Privacy Policy
Last updated: February 14, 2026
Welcome to iDineOS (βweβ, βourβ, βusβ).
We are committed to protecting your personal data and respecting your privacy in accordance with:
- MALAYSIA Malaysia Personal Data Protection Act 2010 (PDPA)
- EU EU General Data Protection Regulation (GDPR)
- USA California Consumer Privacy Act (CCPA)
This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when you use our website, applications, POS systems, and related services (collectively, the βServicesβ).
1. Personal Data We Collect
a. Personal & Business Information
- Full name
- Email address
- Phone number
- Business / restaurant name
- Billing address
- Payment and subscription details
- Account credentials
b. Restaurant Operational Data
- Orders, menus, pricing, and transactions
- Table reservations and booking records
- Staff roles and access permissions
- Reports and analytics
c. Customer Data (Processed on Behalf of Restaurants)
- Order details
- Table booking data
- Contact details (if provided by restaurant)
Note: Restaurants are the Data Users / Controllers for their customers' data. iDineOS acts as a Data Processor.
d. Technical & Usage Data
- IP address
- Device and browser information
- Operating system
- Log files and usage analytics
2. Purpose of Data Collection (PDPA Compliance)
Under the Malaysia PDPA, personal data is collected and processed for lawful purposes, including:
- Providing and operating iDineOS services
- Account management and authentication
- Payment processing and invoicing
- Customer support and technical assistance
- System security and fraud prevention
- Service improvement and analytics
- Legal and regulatory compliance
3. Consent & Lawful Basis
Malaysia (PDPA)
By using our Services, you consent to the collection and processing of your personal data as described in this policy.
GDPR (EU Users)
We process personal data under the following lawful bases:
- Performance of a contract
- Legal obligations
- Legitimate business interests
- Consent (where required)
CCPA (California Users)
We collect personal data for business purposes only and do not sell personal information.
4. Disclosure of Personal Data
We do not sell or rent personal data.
We may disclose data to:
- Payment gateways and billing providers
- Cloud hosting and infrastructure providers
- Analytics and system monitoring services
- Legal or regulatory authorities (if required by law)
All third parties are contractually required to protect personal data and comply with applicable laws.
5. Data Security Measures
We take reasonable and practical steps to protect your data, including:
- SSL / TLS encryption
- Secure cloud servers
- Role-based access control
- Regular system updates and monitoring
Despite best efforts, no digital system is completely secure.
6. Data Retention Policy
We retain personal data only for as long as necessary:
- To provide our services
- To comply with legal, tax, and regulatory requirements
- Upon account termination, data will be securely deleted or anonymized unless retention is legally required.
7. Your Rights Under PDPA, GDPR & CCPA
Malaysia PDPA Rights
You have the right to:
- Access your personal data
- Request correction of inaccurate data
- Withdraw consent (subject to legal obligations)
GDPR Rights (EU Residents)
You have the right to:
- Access, rectify, or erase your data
- Restrict or object to processing
- Data portability
- Withdraw consent at any time
- Lodge a complaint with a supervisory authority
CCPA Rights (California Residents)
You have the right to:
- Know what personal data is collected
- Request deletion of personal data
- Opt out of data sharing (if applicable)
- Not be discriminated against for exercising your rights
To exercise any of these rights, contact us using the details below.
8. Cookies & Tracking Technologies
We use cookies and similar technologies to:
- Improve website functionality
- Analyze system performance
- Enhance user experience
You may disable cookies in your browser settings, but some features may be limited.
9. Cross-Border Data Transfers
Your personal data may be stored or processed outside Malaysia or your country of residence.
We ensure:
- Adequate security safeguards
- Compliance with PDPA, GDPR, and applicable international standards
10. Children's Data
Our Services are not intended for individuals under 18 years of age.
We do not knowingly collect personal data from minors.
11. Third-Party Links
Our Services may contain links to external websites.
We are not responsible for the privacy practices of those third parties.
12. Changes to This Privacy Policy
We may update this Privacy Policy periodically.
Any changes will be posted on this page with a revised "Last updated" date.
13. Contact Information (Data Protection)
For privacy-related inquiries, data access requests, or complaints, contact us:
I HOST BOSS SDN. BHD.
Menara Keck Seng
203 Jalan Bukit Bintang
Kuala Lumpur 55100
Malaysia
Data Protection Officer (DPO):
Name: Sabah Chen
Email: admin@gagesis.online
Direct Line: +601 4664 0048
This Privacy Policy was last updated on February 14, 2026. It supersedes any prior versions.