Privacy Policy

Last updated: 23 Aug 2026

Draft. This document is pending professional legal review and may change. Questions? Contact us.

Leish! (“we”, “us”), operated by [LEISH OPERATING COMPANY SDN BHD] (company no. [NUMBER]), respects and is committed to the protection of your personal data under the Personal Data Protection Act 2010 (“PDPA”). This policy explains what we collect, why, who we share it with, and your rights.

1. What we collect

  • Account data: name, email address, password (hashed — we never store it in readable form).
  • Booking data: service, event type, date, time, venue, guest count, notes you provide.
  • Payment data: amounts and payment references via our gateway (Billplz). We do not store card or bank credentials on our servers.
  • Communications: messages sent through booking threads, and support correspondence.
  • Technical data: IP address and basic request logs for security and debugging.

2. Why we use it

  • To create and manage your account and bookings.
  • To connect you with the artist/studio you booked: they receive the details needed to perform the service (name, contact, event details).
  • To collect deposits and balances, issue invoices and process refunds through our payment gateway.
  • To send transactional emails: verification, booking updates, quotation notices, balance reminders. Marketing emails are opt-in and every message includes an unsubscribe link.
  • To prevent fraud, enforce our terms, and keep the platform secure.

3. Who we share it with

  • The professional you book — only the details necessary to deliver the service.
  • Payment gateway (Billplz) — payment processing, under their own privacy terms.
  • Email delivery providers — to send you transactional mail.
  • Authorities — where required by law.

We never sell your personal data.

4. Retention

DataRetention
Invoices & payment records[7 years], as required by Malaysian law; personal identifiers are then stripped.
BookingsAnonymised [2 years] after the event date.
Security & request logs[30 days].
Account dataUntil you delete your account, plus any legally required retention period.

5. Security

Passwords are hashed with a memory-hard algorithm (scrypt); sessions use signed, HTTP-only cookies; data in transit is encrypted (TLS); database access follows least-privilege practices.

6. Your rights

Under PDPA you may request access to your personal data, corrections, or withdrawal of consent (which may end our ability to provide services). You can also export a copy of your booking data anytime from your dashboard. Write to [DPO / PRIVACY EMAIL] — we respond within [21 days]. You may complain to the Personal Data Protection Department (JPDP) at any time.

7. Cookies

We use a single essential cookie for your login session and store your light/dark theme preference locally in your browser. No advertising trackers.

8. Changes

We may update this policy from time to time; material changes will be announced on-site or by email. Questions? Contact us.