Privacy Policy

Last updated: 2026-04-26 · W Insight Sdn Bhd

This Privacy Policy explains how W Insight Sdn Bhd ("we", "us") collects, uses, and protects your personal data when you use our TikTok ad management service at winsight.com.my. We process personal data in accordance with the Personal Data Protection Act 2010 (PDPA) of Malaysia.

1. Data we collect

CategoryExamplesWhy
AccountName, email, username, password (hashed), phoneAccount creation, login, support
Company / billingCompany name, SSM, TIN, SST, IC, business address, billing contactSubscription billing, LHDN e-invoicing
PaymentCard details (collected and stored by Stripe, not us)Process payments
TikTok integrationOAuth access token, advertiser ID, store ID, campaign data, ad spend metricsManage your ad campaigns on your behalf
TechnicalIP address, browser user agent, login timestampsSecurity, audit log, fraud prevention

2. How we use your data

3. Third parties we share data with

We do not sell your personal data to anyone, ever.

4. Cross-border data transfer (PDPA Section 129)

Some processors above (Stripe, TikTok APIs) may store or process data outside Malaysia. By using the service, you consent to this transfer. We only work with providers who maintain at least equivalent data protection standards.

5. How long we keep your data

We retain account and billing data for the lifetime of your subscription plus 7 years afterwards (to comply with Malaysian tax record-keeping requirements). Marketing consent records are retained as long as you remain subscribed to our marketing list. You can request earlier deletion in writing — see Section 7.

6. Security

We protect your data with industry-standard measures: passwords are hashed with bcrypt (cost factor 12), payment data is handled by PCI-compliant Stripe, and database access is restricted to authorised W Insight personnel. No system is perfectly secure, but we treat your data with the seriousness it deserves.

7. Your rights under the PDPA

You have the right to:

To exercise any of these, email winsightmarketing@winsight.com.my. We will respond within 21 days.

8. Cookies

We use session cookies for login, "remember me" tokens for convenience, and trusted-device tokens for security. We don't use third-party advertising or analytics cookies. See our Cookie Policy for details.

9. Changes to this policy

We may update this policy as our service evolves. The "Last updated" date at the top reflects the current version. Material changes will trigger a re-acceptance prompt at next login.

10. Contact

Questions, complaints, or requests under the PDPA? Email winsightmarketing@winsight.com.my. If you're unsatisfied with our response, you have the right to escalate to the Personal Data Protection Department of Malaysia (JPDP).

← Back to login