Version 1.0 — effective [ ] 2026. This notice is issued under section 7 of the Personal Data Protection Act 2010 (Malaysia).
1. Who is responsible for your data
Beyside Sdn. Bhd. (registration no. 202501027740 (1629152-A)), RA-22-2 & RA-22-4, Lot Kedai Almas, Persiaran Laksamana, Puteri Harbour, 79250 Iskandar Puteri, Johor, Malaysia, is the data controller for Beysider. Privacy questions and requests go to beysidemy@gmail.com. We have not yet appointed a Data Protection Officer; when we do, their name and contact will be listed here.
Section 7(3) of the PDPA requires this notice to be given in both Bahasa Malaysia and English, so a Bahasa Malaysia version is published at beysider.com/privasi. The English version prevails if they differ. The Terms of Service are in English only.
2. What we collect and why
We collect only what each feature needs. Nothing from your Google account beyond a verification token and its stable account ID is copied into Beysider.
| Data | Where it comes from | Why we use it | PDPA / GDPR basis |
|---|---|---|---|
| Google account ID and sign-in token | Google sign-in | To sign you in and prevent duplicate accounts | Contract (providing the Service) |
| Email address for notices | Google sign-in, stored separately from your profile | Account, safety and legal notices; never shown to other users | Contract; legal obligation |
| Blader Name, avatar, clan, status line, home area | You | Your public profile and map pin | Contract; your choice to publish |
| Date of birth (month and year) and, if under 18, guardian email | You | Age gating, guardian consent, disabling photos for minors | Legal obligation; consent |
| WhatsApp phone number, with its country code | You | Shown to a blader only after you both accept a practice, duel or trade, so you can coordinate on WhatsApp; never shown on your profile or anywhere else | Performance of the service you asked for (connecting you with the blader you agreed to meet) |
| Location while present | Your device, only when you tap to go on the map | Your pin, the 10 km list, the 100 m handshake check | Consent, withdrawable by going off the map |
| Practice, duel, rating, tournament and trade records | Your activity | Running the features, caps and cool-downs, League standings, dispute handling | Contract; legitimate interest in fair play |
| Session photos and duel evidence photos | You, with camera or upload | Share cards; verifying disputed results | Consent; legitimate interest |
| Reports you make or that are made about you | Users | Moderation and safety | Legitimate interest; legal obligation |
| Device, browser, IP address, push subscription, error logs | Your device automatically | Security, keeping the app working, sending notifications you asked for | Legitimate interest; consent for push |
| Terms version and time of acceptance | You | Proof of agreement | Legal obligation |
We do not collect sensitive personal data as defined in the PDPA (health, religion, political opinions, biometric data or criminal record). A face in a photo is stored as an image only and is never processed to identify anyone. We do not sell personal data, show advertising or use your data to train models.
3. Automated decisions
The app applies rules automatically: invite expiry, caps, cool-downs, the 24-hour pause after three cancellations, the profanity filter and the auto-confirmation of duel results. These affect only what you can do inside the Service, and every one of them can be reviewed by a human admin if you email us. No automated decision has a legal or similarly significant effect on you.
4. Location data
Your location is read from your browser only when you tap to go on the map, and only for as long as you stay on it. While present, other signed-in bladers see your pin at your current position and your distance from them; if you are under 18, your pin is shown at reduced precision and your exact position is sent only to your guardian. Nobody who is not signed in sees any player. When you go off the map, or presence expires, your live location is removed. We keep a coarse record (the area, not coordinates) of where practice sessions, duels and tournament check-ins happened, because caps, the 100 m handshake and dispute handling depend on it.
We never read your location in the background, and we do not build movement histories.
5. Children and guardians
Bladers under 18 give a guardian email at sign-up. We email the guardian to explain the map, presence and location features, with a one-tap link to confirm they are the guardian (confirmation is not required for the account to work), and then keep them informed automatically: each time the minor sends or accepts a practice, duel or trade invite, or accepts a friend request, the guardian receives an email with the kind of invite, the other blader's Blader Name, clan, rating and profile link, the time, and the minor's exact GPS position at that moment as a map link (or a note that location was unavailable). The minor is told on the invite screen that this email is sent. We also email the guardian if the account is reported, suspended or closed. Guardians can see what data we hold about the child, correct it, or ask for the account to be closed, by writing to beysidemy@gmail.com. We do not knowingly allow anyone under 13 to use the Service; if we learn that we have, we delete the account and its data.
For under-18 accounts the optional social photos on practice sessions and duels are disabled. The private duel evidence photo (section 2) is still taken for every League duel, including a minor's; it is seen only by the two bladers and Beyside staff, is never shown on a profile, log or share card, and is deleted after 90 days.
6. How long we keep data
| Data | Kept for |
|---|---|
| Live location | Until you go off the map, at most a few hours |
| Session photos | 7 days after the session, then deleted from storage |
| Duel evidence photos | 90 days after the duel, then deleted |
| Rejected status lines and names (profanity filter) | Not stored |
| Practice, duel, rating and tournament records | While your account is open; anonymised (Blader Name replaced by "Deleted blader") when the account is deleted after the 30-day undo window, so the other player's history and League tables stay intact |
| Reports and moderation notes | 24 months, or longer while a dispute or legal matter is open |
| Released Blader Names | 30-day hold, then free |
| Account, email, guardian email, terms acceptance | While the account is open, then 30 days for you to change your mind, then deleted |
| Server and security logs | 30 days |
| Backups | Rolling, overwritten within 30 days |
Counts that other bladers rely on, such as how many duels a pair has had this month, are kept as numbers only after the underlying records are anonymised.
7. Who we share data with
We share personal data only with the providers that run the Service, each acting on our instructions under a written contract, and only the data they need:
| Provider | What they process | Where |
|---|---|---|
| Supabase (database, file storage, real-time, authentication) | All account and activity data, photos | Singapore region |
| Netlify (hosting, serverless functions) | Requests to the app, IP addresses, logs | Singapore functions region; global edge network for static files |
| Google (sign-in) | Your Google account ID at sign-in | Google's global infrastructure, under Google's own privacy policy |
| Resend (email) | Your email or guardian email and the content of notices | United States |
| Web Push providers (Google, Apple, Mozilla, depending on your device) | An anonymous push token and notification text | Provider's infrastructure |
| OpenFreeMap (map tiles) | Your IP address and the map area you view; no account data | Europe |
Other users see what your profile and activity show them: Blader Name, avatar, clan, status, pin while present, practice and duel history with them, League standing, listings, and your WhatsApp contact only after a mutual acceptance. A clan's or gym's WhatsApp group invite link is shown only to that clan's members or that gym's regulars, and a tournament's or group practice's link only to signed-in players; Beysider never posts in those groups and holds no copy of what is said there.
Reports, duel evidence photos and moderation tools are seen by Beyside Sdn. Bhd. staff only; we do not use volunteer moderators. Beysider data is kept separate from the Beyside store's membership and loyalty records. If we ever decide to link them, we will update this notice, explain what is shared and why, and ask for your consent before doing so.
We disclose data to the police, courts or regulators when the law requires it or to protect someone's safety, and to a successor operator if the Service changes hands, on notice to you. We do not share data with advertisers or data brokers.
8. Transfers outside Malaysia
Our database and files are hosted in Singapore, and emails are sent through a provider in the United States. The PDPA (as amended in 2024) allows transfers to a country with substantially similar protection, or where we have taken reasonable precautions such as contractual clauses, or where the transfer is needed to perform our contract with you. Singapore's Personal Data Protection Act 2012 offers comparable protection, and each provider signs a data processing agreement with security and confidentiality terms. By using the Service you also consent to these transfers as described here. You can ask us for a copy of the safeguards.
9. Security
Data is encrypted in transit (TLS) and at rest. Access to the database is restricted by row-level security so that each blader can only read what the app is meant to show them; admins have logged, role-based access. Photos are stored in private buckets and served through short-lived links. We keep the amount of data we hold small, and we delete on the schedule in section 6.
If a breach is likely to cause you significant harm, we will notify the Personal Data Protection Commissioner within 72 hours of discovering it and notify you within 7 days after that, as the PDPA requires, and we will tell you what happened and what to do.
10. Your rights
Under the PDPA, and under similar laws elsewhere, you can:
- Access the personal data we hold about you. Settings gives you a download of your profile, records and photos; or email us.
- Correct anything inaccurate. Your profile fields are editable in the app.
- Withdraw consent for optional processing: go off the map, remove your WhatsApp contact, delete a photo you uploaded, or turn off push notifications in Settings.
- Object to or limit processing, including for direct marketing (we do none).
- Port your data to another service in a machine-readable form, where technically feasible.
- Close your account and have your data deleted on the schedule in section 6.
- Complain to us first at beysidemy@gmail.com; we answer within 21 days, the PDPA's statutory period. You may also complain to the Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi, pdp.gov.my), or to your local data protection authority if you live outside Malaysia.
We may need to verify that a request comes from you or, for a minor, from the registered guardian. We do not charge for requests unless the PDPA permits a fee for access requests, and we will tell you before charging.
11. Cookies, local storage and notifications
Beysider uses no advertising or analytics cookies. It stores a sign-in session cookie (needed to keep you signed in), and uses your browser's local storage and cache for the map tiles, the last screen you were on, and the installed-app shell so the Service works offline. Push notifications are sent only after you allow them in your browser; you can turn them off in Settings or your browser at any time. Because there are no non-essential cookies, no cookie banner is shown.
12. Changes to this notice
We update this notice when our practices change. Material changes are announced in the app at least 14 days in advance and you are asked to accept the new version on your next visit. The version number and date at the top tell you which version applies.