Privacy Policy

Effective Date: [2025-03-26]

Last Update Date: [2025-03-26]

CepatGo ("We", "Our" or "Our Company") is committed to protecting your privacy. This Privacy Policy ("This Policy") explains how we collect, use, disclose and protect your personal information when you use the CepatGo mobile application ("Application") and related services (limited to Malaysia). By accessing or using the application, you indicate your consent to the terms of this policy.

1. Scope and Applicability

This policy applies to all users of the CepatGo application in Malaysia. It regulates the processing of personal data collected through the application, including during account registration, charging, payment, and customer support interactions.

2. Information We Collect

2.1 Personal Information

We collect the following types of personal data:

Account Information: Full name, email address, mobile phone number, personal profile picture, and password.

Vehicle Details: Electric vehicle (EV) model, license plate number (optional), charging records, and preferred charging settings.

Payment Information: Credit/debit card details, electronic wallet credentials (such as paycools), transaction records, and billing address.

Location Data: Real-time Global Positioning System coordinates (subject to your consent) or manually entered location information for locating nearby charging stations.

Identification: Government-issued identification documents (such as passport, Malaysian ID), for verifying enterprise accounts (if applicable).

2.2 Technical and Usage Data

Device Information: IP address, device model, operating system (iOS/Android), unique device identifier (such as IMEI), and browser type.

Application Analytics: Session duration, accessed functions, error logs, charging station search queries, and interaction patterns.

Cookies and Tracking Technologies: Data collected through cookies, pixels, or software development kits, for enhancing functionality (such as authentication tokens, language preference settings).

3. Purposes for Data Processing

We will process your data to:

Provide Services: Create and manage accounts, handle payments, book charging stations, and provide real-time availability updates.

Personalized Experience: Recommend charging stations based on usage history, location, and preferences.

Enhance Functionality: Analyze usage trends, debug errors, and optimize application performance.

Communication Content: Send service notifications (such as session completion notifications), promotional information (with user consent), and policy updates.

Legal Compliance: Fulfill obligations under Malaysian laws (such as tax filings, requirements of the Personal Data (Privacy) Act) and respond to legal requests.

4. Legal Basis for Processing

Contractual Requirements: To fulfill user agreements (such as handling payment for charging periods).

Consent: For marketing communications, precise location tracking, and optional data sharing.

Legitimate Interests: To prevent fraud, ensure network security, and improve service quality.

Legal Obligations: Comply with relevant regulatory requirements of Malaysian authorities.

5. Data Sharing and Disclosure

5.1 Third-Party Recipients

Charging Network Partners: Provide session details (such as time, location, payment method) to charging station operators to facilitate reservations.

Payment Processors: Can choose Paycooler for secure transaction processing, or a local service provider in Hong Kong (such as Omise).

Cloud Service Providers: Alibaba Cloud, or for data storage and processing in regional data centers. Analysis tools: Google Analytics, Firebase, or Mixpanel can be chosen for usage trend analysis.

5.2 Legal Statement

We may disclose data to:

Malaysian government agencies (such as the Traffic Affairs Department) for compliance monitoring purposes.

Law enforcement actions conducted in accordance with court orders or subpoenas.

Acting as legal advisors in disputes or lawsuits.

5.3 Business Transactions

During corporate mergers, acquisitions, or asset sales, user data may be transferred to subsequent entities.

6. International Data Transfer

Your data may be transferred to other countries outside Malaysia (such as Singapore, the European Union), and processed in these regions. We ensure such data transfers comply with the requirements of the Personal Data Protection Act through the following methods:

Appropriate Decision: Receiving countries with approved data protection standards by the Personal Data Protection Authority.

Security Measures: Standard Contract Clauses (SCC) or Binding Corporate Rules (BCR).

7. Data Security Measures

We have taken the following security measures:

Encryption: Data transmission uses TLS/SSL encryption; data storage uses AES-256 encryption.

Access Control: Role-based permission settings and multi-factor authentication (MFA).

Audit: Conduct penetration testing and vulnerability assessment annually.

Event Response: Need to notify users and regulatory authorities of violations within 72 hours, which complies with the requirements of the Personal Data Protection Act.

8. Your Rights under the Personal Data Protection Act

You can:

Access/Correct Data: View or update your personal information through the "Account Settings" page of the application. Data Portability: Request to achieve machine-readable format