Privacy Policy – Marigig

Last Updated: July 2026

Marigig ("we," "our," or "the Platform") values your trust and is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our services, including our websites, applications, and related tools (collectively, the "Platform"). The Platform is operated by Marigig Sdn Bhd.

1. Who We Are and Scope

This Privacy Policy applies to all users of the Marigig Platform, including:

  • Members / Buyers who browse services, contact sellers, or save posts.
  • Sellers (freelancers, self-employed, businesses) who create profiles, subscribe to plans, and publish posts.
  • Inviting Users who participate in Invitation Programmes (Invitation Links, Invitation Codes, usernames, or other approved invitation mechanisms).
  • Authorised Organisations and their Authorised Users who access organisation-level features and services under a separate organisation services agreement.
  • Visitors who access our websites or interact with our marketing pages.

By using the Platform, you agree to the practices described in this Privacy Policy, in addition to our Terms of Use.

2. Information We Collect

We collect the following categories of information:

2.1 Account Registration

  • Email address (verified via Email OTP)
  • Password (stored in hashed form)
  • Name, state, district, preferred language and basic profile settings

2.2 Seller Verification & Profile Data

  • Identification documents (e.g., IC upload), where required
  • Phone number (verified via SMS OTP)
  • Business-related information (services, pricing ranges, advertisements, portfolio, social links, videos, service locations, etc.)
  • Subscription and plan information (plan type, trial status, quotas and plan history)

2.3 Platform Activity & Content

  • Services and posts you browse, click, save, like, share or report
  • Listings, photos, videos, descriptions and other content you create or upload
  • Views of phone numbers and actions such as "Call" or "WhatsApp" on seller profiles
  • Messages or interactions (where available) between buyers and sellers

2.4 Technical & Device Information

  • Device type, operating system, browser type and version
  • IP address and approximate location (e.g., city/state level)
  • Log data such as access times, pages viewed, referral URLs and error logs
  • Information used for bot-detection and fraud-prevention (e.g., device fingerprint signals)

2.5 Subscription, Billing & Payment Data

  • Plan type, trial eligibility, billing cycle, renewal status and quota usage
  • Billing history (dates, amounts, status of subscription payments and renewals)
  • Payment method details shared with our payment partners (e.g. masked card information, payment reference IDs) — we do not store full card numbers on our servers.

2.6 Communications & Support

  • Messages and information you provide when you contact us (e.g. via contact forms or support email)
  • Marketing and notification preferences (e.g. email preferences, language)

2.7 Cookies & Similar Technologies

We use cookies, pixels, local storage and similar technologies to remember your preferences, secure your session, associate Invitation Link or Invitation Code visits where applicable, and measure traffic and performance. More details are provided in the Cookie Policy section below.

2.8 Wallet Credits & Withdrawals

  • Wallet Credit balances, ledger entries, and transaction metadata (e.g. credit/debit reason, related programme or Promotional Benefit)
  • Withdrawal requests: amounts, fees, status history, and timestamps
  • Payout destination details you provide for a withdrawal (e.g. recipient name, phone number, email, or other identifier type required by the selected payout method), stored as a snapshot with the request
  • Admin review notes and payment references related to approved or rejected withdrawals
  • Additional verification data we may request for payment compliance, fraud prevention, or anti-money-laundering checks (for example, identity documents or confirmation that payout details match your account). If you do not provide required verification, we may refuse, delay, or cancel the withdrawal

2.9 Invitation Programmes

  • Invitation usernames, Invitation Links or Codes you create, and related configuration
  • Association data when someone uses your link or code (e.g. click/open identifiers, cookies or equivalent storage, referring URL, and qualifying registration or event timestamps)
  • Signals used to detect abuse such as self-invitation or multi-account farming (e.g. linked or related accounts, device or browser identifiers, IP address, and similar technical signals), consistent with our Terms of Use
  • Promotional Benefit fulfilment and clawback records linked to Invitation Programmes (often Benefits or Wallet Credits). Clawback or cancellation of a Promotional Benefit does not by itself make prior anti-abuse processing unlawful

2.10 Authorised Organisations & Aggregated Analytics

  • Authorised Organisation details and Authorised User login identifiers (email, role, invitation / password-setup status)
  • Approved Programme configuration (capacity, validity, benefit template selection) and Promotional Code issuance metadata
  • Aggregated programme outcome metrics shown to Authorised Organisations (e.g. redemptions, activations, published counts). Authorised Organisations do not receive Seller personal contact lists, IC numbers, phone numbers, or individual store identities for analytics
  • Authorised Organisations and Authorised Users must not attempt to re-identify individuals from aggregated metrics or disclose such data outside authorised organisation-service use. Breach may lead to suspension or termination under the applicable organisation services agreement

3. How We Use Your Information

We use your data to:

  1. Verify your identity and secure your account (Email OTP for all users, SMS OTP + IC verification for sellers).
  2. Create, operate and personalise your account and seller profile.
  3. Publish and display seller information (such as services, ads, photos, videos and reviews) to potential buyers.
  4. Facilitate communication between buyers and sellers, including phone-reveal and "Call/WhatsApp" interactions.
  5. Administer subscriptions, trials, renewals and billing; generate invoices and payment records; and detect chargeback abuse.
  6. Operate Wallet Credits, process withdrawal requests, verify payout details (including any additional compliance or anti-fraud checks we require), and prevent fraudulent or abusive withdrawals. Required payout or verification data is mandatory for withdrawal features; without it we may be unable to complete a payout.
  7. Associate qualifying events with Invitation Programmes, issue and claw back related Promotional Benefits, and detect self-invitation or multi-account abuse (including using related-account and technical signals described in Section 2.9), under our Terms of Use.
  8. Administer Approved Programmes and organisation-level services for Authorised Organisations; provide aggregated analytics only; enforce confidentiality and anti-re-identification obligations.
  9. Apply viewing and contact limits (for example, tiered phone-reveal rules) to prevent abuse and protect sellers.
  10. Improve Platform performance, user experience, relevance of listings and search quality.
  11. Monitor for fraud, scams, bots and misuse of the Platform, and enforce our Terms of Use.
  12. Send important service messages (e.g. security alerts, material changes to Terms or Privacy Policy via in-app notice and/or email) and, where permitted, marketing messages.
  13. Comply with legal obligations and cooperate with regulators or law enforcement where required.

4. Legal Basis and Consent

Where required by applicable law (including the Personal Data Protection Act), we rely on one or more of the following legal bases to process your personal data:

  • Consent – for example, when you agree to create an account, upgrade to a seller plan, accept cookies, or opt in to marketing communications.
  • Contractual necessity – to provide the services you request, such as managing your account, subscription, and access to seller features.
  • Legitimate interests – such as improving the Platform, protecting users from fraud and abuse, enforcing our Terms, analysing usage, and developing new features, in a way that does not unfairly impact your rights.
  • Legal obligations – to comply with applicable laws, regulations or lawful requests (for example, keeping certain records for audit, tax, or law-enforcement purposes).

5. What Information is Public

Normal Members (Buyers): Your email, IC and phone number are not shown publicly on the Platform.

Sellers (Service Providers): By upgrading to seller and publishing content, you consent to making the following information publicly visible on the Platform:

  • Service listings, advertisements, descriptions, photos and videos
  • Business name / personal name and basic profile details (e.g. service area, categories)
  • Reviews and ratings from clients
  • WhatsApp or phone contact entry points (for example, click-to-reveal phone number or "WhatsApp" button, subject to our phone-reveal limits and anti-abuse rules)

We may also display aggregated statistics (for example, number of views or phone-reveals) without exposing individual user identities.

6. Data Sharing and Third Parties

We do not sell your personal information. We may share your information only with:

  • Service providers who help us operate the Platform, such as:
    • Cloud hosting and infrastructure providers
    • Email and SMS OTP providers
    • Payment processors and payment gateways
    • Analytics, anti-fraud, and security vendors
    • Moderation and AI-based content analysis services, where used
  • Business partners where we integrate or co-offer products or services (for example, payment or verification partners), in which case we will clearly describe the arrangement where required.
  • Payout / withdrawal partners (e.g. banks or transfer service providers) with the recipient details needed to complete a Wallet withdrawal you requested.
  • Authorised Organisations: limited to organisation contact and Authorised User account data for that organisation, plus aggregated Approved Programme metrics. We do not share other Members' or Sellers' personal data with Authorised Organisations for analytics purposes. Authorised Organisations must not re-identify individuals from aggregates or onward-disclose them except as allowed under the applicable organisation services agreement.
  • Legal and regulatory authorities when required by law, court order, or to protect our users, our rights, or the rights of others.
  • Corporate transactions, such as a merger, acquisition, financing or sale of all or part of our business, where your data may be transferred as part of that transaction, subject to appropriate safeguards.

Where we transfer personal data outside of Malaysia, we take steps to ensure that an adequate level of protection is provided in accordance with applicable law.

7. Data Retention & Deletion

  • We retain your personal data only for as long as necessary to provide the Platform, operate our business, and meet legal, accounting or reporting requirements.
  • Account and profile data are generally kept while your account is active. If you request deletion, we will remove or anonymise your personal data, except where we are required or permitted to keep certain information (for example, for fraud prevention, dispute resolution or legal obligations). For step-by-step instructions, see our User Data Deletion page.
  • Wallet and Invitation Programme integrity records — including withdrawal payout snapshots, Wallet ledger entries, invitation association and visit logs, and Promotional Benefit fulfilment / clawback records — may be retained for accounting, tax, audit, and anti-fraud purposes for the periods in Section 16. An account-deletion request does not require us to erase these records immediately where they are still needed for an open withdrawal, Promotional Benefit dispute, investigation, or legal obligation.
  • Seller advertisements, reviews and public posts may remain visible or stored in backup systems for a reasonable period, even after account closure, unless removal is required by law or technically feasible.
  • Logs and security records (such as device, IP and phone-reveal logs) may be retained for a period necessary to investigate abuse, enforce our Terms, and comply with law.

8. Security Measures

  • OTP verification for account security (Email OTP for all users, SMS OTP + IC verification for sellers).
  • Use of industry-standard security practices to protect data in transit and at rest, including encryption for sensitive information where appropriate.
  • Access controls to ensure only authorised staff and service providers can access personal data where necessary.
  • Monitoring and logging to help detect suspicious activity, abuse or security incidents.

However, no method of transmission over the internet or electronic storage is completely secure. While we strive to protect your personal data, we cannot guarantee absolute security.

9. Your Rights and Choices

As a Marigig user, and subject to applicable law, you have the right to:

  • Access the personal information we hold about you.
  • Update or correct inaccurate or incomplete personal information via your account settings or by contacting us.
  • Request deletion of your account and personal data, subject to our legal obligations and legitimate interests as explained above. See our User Data Deletion page for how to submit a request.
  • Withdraw consent for certain processing where we rely on consent (for example, marketing communications), without affecting the lawfulness of processing based on consent before its withdrawal.
  • Object to or request restriction of certain processing where permitted by law.
  • Manage cookies and tracking technologies through your browser or device settings, and through any cookie banners or preferences we provide.
  • Report misuse, scams or privacy concerns via our contact channels.

To exercise any of these rights, please contact us using the details in Section 12 below, or follow the process in Section 18. We may need to verify your identity before fulfilling your request.

Limitations. Where permitted by law, we may delay, limit, or refuse access or deletion requests that would impair fraud or security investigations, ongoing Wallet withdrawal or Promotional Benefit disputes, accounting or tax records we must keep, or the rights of other persons. We will explain the basis for any refusal or limitation where we are required to do so.

10. Children

The Platform is intended for adults and business users. If you are under 18, you should only use the Platform with the consent and supervision of a parent or legal guardian. We do not knowingly collect personal data from children in violation of applicable law. If you believe a child has provided us with personal data without appropriate consent, please contact us and we will take appropriate steps.

11. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. Any changes will be posted on this page with an updated "Last Updated" date.

Where changes are material (for example, new Wallet withdrawal data, Invitation Programme association, or Authorised Organisation analytics uses), we will provide additional notice consistent with our Terms of Use — typically an in-app banner on the Platform and, where appropriate, email. Continued use of the Platform after the Effective / Last Updated date of a material change constitutes acceptance of the updated Policy, except where applicable law requires a different standard.

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

Marigig Sdn Bhd (1664420-D)

Email: askmarigig@gmail.com

Phone: +6011-1078 2689

13. PDPA Principles and Consent Management

13.1 General Principle (Consent). We will obtain your consent before collecting, using, or disclosing your personal data, except where otherwise permitted by applicable law.

13.2 Consent Records. For compliance and audit purposes, we may keep records of consent and policy acceptance, including the date/time, policy version, language presented, account identifier, and related system logs.

13.3 Withdrawal of Consent. You may withdraw consent for optional processing (for example, marketing communications) at any time via your account settings or by contacting us. Withdrawal does not affect processing lawfully carried out before withdrawal.

14. Notice, Choice, and Mandatory Data

14.1 Notice. We will inform you of the categories of personal data we collect, the purposes of processing, and the classes of third parties to whom data may be disclosed.

14.2 Choice. Where practicable, we provide choices regarding optional data collection and optional communications (such as promotional messages).

14.3 Mandatory Data and Service Impact. Certain data is required to provide core services (for example, account security, fraud prevention, subscription billing, and legal compliance). Payout destination details and any additional withdrawal verification we request are required to use Wallet withdrawal features. If you do not provide required data, we may be unable to create, maintain, or secure your account, complete a payout, or provide certain Platform features.

15. Disclosure Controls and Cross-Border Transfers

15.1 Purpose-Limited Disclosure. We disclose personal data only on a need-to-know and purpose-limited basis to service providers and partners supporting Platform operations.

15.2 Contractual Safeguards. Where we engage third parties, we require appropriate contractual measures, including confidentiality and data protection obligations.

15.3 No Unauthorised Third-Party Marketing. We do not disclose your personal data to unrelated third parties for their own direct marketing purposes without your consent, unless required or permitted by law.

15.4 Cross-Border Transfers. Where personal data is transferred outside Malaysia, we take reasonable steps to ensure comparable protection in accordance with applicable law.

16. Data Retention Schedule

16.1 General Rule. We retain personal data only for as long as necessary for legitimate business purposes and legal obligations.

16.2 Standard Retention Periods. Unless a longer period is required by law, we generally apply the following retention periods:

  • Account and profile data: for as long as the account remains active, and up to 24 months after account closure or prolonged inactivity, unless earlier deletion is requested and legally permissible.
  • Subscription, billing, and payment records: up to 7 years for accounting, audit, tax, dispute, and fraud prevention purposes.
  • Wallet withdrawal records (including payout snapshots, fees, status history, admin review notes, and payment references): up to 7 years for accounting, audit, tax, dispute, and fraud prevention purposes.
  • Wallet Credit and Promotional Benefit ledgers / fulfilment and clawback records: up to 7 years for accounting, audit, dispute, and fraud prevention purposes.
  • Invitation Programme association and visit logs (including invitation identifiers and related technical signals used for abuse detection): up to 24 months, or longer where linked to an open dispute or investigation.
  • Authorised Organisation audit and Approved Programme operation logs (Authorised User login activity, programme/code configuration changes, aggregated analytics generation records): up to 24 months for security, contract, and abuse-prevention purposes.
  • Security and abuse-prevention logs (including IP/device/session records): up to 24 months.
  • Customer support communications: up to 24 months after ticket closure.
  • Backup data: retained in rolling backup cycles and deleted or overwritten according to backup schedules.

16.3 Deletion and Anonymisation. When retention is no longer necessary, data will be deleted or irreversibly anonymised, subject to technical feasibility and legal requirements.

17. Data Accuracy and User Responsibilities

17.1 Accuracy. We take reasonable steps to keep personal data accurate, complete, and up to date for the purposes for which it is used.

17.2 User Responsibility. You are responsible for updating your account information promptly if it changes.

17.3 Re-Verification. We may request additional verification or temporarily restrict features if we reasonably believe certain personal data is inaccurate, incomplete, or outdated.

18. Access, Correction, and Deletion Request Process

18.1 Rights Request Submission. You may request access to, correction of, or deletion of your personal data by contacting us through the channels listed in Section 12 of this Privacy Policy.

18.2 Identity Verification. We may require reasonable proof of identity before processing any request.

18.3 Response Timeline. We aim to acknowledge requests within 7 days and provide a substantive response within 21 days, or within such period as required by applicable law. If additional time is needed, we will inform you of the reason and expected timeline.

18.4 Lawful Limitations. In limited circumstances permitted by law, we may refuse or limit a request (for example, where disclosure would affect legal privilege, ongoing investigations — including suspected fraud, Wallet withdrawal abuse, or Promotional Benefit abuse — security, mandatory accounting records, or rights of other persons).

19. Security Incident Response

19.1 Incident Handling. We maintain processes to identify, contain, investigate, and remediate suspected personal data security incidents.

19.2 Notifications. Where required by applicable law, we will notify relevant authorities and/or affected users within a reasonable timeframe, including information on the nature of the incident and recommended protective steps.

Cookie Policy – Marigig

Last Updated: July 2026

1. What Are Cookies?

Cookies are small text files that are placed on your device (computer, smartphone, or tablet) when you visit our Platform. They help us provide a better user experience by remembering your preferences, analyzing site performance, and delivering personalized content or advertisements.

2. Types of Cookies We Use

(a) Strictly Necessary Cookies

  • Essential for the operation of the Platform.
  • Enable functions such as user login, account verification, and security.
  • Without these cookies, certain services cannot be provided.

(b) Performance & Analytics Cookies

  • Collect anonymous data on how users interact with the Platform.
  • Help us monitor traffic, identify technical issues, and improve performance.
  • Example: Google Analytics cookies.

(c) Functional Cookies

  • Remember your language preference, region, and customized settings.
  • Support Invitation Programme association (e.g. remembering an Invitation Link or Code for a limited period — typically matching the programme association window such as up to about 30 days, or as configured — so a later registration can be associated under programme rules).
  • Core invitation association cookies or equivalent storage are needed to participate in Invitation Programmes. If you block or clear them, we may be unable to associate your visit or issue related Promotional Benefits.
  • Provide a more personalized browsing experience.

(d) Advertising & Targeting Cookies

  • Track browsing habits to deliver relevant advertisements.
  • May be set by us or trusted third-party advertising partners.
  • Used to measure campaign effectiveness and avoid showing repetitive ads.

3. Third-Party Cookies

Some cookies are placed by trusted third-party service providers for purposes such as analytics, advertising, and social media integration (e.g., Google, Facebook, TikTok, YouTube). These third parties may collect data about your online activity across websites and apps.

4. How Long Do Cookies Stay on Your Device?

  • Session Cookies: Temporary and deleted when you close your browser.
  • Persistent Cookies: Remain on your device until they expire or are manually deleted.
  • Invitation association storage: Usually lasts for the programme association window (often up to about 30 days, or as set by Marigig). Clearing it early may prevent correct association.

5. How to Manage or Disable Cookies

You can control cookies by adjusting your browser settings:

  • Block all cookies.
  • Allow only certain cookies.
  • Delete cookies already stored on your device.

⚠️ Note: Disabling cookies may affect platform functionality (e.g., login, saved preferences, or checkout features).

For details, visit:

6. Consent to Use of Cookies

When you first visit the Platform, a cookie banner will appear to inform you that we use cookies. By selecting your preferences, you consent to our use of cookies in accordance with this Policy, unless you disable them in your browser settings.

7. Updates to This Cookie Policy

We may update this Cookie Policy from time to time to reflect changes in technology, applicable law, or our business practices. The updated version will be posted on this page with the "Last Updated" date.

8. Contact Us (Cookies)

If you have any questions or concerns about our use of cookies, please contact us at:

Marigig Sdn Bhd (1664420-D)

Email: askmarigig@gmail.com

Phone: +6011-1078 2689