Legal

Privacy Policy

Effective Date: 1 March 2026  Â·  Compliant with the Personal Data Protection Act 2010 (Malaysia)

1. Who We Are

Revoluzion Automotive ("We", "Us", "Our") operates an online automotive performance parts store. We are a data user under the Personal Data Protection Act 2010 (PDPA) of Malaysia. We are committed to protecting the personal data you entrust to us and processing it lawfully and transparently.

We do not sell, rent, or trade your personal data to any third party for marketing purposes.

2. Data We Collect

2.1 Data You Provide Directly

CategoryDataPurpose
IdentityFull nameOrder processing, LHDN e-invoices
ContactEmail addressAccount registration, order notifications, receipts
ContactPhone numberDelivery coordination, fraud prevention
DeliveryShipping addressParcel delivery via J&T Express
BillingBilling addressPayment processing, LHDN e-invoice
TaxSST number (B2B, if applicable)LHDN e-invoice for business buyers
BusinessCompany name, BRN (Dealer applicants)Dealer programme verification
AuthPassword (bcrypt-hashed, never plain text)Account authentication

2.2 Data Collected Automatically

CategoryDataPurpose
DeviceIP addressFraud prevention, security
BrowserBrowser type, OS, device typeAnalytics, bug detection
CookiesHTTP-only session cookie, CSRF tokenAuthentication and security

2.3 Data from Third Parties

SourceData ReceivedPurpose
Google (OAuth)Name, email, profile photoAccount creation via Google Sign-In
StripePayment status, last 4 digits of cardFraud monitoring, order confirmation

3. Legal Basis for Processing

  1. Contractual necessity – To process and fulfil your orders, issue invoices, and maintain your account.
  2. Legal obligation – To comply with LHDN e-invoice requirements under the Income Tax Act 1967.
  3. Legitimate interest – Fraud prevention, website security, and transactional communications.
  4. Consent – Marketing email opt-in only, where explicitly provided by you.

4. How We Use Your Data

  1. Processing and fulfilling your orders
  2. Issuing tax invoices and LHDN-compliant e-invoices
  3. Sending order status, dispatch, and delivery notifications
  4. Managing your account and dealer application
  5. Fraud detection and prevention
  6. Complying with Malaysian legal obligations
  7. Sending marketing emails – only where you have explicitly opted in. You may opt out at any time.

5. Data Sharing

RecipientData SharedReason
J&T ExpressName, address, phone, order referenceParcel delivery
StripeName, billing address, emailPayment processing
NOWPaymentsOrder amount, email (optional)Crypto payment processing
ResendEmail address, order detailsTransactional emails
VercelSite traffic dataHosting platform
NeonAll stored database recordsCloud PostgreSQL database
LHDN (MyInvois API)Name, address, tax numbers, invoice amountsMandatory e-invoice submission

We do not share your data with advertising networks, data brokers, or marketing third parties.

6. Data Retention

Data CategoryRetention PeriodReason
Order records and invoices7 yearsLHDN audit requirement
Account informationDuration of account + 1 year post-deletionContractual
Communication records2 yearsDispute resolution
IP / access logs90 daysSecurity monitoring

7. Your Rights Under PDPA 2010

  1. Right of Access – Request a copy of the personal data we hold about you (response within 21 days).
  2. Right of Correction – Request correction of inaccurate data, or update directly in account settings.
  3. Right to Withdraw Consent – Withdraw marketing consent at any time. Does not affect order processing.
  4. Right to Restrict Processing – Request restriction in certain circumstances.

To exercise these rights, email zack@revoluzion.io.

8. Cookies

CookiePurposeDuration
next-auth.session-tokenAuthentication session (HTTP-only)30 days
next-auth.csrf-tokenCSRF protectionSession

We use Vercel Analytics for privacy-respecting usage analytics – no personal data is linked to analytics cookies. You may manage cookies through your browser settings; disabling essential cookies will prevent login.

9. Data Security

  • Passwords hashed with bcrypt (12 salt rounds); never stored in plain text
  • TLS 1.2+ encryption for all website traffic
  • Neon PostgreSQL with encryption at rest
  • Payment data not stored on our servers – tokenised by Stripe
  • HTTP-only cookies, CSRF protection, rate-limited authentication
  • Role-based access control at middleware level

10. Children's Privacy

This website is not directed at persons under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, contact us immediately.

11. Changes to This Policy

We may update this Privacy Policy. Changes take effect upon posting. We will notify active account holders by email of material changes.

12. Contact

Privacy enquiries: zack@revoluzion.io