Privacy Policy
Last updated: 6 July 2026
This Privacy Policy explains how BioTree ("we", "us") collects, uses, discloses and protects your personal data when you use biotree.my (the "Service"). We handle personal data in accordance with Malaysia's Personal Data Protection Act 2010 (as amended) ("PDPA"). By using the Service you consent to the practices described here.
1. Data we collect
- Account data — your name, email address, and (if you sign in with Google) your Google profile basics and avatar. If you buy a plan, a phone number for the payment.
- Page content — the display name, bio, links, images and theme you add to your public page.
- Analytics data — for visits to your public page we record aggregate, privacy-preserving signals such as page views, a hashed visitor identifier, approximate country, device type and referring website. We do not sell this data.
- Payment data — processed by toyyibPay. We receive confirmation and reference details, but not your full card or bank credentials.
- Technical data — IP address and standard log data needed to operate and secure the Service.
2. How we use your data
- To create and operate your account and public page.
- To process payments and manage your subscription.
- To send essential service emails (verification, receipts, security and account notices).
- To provide analytics to you about your own page.
- To protect the Service against fraud, abuse and security threats, and to comply with the law.
3. Third parties we share with
We share data only with providers that help us run the Service, under appropriate safeguards:
- Google — optional sign-in.
- toyyibPay — payment processing.
- Resend — sending transactional emails.
- Cloudflare — content delivery and security.
We do not sell your personal data. We may disclose data if required by law or to protect our rights and users.
4. Cookies
We use strictly necessary cookies to keep you logged in and to secure forms. Public pages are designed to load without setting tracking cookies. We do not use third-party advertising cookies.
5. Data retention
We keep your data for as long as your account is active. If you delete your account, we delete or anonymise your personal data within a reasonable period, except where we must retain records to comply with legal, tax or accounting obligations.
6. Security
We use reasonable technical and organisational measures — including encryption in transit, hashed passwords, access controls and rate limiting — to protect your data. No system is perfectly secure, but we work to keep your data safe.
7. Your rights under the PDPA
Subject to the PDPA, you may:
- Access and request a copy of your personal data.
- Correct inaccurate or incomplete data.
- Withdraw consent or limit how we process your data.
- Request deletion of your account and associated data.
To exercise these rights, contact us using the details below. Much of this can also be done directly in your account settings.
8. International transfers
Some of our providers may process data outside Malaysia. Where this happens, we take steps to ensure your data receives a comparable level of protection.
9. Children
The Service is not directed at children under the age required to consent in their jurisdiction. We do not knowingly collect data from such children.
10. Changes
We may update this Policy from time to time. Material changes will be reflected by the "Last updated" date above.
11. Contact
For any privacy request or question, email marketing.kerabatdigital@gmail.com.
This document is a general template and not legal advice. Please have it reviewed by a qualified Malaysian lawyer to ensure full PDPA compliance for your business.