Legal
Privacy Policy
What we collect when you browse, order or register with us, why we collect it, and what you can ask us to do with it.
- Who we are
- What we collect
- Why we use it
- Payments
- Who else sees it
- Cookies and local storage
- How long we keep it
- Your rights
- Security
- Children
- Changes
- Contact us
1. Who we are
SMOVF FRAGRANCE SDN. BHD. (202501015015 (1616430-K)) is the data user responsible for the personal data described here. Our registered address is:
No. 15, Jalan 4/91A, Taman Shamelin Perkasa56100 Kuala Lumpur
Malaysia
2. What we collect
We collect only what a specific thing you do actually requires.
If you place an order
- Your name, mobile number and email address.
- Your delivery address — unless you choose collection, in which case we do not ask for one.
- What you ordered, what you paid, and the order's status history.
- Any note you add to the order, such as gift-wrapping or delivery instructions.
If you send an enquiry
- Your name, contact details and the message you wrote.
If you register through a QR code or a referral link
- Your name and mobile number, and your email if you give one.
- Which campaign code or referral code brought you, so that the right gift is issued and the person who referred you is credited.
Automatically, on every request
- Your IP address and the time of the request, recorded by our hosting provider's logs and — for admin actions and QR scans — in our own activity log.
We do not ask for, and have no use for, your identity card number, your date of birth or your bank account details.
3. Why we use it
- To fulfil your order. Taking payment, packing, arranging delivery, and sending you the confirmation and status updates for that order.
- To answer you. Replying to an enquiry, a WhatsApp message or a question about an order.
- To run the gift and referral scheme. Issuing a voucher, checking it has not already been used, and crediting a referral.
- To keep records. Meeting our accounting and tax obligations, and being able to show what happened if an order is disputed.
- To protect the shop. Detecting and dealing with fraud, abuse of voucher codes, and attacks on the site.
We do not sell personal data, and we do not send marketing messages to people who have not asked for them.
4. Payments
We never see your card or banking credentials. When you pay online you are taken to a licensed Malaysian payment gateway, you enter your details on their page, and they tell us only whether the payment succeeded and what reference it was given. Nothing sensitive passes through this site.
If you pay by bank transfer or DuitNow QR, you transfer directly from your own banking app and send us the reference. If you order over WhatsApp, the conversation is held on WhatsApp and governed by their own privacy terms as well as this one.
5. Who else sees it
We disclose personal data only to parties who need it to do something you have asked for:
- Our payment gateway, to take and verify a payment.
- Our courier, to deliver your parcel. They receive your name, address and phone number, and nothing else.
- Our hosting and email provider, who store the site and send order confirmations on our behalf.
- A regulator, court or law enforcement agency, where we are required by Malaysian law to disclose.
Some of these providers operate servers outside Malaysia. Where that is so, we transfer data only to providers who are contractually bound to protect it to a standard comparable to the PDPA.
6. Cookies and local storage
This site sets no advertising cookies and runs no third-party tracking scripts. What it does use:
- Your cart
- Kept in your own browser's local storage, on your device. It is not sent to us until you check out, and clearing your browser data clears it.
- Admin session cookie
- Set only for our own staff when they sign in to the admin panel. Visitors never receive it.
7. How long we keep it
- Orders and payment records: seven years, which is the retention period Malaysian tax and companies legislation expects of business records.
- Enquiries: two years from your last message to us.
- Customer and gift records: until you ask us to remove them, or two years after your last order or scan.
- Server logs: as long as our hosting provider retains them, typically a matter of weeks.
8. Your rights
Under the PDPA you may ask us to:
- tell you what personal data of yours we hold, and give you a copy;
- correct anything that is wrong or out of date;
- stop using your data for a particular purpose, or delete it, where we have no legal obligation to keep it;
- stop contacting you for anything other than an order in progress.
Ask us using any of the routes in section 12. We will respond within 21 days. There is no charge. We may ask you to confirm something only the account holder would know before we release or change anything — handing someone else's order history to a stranger is the failure this step exists to prevent.
If you are not satisfied with our response, you may complain to the Personal Data Protection Commissioner, Malaysia.
9. Security
The site is served over HTTPS. Passwords for our admin panel are stored hashed, never in a readable form, and database queries are parameterised so that data cannot be extracted through the site's own forms. Access to order data is limited to staff who need it, and every administrative change is logged with the account that made it.
No system is perfectly secure. If a breach ever affects your personal data, we will tell you what happened, what was exposed, and what we are doing about it.
10. Children
This shop is intended for adults. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us their details, tell us and we will delete them.
11. Changes
When this policy changes we update the date at the top of the page. If a change materially affects how we use data you have already given us, we will say so directly rather than relying on you to notice.
12. Contact us
Message us on WhatsApp, call +6019-334 9486, use the contact form, or write to us at the registered address in section 1.