Privacy Policy — Bookly MY
Effective date: 19 June 2026 App: Bookly MY (Malaysia Business Accounting) Developer / Data controller: BooklyMY Contact: bookly.malaysia@gmail.com
This Privacy Policy explains what information Bookly MY (“the app”, “we”) collects, how we use it, and who we share it with. By using the app you agree to this policy.
1. Information we collect
We only collect what is needed to provide the app’s features.
a) Account information
- When you sign in with Google, we receive your name, email address and a Google account identifier, and create a user account for you.
- You can use most of the app offline without an account; cloud sync requires sign-in.
b) Business and financial data you enter
- Transactions, income/expenses, invoices, quotations, delivery orders, credit notes, purchase orders, inventory, payroll, budgets and your company profile.
c) Personal data of your own customers / employees that you enter
- Names, identification numbers (e.g. NRIC/IC), Tax Identification Numbers (TIN), business registration numbers, addresses, phone numbers, emails and bank details.
- You are responsible for having a lawful basis to enter this data; we process it on your behalf solely to provide the app.
d) Subscription / purchase information
- Your Pro subscription status and purchase history (via RevenueCat and Google Play Billing). We do not collect or store your card or bank-card numbers — payments are handled by Google Play.
e) Photos and files you choose
- Company logo, authorised signature, and any bank statement or document you explicitly pick (e.g. for AI-assisted bank-statement import).
f) Camera
- Used only when you scan a barcode/QR code. Scans are processed on-device and not stored as images.
g) Device and advertising identifiers
- If ads are shown to free-tier users, Google AdMob may use a device advertising identifier. Pro users see no ads.
h) Diagnostics
- Minimal crash/diagnostic information to keep the app stable.
2. How we use your information
- To provide and operate the app’s accounting, invoicing and inventory features.
- To sync your data across your devices (when signed in).
- To manage your subscription and unlock Pro features.
- To submit e-Invoices to LHDN MyInvois at your instruction (see section 4).
- To show ads to free-tier users (if enabled) and to provide support.
We do not sell your personal data.
3. AI-assisted features (Google Gemini)
Some optional features (e.g. bank-statement import / AI assistant) send the content you provide to Google’s Gemini API to extract or summarise data. Only the content you choose to process is sent. Do not use these features for data you are not permitted to share.
4. e-Invoice (LHDN MyInvois)
If you use the MyInvois feature:
- The invoice data you choose to submit is sent to LHDN’s MyInvois system via a secure server function, only when you tap submit.
- Your MyInvois API credentials are stored encrypted in our backend and are accessible only to your own account (row-level security); they are never exposed to other users.
- Your digital-signing certificate and private key stay only on your device in the operating system’s encrypted secure storage. They are never uploaded to our servers or anyone else. Only the public certificate is embedded in the signed e-Invoice, as required by LHDN.
5. Third-party services
We use the following processors. Each has its own privacy policy:
| Service | Purpose | Policy |
|---|---|---|
| Supabase | Cloud database / authentication / storage | https://supabase.com/privacy |
| Google Sign-In & Firebase | Sign-in, app infrastructure | https://policies.google.com/privacy |
| Google AdMob | Ads (free tier only) | https://policies.google.com/privacy |
| Google Gemini API | Optional AI features | https://policies.google.com/privacy |
| RevenueCat | Subscription management | https://www.revenuecat.com/privacy |
| LHDN MyInvois | e-Invoice submission (your instruction) | https://www.hasil.gov.my |
6. Storage, security and location
- Cloud data is stored with Supabase (region: Asia-Pacific, Singapore).
- Data in transit is encrypted (HTTPS/TLS).
- Access to your cloud data is restricted to your own account via row-level security. Your signing private key never leaves your device.
7. Data retention and deletion
- We keep your data for as long as your account exists.
- You may delete individual records in the app at any time.
- To delete your account and associated cloud data, contact us at the email above; we will delete it within a reasonable period, except where law requires retention.
8. Children
Bookly MY is a business tool and is not directed to children under 16. We do not knowingly collect data from children.
9. Your rights
Subject to applicable Malaysian law (PDPA 2010), you may request access to, correction of, or deletion of your personal data by contacting us.
10. Changes to this policy
We may update this policy from time to time. Material changes will be notified in the app or on this page, with an updated effective date.
11. Contact
BooklyMY Email: bookly.malaysia@gmail.com