Skip to content

Legal

Privacy Policy

Last updated: 2026-07-22

Data we collect

Account: email, name, hashed password (or OAuth provider identifier).
Shop: TIN, BRN, MSIC code, address, contact details, LHDN client credentials (AES-GCM encrypted at rest).
Invoices: full e-invoice data submitted to LHDN, including buyer TIN, IC (masked in logs), totals, items.
Usage: session metadata, IP address, user agent (90-day retention).

How we use it

Submit invoices to LHDN MyInvois on your behalf using your registered ERP credentials.
Send transactional emails (verification, password reset, pace warnings, billing notifications).
Show your usage analytics on the dashboard.

Data retention

Invoice data is retained for 7 years per Malaysian tax law. Logs and session metadata: 90 days. Cancelled subscriptions retain data until the account is deleted by the user.

Your rights (PDPA 2010)

Under the Personal Data Protection Act 2010 (PDPA 2010, Malaysia) you have the right to access, correct, and delete your personal data.

Export: Download a copy of your data from Account Settings or email privacy@envoice.my.
Delete: Go to Account Settings and use the Delete Account option. Invoice records are retained for 7 years per Malaysian tax law; all other personal data is removed immediately.
Correct: Update your name and contact details directly in Account Settings. For shop/TIN corrections, contact privacy@envoice.my.
For B2B data processor obligations, see our Data Processing Agreement.

Third parties (processors)

We share data only with processors that help us run the service: LHDN MyInvois (invoice submission), Stripe (card payments and subscriptions), Resend (transactional email), Cloudflare R2 (PDF storage) and Cloudflare (content delivery), Vultr in Singapore (application and database hosting), and Sentry (error monitoring). We never sell your data or share it for marketing.

International transfers

Some processors above operate outside Malaysia (for example, application and database hosting in Singapore, and email, monitoring, and payment services in the US or EU). Where data is transferred abroad it is protected by the processor’s contractual data-protection commitments.

Data Protection Officer

Our Data Protection Officer oversees PDPA compliance and handles data-related requests and complaints. Contact the DPO at privacy@envoice.my.

Data breaches

If a personal-data breach likely to cause significant harm occurs, we will notify the Personal Data Protection Commissioner and any affected individuals without undue delay, in line with the PDPA.

Not affiliated

This service is not affiliated with or endorsed by LHDN. We are an independent tool to help you comply with their e-invoice mandate.