Privacy Policy for Moby Soft POS

The documents below describe the personal information we collect, what we do with it, how we use it, who we disclose it to, and certain information privacy rights you may have.

Updated as of July 22, 2026

Moby Money Sdn. Bhd. ("we", "our", or "us") operates the **Moby Soft POS** mobile application (the "App"). This Privacy Policy explains how we handle information in connection with your use of the App, in accordance with the Malaysian **Personal Data Protection Act 2010 (PDPA)**.

**In summary: the Moby Soft POS app does not collect, store, or share any personal data. No personal information is required to use the App.**

## 1. Data We Do Not Collect

We want to be clear about what the App does **not** do. Moby Soft POS does **not** collect, request, or store any of the following:

- **Personal identification information** — name, address, email address, phone number, government ID, or date of birth.
- **Account credentials** — passwords, PINs, or security answers.
- **Payment card details** — card numbers (PAN), expiry dates, CVV/CVC, or cardholder names are **not** stored or retained by the App.
- **Financial account information** — bank account numbers or balances.
- **Location data** — precise (GPS) or approximate location.
- **Contacts, photos, media, or files** from your device.
- **Device identifiers** used for advertising or tracking.
- **Usage analytics or behavioral tracking** for advertising purposes.

## 2. Contactless Payment Processing

Moby Soft POS enables contactless ("tap-to-pay") card acceptance. When a customer taps a payment card or device:

- Card data is read solely to complete that single transaction and is transmitted directly to the certified payment processor and acquiring bank through secure, encrypted       channels.
- This data is **processed transiently** and is **not stored, logged, or retained** within the App or on the device.
- We do not have access to, and do not retain, full card numbers or other sensitive authentication data. All payment processing complies with applicable **PCI DSS**
    requirements handled by our certified payment partners.

## 3. Permissions

The App may request device permissions (such as **NFC**) strictly to enable contactless card reading. These permissions are used only to perform their stated function during a transaction and are not used to collect or transmit personal data about you.

## 4. Data Sharing

Because we do not collect personal data through the App, we do not sell, rent, or share any personal data with third parties. Transaction data necessary to process a payment is handled by regulated payment processors and financial institutions under their own privacy and security obligations.

## 5. Data Security

We apply industry-standard security measures, including encryption of transaction data in transit, to protect information handled during payment processing. Since no personal data is stored by the App, the risk of data exposure through the App is minimized.

## 6. Children's Privacy

The App is intended for use by merchants and businesses and is not directed at children. We do not knowingly collect any information from children.

## 7. Your Rights Under the PDPA

As we do not collect or store your personal data through the App, there is no personal data held by us for you to access, correct, or withdraw consent for. Should you have any questions about your rights under the Personal Data Protection Act 2010, you may contact us using the details below.

## 8. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last updated" date. Continued use of the App after changes constitutes acceptance of the revised policy.

## 9. Contact Us

If you have any questions about this Privacy Policy, please contact us:

**Moby Money Sdn. Bhd.**
Email: **pdpa@airapay.my**