Legal

Privacy Policy

Effective date: 20 February 2026

1. Introduction

MoveMatch (“we”, “our”, or “us”) is a Malaysia-based property intelligence platform. We are committed to protecting your personal data and respecting your privacy in accordance with the Personal Data Protection Act 2010 (PDPA) of Malaysia.

This Privacy Policy describes the types of personal data we collect, how we use and protect it, and your rights as a data subject. By using our website or services, you consent to the practices described in this policy.

2. Personal Data We Collect

We collect the following categories of personal data:

  • Waitlist registration: name, email address, and phone number (optional) submitted through our waitlist form.
  • Account data: email address, name, and (if applicable) a hashed password or OAuth provider identifier, created when you register for a platform account.
  • Usage data: server-side logs including IP address, browser type, pages visited, and timestamps, collected automatically by our hosting infrastructure (Vercel).
  • Session data: a cryptographically signed session token stored in a browser cookie to keep you logged in.

We do not collect sensitive personal data as defined under the PDPA (such as health, financial account, or biometric data).

3. Purpose of Collection

Your personal data is collected and processed for the following purposes:

  • To add you to our early-access waitlist and notify you at product launch.
  • To create and manage your platform account and authenticate your identity.
  • To provide and improve our property intelligence features and reports.
  • To respond to enquiries and provide customer support.
  • To comply with legal obligations.

We will not use your personal data for purposes other than those stated above without obtaining your separate consent.

4. Legal Basis for Processing

Under the PDPA, we process your personal data on the following bases:

  • Consent (PDPA s. 6): by submitting the waitlist form or creating an account, you consent to the collection and processing of your personal data as described here. You may withdraw consent at any time (see Section 7).
  • Legitimate interest: we process usage logs and session data to maintain the security, performance, and reliability of our platform.

5. Third-Party Services

We share or store personal data with the following third-party processors, each bound by their own data protection commitments:

  • Google Sheets (Google LLC): waitlist submissions (name, email, phone, interest, timestamp) are stored in a private Google Sheet accessible only to MoveMatch administrators.
  • Neon / PostgreSQL: account and authentication data is stored in a Neon-hosted Postgres database on AWS infrastructure.
  • Vercel Inc.: our website is hosted on Vercel, which processes request logs including IP addresses.
  • Google OAuth (optional): if you choose to sign in with Google, your name, email, and profile picture are shared with us by Google under their own Privacy Policy.

We do not sell, rent, or otherwise disclose your personal data to unrelated third parties.

6. Data Retention

  • Waitlist data is retained until 12 months after our platform launches publicly, after which it is deleted.
  • Account data is retained for as long as your account is active. If you delete your account, your personal data is removed within 30 days.
  • Server logs are retained by Vercel for up to 30 days in accordance with Vercel's data retention policy.

7. Your Rights Under the PDPA

As a data subject under the PDPA, you have the following rights:

  • Right of access: you may request a copy of the personal data we hold about you.
  • Right of correction: you may request that we correct inaccurate or incomplete personal data.
  • Right to withdraw consent: you may withdraw your consent to processing at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
  • Right to limit processing: in certain circumstances, you may request that we stop processing your data while retaining it.

To exercise any of these rights, email us at privacy@movematch.com. We will respond within 21 days.

You also have the right to lodge a complaint with the Department of Personal Data Protection (JPDP) Malaysia if you believe your data has been processed unlawfully.

8. Cookies

We use a single, strictly necessary session cookie set by our authentication system (NextAuth.js). This cookie:

  • Is HttpOnly and Secure — it cannot be accessed by JavaScript.
  • Expires at the end of your browser session (or after 30 days for “remember me” sessions).
  • Contains only a cryptographically signed session reference — no personal data in plain text.

We do not use advertising, tracking, or analytics cookies. We do not integrate with third-party ad networks.

9. Children's Privacy

Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data without parental consent, we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. The effective date at the top of this page will always reflect the date of the latest revision. Where changes are material, we will make reasonable efforts to notify affected users by email before the changes take effect.

11. Contact Us

For any privacy-related questions, data access requests, or complaints, please contact our data protection team:

MoveMatch
Email: privacy@movematch.com