1 Who We Are
Quantum Web Studio ("we", "us", "the Platform") is a Malaysian company that builds and hosts websites and online storefronts for small and medium businesses. Our customers — referred to in this policy as merchants — are independent businesses. Each merchant gets a storefront website that we host, plus a self-service dashboard where they manage their own shop details, products, and connected accounts.
This policy explains what we collect from merchants who use the Platform, and from visitors who browse the storefront websites we host. It is written to comply with the Personal Data Protection Act 2010 (PDPA) of Malaysia.
2 Information We Collect
From merchants. Business name, address, contact number and email, login credentials, and the content they choose to publish on their own storefront — product listings, photos, prices, and business hours.
From storefront visitors. Basic technical information such as IP address, browser type and pages viewed, used to keep the site running and to give the merchant aggregate traffic counts. If a visitor places an order or submits an enquiry form, we process the details they enter so the merchant can fulfil that request.
From connected accounts. When a merchant chooses to connect a third-party account — for example TikTok, Facebook, Instagram, or Google — we receive only the data that platform releases under the permissions the merchant granted. See section 4.
3 How We Use Information
We use the information above to host and operate each merchant's storefront, to display the content a merchant has chosen to publish, to process orders and enquiries on the merchant's behalf, to provide support, and to keep the Platform secure. We do not sell personal data, and we do not use merchant content to train machine-learning models or to advertise to third parties.
4 Connected Social Accounts
Connecting a social account is entirely optional and is always initiated by the merchant from inside their own dashboard. We never ask a merchant for their social account password. Authorisation happens on the provider's own login screen, and the merchant chooses which permissions to grant.
TikTok. If a merchant connects their TikTok account, we use the TikTok API as follows:
- What we access — the merchant's basic profile (display name, avatar, and where granted, profile link and follower count), and the list of the merchant's own videos, including title, cover image, embed link and public engagement counts.
- What we do with it — we display it in a "Videos" section on that merchant's own storefront website, so visitors can see the business's recent TikTok content without leaving the page. Where a merchant has also granted publishing permission, we post content the merchant themselves submits through their dashboard.
- What we never do — we do not access accounts that have not authorised us, we do not read private messages, we do not download or re-host video files, and we do not combine one merchant's TikTok data with another merchant's.
- Disconnecting — a merchant can disconnect at any time from the same dashboard. This revokes our access token and immediately removes the Videos section from their storefront. The merchant may also revoke access from their TikTok account settings.
Our use of information received from TikTok APIs adheres to the TikTok Developer Terms of Service, and any data received is used only for the purposes described above.
5 Merchant Responsibility
Each merchant is the controller of the customer information collected through their own storefront. Merchants are responsible for handling their customers' data lawfully, for the accuracy of what they publish, and for holding the rights to any content they upload or connect. We act as a processor on their instructions.
6 Storage & Third-Party Services
Data is stored on infrastructure operated by established providers, including Cloudflare (hosting and content delivery) and Supabase (database and application backend). Access tokens for connected accounts are stored encrypted and are readable only by the service processes that need them. We keep data within reputable data centres and apply access controls, encryption in transit, and regular backups.
7 Retention
We keep merchant account data for as long as the merchant maintains an active account with us. Data pulled from a connected social account is cached only to render the storefront and is refreshed or discarded when the merchant disconnects. On account closure, we delete or anonymise personal data within 90 days, except where a longer period is required by law.
8 Your Rights (PDPA 2010)
You have the right to access the personal data we hold about you, to correct it if it is inaccurate, to withdraw consent for optional processing, and to request deletion. Write to us at the address in section 11 and we will respond within 21 days.
9 Children's Privacy
The Platform is intended for business use and is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
10 Changes to This Policy
We may update this policy as the Platform develops. Material changes will be announced in the merchant dashboard and the effective date at the top of this page will be revised.
11 Contact Us
Quantum Web Studio
Kelantan, Malaysia
Email: [email protected]