Privacy Policy
Last updated: 9 May 2026
Antlerzone ("we", "us", "our") operates AntlerPlatform, the homestay operations and channel management portal (the "Service"). This Privacy Policy explains how we collect, use, store, and share personal data when you use the Service. Business time context for operational dates is treated consistently with Malaysia (UTC+8 / Asia/Kuala_Lumpur) unless we state otherwise in product settings.
1. Who this applies to
This policy applies to operators, staff, and other users who sign in to the portal, and to guest or booking-related data processed through the Service on behalf of operators.
2. Data we may collect
Depending on how you use the Service, we may process:
- Account data: name, email, role, organisation, login identifiers;
- Operational data: listings, reservations, messages, documents you upload;
- Technical data: IP address, device/browser type, cookies and similar identifiers;
- Integration data: information exchanged with OTAs, payment, email, or other connected systems.
3. How we use data
We use personal data to:
- provide, secure, and improve the Service;
- authenticate users and enforce access controls;
- sync and display bookings and listings across channels you connect;
- comply with law, respond to lawful requests, and protect rights and safety;
- communicate about the Service, including support and important notices.
4. Legal bases (where applicable)
Where required (for example under the Malaysian Personal Data Protection Act 2010), we rely on contract performance, legitimate interests (such as security and product improvement), consent where we ask for it, and legal obligation.
5. Sharing
We may share data with:
- service providers who host, analyse, or support the Service under contract;
- channel managers, OTAs, and other integrations you or your organisation enable;
- authorities when required by law or to protect users and the Service.
We do not sell your personal data.
6. International transfers
Data may be processed in Malaysia or other countries where we or our providers operate. We use appropriate safeguards where cross-border transfer rules apply.
7. Retention
We keep data only as long as needed for the purposes above, including legal, accounting, and dispute resolution needs, unless a longer period is required by law.
8. Security
We implement technical and organisational measures designed to protect personal data. No method of transmission over the Internet is completely secure; we work to reduce risk in line with industry practice.
9. Your rights
Subject to applicable law, you may request access, correction, or deletion, restrict or object to certain processing, or withdraw consent where processing is consent-based. Contact your organisation's administrator or our support channels to exercise these rights. You may also lodge a complaint with a supervisory authority where the law allows.
10. Cookies
We use cookies and similar technologies for session security, preferences, and analytics as configured for the Service. You can control cookies through your browser settings; some features may not work if cookies are disabled.
11. Children
The Service is not directed at children. We do not knowingly collect personal data from children without appropriate consent.
12. Changes
We may update this policy from time to time. We will post the updated version with a new "Last updated" date and, where appropriate, notify you through the Service.
13. Contact
For privacy questions, contact your account administrator or the support channel we provide for your organisation.