Rujukan Laman

Privacy Policy for your Malaysia account

Account setup, wallet checks, cookie choices and privacy requests are mapped in this Privacy Policy, so you know what data we collect before you open your account.

Malaysia data handlingCookie choices explainedWallet record privacyRequest routes included
tng888 Privacy Policy for your Malaysia account
HELP ROUTES

Three privacy contact routes

Privacy questions should reach the team that can view account records and reply with the right context.

Account privacy email Send privacy requests to the address shown in your account area. We use it for data access, correction, deletion checks and questions about how wallet or identity records are kept.
In-account message desk Use the message desk after login when your request involves account activity. It helps us match your request to the right profile without asking you to repeat private details.
Security report channel Contact the security route if you think someone accessed your account or changed your details. We may ask verification questions before discussing records or making privacy-related changes.
ACCOUNT CARE

Six ways we protect your data

Our privacy work covers more than a policy page. We limit what we collect, separate sensitive checks from general account activity, and give you clear ways to ask for changes.

Data collection

We collect the data needed to open your account, verify access, keep wallet records, answer messages and maintain security logs. Extra data is avoided unless a function or legal duty requires it.

Cookie controls

Cookies help keep sessions active, remember language choices and detect repeated failed access attempts. You can change browser settings, but some account and security features may not work as intended.

Wallet record handling

Touch 'n Go, GrabPay, Boost dan FPX references are stored as transaction records, not as full payment credentials. We use them for reconciliation, dispute checks and account statement accuracy.

Account security

We use login checks, session controls and restricted staff access to reduce misuse of account data. If we notice unusual activity, we may pause certain changes while identity is checked.

Retention periods

Account, wallet, contact and security records are kept only as long as needed for operations, legal duties, dispute handling or audit needs. After that, data is deleted or anonymised.

Change requests

You may ask us to correct data, provide a copy, limit certain uses or delete records where lawful. We verify your identity before acting so another person cannot change your file.

Privacy questions before you join

These answers explain how the Privacy Policy works in everyday account situations. They cover the data we collect, why payment references are stored, how cookies affect your session and how to contact us. For any request tied to access or eligibility, the answer depends on local law and is available where local law permits.

We collect account details, contact data, device identifiers, login records and wallet references needed to set up and protect your account. Some checks may depend on your location, payment route and local law.

We store payment references to match wallet activity, resolve disputes, check account ownership and meet record duties. We do not store full payment credentials from these services in the account profile.

Yes, you may request a copy of personal data linked to your account. We will verify your identity first, then provide the data we can release under applicable law and safety rules.

You can ask us to correct inaccurate data or delete records where lawful. Some wallet, security or legal records may need to be kept for a set period before removal is allowed.

Cookies help maintain your session, remember language choices, measure page errors and detect unusual login patterns. If you block cookies, some account features may require repeated checks or may not load correctly.

Access is limited to staff or service partners who need the data for account help, wallet checks, security, technical upkeep or legal handling. Access is controlled and tied to work purpose.

Use the privacy email or in-account message desk shown after login. Include your account name and request type, but do not send passwords, one-time passcodes or another person’s private data.