1. Who is responsible for your data
The Shelf Enterprise (registration no. 202001012345 (1234567-X)), of No.3, Jalan BP 6/2, Bandar Bukit Puchong, 47100 Puchong, Selangors, Malaysia, is the data user under the Personal Data Protection Act 2010 ("PDPA"). This policy explains how we handle personal data when you visit our website, shop with us, apply as a vendor, or work with us.
For anything about your personal data, contact privacy@theshelf.my.
2. What we collect
- Shoppers: name, phone number and email when you use self-checkout or pre-order; what you bought, when and where; payment status (we never see or store your full card number).
- Vendors and applicants: your name, business name, email, phone, business registration (SSM) and tax details, business addresses, product information, and bank account details for payouts.
- Staff: name, email, role and branch, and a record of actions you take in our systems.
- Everyone: technical data such as IP address, device and browser type, and error reports, collected when you use the website.
3. Why we use it
- to complete and support your orders, pre-orders and collections, and to issue receipts;
- to assess vendor applications, manage consignment stock, calculate and pay what we owe vendors, and keep the records the law requires;
- to run, secure and improve our systems, prevent fraud and abuse, and diagnose faults;
- to send you service messages about your order or application;
- to send marketing, only if you have opted in — you can withdraw at any time.
5. Transfers outside Malaysia
Some of our providers store or process data outside Malaysia. Where that happens we take steps to make sure your data is protected to a standard comparable with the PDPA, and we only transfer it as the PDPA permits. [Confirm the regions your providers use.]
6. How long we keep it
We keep personal data only as long as we need it for the purposes above. Sales and accounting records must be kept for [7] years to meet tax and company law; where a shopper asks us to erase their data we anonymise the personal details on those records rather than deleting the transaction itself. [Confirm retention periods with your accountant.]
7. How we protect it
Access to our systems is restricted by role and branch, every change is logged against the person who made it, sensitive details such as bank account numbers are stored encrypted, and payments are handled by a certified provider. No system is perfectly secure; if a breach is likely to cause you significant harm we will notify you and the Personal Data Protection Commissioner as the law requires.
8. Your rights
Under the PDPA you may ask to see the personal data we hold about you, ask us to correct it, withdraw consent to marketing or other optional uses, and limit how we process it. We will respond within the time the law allows.
You can also ask us to erase your personal data, using our data removal request form.
- Request erasure: Remove my data (/data-request)
- Anything else: privacy@theshelf.my
If you are unhappy with how we have handled your data you may complain to us first, and you may also contact the Personal Data Protection Commissioner.
9. Children
The Services are not directed at children under 18, and we do not knowingly collect their personal data. If you believe a child has given us data, contact us and we will delete it.
11. Bahasa Malaysia
[A Bahasa Malaysia version of this notice is to be provided — the PDPA expects privacy notices in both national language and English.]
12. Changes to this policy
We will post any changes here and update the date at the top. If a change is significant we will tell you directly.
Questions about this document? See Contact us.
