Last updated: 14 August 2026
For customers in Malaysia / Untuk pelanggan di Malaysia: This Personal Data Protection Notice is also available in Bahasa Malaysia — Baca dalam Bahasa Malaysia. Notis Perlindungan Data Peribadi ini juga tersedia dalam Bahasa Malaysia. Where there is any inconsistency between the two versions, the English version prevails.
This Policy is issued by:
Together, “Smartstripe”, “we”, “us” or “the Company”. Each company is responsible only for the personal data it controls.
Where a business customer engages us to personalise cards and supplies us with cardholder details, we act as a data processor (data intermediary) for that customer. We handle those details on their instructions, and their own privacy notice — not this one — governs how that data may be used. Section 4 explains what we do with it.
This Policy is intended to comply with Singapore’s Personal Data Protection Act 2012 (“PDPA Singapore”) and Malaysia’s Personal Data Protection Act 2010 as amended by the Personal Data Protection (Amendment) Act 2024 (“PDPA Malaysia”).
This Policy describes our general practices. It does not form part of any contract between us and any person, and it does not create any right or entitlement beyond those conferred by applicable law.
This Policy applies to personal data we collect through our websites at smartstripe.com, smartstripe.com.sg and smartstripe.com.my (the “Site”) and through our other business channels — enquiries and quotations by email, telephone or messaging app, purchase orders and account forms, trade shows and exhibitions, site visits, and artwork or data files sent to us for production.
It does not cover our employees or job applicants, who are dealt with separately.
Enquiry and contact data. Your name, company name, job title, business address, telephone number and email address, and the content of your enquiry or quotation request.
Customer and order data. Billing and delivery addresses, purchase order and invoice records, delivery contact details, bank transfer references, and correspondence about your orders.
Newsletter data. Your email address if you subscribe through our Site, together with the date you subscribed and a record of any later withdrawal.
Technical and Site usage data. Browser type, device type, IP address, referring page and pages visited. Where this can be linked to you it is treated as personal data; otherwise it is used in aggregate to understand how the Site performs.
Payments. We do not take payments through the Site. Orders are invoiced and settled by bank transfer, and we do not collect or store payment card numbers from you.
Identity numbers. We do not routinely collect NRIC, FIN, MyKad or passport numbers. Where a particular job or a legal requirement makes it necessary, we collect only what is required for that purpose. We do not use any national identification number as a login or authentication credential.
You are responsible for the accuracy and completeness of the information you give us, and for ensuring you are entitled to provide any information relating to another person.
Where an organisation engages us to personalise cards, it sends us a file containing details of the individuals who will hold those cards. That file typically contains cardholder names and reference numbers, and may contain photographs and, in some cases, dates of birth.
We do not collect these details from cardholders directly — they reach us from the employer, school or other organisation placing the order. That organisation is responsible for establishing a lawful basis for the processing and for obtaining any consent the law requires, including the explicit consent needed under the PDPA Malaysia where the data is sensitive personal data. We rely on that organisation’s instructions and on its confirmation that it is entitled to provide the data to us.
Our handling of those files is deliberately narrow:
Because we do not retain these files, a reprint requires the organisation to send the file to us again.
We obtain personal data directly from you when you complete a form on the Site, contact us by email or telephone, subscribe to our newsletter, place an order or meet us at an event; from the organisation you represent, where it places an order or supplies a cardholder file; from your device, through cookies and server logs; and occasionally from publicly available business sources when verifying business contact details.
Giving us your personal data is voluntary, but some of it is necessary for us to act:
We use personal data for the purposes for which it was given, and for related purposes, namely to:
In most cases we rely on your consent, given when you submit your data for a stated purpose. We may also process personal data where an exception under the applicable PDPA applies — for example where processing is necessary to perform a contract with you, to recover a debt, or to comply with the law.
We do not sell your personal data.
You may withdraw your consent to any or all of our uses of your personal data at any time by contacting our Data Protection Officer (section 19). We will give effect to your request within the period required by the applicable PDPA.
Please note the consequence: if you withdraw consent to our using your data to fulfil orders, we will not be able to continue supplying goods or services to you, and any open orders may have to be cancelled. Withdrawal does not affect the lawfulness of processing carried out before it took effect, and does not require us to delete records we are entitled or required to retain (section 12).
We disclose personal data where it is needed for the purposes in section 7, to the following classes of recipient:
We require our service providers, by written terms, to handle personal data only as instructed, to keep it secure, to notify us of any breach, and to return or delete it when their engagement ends.
We operate in Singapore and Malaysia, and personal data moves between our two companies as needed to handle orders and support customers.
Some of our service providers store or process data outside these two countries. In particular, our website host operates servers in the United States, so data submitted through forms on the Site is processed there.
Before personal data leaves Singapore, we take reasonable steps to satisfy ourselves that the recipient is bound to a standard of protection at least comparable to that required under the PDPA Singapore, normally through contractual terms.
Before personal data leaves Malaysia, we take reasonable steps to assess whether the destination has in force a law substantially similar to the PDPA Malaysia or otherwise ensures an adequate level of protection, having regard to the applicable guidelines on cross-border personal data transfer. Where neither applies, we transfer only on another basis permitted by section 129 of the PDPA Malaysia, including your consent.
We send newsletters and product updates to people who have subscribed. Marketing emails include a means to unsubscribe, and you may also opt out at any time by contacting our Data Protection Officer. We give effect to opt-out requests within a reasonable period.
We do not currently carry out telemarketing. If that changes, we will check Singapore telephone numbers against the Do Not Call Registry as required by the PDPA Singapore before sending specified marketing messages.
If you are in Malaysia, section 43 of the PDPA Malaysia entitles you to require us in writing at any time to stop, or not to begin, using your personal data for direct marketing.
We keep personal data for as long as it serves the purpose it was collected for, or as long as the law permits or requires. The periods below are indicative rather than fixed, and we may retain personal data for longer where necessary to comply with a legal or regulatory obligation, or to establish, exercise or defend legal claims.
| Data | Indicative period |
|---|---|
| Enquiries that do not result in an order | Around 24 months from last contact |
| Customer and order records, invoices | Not less than 5 years (Singapore) and 7 years (Malaysia) from the end of the financial year, to meet accounting and tax obligations |
| Cardholder files supplied for personalisation | Deleted on completion of the job, and in any event within 7 days of delivery, subject to section 4 |
| Newsletter subscriber records | Until you unsubscribe, and thereafter for a period sufficient to evidence the withdrawal |
| Website server logs | Around 12 months |
When personal data is no longer needed we take reasonable steps to delete it, or to anonymise it so that it no longer identifies you.
We take reasonable technical and organisational measures, appropriate to the nature of the data and the harm that might result from its compromise, to protect personal data against loss, misuse, and unauthorised or accidental access, disclosure, alteration or destruction. These measures are reviewed from time to time and may change.
We also take reasonable steps to keep personal data accurate and complete where we use it to make a decision affecting you. Please tell us if your details change.
No transmission over the internet or method of electronic storage is completely secure. While we take the measures described above, we do not warrant or guarantee the security of any personal data transmitted to or held by us, and any transmission is made at your own risk. To the fullest extent permitted by law, we are not liable for any loss or damage arising from unauthorised access to, or loss, misuse or alteration of, personal data occurring despite our having taken reasonable measures, or from any act or omission of a third party.
We maintain internal procedures for assessing and responding to personal data breaches and keep records of them. Where a breach is notifiable, we will notify the Personal Data Protection Commission (Singapore) or the Personal Data Protection Commissioner (Malaysia), and where required affected individuals, in accordance with the requirements and timeframes set out in the applicable PDPA.
Subject to and in accordance with the applicable law, you may:
To make a request, contact our Data Protection Officer using the details below. We will verify your identity before responding and may require further information to locate the data. We will respond within the period required by the applicable PDPA, and where a fee is permitted we will notify you of it before proceeding.
We may refuse or limit a request where the applicable law permits or requires us to do so — including where responding would reveal personal data about another person, breach a legal obligation or duty of confidence, or where the request is manifestly unreasonable or repetitive. Where we refuse, we will tell you so far as we are permitted.
Our Site and services are directed at businesses, not children. We do not knowingly collect personal data from a child in Singapore under 13 without parental consent. In Malaysia, where an individual is under 18, consent must be given by a parent or legal guardian. We rely on the information provided to us as to age and authority. If you believe we hold a child’s personal data without the necessary consent, contact our Data Protection Officer and we will take reasonable steps to delete it.
Our websites are hosted on Webflow and use a small number of cookies.
Essential cookies are necessary for the Site to function — for example to handle form submissions and guard against spam — and cannot be switched off.
We do not currently use analytics, advertising, remarketing or cross-site tracking cookies. If we introduce any, they will be set only with your consent through a cookie banner, and you will be able to change your choice at any time.
You can manage or block cookies through your browser settings, though parts of the Site may not function properly if you do.
The Site contains links to other websites, including social media platforms. Those sites are not under our control. We are not responsible for their privacy practices, security or content, this Policy does not apply to them, and we accept no liability in respect of them. Please read the privacy notice of any site you visit through a link from ours.
Our Data Protection Officer is:
Kai Rei, Operations
Email: kairei@smartstripe.com
Or write to us through our contact page.
Please contact the Data Protection Officer with any question about this Policy, to exercise your rights, or to make a complaint. We will acknowledge and respond to complaints as soon as reasonably practicable.
If you are not satisfied with our response, you may complain to the relevant regulator:
We may update this Policy from time to time to reflect legal, technological or operational developments. The “Last updated” date above shows when it was last revised. Where a change materially affects how we use personal data you have already given us, we will take reasonable steps to bring the change to your attention and, where the law requires, obtain your consent before applying it. Otherwise, the version published on the Site applies from the date it is posted.
This Policy does not form part of any contract and does not confer any right or remedy beyond those provided by applicable law. Nothing in it limits or excludes any liability that cannot lawfully be limited or excluded, and nothing in it is intended to reduce your statutory rights under the PDPA Singapore or the PDPA Malaysia.
If any provision of this Policy is found to be unenforceable, the remaining provisions continue in effect.
This Policy, and any dispute arising out of or in connection with it, is governed by the law of Singapore where the relevant data controller is Smartstripe Marketing Pte Ltd, and by the law of Malaysia where the relevant data controller is Smartstripe Marketing Sdn Bhd, and the courts of that country have jurisdiction, without prejudice to any right you have to complain to a regulator.