Rujukan Laman

How my36 Protects Your Personal Data

At my36, we take your privacy seriously — this policy sets out exactly what data we collect when you open an account, how we store it, and the…

Data Encrypted at RestNo Third-Party SellingMalaysian Jurisdiction ContextYour Right to AccessTransparent Retention Policy
my36 How my36 Protects Your Personal Data
PRIVACY CONTACT

Reach Our Data Team Directly

If you want to request a copy of your data, ask us to correct inaccurate records, or submit a deletion request, our dedicated privacy team is…

Email Privacy Team Send your data-access or deletion request to our privacy inbox at my36.pro.
Live Chat Support Start a live chat session on my36.
Written Postal Request For formal written requests, send your query to the registered correspondence address listed at…
DATA PRACTICES

Six Ways We Safeguard Your Account Data

From the moment you complete registration to the day you close your account, every piece of data you share with us passes through security and governance controls we have built specifically for…

Encryption in Transit and at Rest

All data moving between your device and our servers uses TLS 1.2 or higher. Stored account data — including your email, phone number and payment references — is encrypted using AES-256 at the database level so it cannot be read in plain text.

Cookie Use and Your Choices

We use essential cookies to keep your session active and preference cookies to remember your language and layout settings. You can manage or reject non-essential cookies through the cookie banner that appears on your first visit to my36.pro.

Account Security Controls

Your account password is hashed and never stored in plain text. We also offer two-factor authentication via your registered mobile number, and our system flags unusual login locations — including logins from outside Malaysia — for your review.

Data Retention Periods

We keep active account data for as long as your account remains open. After account closure, transaction records are retained for the period required by applicable financial regulations, then permanently deleted. We do not keep data longer than necessary.

Who We Share Data With

Data is shared only with payment processors handling Touch 'n Go, GrabPay, Boost dan FPX transactions, fraud-detection partners, and regulatory authorities when required by law. Every third party we work with is bound by a data-processing agreement.

How to Request Changes to Your Data

Log into your account on my36.pro, go to Account Settings, and select Privacy to update your contact details or download a copy of your data. For deletion or correction requests that go beyond self-service, contact our privacy team via email or live chat.

Your Privacy Questions, Answered

Below you will find answers to the questions we receive most often about how my36 handles personal data. If your question is not covered here, our privacy team can be reached through the contact channels listed above — we are happy to explain any part of this policy in more detail.

We collect your name, email address, mobile number and date of birth at registration. Payment-method identifiers — such as your Touch 'n Go or GrabPay reference — are added when you make your first deposit. Device and session data is collected automatically for security purposes.

No. We do not sell, rent or trade your personal data to advertisers or unaffiliated companies. Data is shared only with payment processors, fraud-prevention services, and authorities where the law in Malaysia requires us to do so.

Log into your account on my36.pro, navigate to Account Settings, and choose the Privacy section to request a data export. Alternatively, email our privacy team directly and we will prepare your data package within seven working days.

Yes. Submit a deletion request via email or live chat. We will close your account and remove personally identifiable data, retaining only the transaction records we are required to keep under applicable financial regulations for the legally mandated period.

Personal profile data is deleted within 30 days of account closure. Transaction and payment records — including Boost dan FPX histories — are kept for the period required by applicable law in Malaysia, after which they are permanently and securely destroyed.

We use essential cookies for login sessions and optional preference cookies for layout and language settings. A cookie management banner appears on your first visit; you can adjust or withdraw consent for non-essential cookies at any time through that banner or your browser settings.

Reach our privacy team via the email address or live chat on my36.pro. State your account email and the nature of your concern. We will acknowledge your complaint within two working days and provide a resolution or escalation path within 14 working days.