Skip to content
Exicash
Home
WalletCollectionDisburseEarnAdvance
About UsContact Us
HomeOur SolutionsWalletCollectionDisburseEarnAdvanceAbout UsContact Us

Data Protection

Privacy Policy

Please read this document carefully. By using our services, you acknowledge and agree to the terms set out herein.

Last Updated16 August 2026
Issued ByEXICASH SDN BHD202601015752 (1677849-M)
JurisdictionMalaysia
Document navigationBrowse sections29
1Introduction2WHO WE ARE3OUR ROLE IN RELATION TO MERCHANT AND CUSTOMER DATA4WHAT PERSONAL DATA WE MAY COLLECT5HOW WE COLLECT PERSONAL DATA6WHY WE PROCESS PERSONAL DATA7BASIS ON WHICH WE PROCESS PERSONAL DATA8IS PROVIDING PERSONAL DATA MANDATORY?9WHO WE MAY DISCLOSE PERSONAL DATA TO10PAYMENT PARTNERS MAY PROCESS DATA FOR THEIR OWN PURPOSES11CROSS-BORDER TRANSFERS12HOW LONG WE RETAIN PERSONAL DATA13HOW WE PROTECT PERSONAL DATA14PERSONAL DATA BREACHES15COOKIES AND SIMILAR TECHNOLOGIES16DIRECT MARKETING AND COMMUNICATION PREFERENCES17FRAUD, RISK ANALYSIS AND AUTOMATED TOOLS18YOUR PERSONAL DATA RIGHTS19HOW TO EXERCISE YOUR RIGHTS20REQUESTS RELATING TO A MERCHANT21ACCURACY OF PERSONAL DATA22PERSONAL DATA RELATING TO OTHER PEOPLE23THIRD-PARTY WEBSITES AND SERVICES24BUSINESS TRANSFERS AND CORPORATE CHANGES25AGGREGATED AND ANONYMISED INFORMATION26CHANGES TO THIS PRIVACY POLICY27APPLICABLE LAW28CONTACT US29COMPLAINTS

Contents

29 clauses
1Introduction2WHO WE ARE3OUR ROLE IN RELATION TO MERCHANT AND CUSTOMER DATA4WHAT PERSONAL DATA WE MAY COLLECT5HOW WE COLLECT PERSONAL DATA6WHY WE PROCESS PERSONAL DATA7BASIS ON WHICH WE PROCESS PERSONAL DATA8IS PROVIDING PERSONAL DATA MANDATORY?9WHO WE MAY DISCLOSE PERSONAL DATA TO10PAYMENT PARTNERS MAY PROCESS DATA FOR THEIR OWN PURPOSES11CROSS-BORDER TRANSFERS12HOW LONG WE RETAIN PERSONAL DATA13HOW WE PROTECT PERSONAL DATA14PERSONAL DATA BREACHES15COOKIES AND SIMILAR TECHNOLOGIES16DIRECT MARKETING AND COMMUNICATION PREFERENCES17FRAUD, RISK ANALYSIS AND AUTOMATED TOOLS18YOUR PERSONAL DATA RIGHTS19HOW TO EXERCISE YOUR RIGHTS20REQUESTS RELATING TO A MERCHANT21ACCURACY OF PERSONAL DATA22PERSONAL DATA RELATING TO OTHER PEOPLE23THIRD-PARTY WEBSITES AND SERVICES24BUSINESS TRANSFERS AND CORPORATE CHANGES25AGGREGATED AND ANONYMISED INFORMATION26CHANGES TO THIS PRIVACY POLICY27APPLICABLE LAW28CONTACT US29COMPLAINTS

1Introduction

EXICASH SDN. BHD. [Registration No. 202601015752 (1677849-M)] (“EXICASH”, “we”, “us” or “our”) respects your privacy and is committed to protecting Personal Data that we process in connection with our website, Platform and Services.

This Privacy Policy explains how we collect, use, disclose, store, transfer and otherwise process Personal Data.

It applies to Personal Data processed by EXICASH in connection with:

  • our website;
  • merchant registration and onboarding;
  • the EXICASH Platform;
  • Merchant Accounts;
  • payment acceptance functionality;
  • Payout functionality;
  • Refunds and Chargebacks;
  • settlement administration and reconciliation;
  • merchant and technical support;
  • fraud, risk and security management;
  • compliance and regulatory activities; and
  • our other payment-related technology, connectivity, orchestration, administration and support services.

2WHO WE ARE

EXICASH SDN. BHD. is a company incorporated in Malaysia.

Our details are:

EXICASH SDN. BHD.
Registration No. 202601015752 (1677849-M)
16-19, Menara Mutiara Sentral
No. 2, Jalan Desa Aman 1
Cheras Business Centre
56000 Kuala Lumpur
Malaysia

For the purposes of applicable personal data protection laws, EXICASH may act as a Data Controller in respect of certain Personal Data and as a Data Processor on behalf of a Merchant in respect of other Personal Data.

The role we perform depends on the relevant processing activity.

3OUR ROLE IN RELATION TO MERCHANT AND CUSTOMER DATA

2.1 Where EXICASH acts as Data Controller

EXICASH may act as a Data Controller where we determine the purposes or manner in which Personal Data is processed for our own legitimate operational, contractual, security, risk, compliance or legal requirements.

This may include Personal Data processed for:

  • Merchant registration;
  • Merchant onboarding;
  • identity and business verification;
  • account administration;
  • beneficial ownership verification;
  • sanctions and financial-crime screening;
  • fraud prevention and investigation;
  • Platform and account security;
  • legal and regulatory compliance;
  • maintaining Transaction and accounting records;
  • responding to regulators, law enforcement or lawful requests;
  • managing our Payment Partner relationships;
  • protecting our rights and the integrity of our Services; and
  • managing risks associated with the Services.

Where we act as a Data Controller, this Privacy Policy describes how EXICASH processes your Personal Data.

2.2 Where EXICASH acts on behalf of a Merchant

In some circumstances, a Merchant may determine the purposes for which Customer or Beneficiary Personal Data is processed and EXICASH may process that Personal Data on the Merchant’s behalf in order to provide the Services.

In those circumstances, the Merchant may be primarily responsible for providing you with information about that processing and handling requests concerning your Personal Data.

Our contractual obligations to Merchants concerning such processing are further described in our Data Processing Policy.

If you are a Customer of one of our Merchants and your request concerns Personal Data controlled by that Merchant, we may refer you to the relevant Merchant where appropriate.

4WHAT PERSONAL DATA WE MAY COLLECT

The Personal Data we collect depends on your relationship with EXICASH and how the Services are used.

We may collect the following categories of Personal Data.

3.1 Identity information

This may include:

  • full name;
  • identification number;
  • passport or other identity-document information;
  • date of birth where required;
  • nationality where required;
  • photographs or identity-verification images;
  • signatures;
  • identity verification results; and
  • other information reasonably necessary to verify an individual’s identity.

3.2 Contact information

This may include:

  • email address;
  • telephone or mobile number;
  • residential address;
  • business address;
  • registered address;
  • mailing address; and
  • other contact details.

3.3 Merchant, employment and business relationship information

Where you are associated with a Merchant, we may collect:

  • job title;
  • designation;
  • employer or business name;
  • company registration details;
  • directorship information;
  • shareholder information;
  • beneficial ownership information;
  • percentage of ownership where relevant;
  • authority to act for a Merchant;
  • Authorised User status;
  • business licences or approvals;
  • nature of business;
  • business activities;
  • products and services;
  • website or application information; and
  • other information concerning your relationship with the Merchant.

3.4 Financial and settlement information

We may collect information such as:

  • bank name;
  • bank account holder name;
  • bank account number;
  • settlement account information;
  • payout information;
  • source-of-funds information where required;
  • source-of-revenue information;
  • financial information supplied for due diligence or risk assessment; and
  • other information reasonably necessary for payment, settlement, verification or compliance purposes.

3.5 Transaction and payment-related information

When the Services are used, we may process information relating to Transactions, including:

  • Transaction identifiers;
  • Merchant identifiers;
  • Customer or Beneficiary identifiers;
  • Transaction amount;
  • currency;
  • payment method;
  • Transaction date and time;
  • Transaction status;
  • payment routing information;
  • settlement information;
  • Payout information;
  • Beneficiary details;
  • Refund information;
  • Chargeback information;
  • dispute information;
  • payment-related reference numbers; and
  • information received from Payment Partners, Payment Networks, banks or other payment participants.

We do not necessarily receive or store every piece of information involved in a payment. The information available to EXICASH depends on the applicable Supported Payment Method, technical integration and Payment Partner arrangement.

3.6 Merchant Account and authentication information

We may process:

  • Merchant Account identifiers;
  • Authorised User identifiers;
  • usernames;
  • authentication records;
  • login history;
  • account permissions;
  • account configuration;
  • security events;
  • API activity;
  • credential-related metadata;
  • access logs; and
  • records of actions performed through the Platform.

Passwords and other credentials may be stored or protected using appropriate security mechanisms rather than in readable form.

3.7 Device and technical information

When you access our website, Platform or Services, we may automatically collect technical information including:

  • Internet Protocol address;
  • device identifiers;
  • device type;
  • browser type;
  • operating system;
  • language settings;
  • session information;
  • login timestamps;
  • access times;
  • referring pages;
  • pages or Platform features accessed;
  • API request information;
  • network information;
  • error and diagnostic information;
  • security logs; and
  • other technical information relating to your interaction with our systems.

3.8 Fraud, security, risk and compliance information

We may process information used to identify or manage potential fraud, security, regulatory or financial-crime risks, including:

  • fraud indicators;
  • risk indicators;
  • Transaction patterns;
  • unusual activity indicators;
  • screening results;
  • sanctions-related information;
  • identity-verification results;
  • due-diligence information;
  • account-security signals;
  • device signals;
  • investigation records;
  • Chargeback or dispute history; and
  • information received from Payment Partners, fraud-prevention providers, verification providers or other authorised sources.

3.9 Communications and support information

If you contact us, we may collect:

  • correspondence;
  • emails;
  • support tickets;
  • telephone or chat communications;
  • complaints;
  • Transaction enquiries;
  • technical support information;
  • dispute records;
  • documents you submit; and
  • other information contained in communications with us.

3.10 Website and cookie information

We may collect information through cookies, logs and similar technologies when you interact with our website or Platform.

Further information is provided in Section 14 below.

3.11 Marketing and communication preferences

Where relevant, we may record:

  • whether you have agreed to receive marketing communications;
  • your communication preferences;
  • unsubscribe requests; and
  • other preferences relating to communications from EXICASH.

3.12 Other information

We may collect other Personal Data where:

  • you voluntarily provide it to us;
  • a Merchant provides it to us in connection with the Services;
  • it is reasonably necessary for the Services;
  • a Payment Partner requires it;
  • it is required for fraud, risk or security purposes; or
  • Applicable Law requires or permits us to collect it.

5HOW WE COLLECT PERSONAL DATA

We may obtain Personal Data from a number of sources.

4.1 Directly from you

We may collect Personal Data when you:

  • register a Merchant Account;
  • complete an onboarding form;
  • provide identification documents;
  • provide company or beneficial ownership information;
  • submit bank or settlement details;
  • communicate with us;
  • contact customer support;
  • submit a Transaction-related request;
  • respond to a verification request;
  • use our website or Platform; or
  • otherwise provide information directly to EXICASH.

4.2 From Merchants

A Merchant may provide Personal Data concerning its:

  • directors;
  • shareholders;
  • beneficial owners;
  • employees;
  • Authorised Users;
  • authorised representatives;
  • Customers;
  • Beneficiaries;
  • business contacts; and
  • other persons involved in Transactions or the Merchant relationship.

If you provide another person’s Personal Data to EXICASH, you are responsible for ensuring that you are authorised to provide that information and that any notices, consents or other requirements applicable to that disclosure have been satisfied.

4.3 From Payment Partners and payment participants

We may receive information from:

  • banks;
  • merchant acquirers;
  • payment service providers;
  • electronic money issuers;
  • Payment Networks;
  • settlement institutions;
  • receiving institutions; and
  • other entities involved in processing, clearing, routing or settling Transactions.

4.4 From verification, fraud and compliance providers

We may obtain information from third parties that assist us with:

  • identity verification;
  • business verification;
  • beneficial ownership verification;
  • fraud prevention;
  • security;
  • sanctions screening;
  • compliance;
  • risk assessment; and
  • other due-diligence activities.

4.5 From publicly available and official sources

Where appropriate, we may obtain information from:

  • corporate registries;
  • regulatory databases;
  • government records;
  • sanctions lists;
  • publicly available business information;
  • public websites; and
  • other lawful public sources.

4.6 Automatically

Certain information may be collected automatically when you use our website, Platform, APIs or other Services, including technical, device, security and usage information.

6WHY WE PROCESS PERSONAL DATA

We may process Personal Data for the following purposes.

5.1 Registration and onboarding

To:

  • create and administer Merchant Accounts;
  • process Merchant applications;
  • verify Merchant particulars;
  • identify directors and beneficial owners;
  • verify authorised representatives;
  • verify settlement accounts;
  • determine eligibility for Services; and
  • complete required onboarding procedures.

5.2 Providing the Services

To:

  • operate the Platform;
  • provide payment-related technology;
  • provide payment acceptance functionality;
  • transmit Transaction instructions;
  • route Transactions;
  • facilitate Payout instructions;
  • facilitate Refunds;
  • provide Transaction status information;
  • administer Merchant Accounts;
  • maintain APIs and integrations; and
  • otherwise provide the Services.

5.3 Payment routing and Payment Partner connectivity

To:

  • transmit information to Payment Partners;
  • select or support Transaction routes;
  • connect Merchants with applicable payment infrastructure;
  • facilitate Transaction processing;
  • support authorisation, clearing or settlement processes; and
  • communicate Transaction information between relevant participants.

5.4 Settlement, reconciliation and reporting

To:

  • administer settlement information;
  • reconcile Transactions;
  • produce Transaction reports;
  • calculate or display settlement information;
  • investigate discrepancies;
  • manage invoices;
  • administer Fees; and
  • maintain financial and operational records.

5.5 Payouts, Refunds and Chargebacks

To:

  • transmit Payout instructions;
  • process or facilitate Refund requests;
  • manage Chargebacks;
  • investigate payment disputes;
  • receive and transmit supporting evidence;
  • reconcile payment adjustments; and
  • communicate with relevant Payment Partners and Payment Networks.

5.6 Merchant and technical support

To:

  • respond to enquiries;
  • troubleshoot technical issues;
  • investigate Transaction problems;
  • respond to complaints;
  • provide Platform support;
  • communicate service information; and
  • manage our relationship with Merchants.

5.7 Fraud prevention and risk management

To:

  • detect potential fraud;
  • identify suspicious activity;
  • monitor unusual Transaction patterns;
  • assess Merchant and Transaction risk;
  • investigate security events;
  • protect Customers and Merchants;
  • manage credit or payment-system exposure;
  • prevent misuse of our Platform; and
  • protect the integrity of the payment ecosystem.

5.8 Identity, compliance and financial-crime controls

To:

  • verify identity;
  • conduct due diligence;
  • identify beneficial owners;
  • perform sanctions screening;
  • conduct financial-crime checks;
  • investigate suspicious activity;
  • respond to Payment Partner compliance requests;
  • comply with Payment Network requirements; and
  • comply with applicable legal or regulatory obligations.

5.9 Security

To:

  • authenticate users;
  • control Platform access;
  • protect accounts and credentials;
  • detect unauthorised activity;
  • monitor security events;
  • investigate suspected compromises;
  • prevent cyber threats;
  • maintain system integrity; and
  • improve the security of our systems and Services.

5.10 Legal and regulatory purposes

To:

  • comply with Applicable Law;
  • respond to lawful requests from authorities;
  • comply with court orders;
  • cooperate with regulators;
  • maintain legally required records;
  • establish, exercise or defend legal claims;
  • enforce contractual rights;
  • resolve disputes; and
  • protect our legal interests.

5.11 Platform operation and improvement

We may process appropriate information to:

  • monitor Platform performance;
  • diagnose errors;
  • understand how our Services function;
  • improve reliability;
  • improve security;
  • improve user experience;
  • develop or improve Platform functionality;
  • perform operational analytics; and
  • plan system capacity.

Where reasonably practicable, we may use aggregated or anonymised information for these purposes.

5.12 Communications

We may use contact information to send:

  • account notices;
  • Transaction-related communications;
  • security alerts;
  • compliance requests;
  • operational communications;
  • service updates;
  • maintenance notices;
  • legal notices; and
  • other communications necessary for our relationship with you or the Merchant.

5.13 Marketing

Where permitted by Applicable Law, we may use business contact information to communicate with you regarding:

  • EXICASH products;
  • new Platform functionality;
  • relevant services;
  • business updates;
  • events; or
  • other promotional information.

You may opt out of direct marketing as described in Section 15.

7BASIS ON WHICH WE PROCESS PERSONAL DATA

We process Personal Data only where permitted under Applicable Law.

Depending on the circumstances, processing may occur:

  • with your consent where consent is required;
  • to provide or administer Services requested by you or a Merchant;
  • to perform contractual obligations;
  • to comply with legal or regulatory obligations;
  • for fraud-prevention, security, risk-management or compliance purposes;
  • to establish, exercise or defend legal rights;
  • where processing is otherwise authorised or permitted by Applicable Law; or
  • on the documented instructions of a Merchant where EXICASH acts as a Data Processor.

Where we rely on consent and Applicable Law allows you to withdraw that consent, you may do so subject to the consequences described in this Privacy Policy and any applicable legal limitations.

8IS PROVIDING PERSONAL DATA MANDATORY?

Whether you are required to provide Personal Data depends on the circumstances.

Certain information is mandatory where reasonably required for:

  • Merchant registration;
  • identity verification;
  • beneficial ownership verification;
  • account creation;
  • compliance;
  • fraud and risk assessment;
  • Settlement Account verification;
  • Transaction processing;
  • Payouts;
  • Payment Partner requirements;
  • security; or
  • legal or regulatory obligations.

Other information may be optional.

Where information is marked as mandatory or is reasonably necessary for the relevant purpose, failure to provide accurate and complete information may result in:

  • inability to complete registration;
  • delay or rejection of onboarding;
  • inability to create or activate a Merchant Account;
  • inability to enable a Supported Payment Method;
  • Transaction rejection or delay;
  • inability to process a Payout or Refund;
  • limits being imposed on the Merchant Account;
  • further verification being required;
  • suspension or restriction of Services; or
  • inability for us to provide some or all of the Services.

Where Personal Data is requested for an optional purpose, you may generally choose whether to provide it.

9WHO WE MAY DISCLOSE PERSONAL DATA TO

We may disclose or make Personal Data available to the following categories of recipients where reasonably necessary for the purposes described in this Privacy Policy.

8.1 Payment Partners

This may include:

  • banks;
  • licensed financial institutions;
  • merchant acquirers;
  • payment service providers;
  • electronic money issuers;
  • payment system operators;
  • settlement institutions; and
  • other authorised payment providers.

8.2 Payment Networks and payment participants

This may include:

  • payment schemes;
  • banking networks;
  • clearing networks;
  • issuers;
  • receiving banks;
  • settlement institutions; and
  • other parties involved in processing or administering Transactions.

8.3 Service providers

We may use service providers that assist us with:

  • cloud infrastructure;
  • hosting;
  • data storage;
  • identity verification;
  • fraud prevention;
  • security monitoring;
  • communications;
  • customer support;
  • software;
  • technical infrastructure;
  • analytics;
  • professional services; and
  • other functions necessary to operate our business and Services.

Such providers may receive Personal Data only to the extent reasonably necessary for the relevant service and subject to applicable contractual and legal requirements.

8.4 Merchants

Where relevant to a Transaction or the Services, information may be provided to the applicable Merchant.

For example, Transaction status, Customer payment information or dispute information may be made available to the Merchant in connection with the Merchant’s Transactions.

8.5 Professional advisers

We may disclose Personal Data to professional advisers including:

  • lawyers;
  • accountants;
  • auditors;
  • insurers;
  • consultants; and
  • other professional advisers,

where reasonably necessary.

8.6 Governmental, regulatory and law-enforcement authorities

We may disclose Personal Data to:

  • regulators;
  • government authorities;
  • law-enforcement agencies;
  • courts;
  • tribunals;
  • tax authorities; or
  • other competent authorities,

where required or permitted by Applicable Law or reasonably necessary to protect legal rights.

8.7 Corporate transactions

If EXICASH undergoes a merger, acquisition, restructuring, financing, sale of business or assets or similar corporate transaction, Personal Data may be disclosed to appropriate prospective or actual counterparties and their advisers, subject to appropriate confidentiality and legal safeguards.

8.8 Other disclosures

We may disclose Personal Data:

  • with your consent;
  • at your direction;
  • at the direction of a Merchant where lawful;
  • where necessary to protect the security of the Platform;
  • where necessary to investigate fraud or unlawful activity;
  • where necessary to protect our rights or the rights of others; or
  • where otherwise permitted or required by Applicable Law.

10PAYMENT PARTNERS MAY PROCESS DATA FOR THEIR OWN PURPOSES

Certain Payment Partners, Payment Networks, banks and other payment participants may process Personal Data independently from EXICASH.

For example, they may process information for their own:

  • payment processing;
  • settlement;
  • fraud prevention;
  • risk management;
  • sanctions screening;
  • regulatory compliance;
  • security; and
  • legal obligations.

Their processing may be governed by their own privacy policies, notices or legal obligations.

EXICASH does not control every independent processing activity carried out by such third parties.

11CROSS-BORDER TRANSFERS

EXICASH is based in Malaysia, but the infrastructure and organisations involved in providing the Services may operate in other countries.

As a result, Personal Data may be transferred to, stored in, accessed from or processed outside Malaysia where reasonably necessary in connection with:

  • cloud infrastructure;
  • Payment Partners;
  • Payment Networks;
  • international banking or payment infrastructure;
  • fraud-prevention services;
  • identity-verification services;
  • security services;
  • technical support;
  • service providers;
  • business continuity; or
  • other legitimate purposes connected with the Services.

Where Personal Data is transferred outside Malaysia, EXICASH will take such steps and implement such measures as are required by Applicable Law for the relevant transfer.

The level of data protection and legal requirements applicable in another country may differ from those in Malaysia.

12HOW LONG WE RETAIN PERSONAL DATA

We do not intend to retain Personal Data longer than reasonably necessary for the purposes for which it is processed, subject to applicable legal, regulatory, contractual, security and operational requirements.

Retention periods may vary depending on the nature of the information and why we hold it.

We may retain Personal Data where reasonably necessary for:

  • maintaining a Merchant Account;
  • providing the Services;
  • processing Transactions;
  • settlement and reconciliation;
  • accounting;
  • tax and financial records;
  • compliance obligations;
  • regulatory requirements;
  • fraud prevention;
  • security;
  • audits;
  • investigations;
  • Chargebacks;
  • Refunds;
  • disputes;
  • complaints;
  • enforcement of contractual rights;
  • establishment, exercise or defence of legal claims; and
  • other lawful purposes.

Following expiry of the applicable retention period, Personal Data may be securely deleted, destroyed or anonymised in accordance with our applicable procedures and legal obligations.

Information contained in system backups may remain until overwritten or deleted in accordance with normal backup and recovery cycles.

13HOW WE PROTECT PERSONAL DATA

We maintain reasonable administrative, technical and organisational safeguards designed to protect Personal Data against:

  • unauthorised access;
  • unauthorised disclosure;
  • misuse;
  • alteration;
  • accidental loss;
  • unlawful loss;
  • destruction; and
  • other security threats.

Depending on the nature of the system and risk, measures may include:

  • access controls;
  • authentication;
  • credential management;
  • encryption or other appropriate protection;
  • logging;
  • monitoring;
  • vulnerability management;
  • security patching;
  • network security;
  • incident-response procedures;
  • backups;
  • recovery measures;
  • personnel confidentiality requirements; and
  • appropriate controls over service providers.

No electronic system or transmission method can be guaranteed to be completely secure. You are also responsible for maintaining the confidentiality and security of credentials used to access your Merchant Account.

If you believe your Merchant Account, password, API credentials, security tokens or other credentials may have been compromised, you should notify EXICASH promptly through our designated support channel.

14PERSONAL DATA BREACHES

EXICASH maintains procedures designed to identify, investigate, manage and respond to suspected Personal Data Breaches and other security incidents.

Where a Personal Data Breach occurs, we will take appropriate steps having regard to:

  • the nature of the incident;
  • the Personal Data involved;
  • potential consequences;
  • affected individuals;
  • our role in relation to the relevant Personal Data; and
  • applicable legal and regulatory requirements.

Where notification to affected individuals, Merchants, regulators or other parties is required by Applicable Law, we will make or support the relevant notification in accordance with our applicable obligations.

15COOKIES AND SIMILAR TECHNOLOGIES

14.1 What cookies are

Cookies and similar technologies are small files, identifiers or technologies that may be stored or accessed when you visit a website or use an online service.

We may use cookies or similar technologies on our website and Platform.

14.2 Types of cookies and technologies we may use

Strictly necessary technologies

These may be required to:

  • operate our website or Platform;
  • maintain sessions;
  • authenticate users;
  • protect accounts;
  • prevent fraud;
  • maintain security; and
  • provide functionality requested by the user.

Disabling necessary technologies may prevent parts of the website or Platform from operating correctly.

Functional technologies

These may be used to:

  • remember preferences;
  • remember settings;
  • improve navigation; and
  • provide requested functionality.

Analytics and performance technologies

These may help us understand:

  • website or Platform usage;
  • performance;
  • errors;
  • page interactions;
  • feature usage; and
  • technical issues.

We may use this information to improve reliability, security and user experience.

14.3 Cookie choices

Depending on the technologies used and Applicable Law, you may be able to manage cookies through:

  • your browser settings;
  • device settings;
  • a cookie preference tool made available by EXICASH; or
  • other controls made available on the website.

Blocking certain cookies may affect website or Platform functionality.

Where consent is required for a particular technology, we will seek such consent in accordance with Applicable Law.

16DIRECT MARKETING AND COMMUNICATION PREFERENCES

You may ask us to stop using your Personal Data for direct marketing purposes.

Where marketing communications are sent electronically, we may provide an unsubscribe mechanism or other method for changing your marketing preferences.

You may also contact EXICASH using the contact details in this Privacy Policy to request that we cease direct marketing communications.

Opting out of marketing communications does not prevent us from sending communications that are necessary for:

  • your Merchant Account;
  • Transactions;
  • security;
  • compliance;
  • legal notices;
  • service operation;
  • Payment Partner requirements; or
  • our contractual relationship with a Merchant.

17FRAUD, RISK ANALYSIS AND AUTOMATED TOOLS

Due to the nature of payment services, EXICASH and its Payment Partners may use technological tools to identify fraud, security threats, suspicious activity or other risks.

Such tools may analyse information including:

  • Transaction patterns;
  • Transaction amounts;
  • account activity;
  • device information;
  • technical signals;
  • previous activity;
  • risk indicators; and
  • other relevant information.

The output of such systems may result in:

  • additional verification;
  • manual review;
  • Transaction delay;
  • Transaction rejection;
  • reduced limits;
  • restriction of a payment method;
  • security measures; or
  • temporary account restrictions.

Where Applicable Law gives you rights concerning automated decision-making or profiling, those rights will apply in accordance with Applicable Law.

18YOUR PERSONAL DATA RIGHTS

Subject to Applicable Law and any applicable limitations or exemptions, you may have rights concerning Personal Data held by EXICASH.

These may include the following.

17.1 Right to be informed

You may have the right to receive information concerning:

  • whether your Personal Data is being processed;
  • the purposes for which it is processed;
  • the sources from which it is obtained; and
  • the categories of persons to whom it may be disclosed.

This Privacy Policy is intended to provide information concerning our general processing activities.

17.2 Right of access

You may request access to Personal Data held by EXICASH concerning you, subject to Applicable Law.

We may require sufficient information to verify your identity before processing an access request.

17.3 Right of correction

If Personal Data held by us is inaccurate, incomplete, misleading or not current, you may request correction in accordance with Applicable Law.

17.4 Withdrawal of consent

Where our processing is based on your consent, you may withdraw your consent in accordance with Applicable Law.

Withdrawal does not necessarily affect processing already lawfully carried out before the withdrawal.

It may also affect our ability to provide a Service where the relevant Personal Data is necessary for that Service.

17.5 Prevention of processing likely to cause damage or distress

Where provided by Applicable Law, you may request that certain processing be stopped or restricted where the applicable legal conditions are satisfied.

17.6 Direct marketing

You may request that EXICASH cease processing your Personal Data for direct marketing purposes.

17.7 Data portability

Where a right to data portability applies under Applicable Law, you may request the transfer or provision of applicable Personal Data subject to the conditions, limitations and technical requirements prescribed by law.

17.8 Automated decision-making

Where Applicable Law provides rights concerning decisions based solely or materially on automated processing, you may exercise those rights subject to applicable conditions and exceptions.

17.9 Other rights

You may have additional rights as Applicable Law develops or applies to a particular processing activity.

19HOW TO EXERCISE YOUR RIGHTS

Requests concerning Personal Data may be submitted to EXICASH in writing.

Please provide sufficient information for us to:

  • identify you;
  • understand your request;
  • identify the relevant Personal Data; and
  • verify that you are entitled to make the request.

You may send privacy-related requests to:

Privacy / Data Protection
EXICASH SDN. BHD.
16-19, Menara Mutiara Sentral
No. 2, Jalan Desa Aman 1
Cheras Business Centre
56000 Kuala Lumpur
Malaysia

You may also use any designated privacy contact method made available on our website or Platform.

Where EXICASH is required to appoint a Data Protection Officer under Applicable Law, the relevant business contact details may also be made available through our website or Platform.

We may request identity verification before acting on a request in order to protect Personal Data against unauthorised disclosure.

Certain requests may be subject to restrictions, exceptions, procedures, fees or time periods permitted by Applicable Law.

20REQUESTS RELATING TO A MERCHANT

If you are a Customer, Beneficiary or other individual whose Personal Data was submitted to EXICASH by a Merchant, the Merchant may be the Data Controller responsible for certain processing activities.

If your request relates primarily to the Merchant’s collection or use of your Personal Data, you should contact the Merchant directly.

Where appropriate, EXICASH may:

  • refer your request to the Merchant;
  • inform you that the Merchant is the appropriate contact; or
  • assist the Merchant in responding to your request where required under our Data Processing Policy or Applicable Law.

21ACCURACY OF PERSONAL DATA

We rely on individuals, Merchants, Payment Partners and other authorised sources to provide accurate information.

You should ensure that Personal Data you provide to EXICASH is:

  • accurate;
  • complete;
  • not misleading; and
  • kept reasonably current.

Merchants are responsible for updating information maintained in their Merchant Profile.

If you believe information concerning you is incorrect, you may contact us to request correction where applicable.

22PERSONAL DATA RELATING TO OTHER PEOPLE

If you provide Personal Data concerning another person to EXICASH—for example a director, beneficial owner, employee, Authorised User, Beneficiary or business contact—you confirm that you are authorised to provide the information and that you have complied with applicable notice, consent or other legal requirements relating to that disclosure.

Where appropriate, you should make this Privacy Policy available to that individual.

23THIRD-PARTY WEBSITES AND SERVICES

Our website or Platform may contain links to third-party websites, applications or services.

This Privacy Policy does not govern the independent privacy practices of third parties that EXICASH does not control.

You should review the privacy notices of the relevant third party before providing Personal Data to it.

24BUSINESS TRANSFERS AND CORPORATE CHANGES

If EXICASH is involved in a:

  • merger;
  • acquisition;
  • restructuring;
  • reorganisation;
  • financing;
  • sale;
  • transfer of assets;
  • transfer of business; or
  • similar corporate transaction,

Personal Data may be disclosed or transferred as part of that transaction, subject to Applicable Law and appropriate confidentiality or data-protection requirements.

25AGGREGATED AND ANONYMISED INFORMATION

We may aggregate, de-identify or anonymise information so that it no longer identifies an individual and no longer constitutes Personal Data under Applicable Law.

We may use such information for purposes including:

  • analytics;
  • statistical analysis;
  • fraud analysis;
  • security;
  • Platform improvement;
  • operational reporting;
  • capacity planning;
  • research relating to our Services; and
  • development of new functionality.

We will not intentionally attempt to re-identify properly anonymised information except where permitted or required for security, testing or legal purposes and in accordance with Applicable Law.

26CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect changes in:

  • our Services;
  • our Platform;
  • our processing activities;
  • our Payment Partners or service providers;
  • Applicable Law;
  • regulatory requirements;
  • security practices; or
  • our business operations.

When we update this Privacy Policy, we will revise the “Last Updated” date at the top of the document.

Where a change materially affects how we process Personal Data, we may provide additional notice where reasonably appropriate or required by Applicable Law.

The version made available through our website or Platform will be the current published version.

27APPLICABLE LAW

This Privacy Policy is intended to be read consistently with the Personal Data Protection Act 2010 of Malaysia, as amended from time to time, and other Applicable Law relating to Personal Data.

Where Applicable Law provides a right, obligation or protection that differs from this Privacy Policy, the applicable legal requirement will prevail to the extent required by law.

28CONTACT US

If you have questions, concerns or requests concerning this Privacy Policy or EXICASH’s processing of Personal Data, you may contact:

EXICASH SDN. BHD.
Attn: Privacy / Data Protection
Registration No. 202601015752 (1677849-M)
16-19, Menara Mutiara Sentral
No. 2, Jalan Desa Aman 1
Cheras Business Centre
56000 Kuala Lumpur
Malaysia

You may also contact us through the designated privacy or support channel made available on the EXICASH website or Platform.

29COMPLAINTS

If you have concerns about how EXICASH processes your Personal Data, we encourage you to contact us first so that we can review and respond to your concern.

You may also have the right to make a complaint to the competent personal data protection authority in accordance with Applicable Law.

Powering smarter
payment operations.

Certified by:PCI DSS Compliant All rights reserved. Copyright © 2026 EXICASH SDN BHD 202601015752 (1677849-M)
Exicash
Privacy PolicyTerms of ServiceData Processing