Skip to content
ExiCash
HomeAbout Us
ControlEarnAdvanceCollectionDisburse
CareersContact Us
HomeAbout UsOur SolutionsControlEarnAdvanceCollectionDisburseCareersContact Us
Home›Privacy Policy

Data Protection

Privacy Commitment for Merchants and Partners

Please read this document carefully. By using our services, you acknowledge and agree to the terms set out herein.

Document Info

Last UpdatedJuly 2026
Issued ByEXICASH SDN BHD202601015752 (1677849-M)

Document Currently In Effect

Contents

1Introduction2Definitions3Personal Data We Collect4How We Collect Personal Data5How We Use Personal Data6Legal Basis and Consent7Disclosure of Personal Data8International Data Transfers9Card Data and PCI Security10Security of Personal Data11API Key and Credential Security12Data Breach and Security Incidents13Data Retention14Your Rights15Merchant Responsibilities for Personal Data16Cookies and Similar Technologies17Direct Marketing18Third-Party Websites and Services19Accuracy of Personal Data20Data Protection Officer / Privacy Contact21Changes to This Privacy Policy22Language23Contact Us

1Introduction

This Privacy Policy explains how EXICASH SDN BHD ("EXICASH", "we", "us", or "our") collects, uses, stores, processes, discloses, transfers, and protects personal data when you access or use our website, merchant dashboard, payment gateway technology, APIs, plugins, payment links, QR payment tools, reconciliation dashboard, reporting tools, fraud monitoring tools, white-label frontend, onboarding support, technical support, and related services.

EXICASH provides technology, integration, dashboard, API, reporting, onboarding support, and technical support services only. Regulated payment processing, settlement, acquiring, payout, refunds, chargebacks, reversals, and related regulated payment services are provided by licensed or registered banks, acquirers, e-money issuers, payment gateways, financial institutions, card schemes, wallet providers, BNPL providers, or other regulated payment partners where applicable.

This Privacy Policy applies to merchants, authorised users, directors, shareholders, beneficial owners, representatives, consumers, payers, referral partners, business partners, service providers, website visitors, and any individual whose personal data is provided to or processed by EXICASH.

We are committed to handling personal data in accordance with the Personal Data Protection Act 2010 of Malaysia, as amended from time to time, and other applicable personal data protection laws.

By accessing our website, registering for an account, submitting onboarding documents, using our dashboard, integrating our APIs, using payment links, making or receiving payment through supported payment flows, contacting us, or otherwise using our services, you acknowledge that you have read and understood this Privacy Policy.

2Definitions

For the purpose of this Privacy Policy:

"Merchant" means a company, sole proprietor, partnership, association, NGO, organisation, or other entity that registers for or uses EXICASH services.

"Authorised User" means any person authorised by a Merchant to access the EXICASH account, dashboard, API, plugin, reports, or services.

"Consumer" or "Payer" means an individual or entity making payment to a Merchant through payment flows supported by EXICASH technology and licensed payment partners.

"Licensed Payment Partner" means any licensed bank, registered merchant acquirer, e-money issuer, payment gateway, financial institution, card processor, e-wallet provider, BNPL provider, or other regulated payment partner involved in payment processing, acquiring, settlement, refund, chargeback, payout, risk review, or related regulated services.

"Personal Data" means any information that relates directly or indirectly to an identified or identifiable individual.

"Transaction Data" means information relating to payment attempts, payment status, payment references, transaction history, settlement reports, refund status, chargeback status, reversals, IP address, device data, API logs, webhook logs, fraud signals, and related payment metadata.

3Personal Data We Collect

We may collect personal data directly from you, from Merchants, from Authorised Users, from Consumers, from Licensed Payment Partners, from service providers, from public sources, from verification providers, from transaction activity, or automatically through your use of our website, dashboard, APIs, plugins, or payment tools.

The personal data we collect may include the categories below.

3.1 Merchant Account Information

When a Merchant registers for or uses EXICASH services, we may collect:

  • company or business name;
  • company registration number;
  • business type;
  • business address;
  • business email address;
  • business phone number;
  • website, social media, or store URL;
  • business description;
  • nature of business;
  • product or service information;
  • expected transaction volume;
  • account status;
  • service preferences;
  • dashboard settings;
  • payment method requests.

3.2 Authorised User Information

For individuals who register, access, manage, or use a Merchant account, we may collect:

  • full name;
  • email address;
  • mobile phone number;
  • job title or role;
  • username;
  • encrypted password credentials;
  • login records;
  • access permissions;
  • dashboard activity;
  • account activity;
  • support request history;
  • security verification information.

3.3 Director, Shareholder, Beneficial Owner, and Representative Information

For onboarding, KYB, KYC, verification, risk review, partner submission, fraud prevention, and compliance purposes, we may collect information relating to directors, shareholders, beneficial owners, office bearers, authorised representatives, or controllers of a Merchant, including:

  • full name;
  • NRIC or passport details;
  • nationality;
  • date of birth;
  • residential or correspondence address;
  • email address;
  • phone number;
  • ownership percentage;
  • role or designation;
  • identification documents;
  • proof of address;
  • beneficial ownership information;
  • politically exposed person or sanctions screening information, where applicable;
  • any other information required by EXICASH or Licensed Payment Partners.

3.4 KYB, KYC, and Onboarding Documents

We may collect and store onboarding documents, including but not limited to:

  • SSM statutory documents;
  • company profile;
  • business registration documents;
  • director and shareholder details;
  • NRIC or passport copies;
  • bank statements;
  • business bank account information;
  • website, social media, or store information;
  • nature of business documents;
  • product or service information;
  • licences, approvals, permits, or certificates;
  • beneficial ownership information;
  • tax information;
  • proof of address;
  • transaction history or transaction projection;
  • fulfilment, delivery, refund, or chargeback information;
  • any additional documents requested by EXICASH or Licensed Payment Partners.

These documents may be collected for EXICASH's internal records, safe keeping, risk review, onboarding assistance, partner submission, audit, legal compliance, fraud prevention, and service operation.

3.5 Bank Account and Settlement Information

Although EXICASH does not receive, hold, pool, control, or settle merchant funds, we may collect or process certain bank and settlement-related information for onboarding, dashboard display, reconciliation, reporting, invoicing, technical integration, or partner submission purposes.

This may include:

  • business bank account name;
  • bank name;
  • account number;
  • settlement account details;
  • bank statement;
  • settlement report data;
  • payout status;
  • transaction references;
  • reconciliation data;
  • invoice and billing information.

Settlement, payout, fund holding, refund, chargeback, reversal, and payout withholding are handled by the relevant Licensed Payment Partner according to their terms and applicable laws.

3.6 Consumer and Payer Information

When Consumers make payments to Merchants through payment flows supported by EXICASH technology, we may collect or process limited Consumer-related information, depending on the payment method and technical flow.

This may include:

  • payer name;
  • payer email address;
  • payer phone number;
  • payment reference;
  • transaction amount;
  • transaction date and time;
  • payment status;
  • payment method type;
  • masked card information, where applicable;
  • bank or issuer response information;
  • IP address;
  • device information;
  • payment page activity;
  • fraud or risk signals;
  • receipt or confirmation information.

EXICASH is not responsible for the Merchant's goods, services, delivery, refunds, warranties, customer service, or consumer relationship. Consumers should contact the Merchant for order, product, service, refund, or fulfilment issues.

3.7 Payment and Transaction Data

We may collect and process payment and transaction-related data, including:

  • transaction history;
  • payment attempts;
  • successful payments;
  • failed payments;
  • cancelled payments;
  • pending payments;
  • refund status;
  • chargeback status;
  • reversal status;
  • settlement report data;
  • reconciliation records;
  • payment method type;
  • payment reference numbers;
  • acquirer or partner references;
  • error codes;
  • system response data;
  • webhook events;
  • API request and response logs;
  • fraud monitoring indicators;
  • risk scoring information;
  • device, browser, and IP data connected with transactions.

3.8 API, Webhook, Plugin, and Technical Data

When Merchants integrate or use our APIs, webhooks, plugins, payment links, white-label frontend, dashboard, or related tools, we may collect:

  • API keys or token references;
  • API usage logs;
  • webhook logs;
  • request and response metadata;
  • error logs;
  • integration status;
  • sandbox and production activity;
  • merchant system identifiers;
  • IP addresses;
  • browser and device information;
  • plugin version;
  • website or application URL;
  • authentication logs;
  • security logs;
  • access logs;
  • system performance data.

We may use this information to provide services, troubleshoot issues, maintain security, monitor usage, detect misuse, prevent fraud, and improve our platform.

3.9 Fraud, Risk, AML/CFT, and Sanctions Information

We may collect, generate, receive, or process information relating to fraud prevention, suspicious activity, AML/CFT risk, sanctions screening, prohibited business checks, partner risk review, and compliance monitoring.

This may include:

  • risk alerts;
  • fraud signals;
  • transaction pattern analysis;
  • suspicious activity reports;
  • screening results;
  • business category risk;
  • chargeback or dispute indicators;
  • merchant complaint history;
  • consumer complaint information;
  • partner investigation requests;
  • regulatory or law enforcement requests;
  • internal risk review notes.

3.10 Support, Communication, and Ticket Information

When you contact us, we may collect:

  • name;
  • email address;
  • phone number;
  • company name;
  • support ticket details;
  • screenshots;
  • documents;
  • issue descriptions;
  • call notes;
  • email correspondence;
  • chat records;
  • technical logs;
  • resolution notes;
  • feedback.

We may use this information to respond to enquiries, provide technical support, resolve issues, investigate incidents, and improve our services.

3.11 Website and Device Information

When you visit our website or use our dashboard, we may automatically collect:

  • IP address;
  • browser type and version;
  • device type;
  • operating system;
  • pages viewed;
  • date and time of access;
  • referring website;
  • session data;
  • click activity;
  • approximate location based on IP address;
  • cookies and similar identifiers.

3.12 Referral Partner Information

If you participate in any referral, partner, reseller, or business development arrangement with EXICASH, we may collect:

  • individual or company name;
  • contact details;
  • bank account details;
  • referral tracking information;
  • referred merchant information;
  • commission or referral fee information;
  • tax or invoice information;
  • agreement records;
  • performance reports;
  • communication history.

4How We Collect Personal Data

We may collect personal data when:

  • you register for EXICASH services;
  • you submit onboarding or KYB/KYC documents;
  • you request access to payment methods;
  • you access or use the dashboard;
  • you use our APIs, plugins, webhooks, payment links, or white-label frontend;
  • you create or request sub-user access;
  • you contact our support team;
  • you submit a support ticket;
  • you make or receive payment through supported payment flows;
  • a Merchant provides Consumer or Authorised User information to us;
  • Licensed Payment Partners provide transaction, onboarding, risk, or settlement information to us;
  • verification providers, fraud monitoring providers, or service providers provide information to us;
  • information is generated through transaction activity, API activity, webhook events, or system logs;
  • you participate in referral, partner, or marketing activities;
  • you browse our website;
  • you voluntarily provide information to us.

5How We Use Personal Data

We may use personal data for the purposes below.

5.1 Account Registration and Service Access

We may use personal data to:

  • create and manage Merchant accounts;
  • verify Authorised Users;
  • set up dashboard access;
  • create sub-users or admin roles upon request;
  • manage user permissions;
  • authenticate access;
  • maintain account security;
  • provide sandbox and production access;
  • administer service subscriptions.

5.2 Onboarding, KYB, KYC, and Partner Submission

We may use personal data to:

  • assist Merchant onboarding;
  • collect and review KYB/KYC documents;
  • verify business information;
  • verify directors, shareholders, beneficial owners, and representatives;
  • assess eligibility for EXICASH services;
  • submit required documents to Licensed Payment Partners;
  • support partner approval processes;
  • respond to Licensed Payment Partner requests;
  • conduct internal risk checks;
  • maintain records for audit and compliance purposes.

5.3 Technology Service Delivery

We may use personal data to:

  • provide payment gateway technology;
  • enable payment links;
  • support QR payment integration;
  • support FPX, card, e-wallet, BNPL, payout, and disbursement connectivity;
  • provide dashboard access;
  • provide reconciliation tools;
  • display settlement reports;
  • provide fraud monitoring tools;
  • process API and webhook activity;
  • provide plugins and integration tools;
  • support white-label frontend configuration;
  • provide technical support.

5.4 Transaction Processing Support

Although regulated payment processing is handled by Licensed Payment Partners, EXICASH may process Transaction Data to:

  • route transaction requests;
  • display transaction status;
  • generate transaction references;
  • support payment confirmation;
  • provide technology-based receipts or confirmations;
  • display reconciliation information;
  • support settlement report viewing;
  • troubleshoot payment issues;
  • support communication between Merchant and Licensed Payment Partner;
  • assist with transaction investigations on a best-effort basis.

5.5 Fraud Prevention, Security, and Risk Monitoring

We may use personal data to:

  • detect suspicious activity;
  • identify possible fraud;
  • monitor transaction patterns;
  • detect API misuse;
  • detect leaked or compromised credentials;
  • prevent prohibited business activity;
  • support AML/CFT and sanctions controls;
  • investigate security incidents;
  • protect the EXICASH platform;
  • comply with partner, legal, and regulatory requirements.

5.6 Billing, Fees, and Commercial Administration

We may use personal data to:

  • issue invoices;
  • track monthly subscriptions;
  • calculate MDR markups or technology service charges;
  • charge integration fees;
  • charge API usage fees;
  • manage billing records;
  • collect unpaid amounts;
  • process commission or referral payments;
  • maintain accounting and tax records.

5.7 Customer Support and Communications

We may use personal data to:

  • respond to enquiries;
  • provide technical support from 8:00 a.m. to 10:00 p.m. Malaysia time, unless otherwise stated;
  • troubleshoot integration issues;
  • send service updates;
  • notify you about API, dashboard, or payment method changes;
  • inform you about maintenance;
  • respond to complaints;
  • provide operational notices.

5.8 Legal, Compliance, and Enforcement Purposes

We may use personal data to:

  • comply with applicable laws and regulations;
  • respond to lawful requests from authorities;
  • cooperate with Licensed Payment Partners;
  • enforce our Terms of Service;
  • enforce our policies;
  • investigate prohibited or restricted business activity;
  • prevent fraud, scams, bribery, corruption, money laundering, terrorism financing, sanctions evasion, or misuse of services;
  • resolve disputes;
  • protect our legal rights and interests.

5.9 Marketing and Business Development

Where permitted by law or with your consent, we may use personal data to:

  • send product updates;
  • send service announcements;
  • share information about new features;
  • send promotional or business development communications;
  • invite you to events, webinars, or campaigns;
  • manage referral or partner programmes.

You may opt out of direct marketing communications at any time.

6Legal Basis and Consent

Where required by applicable law, we rely on one or more of the following grounds to process personal data:

  • your consent;
  • performance of a contract;
  • steps taken before entering into a contract;
  • compliance with legal obligations;
  • legitimate business interests;
  • fraud prevention and security;
  • protection of legal rights;
  • compliance with Licensed Payment Partner requirements;
  • purposes directly related to the services requested.

Where personal data is provided to us by a Merchant, the Merchant is responsible for ensuring that it has given the required notices and obtained the required consents from the relevant individuals, including Authorised Users, directors, shareholders, beneficial owners, representatives, employees, Consumers, and payers.

7Disclosure of Personal Data

We do not sell personal data.

We may disclose personal data to the following parties where necessary for the purposes described in this Privacy Policy.

7.1 Licensed Payment Partners

We may disclose personal data to Licensed Payment Partners, including banks, registered merchant acquirers, e-money issuers, payment gateways, card processors, e-wallet providers, BNPL providers, payout providers, and other regulated payment partners.

This may be necessary for onboarding, payment method approval, payment processing, settlement, payout, refunds, chargebacks, reversals, risk review, transaction monitoring, regulatory compliance, or investigation.

7.2 Banks, Acquirers, Card Schemes, and Payment Networks

We may disclose personal data or transaction-related information to banks, acquirers, card schemes, payment networks, FPX, DuitNow QR providers, wallet providers, BNPL providers, and other payment infrastructure providers where required to support payment services.

7.3 Verification, KYB/KYC, Fraud, and Compliance Providers

We may disclose personal data to third-party service providers that assist with:

  • identity verification;
  • company verification;
  • beneficial ownership checks;
  • document verification;
  • fraud monitoring;
  • sanctions screening;
  • AML/CFT risk checks;
  • device intelligence;
  • transaction monitoring;
  • suspicious activity review.

7.4 Technology, Hosting, and Security Providers

We may disclose personal data to service providers that assist with:

  • cloud hosting;
  • data storage;
  • cybersecurity;
  • API infrastructure;
  • system monitoring;
  • database management;
  • email delivery;
  • SMS or notification services;
  • analytics;
  • backup and disaster recovery;
  • technical support tools.

7.5 Professional Advisers

We may disclose personal data to lawyers, auditors, accountants, insurers, consultants, compliance advisers, and other professional advisers.

7.6 Regulators, Authorities, and Law Enforcement

We may disclose personal data where required or permitted by law, regulation, court order, regulatory request, law enforcement request, investigation, or legal process.

This may include disclosure to Bank Negara Malaysia, the Personal Data Protection Commissioner, law enforcement agencies, tax authorities, courts, regulators, or other competent authorities where applicable.

7.7 Business Transfers

If EXICASH undergoes a merger, acquisition, restructuring, financing, sale of business, transfer of assets, or corporate transaction, personal data may be disclosed or transferred as part of that transaction, subject to appropriate safeguards and applicable law.

7.8 Referral Partners and Business Partners

Where you participate in a referral, reseller, technology, or partner arrangement, we may disclose limited information necessary to track referrals, manage commissions, confirm merchant onboarding status, or operate the partner relationship.

8International Data Transfers

EXICASH is based in Malaysia and currently supports Malaysia-based Merchants. However, some Licensed Payment Partners, service providers, cloud providers, fraud monitoring providers, verification providers, or support providers may process, store, access, or transfer personal data outside Malaysia.

Where personal data is transferred or accessed internationally, we will take reasonable steps to ensure that appropriate safeguards are in place and that the transfer complies with applicable data protection requirements.

9Card Data and PCI Security

EXICASH maintains PCI certification relevant to its role and service scope.

Where card payment functionality is made available, card processing may be handled by Licensed Payment Partners, payment processors, tokenisation providers, or other authorised payment service providers.

EXICASH does not require Merchants to store sensitive cardholder data. Merchants must not collect, store, process, transmit, expose, or misuse cardholder data or sensitive authentication data except in accordance with PCI DSS requirements, Licensed Payment Partner rules, card scheme rules, and EXICASH's instructions.

If a Merchant handles cardholder data outside the authorised EXICASH or Licensed Payment Partner payment flow, the Merchant is responsible for all legal, regulatory, scheme, partner, security, and financial consequences arising from such handling.

10Security of Personal Data

We implement reasonable technical, organisational, and administrative measures to protect personal data against unauthorised access, disclosure, alteration, loss, misuse, destruction, or compromise.

These measures may include:

  • access controls;
  • authentication controls;
  • encryption where appropriate;
  • secure hosting;
  • monitoring and logging;
  • vulnerability management;
  • incident response procedures;
  • API security controls;
  • internal access restrictions;
  • staff awareness;
  • service provider controls;
  • data backup procedures.

However, no method of transmission over the internet or electronic storage is completely secure. You are responsible for securing your own systems, devices, passwords, API keys, credentials, plugins, webhooks, servers, applications, and staff access.

11API Key and Credential Security

Merchants are responsible for keeping API keys, tokens, secrets, login details, passwords, webhook endpoints, and integration credentials confidential and secure.

If your API key or credential is leaked, compromised, exposed, shared, stolen, or used for unauthorised or prohibited activity, you must notify EXICASH immediately.

EXICASH may suspend, rotate, revoke, restrict, or disable API access if we suspect credential compromise, API misuse, prohibited activity, security risk, partner instruction, regulatory concern, or breach of our Terms.

The Merchant is responsible for consequences arising from leaked or compromised API keys or credentials caused by the Merchant, its Authorised Users, employees, contractors, service providers, systems, websites, or integrations.

12Data Breach and Security Incidents

If we become aware of a personal data breach or security incident involving personal data under our control, we will assess the incident and take reasonable steps to contain, investigate, and remediate the issue.

Where required by applicable law, regulation, or regulatory guidance, we may notify the relevant authority and/or affected individuals within the required timeframe.

Merchants must notify EXICASH immediately if they become aware of any actual or suspected data breach, credential leak, API key exposure, unauthorised access, system compromise, fraud incident, or security incident that may affect EXICASH services, transaction data, Consumers, or Licensed Payment Partners.

13Data Retention

We retain personal data only for as long as necessary to fulfil the purposes described in this Privacy Policy, provide our services, comply with legal and regulatory obligations, resolve disputes, prevent fraud, support audit and accounting requirements, enforce agreements, and protect our rights.

Different categories of data may be retained for different periods.

Transaction records, onboarding records, KYB/KYC documents, bank account records, account records, invoices, support tickets, risk records, fraud monitoring records, API logs, webhook logs, and compliance records may be retained for up to seven (7) years or such longer period as may be required or permitted by law, regulatory requirements, Licensed Payment Partner requirements, audit obligations, tax requirements, dispute handling, or legal proceedings.

Some technical logs may be retained for a shorter period unless required for security, investigation, audit, or compliance purposes.

Upon expiry of the applicable retention period, personal data may be securely deleted, destroyed, anonymised, or archived in accordance with our internal procedures and applicable law.

14Your Rights

Subject to applicable law, you may have rights in relation to your personal data, including:

14.1 Right of Access

You may request access to personal data we hold about you.

14.2 Right of Correction

You may request correction of personal data that is inaccurate, incomplete, misleading, or outdated.

14.3 Right to Withdraw Consent

Where processing is based on consent, you may withdraw consent at any time, subject to legal, contractual, regulatory, transaction, security, fraud prevention, and operational requirements.

Withdrawal of consent may affect our ability to provide services.

14.4 Right to Prevent Processing for Direct Marketing

You may request that we stop processing your personal data for direct marketing purposes.

14.5 Right to Request Account Closure

A Merchant may request closure of its account, subject to outstanding fees, contractual obligations, legal requirements, partner requirements, transaction records, compliance obligations, fraud prevention needs, and data retention requirements.

14.6 Right to Data Portability

Where applicable under Malaysian personal data protection law and where technically feasible, you may request data portability in respect of personal data that is subject to such right.

14.7 Complaints and Enquiries

You may contact us if you have questions, concerns, or complaints regarding our handling of personal data.

We may request verification of identity or authority before processing certain requests.

15Merchant Responsibilities for Personal Data

Merchants are responsible for ensuring that all personal data provided to EXICASH has been collected and disclosed lawfully.

Merchants must:

  • provide proper privacy notices to Consumers, Authorised Users, directors, shareholders, beneficial owners, representatives, employees, and other individuals;
  • obtain all required consents;
  • ensure that personal data provided to EXICASH is accurate and up to date;
  • ensure that Consumers are informed that their payment and transaction data may be processed by EXICASH and Licensed Payment Partners;
  • comply with applicable personal data protection laws;
  • protect access to dashboards, APIs, plugins, and transaction data;
  • notify EXICASH promptly of data breaches, security incidents, or unauthorised access;
  • not submit personal data that is unnecessary, unlawful, excessive, false, or misleading.

16Cookies and Similar Technologies

Our website and dashboard may use cookies and similar technologies to:

  • maintain login sessions;
  • remember user preferences;
  • support security;
  • detect suspicious activity;
  • analyse usage;
  • improve website performance;
  • support service functionality;
  • support marketing or analytics activities.

You may disable cookies through your browser settings. However, some website or dashboard functions may not operate properly if cookies are disabled.

17Direct Marketing

Where permitted by law or with your consent, EXICASH may send you marketing communications about products, services, features, updates, campaigns, events, or partner programmes.

You may opt out of direct marketing communications at any time by following the unsubscribe instructions in our communications or contacting us directly.

Even if you opt out of marketing, we may still send service-related communications, including account notices, payment method updates, API changes, security alerts, invoices, support messages, policy updates, or legal notices.

18Third-Party Websites and Services

Our website, dashboard, payment pages, documentation, emails, or plugins may contain links to third-party websites or services, including Licensed Payment Partners, payment pages, bank pages, e-wallet pages, BNPL provider pages, documentation platforms, or support tools.

We are not responsible for the privacy practices, content, security, availability, or data handling of third-party websites or services.

You should review the relevant third-party privacy policies and terms before using those services.

19Accuracy of Personal Data

You must ensure that all personal data provided to EXICASH is accurate, complete, current, and not misleading.

This includes Merchant information, Authorised User information, director and shareholder information, beneficial ownership information, bank account details, business information, Consumer information, transaction information, and support information.

EXICASH is not responsible for delays, rejected onboarding, failed payment method activation, inaccurate reports, failed communication, or service issues caused by inaccurate, incomplete, or outdated information provided by you.

20Data Protection Officer / Privacy Contact

Where required by applicable law, EXICASH may appoint or designate a person responsible for personal data protection matters.

For privacy questions, requests, complaints, or data protection matters, you may contact:

EXICASH SDN BHD Email: support@exicash.com Address: 16-19, Menara Mutiara Sentral, No. 2, Jalan Desa Aman 1, Cheras Business Centre, 56000 Kuala Lumpur, Malaysia

Please include sufficient details for us to identify your request and verify your authority.

21Changes to This Privacy Policy

EXICASH may update, amend, or replace this Privacy Policy from time to time to reflect changes in law, regulation, technology, partner requirements, payment methods, data practices, security practices, or business operations.

The updated Privacy Policy may be published on our website or notified through the dashboard, email, or other communication channels.

Your continued use of EXICASH services after the updated Privacy Policy is published means that you acknowledge the updated Privacy Policy.

22Language

This Privacy Policy may be made available in more than one language.

If there is any conflict or inconsistency between the English version and any translated version, the English version shall prevail unless otherwise required by applicable law.

23Contact Us

If you have any questions, requests, concerns, or complaints regarding this Privacy Policy or our handling of personal data, please contact:

EXICASH SDN BHD Company Registration No.: 202601015752 (1677849-M) Address: 16-19, Menara Mutiara Sentral, No. 2, Jalan Desa Aman 1, Cheras Business Centre, 56000 Kuala Lumpur, Malaysia Email: support@exicash.com Website: www.exicash.com

ExiCash

Practical, secure payment technology for merchants and partners.

Reg. No. 202601015752 (1677849-M)
16-19, Menara Mutiara Sentral, No. 2, Jalan Desa Aman 1, Cheras Business Centre, 56000 Kuala Lumpur, Malaysia support@exicash.com

Our Solutions

ControlEarnAdvanceCollectionDisburse

Our Policy

Privacy PolicyTerms & ConditionsAML/CFT PolicySecurity & Risk ManagementAnti-Bribery PolicyPayment Provider DisclosureData Processing Agreement
Back to top