Privacy Policy
Your data, your rights.
This page explains what personal data LokalGig collects, why we collect it, how we protect it, and how to exercise your rights under Malaysia’s Personal Data Protection Act 2010 (PDPA).
Last updated: 30 April 2026· Operator: LokalGig (Malaysia)
The short version
- We don’t sell your data. Ever. Not to advertisers, not to data brokers, not to AI training providers outside the scope needed to run LokalGig.
- We don’t see your WhatsApp chats. Buyer-seller conversations happen on WhatsApp directly. LokalGig only logs that a “Contact on WhatsApp” click happened, not what you typed.
- We don’t handle your money. LokalGig takes zero commission. Payment happens between buyer and seller off-platform (cash, DuitNow, online transfer, etc.) — so we never collect bank accounts, card numbers, or transaction amounts.
- No mandatory IC upload. You can post a gig without ever giving us your IC, passport, or selfie. Verification is optional and earns trust badges, not access.
- You can delete everything. Email hikayatdaily.app@gmail.com from your registered address and we’ll erase your account and personal data within 30 days, except where Malaysian law requires us to retain something.
1.Who we are
LokalGig (“LokalGig”, “we”, “us”, “our”) operates the website at lokalgig.my — a digital launchpad that helps Malaysians publish service listings and receive enquiries via WhatsApp. We are based in Malaysia and act as a data user as defined under Section 4 of the PDPA 2010.
For privacy questions, data access requests, or complaints, contact our data protection contact at hikayatdaily.app@gmail.com.
2.What personal data we collect
We only collect what we need to run the service. In practice, that is:
| Category | What it includes | Why we have it |
|---|---|---|
| Account identifiers | Email address, password hash (we never see plain passwords), display name, username, optional avatar. | Required to create and secure your account. |
| Profile data you publish | Bio, gig title, gig description, price, category, state, gallery images, languages, optional WhatsApp number. | You publish these voluntarily; they are visible on the public site. |
| WhatsApp number (optional) | Stored only if you choose to enable WhatsApp contact. Visible publicly only via the click-to-chat link, not as raw text. | Lets buyers reach you on WhatsApp. You can remove it any time. |
| Login signals | IP address, device/browser user agent, login timestamps, session cookies. | Account security, fraud prevention, abuse investigations. |
| Usage analytics | Pages viewed, gigs viewed, search queries, click events (e.g. 'WhatsApp click', 'share clicked'). Aggregated, not tied to your name in our analytics tools. | Improve the product and measure the impact of new features. |
| AI helper inputs | Rough notes you paste into the AI Gig Builder are sent to our LLM provider to generate a draft listing. We log usage counts and approximate cost, not the full text long-term. | Generate your draft listing; enforce daily fair-use limits. |
| Verification documents (optional) | If you choose to verify your identity for a trust badge, we may request an IC, business registration (SSM), or selfie. Stored encrypted, never displayed publicly. | Award trust badges only. You can decline and still use LokalGig. |
| Communications | Emails you send us, support tickets, abuse reports. | Respond to you and keep records for safety. |
What we do NOT collect:bank account numbers, credit/debit card numbers, transaction amounts between buyer and seller, the contents of your WhatsApp messages, your phone’s contact list, your location beyond the state you select, or biometric data (other than an optional verification selfie if you opt in).
3.Why we use your data (purposes)
Under PDPA Section 6, we process personal data only for these stated purposes:
- Run the service— create and secure your account, render your gig listings, route “Contact on WhatsApp” clicks.
- Communicate with you — transactional emails (sign-up, password reset, booking enquiries, policy changes). Marketing emails only with your separate opt-in.
- Keep the platform safe — detect fraud, scams, scraping, spam, abusive behaviour, and ToS violations.
- Improve the product — measure feature performance and bug rates using aggregated analytics.
- AI-assisted features — process the rough notes you paste into the AI Gig Builder so it can return a polished bilingual listing.
- Comply with the law — respond to lawful Malaysian regulatory and law enforcement requests.
We do not use your data for automated decision-making that produces legal effects on you (e.g. credit scoring). Account suspensions are reviewed by a human operator.
4.Legal basis (PDPA)
We rely on the following lawful bases under the PDPA 2010:
- Your consent — for optional features like marketing emails, identity verification, or WhatsApp contact display.
- Contractual necessity — to provide the service you signed up for (your account, your gigs, your dashboard).
- Legitimate interest — fraud prevention, security logging, and aggregated product analytics, balanced against your rights.
- Legal obligation — when required by Malaysian law, regulators, or valid court orders.
5.Who we share data with
We do not sell or rent personal data. We share only with the following categories of processors, all bound by confidentiality and data-protection terms:
| Category | What it includes | Why we have it |
|---|---|---|
| Hosting & database | Supabase (Postgres), Vercel (Next.js hosting). Data primarily stored in Supabase regions chosen for performance. | Run the website and database. |
| Email delivery | Transactional email provider for sign-up, password reset, and booking notifications. | Send the messages you expect. |
| AI / LLM provider | Inputs you paste into the AI Gig Builder are processed by a large-language-model API (e.g. OpenAI / Anthropic). Providers are contractually prevented from training on your content where the API supports that flag, which we enable. | Generate your draft listing in seconds. |
| Analytics | Privacy-respecting product analytics. We do not load Google Analytics or third-party ad pixels. | Understand which features help users. |
| Authorities (when required) | PDRM, MCMC, the Personal Data Protection Commissioner, or a Malaysian court — only on a valid legal request. | Legal compliance. |
Cross-border transfer.Some of our processors (e.g. AI providers, hosting CDN edges) are located outside Malaysia. We rely on contractual safeguards and the PDPA’s permitted transfer conditions (Section 129) when this happens. We do not transfer your data to a country that materially weakens your PDPA rights.
6.Cookies and similar technologies
We use a minimal set of cookies and local-storage entries:
- Essential — auth/session cookies (so you stay logged in), CSRF tokens, language preference (BM/EN), theme preference (Terang/Malam). Cannot be turned off without breaking the site.
- Functional — remembers your bookmarks, draft gig autosave, recent searches.
- Analytics — counts page views and clicks, in aggregate.
We do not run third-party advertising trackers, fingerprinting libraries, or remarketing pixels. You can clear cookies anytime via your browser settings.
7.A note on WhatsApp
LokalGig is WhatsApp-first. When a buyer taps “Contact on WhatsApp” on your gig, they are taken to wa.me with a pre-filled message and your number. From that point on, the conversation is between you and the buyer on WhatsApp’s servers — not on LokalGig.
We log only the click event (which gig, what time) for analytics and abuse prevention. We never see your WhatsApp messages, media, or call logs. WhatsApp’s own privacy policy applies to that conversation.
8.How long we keep data
- Active accounts: for as long as your account is open.
- Closed accounts: personal data is erased or anonymised within 30 days of closure, except for records we must retain by law (e.g. abuse investigations, financial records if any).
- Server logs: 90 days, then aggregated.
- AI helper inputs: raw inputs are retained at most 30 days for debugging; aggregated cost/usage metrics are retained indefinitely with no personal content.
- Backups: encrypted backups may persist up to 60 days after deletion before they roll off.
9.Your rights under the PDPA
As a data subject under Malaysian law, you have the following rights. To exercise any of them, email hikayatdaily.app@gmail.com from the address registered on your account. We respond within 21 days.
- Right of access (s.30): request a copy of the personal data we hold about you.
- Right of correction (s.34): ask us to correct inaccurate or incomplete data. Most fields are editable directly in your profile.
- Right to withdraw consent (s.38): opt out of marketing or any consent-based processing at any time.
- Right to limit processing (s.42): ask us to pause processing for direct-marketing purposes.
- Right to delete: request closure of your account and erasure of your personal data, subject to lawful retention obligations.
- Right to lodge a complaint:with the Personal Data Protection Department (JPDP), Ministry of Digital, Malaysia. We’d appreciate the chance to address your concern first.
10.How we protect your data
- HTTPS/TLS on every page; HSTS preload-eligible.
- Passwords are hashed with bcrypt-class algorithms; we never store them in plain text.
- Database access is row-level security (RLS) protected — even our backend code can’t read another user’s row without an explicit policy match.
- Service-role credentials are restricted to server-side cron and admin paths.
- Verification documents (if uploaded) are stored in a private bucket and never linked into public URLs.
- Internal access is least-privilege and audit-logged.
No system is unbreakable. If we ever discover a breach affecting your personal data, we will notify affected users without undue delay and report to the Commissioner where required by law.
11.Children
LokalGig is not intended for users under 18. If you are under 18, please do not create an account or post a gig. If we learn we have collected personal data from someone under 18, we will delete it.
12.Changes to this policy
We may update this policy as the platform evolves. When we make a material change, we will:
- Update the “Last updated” date at the top of this page.
- Email registered users at least 14 days before changes that reduce your rights take effect.
- Surface an in-app notice on your dashboard.
Continued use of LokalGig after the effective date means you accept the updated policy. If you don’t agree, you can close your account at any time.
13.Contact
Privacy questions, data requests, or complaints — email hikayatdaily.app@gmail.com.
For everything else, hikayatdaily.app@gmail.com works.

