Privacy Policy
Last updated 7 August 2026
1. Who we are
Placeholder. Name the legal entity operating SewaKira, its registered address, and a contact point for privacy questions. Malaysia's Personal Data Protection Act 2010 applies to the personal data handled here.
2. What we collect about you
Placeholder. Cover the account data a landlord provides: name, email address, phone number, bank details used on receipts, and the plan and billing identifiers held for Stripe.
3. What you enter about your tenants
Placeholder. This is the section that matters most. Cover tenant names, identification numbers, phone numbers, tenancy terms, payment records, and uploaded documents. State that the landlord is the party responsible for that data and SewaKira processes it on their behalf.
4. Why we hold it and for how long
Placeholder. Cover the purposes, the retention period, and what happens on account closure.
5. Who we share it with
Placeholder. Name the processors actually in use: Supabase for database and file storage, Vercel for hosting, Stripe for subscription billing, Resend for transactional email, and Google Drive only where a landlord connects it themselves. State where each stores data.
6. Marketing email
Product and feature announcements are optional and can be turned off at sign-in or later in Settings. Transactional messages about your account, your billing, and your records are not optional while the account is open.
7. Security
Placeholder. Cover encryption in transit and at rest, per-account isolation of records, private file storage reached only through short-lived signed links, and how to report a suspected problem.
8. Your rights
Placeholder. Cover access, correction, deletion, withdrawal of consent, and how to make a request. State the response time you commit to.
9. Changes to this policy
Placeholder. Cover how changes are notified and where the current version lives.