Rujukan Laman

How rm666 Protects Your Personal Data

Our Privacy Policy tells you what data rm666 collects during account creation, payments and activity, why we need it, and which choices remain yours.

Clear data choicesCookie controlsSecure request paths
rm666 How rm666 Protects Your Personal Data
PRIVACY CONTACT PATHS

Reach Us About Your Privacy

Privacy questions can involve identity checks, payment references, cookie choices or records linked to your account. We provide three authenticated contact paths so you can ask about collection, request a copy or report an inaccurate field. Choose the channel available after signing in and explain the privacy outcome you want. We may confirm your identity before disclosing or changing personal data, which helps prevent another person from controlling your records.

Team online

Signed-in live chat

Open live chat from your signed-in account and ask for the privacy team. We use the authenticated session to locate your records without asking you to repeat unnecessary account details.

Privacy request form

Submit the privacy request form in our support centre when you need a copy, correction or deletion assessment. Include your account ID and the email or mobile number already linked to it.

Secure account inbox

Use the secure account inbox for supporting files or a written privacy request. Avoid sending identity documents through public messages, and mask unrelated numbers before attaching a payment record.

DATA CARE PRACTICES

Controls Behind Your Data Choices

Personal data moves through defined stages at rm666: collection, permitted use, controlled storage, limited sharing and deletion or anonymisation when retention is no longer required.

Purpose-based collection

We collect fields needed to create and protect your account, process wallet activity, meet legal duties and answer privacy requests. Optional fields are identified separately where the account flow allows a choice.

Cookie choices

Essential cookies maintain sign-in state and security checks. Where optional analytics or preference cookies are used, you can adjust their categories through the cookie panel and change that choice later.

Account safeguards

We protect account records with encrypted connections, access controls and activity monitoring. Staff access is restricted by role, while unusual sign-in or profile-change patterns may trigger an additional identity check.

Retention decisions

Retention periods reflect the record type, transaction history, dispute needs and applicable legal duties. When continued identification is unnecessary, we delete the record or remove account-linked elements using controlled processes.

Limited data sharing

We disclose relevant data to payment processors, identity-check services, hosting providers and authorities where legally required. Each disclosure is limited to its purpose, and contractual controls apply where we appoint a service provider.

Corrections and changes

Contact our privacy team through live chat, the request form or your secure inbox to change inaccurate account data. We verify your identity, assess the request and explain any lawful restriction.

Your Privacy Questions Answered Clearly

These answers explain how our Privacy Policy applies to account details, payment metadata, cookies, security records and your requests. They also clarify when identity confirmation is necessary and how service providers may handle limited data for us. If your situation needs account-specific checking, contact the privacy team through a signed-in channel. That route lets us respond without exposing personal records through an unauthenticated conversation.

We collect details you provide, such as your name, contact fields and verification records, plus device, sign-in, account-activity and transaction metadata created when you use our account services.

When you use Touch 'n Go, GrabPay, Boost dan FPX, we receive transaction references, amounts, times and status results. These records help reconcile your wallet, investigate disputes and meet applicable record-keeping duties.

Where applicable law provides the right, you may request a copy of qualifying personal data or ask us to correct an inaccurate field. We confirm identity before completing changes or disclosing records.

Use the cookie panel to accept or decline optional categories and adjust your preferences later. Essential cookies remain active where needed for sign-in, fraud checks, session security and requested account functions.

The period depends on the record type, legal duties, transaction history, security needs and unresolved disputes. We delete or anonymise qualifying data when its required retention period and active purpose have ended.

Some service providers may process limited data from another location when supporting hosting, payments, security or identity checks. We apply contractual and access controls appropriate to the transfer and its stated purpose.

Send an authenticated request through live chat, the privacy form or your secure inbox. State the account data involved and your requested outcome; we will assess it against applicable law and necessary retention duties.