UAT — demo environment. Data may be reset. Login code: 888888.

Skip to content

privacy policy

Last updated 29 September 2026

This policy explains what personal data uppwallet handles, why, and the choices you have. It is written for two groups: merchants who use uppwallet to run loyalty programmes, and the customers of those merchants who carry a uppwallet-powered card in their phone wallet.

Who we are

uppwallet is operated by LOOP TECH SOLUTIONS SDN BHD (Registration No. 202601029991), a company registered in Malaysia (“uppwallet”, “we”, “us”). We follow the Personal Data Protection Act 2010 (“PDPA”). You can reach us about anything in this policy at hello@uppwallet.com.

Our two roles

  • For merchant accounts, we decide how the data is used, so we are responsible for it (the “data user” under the PDPA).
  • For a merchant’s customers, the merchant decides what to collect and how to use it. We process that data on the merchant’s behalf and only on their instructions. If you are a customer, the merchant whose card you hold is your first point of contact, and we will help them answer you.

What we collect

Merchants

  • Your name, business email and phone number, and the details of your business and its stores.
  • Billing details. Card numbers are collected and stored by our payment provider, Stripe; we only keep the card brand, last four digits and expiry date, plus your invoices and payment history.
  • The content you upload, such as logos, card designs and message templates.
  • Messages you send our support team.

Merchants’ customers

  • Name, mobile number and email address.
  • Date of birth, if the merchant asks for it (for example, for a birthday reward).
  • Whether you agreed to receive marketing messages, and when.
  • Loyalty activity: stamps, points, vouchers, rewards redeemed, tier and referrals, including the date, time and store of each visit a merchant records.
  • Whether your card is saved in Google Wallet or Apple Wallet.
  • WhatsApp messages you exchange with a merchant’s programme through uppwallet.

Everyone

  • One-time sign-in codes (stored only in a scrambled, unreadable form) and which device signed in.
  • Technical logs, such as IP address, browser type and the time of each request, which we use to keep the service secure and working.

We do not use advertising cookies or third-party analytics. Our sites store only what is needed to keep you signed in.

How we use it

  • To run the service: issue and update wallet cards, record visits and rewards, and show merchants their programme results.
  • To confirm it is really you, by sending one-time codes by email, SMS or WhatsApp.
  • To bill merchants and send receipts and invoices.
  • To send service messages, such as a code, a reward update or a payment problem.
  • To send marketing from a merchant to their customers, only where the customer has agreed. You can withdraw that at any time, for example by replying STOP on WhatsApp.
  • To prevent fraud and abuse, fix problems and meet our legal obligations.

We do not sell personal data, and we do not use a merchant’s customer data for anyone else.

Who we share it with

We use trusted providers to run uppwallet. Each receives only what it needs:

  • Google Cloud: hosting and database, in the Singapore region.
  • Google Wallet and Apple Wallet: the details shown on a wallet card.
  • Meta (WhatsApp Business Platform): WhatsApp messages and the numbers they are sent to.
  • Resend: sending email.
  • Twilio: sending SMS, where SMS is used.
  • Stripe: taking merchant payments and storing cards.

We may also disclose data where the law requires it, or to protect the rights and safety of our users and the public. If uppwallet is ever sold or merged, data would move to the new owner under this same policy.

Transfers outside Malaysia

Our servers are in Singapore, and some of our providers process data in other countries, including the United States. We only use providers that protect personal data to a standard comparable to the PDPA.

How long we keep it

We keep data while a merchant account is active. When a customer leaves a programme, their card is archived rather than erased, so the merchant keeps an accurate history. When a merchant closes their account, we delete or anonymise its data within a reasonable time, except records the law requires us to keep, such as invoices, which Malaysian law requires us to keep for seven years.

Security

Data is encrypted in transit, sensitive credentials are encrypted at rest, and access inside uppwallet is limited to people who need it. No system is perfectly secure; if a breach affects your personal data, we will notify you and the authorities as the PDPA requires.

Your rights

You can ask to:

  • see the personal data we hold about you, and get a copy;
  • correct data that is wrong or out of date;
  • withdraw consent, including for marketing;
  • limit how your data is processed, or have it moved to another provider.

Merchants can email us at hello@uppwallet.com. Customers can ask the merchant, or email us and we will pass the request to them. We reply within 21 days. If you are not satisfied, you can complain to the Personal Data Protection Commissioner of Malaysia.

Children

uppwallet is not meant for children under 13, and merchants should not enrol them without a parent’s consent.

Changes to this policy

If we make a significant change, we will update the date above and let merchants know by email before it takes effect.

Questions about this page? hello@uppwallet.com