Legal

Privacy Policy

Last updated: 3 September 2026

APRide is operated by DUOCODE TECHNOLOGY, a business registered in Malaysia under registration number LA0087244-A, which is the data user for everything described here. This policy explains what personal data we process and why, in line with the Personal Data Protection Act 2010 (Act 709).

This notice is also published in Bahasa Malaysia at Notis Privasi (Bahasa Malaysia). If the two versions conflict, the English version prevails. Notis ini turut diterbitkan dalam Bahasa Malaysia. Sekiranya terdapat percanggahan antara kedua-dua versi, versi Bahasa Inggeris yang terpakai.

01

What we collect

  • APU email address — used to verify you belong to the APU community and to sign you in.
  • TP number and display name — shown (TP partially masked) so matches know who they are riding with.
  • Microsoft Teams contact — shared with matched users so you can coordinate off-platform.
  • Ride posts — route, date/time, seats, and notes you choose to publish.
  • Premium subscription status — plan and billing state mirrored from Stripe.
  • Safety reports — the reason you pick and the note you write about another member of a ride you were both on, stored with your account, the reported member's account, and the ride concerned.
  • Contact form messages — the name, email address, subject, and message you send us through the contact form.
02

Where it lives

Your account, ride, and safety-report data is stored in Supabase (managed Postgres) and served through Vercel. Payments for Premium are processed by Stripe — your card number never touches APRide servers; we only keep a customer reference and subscription state. Transactional email, contact form messages, and the alert that tells us a safety report was filed are all sent through Zoho Mail; a contact form message reaches us as email only and is not written to the database.

03

Analytics

Every page — including before you sign in — loads Umami, so we can see which parts of APRide get used. It records page views, interactions, and a region approximated from your IP address. It sets no cookie and assigns you no identifier that persists between days. Our Umami instance is self-hosted on a DUOCODE TECHNOLOGY server at fluentdojo.com, so those page views leave APRide's own domain. None of it is used for advertising, and APRide shows no ads.

APRide used to load Google Analytics 4 alongside Umami, which set a _gaidentifier cookie. That was removed in August 2026 and nothing here loads it any more.

04

How we use it

  • To match ride posts and display them to other verified APU users.
  • To operate your account, sign-in emails, and Premium entitlements.
  • To respond when you contact us.
  • We do not sell your personal data, and we do not use it for third-party advertising.
05

Sharing

Ride posts (including your display name, masked TP number, and — once matched — your Teams contact) are visible to other verified users as part of how the board works. Beyond that, data is shared only with the processors named above (Supabase, Vercel, Stripe, and Zoho) to run the service, or where the law requires disclosure. The analytics in section 3 runs on a server DUOCODE TECHNOLOGY operates itself, so no analytics company receives it.

06

Retention and deletion

We keep your data while your account is active. APRide and its user accounts are operated by DUOCODE TECHNOLOGY (registration number LA0087244-A, Malaysia), the data user for everything described here.

How to ask. Email contact@apride.net from your registered APU address with the subject “Delete my account”, or send the same request through the contact form. Sending from the registered address is how we verify it is you; we confirm by reply and complete the deletion within 30 days. You can also use the same address to ask for a copy of your data or a correction instead of deletion.

What gets deleted. Your sign-in account and everything in section 1 that identifies you:

  • Your profile — APU email, TP number, display name, and Microsoft Teams contact.
  • Ride posts you created, including their routes, times, and notes.
  • Your seats on rides other people created, and your ride history.
  • Any active Premium subscription, which we cancel at Stripe so you are not charged again.

What we keep, and for how long. Billing records — invoices, payment references, and the Stripe customer record — are retained for seven years, because Malaysian tax and accounting law requires it. Safety reports filed about a deleted account are kept with the identifiers stripped (no email, no TP number) where we still need the record to keep the board safe for everyone else. Analytics events in section 3 are never linked to your account, so nothing there identifies you after deletion. Residual copies in routine encrypted database backups age out within 30 days of the deletion.

Deletion is permanent — we cannot restore an account or its ride history afterwards.

07

Your PDPA rights

Under the PDPA you may request access to and correction of your personal data, and withdraw consent to processing (which may mean we can no longer provide the service). We answer these requests via the contact below.

Questions? Email contact@apride.net or use the contact form.