Legal
Last updated: 9 March 2026
Payments are handled by Stripe, a PCI DSS Level 1 certified payment processor. We never see, store, or have access to your full card details. We only store a reference to your Stripe payment session for order fulfilment.
Under Malaysia's Personal Data Protection Act 2010 (PDPA), you have the right to:
We use Supabase (hosted on AWS) with row-level security policies, encrypted storage, and HTTPS for all communications. Authentication is handled via Supabase Auth with industry-standard token management.
For privacy inquiries or data requests, contact us at: privacy@taxfind.my