NAVIXA NAVIXA
EN BM

NAVIXA SOLUTIONS SDN BHD

Navigating Technology, Managing Possibilities

Privacy Policy

Personal data protection notice for navixa.com.my and all Navixa Solutions applications and services

Company No. 202601007357
Effective date 18 August 2026
Version 1.1
Published at https://navixa.com.my/privacy
Applies to navixa.com.my · JomHantar · RaciHub · UAD
Governing law Personal Data Protection Act 2010 (Malaysia), as amended by the PDP (Amendment) Act 2024
Contact dpo@navixa.com.my

© 2026 Navixa Solutions Sdn Bhd. All rights reserved.

1. Introduction

Navixa Solutions Sdn Bhd "Navixa" is a technology company incorporated in Malaysia. We respect your privacy and are committed to protecting the personal data you entrust to us.

This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It is issued in accordance with the Personal Data Protection Act 2010 of Malaysia, as amended by the Personal Data Protection (Amendment) Act 2024 ("PDPA"), under which Navixa acts as a data controller.

By using our website, registering for an account, or using any Navixa application, you acknowledge that you have read and understood this Policy.

Where to find this Policy: it is published at https://navixa.com.my/privacy and is also available from within each of our mobile applications, under Profile → Legal → Privacy Policy, and at the point of registration before any account is created.

2. Scope

This Policy covers personal data processed through:

  • navixa.com.my — our corporate website, contact and enquiry forms
  • JomHantar — our food delivery platform, including the customer app, the rider app, the restaurant/merchant dashboard and the JomHantar website
  • RaciHub — our building and facility management system
  • UAD — our application security and privacy protection product
  • Any other Navixa product, mobile application, dashboard or service that links to this Policy
  • Business correspondence, sales enquiries, support requests and recruitment applications

Where a specific Navixa product requires additional or product-specific disclosures, those will be provided in a supplementary notice within that product. In the event of a conflict, the product-specific notice prevails for that product.

3. Who this Policy applies to

We process personal data relating to several groups of people, and what we collect differs by group:

Category Who this is
Website visitors Anyone browsing navixa.com.my or submitting an enquiry
JomHantar customers End customers placing or receiving a food delivery order
JomHantar riders Independent delivery riders registered on our rider platform
JomHantar merchants Restaurants and food businesses registered on our platform, and their staff
Business contacts Clients, partners, vendors and their representatives
Applicants People applying for roles or rider positions with us

4. Personal data we collect

4.1 Website visitors and business enquiries

  • Name, company name, job title
  • Email address, telephone or WhatsApp number
  • The content of your enquiry or message
  • Technical data: IP address, browser type and version, device type, operating system, referring URL, pages viewed, date and time of visit
  • Cookie and analytics identifiers (see Section 11)

4.2 JomHantar — customers

  • Identity and contact data: name, mobile number, email address
  • Delivery data: delivery address, unit or floor details, drop-off instructions, recipient name and contact number where you order on someone else's behalf
  • Location data: approximate or precise device location, used to set your delivery pin and to show you live tracking of your order. Location is collected only while the app is in use, and only after you grant permission in your iOS or Android settings
  • Order data: items ordered, order value, delivery fee, payment method (prepaid or cash on delivery), order history, special instructions
  • Payment data: payment method type, transaction reference, payment status. Navixa does not store your full card number, CVV or online banking credentials — card and FPX payments are handled directly by our licensed payment gateway partners
  • Delivery evidence: the geotagged, timestamped photograph a rider takes at the drop-off point as proof of delivery, and records of call and message attempts, in accordance with our failed-delivery procedure
  • Communications: in-app chat messages, in-app voice call records, support tickets, complaints, ratings, reviews and feedback
  • Device and usage data: device model, operating system version, app version, unique device or installation identifier, push notification token, crash logs, in-app activity

4.3 JomHantar — riders

Riders provide more data than any other group because we are legally and operationally required to verify who is delivering food and to pay them correctly.

  • Identity data: full name, date of birth, nationality, NRIC (MyKad) number and a copy of your NRIC, and a verification photograph or selfie
  • Contact data: mobile number, email address, residential address, emergency contact name and number
  • Eligibility documents: driving licence, motorcycle or vehicle registration document (Geran), road tax status, vehicle insurance details, vehicle make, model, colour and registration plate number
  • Right-to-work documents: for non-Malaysian riders, passport, visa or work permit details where required by law
  • Financial data: bank name, bank account number and account holder name, or DuitNow / e-wallet identifier, used to pay out your earnings; rider wallet balance and withdrawal history
  • Location data: precise GPS location, including while the app is running in the background. Location tracking is an intrinsic part of performing a delivery job, not a condition of being paid: it is what allows the app to show you jobs near where you actually are, give the restaurant and the customer live tracking of the food they are waiting for, measure distance for the delivery fee, confirm arrival at the pickup and drop-off points, and resolve disputes about whether a delivery was attempted. Location is collected only while you are online and on duty. It stops the moment you go offline, and you can revoke the permission at any time in your device settings — you will still be able to open the app, view your earnings and manage your account, but you will not be able to receive job offers while the permission is off
  • Job and performance data: jobs offered, accepted, rejected, completed and cancelled; distance travelled; timestamps; delivery photos you take; earnings; incident and strike records; ratings and feedback
  • Communications: in-app chat and voice call records with customers, restaurants and our support team

4.4 JomHantar — restaurants and merchants

  • Business name, business registration number, business address and pickup address
  • Owner or authorised representative name, mobile number and email address
  • Bank or e-wallet payout details, where applicable
  • Menu, pricing, operating hours and delivery zone settings
  • Order, transaction, commission and settlement records
  • Dashboard login credentials and activity logs

4.5 Sensitive personal data

Some of the data we collect from riders is sensitive personal data under the PDPA. This includes:

  • Your NRIC copy and verification photograph — the verification photograph is processed as biometric data, which the PDPA expressly classifies as sensitive personal data
  • Any health declaration relevant to road safety, and any criminal record declaration, where we require one as part of vetting

We process sensitive personal data only where you have given explicit consent, or where the processing is required or authorised by law. Consent for each category of sensitive personal data is requested separately during rider registration — it is not bundled into your general acceptance of our terms — and the fact, date and scope of that consent are logged. You may withdraw your consent at any time by contacting our Data Protection Officer. Because we cannot lawfully operate a delivery platform with unverified riders, withdrawing this consent will mean we can no longer verify you and your rider account will be deactivated.

4.6 Mandatory and optional data

The PDPA requires us to tell you which data you must supply and what happens if you do not.

Group Mandatory data Optional data If mandatory data is not supplied
Customer Name, mobile number, delivery address Email address, saved addresses, drop-off notes, profile photo, marketing consent We cannot create your account or dispatch a delivery to you
Rider Full name, date of birth, NRIC, verification photograph, driving licence, vehicle documents, bank or e-wallet payout details, mobile number, location permission while on duty Email address, emergency contact, profile photo, referral code, marketing consent We cannot verify or activate your rider account, assign jobs, or pay your earnings
Merchant Business name, SSM registration number, pickup address, contact person and number, payout details Logo, menu photos, extended business description, marketing consent We cannot onboard your business or settle payments to you
Website enquiry Name and one contact method Company, job title, phone number We cannot respond to your enquiry

Declining to provide optional data never affects your access to the core service.

4.7 Device permissions and data we do not collect

Permission Why we ask Can you decline?
Location Delivery pin and order tracking (customers, while in use); job matching, live tracking, distance and arrival verification (riders, including in the background while on duty) Yes. Customers can enter an address manually. Riders can use the app but cannot receive job offers
Camera Capturing geotagged delivery-proof photographs (riders) and, where you choose, photographing a document or a problem with an order Yes. Riders who decline cannot complete the photo-proof step required to close a job
Photo library Uploading verification documents (rider licence, Geran, insurance) and merchant menu or logo images, where you prefer to select an existing file Yes. You can photograph the document instead
Microphone In-app voice calls between a rider and a customer or restaurant during an active delivery Yes. You can use standard phone calls or in-app chat instead
Notifications Order status, job offers, payment and account alerts Yes, though you may miss time-sensitive job offers

Delivery-proof photographs are captured through the in-app camera only and cannot be selected from your gallery, so that the geotag and timestamp remain reliable evidence.

We do not collect your contacts list, your calendar, your health or fitness data from Apple Health or Google Fit, your browsing activity on other companies' apps and websites, or the contents of your photo library beyond the specific files you choose to upload. We do not record the audio content of in-app voice calls; we log only that a call took place, and when.

5. How we collect personal data

  • Directly from you — when you fill in a form, register an account, upload a document, place an order, contact support, or communicate with us
  • Automatically — through cookies, analytics tools, server logs and app SDKs when you use our website or apps
  • From your device, with your permission — the permissions listed in Section 4.7
  • From other users of the platform — for example, a restaurant may enter a customer's name, phone number and delivery address when booking a rider on the customer's behalf; a rider's completed delivery generates data about the customer's order
  • From third parties — payment gateways, mapping and geocoding providers, and identity or document verification services
  • From public business registers — we check merchant business registration details against SSM records. This is a check of business registration data for fraud prevention and merchant onboarding only; we do not compile personal profiles from public sources
  • From referrals — where an existing rider refers you under our referral programme

Where a restaurant or another user provides us with your personal data, that party is responsible for having a lawful basis to do so, and we process the data in accordance with this Policy.

6. Why we use your personal data

We process personal data for the following purposes:

Delivering the service

  • Creating, verifying and managing your account
  • Matching delivery jobs to nearby available riders
  • Calculating distance-based delivery fees and rider earnings
  • Providing live order tracking to customers and restaurants
  • Enabling in-app calls and chat between customers, riders and restaurants
  • Processing payments, cash-on-delivery reconciliation, rider wallet top-ups and withdrawals
  • Sending transactional notifications about orders, jobs, payments and account status

Trust, safety and compliance

  • Verifying rider identity, licence and vehicle eligibility before activation
  • Investigating failed deliveries, unreachable customers, damaged or missing orders, and payment disputes, using GPS records, delivery photographs, and call and message logs
  • Detecting and preventing fraud, abuse, and misuse of cash-on-delivery
  • Applying our strike and account-suspension policies to repeat offenders
  • Meeting our obligations under Malaysian law, and responding to lawful requests from regulators, courts and law enforcement

Improving and supporting

  • Responding to enquiries, complaints and support requests
  • Diagnosing crashes and technical faults
  • Analysing aggregated usage to improve routing, coverage, pricing and app performance
  • Conducting internal research, reporting and business planning

Communications and marketing

  • Sending you service updates and changes to our terms or this Policy
  • With your consent, sending promotional messages, rider incentive campaigns, referral offers and newsletters. You can opt out of marketing at any time, in the app under Profile → Notification Preferences, by using the unsubscribe link in any marketing email, or by contacting us — without affecting your ability to use the service

6.1 Lawful basis for processing

Under the PDPA we process personal data on the basis of your consent, except where the Act permits processing without consent. Where we rely on a ground other than consent, it is one of the grounds set out in section 6(2) of the PDPA:

Ground under s.6(2) How it applies to us
Performance of a contract with the data subject Fulfilling a delivery, paying rider earnings, settling merchant accounts
Taking steps at your request with a view to entering a contract Rider and merchant onboarding and verification
Compliance with a legal obligation Tax, accounting and audit record-keeping; responding to lawful authority requests
Protection of your vital interests Sharing location or contact details in a road accident or medical emergency
Administration of justice Producing delivery evidence in a legal claim or investigation
Exercise of functions conferred by law Complying with directions from a regulator

We process sensitive personal data only with your explicit consent or where the PDPA otherwise permits it. Where we rely on consent, you may withdraw it at any time (see Section 12).

7. Disclosure of personal data

We do not sell your personal data. We disclose it only as set out below.

7.1 To other users of the platform, as necessary to complete a delivery

  • Riders receive the customer's first name, contact number, delivery address and drop-off instructions, and the restaurant's pickup address and contact number — for the duration of the job
  • Customers and restaurants receive the rider's name, photograph, contact number, vehicle type and plate number, and live location while the delivery is in progress
  • Restaurants receive the order details and the customer's name and contact number

Contact numbers may be masked or proxied where technically available. Access to these details is limited to the active job and is withdrawn once the job is closed.

7.2 To service providers acting on our instructions

We share personal data with third parties who perform services on our behalf as data processors, including:

Provider type Purpose
Cloud hosting and database providers Storing and running the platform
Mapping, geocoding and routing providers Address lookup, distance calculation, navigation
SMS, push notification and messaging providers Sending order and job notifications
Identity and document verification providers Verifying rider identity and licences
Analytics and crash-reporting providers Measuring performance and diagnosing faults
Customer support platforms Handling tickets and complaints
Professional advisers Legal, accounting and audit services

Every third party with whom we share user data — including analytics tools, advertising networks, third-party SDKs, and any parent, subsidiary or related entity of Navixa that has access to user data — is contractually required to provide the same or an equal level of protection for that data as is stated in this Privacy Policy. Processors may act only on our documented instructions, only for the purpose we have specified, and may not use the data for their own purposes.

7.3 To parties acting as independent controllers

A small number of recipients determine their own purposes for part of the data and are therefore independent data controllers, not our processors. Their own privacy policies apply in addition to ours:

  • Payment gateways, banks and e-wallet operators — for payment authorisation, settlement, chargeback handling, and their own fraud, anti-money-laundering and regulatory obligations
  • Insurers, where a claim arises from a delivery
  • Government bodies and regulators, where we are required to report

Even in these cases, we share only the minimum data required, and we require each recipient to protect it to a standard equal to that described in this Policy.

7.4 To authorities and in legal proceedings

We may disclose personal data where we are required to do so by law, court order, or a lawful request from a regulator, the Personal Data Protection Commissioner, or law enforcement; or where disclosure is necessary to establish, exercise or defend legal claims, to prevent fraud, or to protect the safety of any person.

7.5 In a corporate transaction

If Navixa is involved in a merger, acquisition, restructuring or sale of assets, personal data may be transferred to the acquiring party, subject to that party continuing to honour this Policy or notifying you of any material change.

8. Cross-border transfer

Our systems and some of our service providers operate outside Malaysia — principally cloud hosting, mapping, analytics and messaging services located in Singapore and other jurisdictions within the Asia-Pacific region.

Where we transfer personal data outside Malaysia, we do so in accordance with the PDPA's cross-border transfer framework, relying on one or more of the following:

  • the receiving jurisdiction has a law substantially similar to the PDPA, or provides an adequate level of protection; or
  • we have put in place binding contractual clauses with the recipient imposing PDPA-equivalent obligations; or
  • another lawful ground under the PDPA applies, including your consent, or the transfer being necessary to perform a contract with you.

Before a new cross-border transfer begins, we carry out and document a transfer impact assessment of the destination jurisdiction and the recipient's safeguards, and we review it periodically. You may contact our Data Protection Officer for information about the safeguards applying to a specific transfer.

9. Data accuracy

We take reasonable steps to ensure that the personal data we hold is accurate, complete, not misleading and kept up to date, having regard to the purpose for which it was collected and further processed. You can review and update most of your details yourself in your account profile, and we ask riders and merchants to re-confirm their documents periodically. Please tell us promptly if any of your details change.

10. Data retention and deletion

We keep personal data only for as long as necessary for the purposes described in this Policy, or for as long as required by law.

Data Indicative retention period
Active account data (customer, rider, merchant) For as long as the account is active
Data after account closure Up to 90 days, then deleted or anonymised, unless a longer period is required below
Order, transaction, payment and commission records 7 years from the transaction date, to meet Malaysian tax, accounting and audit requirements
Rider verification documents (NRIC, licence, vehicle documents) For the duration of the rider relationship and up to 7 years thereafter, for legal, insurance and dispute purposes
Delivery-proof photographs and GPS records 12 months from the delivery date, or until any related dispute, claim or investigation is concluded
In-app chat and call logs 12 months
Support tickets and complaints 24 months from resolution
Marketing consent records Until consent is withdrawn, plus 3 years as proof of consent
Website analytics and server logs Up to 24 months
Unsuccessful job or rider applications 6 months

When a retention period ends, we securely delete the data or irreversibly anonymise it so that it can no longer be linked to you.

10.1 Account deletion

You can delete your account, and the personal data associated with it, at any time. Nothing is required of you first.

  • In the app: open Profile → Account Settings → Delete Account, and confirm. The request is submitted immediately and does not require you to contact support or provide a reason
  • By email: write to dpo@navixa.com.my from your registered email address, or contact us using the details in Section 16

We disable the account immediately on request and complete the deletion within 30 days, after which the residual retention rules in the table above apply. We will confirm to you when the deletion is complete.

Two points to be aware of, neither of which prevents or delays your deletion:

  • Money we owe you. If you are a rider with an unwithdrawn wallet balance, deleting your account does not forfeit it. We will pay out the balance to your registered bank or e-wallet account, and we will retain only the payment record required for tax and audit purposes
  • Records we must keep. Malaysian tax, accounting and dispute-resolution law requires us to retain certain transaction records even after deletion. That retained data is restricted, access-controlled, and used only for those legal purposes. Everything else is erased or irreversibly anonymised

11. Cookies and similar technologies

navixa.com.my and our web dashboards use cookies and similar technologies:

  • Strictly necessary cookies — keep you logged in, maintain session state and protect against fraud. These cannot be switched off
  • Preference cookies — remember your language and display settings
  • Analytics cookies — help us understand how the site is used, in aggregate
  • Marketing cookies — used only where you have given consent

You can control or delete cookies through your browser settings. Blocking strictly necessary cookies may prevent parts of the site from working.

Tracking on iOS: our apps do not currently track you across other companies' apps and websites for advertising purposes. If this ever changes, we will request your permission first through Apple's App Tracking Transparency prompt, and you may decline without losing access to the app.

12. Your rights and how to exercise them

Under the PDPA you have the right to:

  • Access the personal data we hold about you, and request a copy
  • Correct personal data that is inaccurate, incomplete, misleading or out of date
  • Withdraw your consent to our processing at any time, in whole or in part
  • Limit processing, including requiring us to stop processing for direct marketing
  • Prevent processing that is likely to cause you unwarranted substantial damage or distress
  • Data portability — request that your personal data be transmitted directly to another data controller, where this is technically feasible and the formats are compatible
  • Request deletion of your data and closure of your account, as described in Section 10.1
  • Complain to us, and to the Personal Data Protection Commissioner if you are not satisfied with our response

12.1 Controls available directly in the app

You do not need to write to us to exercise the most common choices. In each Navixa app you can:

Control Where
View and edit your personal details Profile → Edit Profile
Turn marketing messages on or off Profile → Notification Preferences
Choose which notification types you receive Profile → Notification Preferences
Grant or revoke location, camera, microphone, photo and notification permissions Profile → App Permissions, or your device Settings
Download a copy of your data Profile → Privacy → Request My Data
Delete your account Profile → Account Settings → Delete Account

12.2 Written requests and response times

For anything not covered above, email dpo@navixa.com.my with the subject line "PDPA Request", telling us which right you wish to exercise. We may ask you to verify your identity before we act, to protect your data from unauthorised disclosure.

  • Data access and data correction requests: we will respond within 21 days of receiving your request, as required by sections 31 and 35 of the PDPA. If we cannot comply within that period, we will notify you in writing before it expires and respond within a further 14 days
  • Consent withdrawal: we will act on it as soon as practicable, and in any event within 21 days
  • Account deletion: processed as described in Section 10.1

In limited cases the PDPA permits us to refuse a request or to charge a prescribed fee; if we refuse, we will tell you why and how to challenge that decision.

Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal, and may mean we can no longer provide part or all of the service to you.

13. Security

We apply administrative, technical and physical safeguards appropriate to the sensitivity of the data, including:

  • Encryption of data in transit (TLS/HTTPS) and encryption at rest for sensitive fields and uploaded documents
  • Role-based access control, so staff and contractors can access only the data their role requires
  • Password hashing, session management and support for multi-factor authentication on administrative accounts
  • Access logging and audit trails on systems holding personal data
  • Contractual data protection obligations imposed on all processors and vendors, who are themselves directly liable for security under the PDPA
  • Staff confidentiality undertakings and periodic security review

No system is completely secure. If you believe your account has been compromised, contact us immediately at dpo@navixa.com.my.

13.1 Data breach notification

If a personal data breach occurs, we will:

  • notify the Personal Data Protection Commissioner as soon as practicable and in any event no later than 72 hours after becoming aware of the breach, using the Commissioner's prescribed form; and
  • notify affected individuals without unnecessary delay and no later than 7 days after we have notified the Commissioner, where the breach causes or is likely to cause significant harm — for example a risk of physical harm, financial loss, or misuse of sensitive personal data — or where it affects a significant number of individuals

Our notification to you will describe the nature of the breach, its likely consequences, the measures we have taken or propose to take in response, and the steps you can take to protect yourself. We maintain an internal register of all breaches, whether or not they are notifiable.

14. Children

Our services are not directed at children. JomHantar riders must be at least 18 years old. Customer and merchant accounts may only be opened by a person aged 18 or above. Where a person under 18 uses the service, it must be with the consent and under the supervision of a parent or legal guardian, who is responsible for that use and who may exercise the rights in Section 12 on the child's behalf. We do not knowingly collect personal data from a person under 18 without such consent. If you believe we hold a child's personal data without proper consent, contact our Data Protection Officer and we will delete it.

15. Third-party links, services and sign-in

Our website and apps may contain links to third-party websites, restaurant menus, payment pages or social media. We are not responsible for the privacy practices of those third parties.

You can browse general information about our services without creating an account. An account is required only for functions that need one — placing or receiving an order, working as a rider, or managing a merchant listing. Where we offer sign-in through a third-party identity provider (such as Apple, Google or Facebook), we receive only your name, email address and a provider identifier; we never receive your password, and you can disconnect the provider or delete the account at any time under Profile → Account Settings. An email-and-password alternative is always offered alongside any third-party sign-in.

16. Contact us and our Data Protection Officer

Navixa has appointed a Data Protection Officer (DPO) in accordance with the PDPA and the Personal Data Protection Guidelines on the appointment of Data Protection Officers, and has registered the appointment with the Personal Data Protection Commissioner. For any question, request or complaint about this Policy or about how we handle your personal data, contact:

The Data Protection Officer

Navixa Solutions Sdn Bhd (Company No. 202601007357)

No. 1-5, 5th Floor, Jalan 15/48A

Sentul Raya Boulevard, Off Jalan Sentul Pasar

51100 Kuala Lumpur, Malaysia

 

Email: dpo@navixa.com.my

General enquiries: info@navixa.com.my

Telephone: +60 3-2722 5440

Website: https://navixa.com.my

If you are not satisfied with our response, you may lodge a complaint with:

Jabatan Perlindungan Data Peribadi

(Personal Data Protection Department), Malaysia

Website: https://www.pdp.gov.my

17. Changes to this Policy

We may update this Policy from time to time to reflect changes in our services, technology or the law. The current version is always available at https://navixa.com.my/privacy and within each Navixa app. Where a change is material, we will notify you by email or through an in-app notice before it takes effect, and where the change requires it we will ask for your consent again. The "Effective date" and "Version" at the top of this document indicate when it was last revised. Your continued use of our services after the effective date of a revised Policy constitutes acceptance of it.

18. Language

In accordance with section 7(3) of the PDPA, this Policy is issued in both English and Bahasa Malaysia. The Bahasa Malaysia version is available at https://navixa.com.my/privasi. In the event of any inconsistency between the two versions, the English version shall prevail, save where Malaysian law requires otherwise.

© 2026 Navixa Solutions Sdn Bhd. All rights reserved. Document reference: NAV-LEGAL-PP-1.1

© 2026 Navixa Solutions Sdn Bhd. All rights reserved.

Home · Privacy Policy · Dasar Privasi