OnlyKipas legal

Privacy notice

This notice explains what OnlyKipas holds, why it is needed, and how business owners and their customers can ask about it.

Last updated: 17 July 2026

Who is responsible

OnlyKipas is operated by OnlyKipas Sdn Bhd (business registration 1582122-V).

The business controls the customer and team records entered into its workspace. OnlyKipas processes those records to provide and protect the service.

What we collect

  • Business details, including SSM or BRN, TIN, SST registration, MSIC code, locations, branding, and service settings.
  • Owner and staff account details, roles, branch access, schedules, and security audit activity.
  • Attendance events, approved network evidence, device information, and selfie evidence captured during clock-in or clock-out.
  • Customer details entered by the business, including names, phone numbers, bookings, packages, memberships, vouchers, and service history.
  • Sales and operational records, including receipts, tenders, refunds, voids, commissions, cash closings, and booking requests.
  • Technical and security data such as IP addresses, browser details, timestamps, rate-limit events, and application logs.

Why we use it

  • To run the business workspace: bookings, checkout, attendance, customer care, reports, and closing.
  • To keep tenants separate, enforce roles, investigate fraud or misuse, and maintain an audit trail.
  • To provide support, recover accounts, improve reliability, and communicate service changes.
  • To meet accounting, tax, employment, and other Malaysian legal obligations that apply to the business or OnlyKipas.

Who helps us process it

We use a small number of service providers to operate OnlyKipas:

  • A managed database and authentication provider, for application data, sign-in, and private file storage.
  • A cloud hosting provider, for running the application and its operational logs.
  • WhatsApp / Meta when a business user chooses to open a prepared WhatsApp message. OnlyKipas does not claim that a message was received or read.
  • An email delivery provider, for service email such as password recovery, receipts, and reminders.

These providers may process data outside Malaysia under their own safeguards. We do not sell customer or staff data.

How long we keep it

  • Attendance selfie files are scheduled for deletion after 45 days; the attendance event and its audit record remain.
  • Business, customer, sales, and accounting records remain while the workspace is active and for any period required for support, disputes, tax, or Malaysian law.
  • Security logs, backups, rate-limit evidence, and expired tokens are kept only for reasonable operational and recovery periods.

When a business leaves, we will agree an export and deletion timetable, subject to records we must retain by law or to resolve a live dispute.

Your choices and requests

Business owners, team members, and customers can ask to access or correct their personal data, withdraw consent where consent is the basis, or request deletion where retention is not legally required. Customers should normally contact the business first because the business controls their record.

For a data request or privacy question, email hi@onlykipas.com. Include the business name and enough detail for us to verify the request without sending unnecessary personal data.

Security and changes

OnlyKipas uses tenant isolation, role checks, encrypted transport, private storage, audit logs, and bounded public endpoints. No online system is risk-free. Businesses must protect their accounts and tell us promptly about suspicious access.

We will update this notice when the service or legal requirements materially change.