Legal
Privacy Policy
Last updated: 29 September 2026
Honoot ("Honoot", "we", "us") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you use the Honoot app and website (the "Platform"), in accordance with the Personal Data Protection Act 2010 ("PDPA") of Malaysia.
1. Personal Data We Collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email, phone number, password (hashed), profile photo | Provided by you |
| Booking data | Travel dates, destinations, passenger names, booking references, payment status | Provided by you / generated on booking |
| Payment data | Last 4 digits of card, payment method type, transaction status | Payment gateway (we do not store full card numbers) |
| Location data | Precise GPS, only if you turn on Crowd Pulse and grant device permission. Searched or viewed destinations. | Device, only after that opt-in; app usage for searches |
| Device and usage data | IP address, device type, OS, app version, and crash logs needed to run and secure the Platform | Collected when you use the Platform |
| Product analytics | Screens and features you use | Only if you enable analytics in Settings |
| Communications | Support messages, trip chat messages, reviews, feedback | Provided by you. Trip chat is visible to the other members of that chat |
| Sign-in data | Name and email from Google, Apple, or Facebook when you use those buttons | The provider, when you choose that sign-in |
2. How We Use Your Data
We process personal data for the following purposes:
- To create and manage your account
- To process and manage bookings with Suppliers
- To process payments and prevent fraud
- To provide customer support
- To personalize recommendations and itineraries from destinations you search and trips you create
- To send booking confirmations and service messages about an account or booking you asked us to perform
- To send marketing only if you opt in separately from creating an account. You can opt out in the message or by emailing privacy@honoot.com
- To understand product usage only if you enable analytics in Settings
- To show Crowd Pulse only if you opt in to precise location
- To comply with legal obligations, such as tax records for bookings
- To enforce our Terms of Service and Acceptable Use Policy
3. Legal Basis / Consent
The PDPA generally requires your consent, with limited exceptions. We rely on:
- Your consent for optional processing: marketing, product analytics, and precise location for Crowd Pulse. Each of these is off unless you turn it on. Withdrawing consent does not affect processing we already lawfully completed.
- A contract with you for the account, trip, or booking you ask us to provide.
- A legal obligation where the law requires us to keep a record, such as tax records for a booking.
Fraud checks and security logs are part of providing the account and booking you requested, and of meeting our duty to protect personal data. We do not treat general product improvement as a reason to collect analytics without consent.
You may withdraw optional consent in Settings, or by emailing privacy@honoot.com. Withdrawing consent for a feature means that feature will stop. It does not cancel a booking that is already confirmed.
4. Disclosure of Personal Data
We may disclose personal data to:
- Suppliers (hotels, activity operators, transport providers) — only the data necessary to fulfil your booking (e.g. name, dates, contact details)
- Payment gateways (including Stripe, where card payments are offered) — to process transactions. We do not store full card numbers.
- Cloud hosting and infrastructure providers — to store and operate the Platform
- Analytics and crash-reporting providers — in aggregated or pseudonymized form where possible
- Professional advisors and regulators — where required by law, court order, or to establish/defend legal claims
- A successor entity — in the event of a merger, acquisition, or asset sale, subject to equivalent privacy protections
We do not sell your personal data to third parties.
Cross-border transfers
Some providers process personal data outside Malaysia, including in the United States and the European Union (for example cloud hosting, sign-in, and card payments). Where we transfer personal data outside Malaysia, we take steps consistent with PDPA section 129, including contractual safeguards with those providers.
5. Data Retention
We keep personal data only as long as the purpose requires.
- Booking and payment records are generally kept for 7 years to meet tax record-keeping practice.
- Account data is kept while your account is open. When you ask us to delete your account, we close your profile 30 days later. Until then you can still sign in and cancel, but new bookings are paused. Once the profile is closed you can no longer sign in. Booking and payment records are kept separately for the period above or for a live dispute. Your name stays on trips, messages and expenses you shared with other members, and a trip you own passes to the member who joined it first.
- Precise location for Crowd Pulse is kept only while the feature is on and only for as long as needed to show that feature. Turning the feature off stops further collection.
- Product analytics, if you enabled them, are kept while the setting stays on and then deleted or de-identified on a rolling basis.
- Trip chat is kept for the life of that conversation unless you or we delete it, and remains subject to what other members have already seen.
You may request deletion at privacy@honoot.com or under Profile → Privacy & data. We may refuse a deletion that the law requires us to keep, and we will tell you if we do.
6. Your Rights Under the PDPA
Subject to the PDPA, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Withdraw consent for marketing, analytics, or precise location, which is as easy as the setting you used to turn it on
- Opt out of direct marketing
To exercise these rights, contact us at privacy@honoot.com. We may need to verify your identity. The PDPA allows a prescribed fee for an access request. You can also manage analytics and Crowd Pulse in Settings, and delete your account under Profile → Privacy & data.
A statutory right to data portability applies only to the extent the relevant PDPA provisions are in force and cover the data you ask for. We do not promise a copy in every format in the meantime. Ask us at privacy@honoot.com and we will tell you what we can provide.
If we become aware of a personal-data breach that creates a real risk of harm, we will notify the affected users and, where the law requires it, the Commissioner of Personal Data Protection.
7. Data Security
We implement reasonable technical and organizational measures — including encryption in transit, access controls, and regular security reviews — to protect personal data against unauthorized access, loss, misuse, or alteration, as required under PDPA's Security Principle.
8. Children's Privacy
The Platform is not for anyone under 18. We do not knowingly collect personal data from anyone under 18. If we learn that we have, we will delete the account and the data.
9. Cookies and Tracking
The website and app use cookies and similar technologies as described in our Cookie Policy.
10. Third-Party Links
The Platform may link to third-party websites (e.g. Supplier sites, social media). This Policy does not apply to those third parties; review their privacy policies separately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via the Platform or email. The "Last updated" date at the top reflects the latest revision.
12. Contact Us / Data Protection Contact
For privacy inquiries, data access/correction requests, or complaints:
Honoot
Email: privacy@honoot.com
If you are unsatisfied with our response, you may lodge a complaint with the Department of Personal Data Protection (JPDP), Ministry of Communications, Malaysia.
