1. Who is responsible and how to contact us
CMY PHONE REPAIR is responsible for the relevant personal data described in this policy.
No. 17A, Jalan Mulia 1, Taman Sri Mulia, Sungai Abong
84000 Muar, Johor, Malaysia
Phone: +60 10-545 5808
General enquiries: admin@cmyphonerepair.com
Privacy and deletion requests: privacy@cmyphonerepair.com2. Scope
This policy applies to visits to this website, repair or training enquiries, the Google Review drafting tool, and authorised connections to the CMY PHONE REPAIR Facebook Page or TikTok account. If a social-platform integration has not been enabled, we do not obtain data through that integration.
3. Data we may handle
Only when the relevant feature is active, the required authorisation exists, or you contact us directly, we may handle:
- contact messages, appointment details and service information that you provide;
- Facebook or TikTok posts, images, videos, comments, direct messages, usernames, platform user IDs or event IDs;
- Page/account information and analytics available within the authorised platform permissions;
- browser and device category, approximate region, pages visited, button interactions and necessary security logs;
- OAuth authorisation status, granted scopes, token expiry and revocation status.
4. Information we do not request
We do not ask for your Facebook or TikTok password, Google password, phone passcode or one-time password (OTP) through this website, OAuth connection or social-platform API. Please do not send this information to us.
5. Why data is used
- to answer enquiries, arrange repair or training, and provide customer support;
- to manage social content, comments or messages after the required authorisation;
- to prepare drafts that a staff member or user must review and approve;
- to secure accounts, prevent abuse, verify webhook sources and reject duplicate events;
- to measure and improve the website after analytics consent.
6. AI-assisted content and customer replies
We may use the OpenAI API to prepare editable review, content or customer-reply drafts from information actively selected or provided by a user. AI must not publish content or make the final decision for the user. A staff member or the user should review and approve a draft before it is sent or published.
7. Sharing and confirmed service providers
We do not sell personal data. Depending on the feature actually used, data may be processed by Facebook/Meta, TikTok, OpenAI, Google Analytics, Google Maps, WhatsApp, Waze, Cloudflare and the website hosting infrastructure. Information may also be disclosed when required by law or reasonably necessary for security, dispute handling or protection of rights.
8. Cross-border processing
These platforms and technical providers may process data outside Malaysia. Where cross-border processing occurs, we use the applicable contractual measures, platform controls, access restrictions and technical safeguards, and follow applicable Malaysian law.
9. OAuth token storage and revocation
If you authorise a Facebook or TikTok connection, access and refresh tokens are kept only in restricted server-side secret or durable storage. They are not placed in front-end JavaScript, a public repository or ordinary logs. You may revoke access in the application/business-integration settings of Facebook/Meta or TikTok/Business Center, or email privacy@cmyphonerepair.com to ask us to revoke and remove the related tokens.
10. Retention
- OAuth tokens: while authorisation remains active; removed within 30 days after revocation or approval of a deletion request;
- webhook deduplication event hashes: no more than 7 days, without storing message text;
- security and necessary technical logs: normally no more than 90 days;
- working copies of social content, comments or messages: only as long as needed for the authorised response, publishing or support task, normally no more than 90 days;
- deletion-request records: up to 24 months to evidence the request and outcome.
Information may be retained longer when required for law, accounting, an unresolved dispute or a security investigation.
11. Security
We use HTTPS, server-side secrets, least-privilege access, OAuth state validation, webhook-signature verification, rate limits, duplicate-event protection and log minimisation. No system can guarantee zero risk; suspected issues are handled according to their impact and applicable requirements.
12. Your rights
Subject to applicable law, you may ask whether we process your personal data and request access, correction, withdrawal of consent, restriction of certain processing or deletion. Email privacy@cmyphonerepair.com. We request only the minimum information needed to verify the requester and locate the relevant records. See the Data Deletion Instructions for the process.
13. Malaysia PDPA
Where applicable, we handle personal data connected with commercial transactions in line with the notice and choice, disclosure, security, retention, data integrity and access principles of Malaysia's Personal Data Protection Act 2010 (PDPA, Act 709), as amended. This policy does not limit rights available under applicable law.
14. Google Analytics and your choice
Google Analytics loads only after you choose “Allow analytics”. It may measure page visits, device category, approximate region and button interactions. It does not record WhatsApp conversations, phone calls, IMEI numbers, phone passwords or data inside repair devices. You may change your choice on this page or in the footer.
15. Third-party links and updates
When you open WhatsApp, Facebook, TikTok, Google Maps or Waze, the relevant provider handles data under its own policy. We may update this policy if our services, applicable law or actual handling practices change, and will show the new update date here.