRetention periods clearly definedContact us anytime to raise a privacy concern
now32 How now32 Handles Your Personal Data
PRIVACY CONTACT PATHS

Reach Our Privacy Team Directly

If you have a question about how your data is used, want to request a copy of what we hold about you, or need to report a concern, our privacy team is…

Email Privacy Request Send a written data request or correction notice to our dedicated privacy address. We log every email on receipt and reply with a reference number so you can track progress without following up blindly.
Live Chat Support Our support chat is available around the clock. Raise a privacy question directly in the chat window and we will escalate it to the privacy team within one business day, with a written response to follow.
In-Account Privacy Centre Log in to your now32 account, navigate to Account Settings and open the Privacy Centre tab. From there you can download your data file, update marketing preferences or submit a deletion request without needing to contact us separately.
HOW WE PROTECT YOUR DATA

Six Ways We Keep Your Account Secure

Data security at now32 is built on layered technical controls, strict internal access policies and regular audits of how personal data flows through our systems.

Encrypted Data Storage

All personal data stored on now32 servers is encrypted at rest using industry-standard AES-256 encryption. Your account credentials, transaction history and contact details are never held in plain text at any layer of our infrastructure.

TLS-Secured Connections

Every connection between your browser or app and our servers is protected by TLS 1.2 or higher. This means your session data, login credentials and payment flows — including Touch 'n Go and GrabPay — cannot be read by third parties in transit.

Cookie Controls in Your Hands

We use cookies to keep your session active, remember your preferences and measure how our pages perform. You can review which cookies are active and withdraw consent for non-essential cookies at any time through the Cookie Settings panel in your account.

Strict Data Retention Limits

We keep your account data only as long as required by law or as necessary for the service. When the retention period ends, data is securely deleted or anonymised. You may request early deletion where no legal obligation requires us to retain it.

Limited Internal Access

Access to personal data inside now32 is restricted on a need-to-know basis. Only staff whose roles require it can view your account details, and every access event is logged so we can audit it if a concern is raised.

Third-Party Data Sharing Rules

We share your data with third parties only where necessary — for example, with Boost or FPX processors to complete a payment — and only under contracts that bind those parties to data-protection standards equivalent to our own. We do not sell your data.

Your Privacy Policy Questions

The questions below cover the most common concerns we receive about data collection, your rights, cookie use and how to contact us. If your question is not listed here, reach out through the Privacy Centre in your account or via live chat and we will respond in writing.

We collect your name, email address, phone number, date of birth, country of residence and the payment-method identifiers you use — such as your Touch 'n Go or GrabPay account reference. We also collect device, browser and session data automatically when you log in.

Payment data is passed to the relevant processor — Touch 'n Go, GrabPay or Boost — to complete your transaction. We retain a transaction reference and amount for our records but do not store your full payment credentials. FPX bank-transfer references are handled the same way.

Yes. Log in and open the Privacy Centre in Account Settings to download your data file, or send a written request to our privacy email. We will provide your data in a portable format within the timeframe required by applicable Malaysian law.

Submit a correction or deletion request through the Privacy Centre tab in your account or via our privacy email. We will action corrections promptly and process deletion requests where no legal obligation requires us to retain the data, confirming the outcome in writing.

We use essential session cookies to keep you logged in, preference cookies to remember your settings, and analytics cookies to measure page performance. Non-essential cookies can be turned off at any time through the Cookie Settings panel — essential cookies cannot be disabled as the site needs them to function.

Data may be shared with payment processors and technology partners who may be located outside Malaysia. Where this occurs, we require contractual data-protection safeguards equivalent to Malaysian standards. We do not sell your personal data to any party under any circumstances.

We keep your account records for the period required by Malaysian financial and regulatory law — typically a minimum of five years from account closure. Once that period ends, your personal data is securely deleted or anonymised, and we will confirm this to you on request.