Legal
Privacy policy
Last updated 10 September 2026
JustBook (justbook.my) is a booking platform for service businesses in Malaysia. This policy explains what personal data we collect, why, who we share it with, and the choices you have. It is written to meet the Personal Data Protection Act 2010 (PDPA) and applies to business owners and staff who use our dashboard ("vendors") and to the people who book through a vendor's page ("customers").
1. Who we are
JustBook is operated from Malaysia. For anything in this policy, write to hello@justbook.my.
For vendor accounts we are the data user (controller). For customer bookings, the vendor you book with decides why your data is collected and we process it on their behalf; the vendor is the data user and we are the data processor. Customers with questions about how a business uses their data should contact that business first.
2. What we collect
Vendors. Name, email address, password (stored as a hash), business name and address, opening hours, services and prices, staff names and emails, brand colour and logo, plan and billing status, and payment gateway settings you enter (we store gateway credentials encrypted and never display them again in full).
Customers. Name, phone number, email address, the service, staff member, date and time booked, notes you add, attendance (checked in, no-show), and payment status. Vendors may also add customers manually from bookings received by phone or WhatsApp.
Payments. Card numbers and bank logins never touch our servers. Payments are made on the pages of ToyyibPay, senangPay or Stripe, who send us the amount, status and a reference.
Automatically. IP address, browser and device type, pages visited and referring page, collected through Vercel Analytics and, on marketing pages, the Meta Pixel. Server logs are kept for a short period for security and debugging.
3. Why we use it
To run the service: create and confirm bookings, prevent double bookings, send confirmation, reminder and cancellation emails, show vendors their calendar and customer history, and process plan payments.
To support you: answer questions, investigate problems, and send service notices such as renewal reminders and receipts.
To improve and promote JustBook: understand which pages are used, measure whether our advertising brings new vendors, and show relevant ads to people who visited our site. We do not sell personal data and we do not use customer booking data for advertising.
To meet legal duties: tax records for payments, responding to lawful requests, and enforcing our terms.
4. Who we share it with
Only the providers we need to run JustBook, each under a contract that limits them to acting on our instructions:
- Supabase (database, authentication and file storage), hosted in Singapore.
- Vercel (web hosting, functions and analytics), served from Singapore.
- Resend (transactional email).
- TypeSafe AI (only when a vendor switches on note highlighting: the text of the note you type while booking is checked for things staff should know, such as an allergy. Your name, phone number and email are never sent with it).
- Stripe, ToyyibPay and senangPay (payments), when a vendor or customer pays.
- Meta Platforms (Meta Pixel on marketing pages only, for advertising measurement).
Vendors see the customers who booked with them. Customers see their own booking through the link in their confirmation email. We share data with authorities only when the law requires it.
Because some providers are outside Malaysia, your data is transferred to Singapore and, for email and payments, to the provider's regions. Each provider commits to security standards at least as strict as this policy.
5. Cookies and tracking
We use a login cookie that keeps vendors signed in. Vercel Analytics counts page views without cookies and without identifying you. The Meta Pixel on marketing pages sets Meta's cookies so we can measure ads and reach visitors again; it is not loaded inside the vendor dashboard or on customer booking pages of vendors.
You can block cookies in your browser. Signing in will not work without the login cookie. Meta's ad settings let you opt out of ad personalisation.
6. How long we keep it
Vendor accounts and their booking records are kept while the account is active. If you delete your business or account, its data is removed within 30 days, except payment records we must keep for seven years for tax purposes.
Customer booking records belong to the vendor's account and follow the same rule. Server logs are deleted within 30 days. Email delivery logs are kept by Resend for a limited period.
7. Your rights
Under the PDPA you may ask for a copy of the personal data we hold about you, ask us to correct it, withdraw consent for marketing, or ask us to stop processing it. Vendors can update most details in Settings. Customers can change or cancel a booking from the link in their confirmation email.
For anything else, email hello@justbook.my from the address on the account. We reply within 21 days. Where we act as processor for a vendor, we will pass the request to them.
8. Security
All traffic is encrypted with TLS. Passwords are hashed. Database access is restricted by row-level security so a vendor can only read their own business. Gateway credentials are encrypted at rest. Access to production systems is limited to the people who run JustBook and protected by two-factor authentication.
No system is perfect. If we learn of a breach affecting your data we will notify you and, where required, the Personal Data Protection Commissioner, without undue delay.
9. Children
JustBook is for businesses and their adult customers. We do not knowingly collect data from anyone under 18 without a parent or guardian making the booking.
10. Changes
We may update this policy as the service changes. The date at the top shows the current version. For material changes we will email vendors before they take effect.
See also the Terms of service.