Privacy Policy

Last updated: 25 August 2026

Syok2Pay is a payment platform operated by Zenova (“we”, “us”, “our”). This policy explains what personal data we collect, why we collect it, and how we handle it when you use syok2pay.com, our merchant portals, our hosted checkout, and our APIs (together, the “Services”). We process personal data in accordance with the Malaysian Personal Data Protection Act 2010 (PDPA).

Data we collect

  • Merchant account data — business name, registration details, contact person, email address, phone number, and settlement bank account details provided during onboarding.
  • Transaction data — payment amount, currency, payment method, order reference, transaction status, and timestamps for payments processed through the platform.
  • Customer checkout data — information a paying customer submits on our hosted checkout (such as the payment method selected). Card data is handled by PCI DSS compliant payment gateways and card networks; we do not store full card numbers on our servers.
  • Technical data — IP address, device and browser information, and security logs collected automatically to operate and protect the Services.

How we use data

  • To provide the Services: processing payments, settling funds to merchants, and generating reports.
  • To send transactional communications, such as payment receipts, transaction notifications, account and security emails (e.g. password resets). These are operational messages, not marketing.
  • To meet legal and regulatory obligations, including anti-money-laundering (AML) checks, fraud prevention, and record-keeping requirements.
  • To secure the platform: monitoring, logging, and investigating suspicious activity.

Sharing

We share data only where necessary to deliver the Services: with banks, card networks, e-wallet providers and payment gateways involved in processing a transaction; with infrastructure providers (such as cloud hosting and email delivery) acting on our instructions; and with regulators or law enforcement where required by law. We do not sell personal data.

Retention & security

Transaction records are retained for as long as required by Malaysian law and financial regulations, after which they are deleted or anonymised. Data is encrypted in transit and at rest, access is role-based and logged, and our infrastructure follows PCI DSS aligned practices.

Your rights

Under the PDPA you may request access to, or correction of, your personal data, and you may withdraw consent to processing that is not required to complete a payment or meet a legal obligation. To exercise these rights, contact us at admin@syok2pay.com.

Contact

Questions about this policy or our data practices can be sent to admin@syok2pay.com. We may update this policy from time to time; the latest version will always be available on this page.