Privacy Policy
Last Updated: 4 September 2025
Welcome to KLShortstay (“we,” “our,” or “us”). We are committed to protecting your privacy and handling your personal data in an open and transparent manner. This Privacy Policy explains how we collect, use, process, and disclose your information in conjunction with your access to and use of the KLShortstay website and services. This policy is designed to comply with the Malaysian Personal Data Protection Act 2010 (PDPA) and the General Data Protection Regulation (GDPR).
By using our website, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
We collect information that you provide directly to us, as well as information that is automatically collected when you use our services.
1.1. Data Provided by You (Guests & Hosts):
To use our services, we collect the following personal data:
- Full Name: To identify you as a user.
- Email Address: For account creation, communication, and notifications.
- Mobile Number: For communication between hosts, guests, and KLShortstay. Please provide it in the international format (e.g., +60 12 345 6789).
- Payment Information: For payout purposes for hosts, we may collect Bank Account Holder Full Name, Account Number, and Bank Name. For making payments, you will provide your card details during the checkout process on our website, which are then securely processed by our third-party payment gateway. We do not store your credit/debit card details on our servers.
1.2. Additional Data Provided by Hosts:
For verification and security purposes, we collect the following additional information from hosts:
- Selfie and Identification Card (IC): To verify your identity and ensure the safety of our community.
- Property Utility Bills: To validate property ownership and address during the listing process.
- Property Details: Information you provide about your listing, including images and location.
2. How We Collect Your Data
Your personal data is collected when you voluntarily provide it through:
- User Profile Forms: When you register for an account and complete your profile on our “My Profile” page.
- Property Listing Forms: When hosts submit the required details to list a property on our platform.
- Communications with Us: When you contact us for support or inquiries via email at inquiry@shortstay.com.my or other channels.
- Comments: When you leave comments on our site, we collect the information provided in the comment form.
3. Comments, Media, and Automatically Collected Data
- Comments: When you leave comments, we collect the data shown in the comments form, your IP address, and browser user agent string to help with spam detection. An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.
- Media Uploads: If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.
4. Cookies and Embedded Content
- Cookies: We use cookies to enhance your experience on our site. If you leave a comment on our site, you may opt in to saving your name, email address, and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. For registered users, we use cookies to remember your login status and screen display choices. Most cookies expire within a reasonable timeframe (login cookies last for two days, while screen options cookies last for a year). You may disable cookies in your browser settings, though this may affect some website functionality.
- Embedded Content from Other Websites: Articles on this site may include embedded content (e.g., videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor had visited the other website. These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content.
5. Why We Collect Your Data (Purpose of Processing)
We use the information we collect for the following purposes:
- Account Creation & Management: To create and maintain your user account and to verify your identity.
- Service Provision: To facilitate bookings, list properties, and enable communication between guests and hosts.
- Communication: To send you service-related messages, booking confirmations, updates, and support messages.
- Safety and Security: To verify user identities, prevent fraud, detect spam, and maintain a secure and trusted environment for all users.
- Legal Compliance: To comply with applicable laws and regulations.
6. Data Sharing and Disclosure
We respect your privacy and will not share your personal data with third parties, except in the following circumstances:
- With Third-Party Service Providers: We share necessary information with our payment gateway to process transactions securely.
- Between Guests and Hosts: To facilitate a booking, we share essential guest details (Full Name, Phone Number, Email) with the host. This is strictly for communication purposes related to the booking.
- For Legal Reasons: We may disclose your information if required to do so by law or in response to valid requests by public authorities.
We do not sell or rent your personal data to third parties for marketing purposes.
7. Data Retention
- Comments: If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.
- User Accounts: For users who register on our website, we store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.
8. International Data Transfers
As we serve a global user base, your information may be transferred to, and maintained on, computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy.
9. Data Security
We take reasonable steps to safeguard your information from unauthorized access, disclosure, alteration, or misuse. We implement appropriate technical and organizational security measures to protect your personal data. However, please be aware that no online platform or method of electronic storage is 100% secure.
10. Your Rights Under PDPA and GDPR
As a user, you have certain rights concerning your personal data:
- Right to Access: You have the right to request a copy of the personal data we hold about you.
- Right to Rectification: You have the right to request that we correct any information you believe is inaccurate or incomplete.
- Right to Erasure (Right to be Forgotten): You have the right to request that we erase your personal data, under certain conditions.
- Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data, under certain conditions.
- Right to Data Portability: You have the right to request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.
- Right to Object: You have the right to object to our processing of your personal data, under certain conditions.
- Right to Withdraw Consent: Where we rely on your consent to process data, you have the right to withdraw that consent at any time.
- Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection authority if you believe our processing of your personal data infringes applicable law.
To exercise any of these rights, please contact us at inquiry@shortstay.com.my.
11. Contact Us
If you have any questions or concerns about this Privacy Policy or our data-handling practices, please contact us at:
Email: inquiry@shortstay.com.my