Privacy Policy
Effective date: 2026-08-01 · Version: 1.0
This page explains, in plain English, what personal data id.gohalal.net
("we", "us") collects, why, what we do with it,
and what choices you have. It applies to every page under
id.gohalal.net. If anything on this page is unclear, email
privacy@gohalal.net.
1. Who we are (the data controller)
The data controller for the personal data described in this policy is HEXIOT SDN BHD (privacy@gohalal.net, 7C-G-03A, Palm Nipah Court 3, Jalan Sri Tanjung Pinang, 10470, Tanjung Tokong, Pulau Pinang). All privacy requests should go to this address.
2. What data we collect, why, and on what legal basis
We collect the personal data you give us, plus a minimal amount of data automatically when you use the service.
2a. Data you provide (account & card creation)
- Email address — to send a one-time login link and card-ready notifications. Legal basis: performance of the service you requested.
- Card fields you fill in: name, job title, company, short bio, profile photo (optional, max 2 MB), phone numbers, email addresses, custom links. Legal basis: your explicit consent at card-creation time (see § 8).
2b. Data collected automatically
- Hashed visitor IP: we never store your raw IP address. For visit-stats we store a one-way salted SHA-256 hash of your IP plus the current UTC date, truncated to 16 hex characters. The salt rotates daily and is never stored, so no cross-day tracking is possible. Legal basis: legitimate interest (analytics for the card owner).
- Browser family, device type, referrer — same purpose. No cookies, no advertising identifiers, no third-party trackers.
- HTTP session — in-memory, identifies you after login. Tomcat default 30-minute idle timeout.
- In-memory rate-limit buckets keyed by your raw IP, used only to prevent abuse (10 card creations / hour). Not persisted.
3. Who we share data with (sub-processors)
- Zoho Mail — sends our transactional email (the one-time login link and the card-ready email). The email subject, recipient, and the link content leave our infrastructure and are stored by Zoho under their own retention rules.
- Linode (an Akamai company) — hosts our application server and database in their Singapore data centre.
We do not sell personal data. We do not share it with advertisers or data brokers.
4. International transfers
Zoho's infrastructure processes email traffic across regions (India, US, EU depending on tenant routing). Our application and database are hosted on Linode's Singapore data centre in the ap-southeast region (Jurong East facility). When data is accessed from outside that region (for example, by a Malaysian visitor travelling overseas), it crosses borders; we rely on the safeguards available to a small service: encryption in transit (TLS), access control on the server, data minimisation, and a data-processing relationship with each sub-processor.
5. How long we keep your data
The numbers below describe what the service does today — not what we wish it did.
- Card data (name, contacts, links, photo, etc.) is kept for as long as you keep the card. Deletion is immediate and permanent — there is no soft-delete and no grace period. When you delete a card, the database record and the photo file on disk are removed together.
- Visit analytics events are deleted automatically after 365 days. After that, only aggregated daily counts (no personal data) remain for the card's lifetime.
- One-time login tokens expire after 15 minutes and the database records are purged after 7 days.
- Your consent to this policy is recorded (see § 8) for as long as the related card exists, for legal defence.
- Account deletion: email privacy@gohalal.net and we delete your account and all your cards within 30 days.
6. Your rights (GDPR / equivalent local laws)
- Access — ask for a copy of the data we hold about you.
- Rectification — fix anything wrong via your card's manage link.
- Erasure — delete your card, or your entire account (see § 5).
- Restriction & objection — ask us to pause or stop processing, where the legal basis is legitimate interest.
- Data portability — your card data is yours; download
it as a
.vcfany time. - Withdraw consent — see § 7.
- Lodge a complaint — see § 9.
7. Withdrawing consent
If you tick the "I agree" box when creating a card, you can withdraw that consent at any time. The simplest way is to delete the card (which removes the card data and stops further analytics processing). Email privacy@gohalal.net for anything else.
8. How we prove you consented (audit trail)
When you publish a card, we record a consent_log entry:
a SHA-256 hash of your IP, a truncated User-Agent string, the version
of this policy and the Terms you agreed to, the card ID, the email
address, and the timestamp. We do this so we can prove consent was
given (GDPR Art. 7(1)). You can request a copy of your consent record
at any time.
9. Lodging a complaint with a supervisory authority
If you are in the European Economic Area and believe we have mishandled your data, you have the right to lodge a complaint with your local data protection authority. If you are in Malaysia, the relevant authority is the Jabatan Perlindungan Data Peribadi (JPDP) (pdp.gov.my) under the Personal Data Protection Act 2010. We will cooperate fully with any such enquiry.
10. Whether providing the data is required
The only required fields are your name and at least one email address — without these the service cannot create a card. Everything else (title, company, bio, photo, additional contacts, links) is optional. Visit-stats data is collected only if you browse a public card.
11. Automated decision-making
We do not subject your data to any automated decision-making or profiling that produces legal or similarly significant effects.
12. "My data is on someone else's card" (non-user takedown)
If you find your personal data on a card you did not create or do not consent to, email privacy@gohalal.net with the card URL and what you'd like removed. We will action reasonable requests promptly.
13. Public cards (design)
A published card is reachable by anyone who has the URL or QR code. The card URL uses a randomly generated 8-character ID (~47 bits of entropy, unguessable in practice), but it is not a secret — treat every published card as public. Card data is view-only: we do not place tracking pixels, the vCard download runs in the visitor's browser, and we do not sell visitor data.
14. Security
We use TLS for traffic in transit, salted hashing (not storage) for analytics IP, and never store raw visitor IPs. Magic-link tokens are stored as SHA-256 hashes. Database access is restricted to the application server. No system is perfectly secure; if you find a vulnerability, please email security@gohalal.net.
15. Changes to this policy
When we change this policy materially we will update the version number at the top and, for new card creators, require a fresh consent tick before publishing. Existing cards are covered by the version they consented to.
16. Contact
Email privacy@gohalal.net. We aim to acknowledge every privacy request within 7 days.