KiraNow Privacy Policy

Effective Date: 2nd January 2026

Last Updated: 2nd January 2026

1. Introduction

KiraNow ("we," "our," or "us") operates the KiraNow mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App.

We comply with the Personal Data Protection Act 2010 (PDPA) of Malaysia, the General Data Protection Regulation (GDPR) for users in the European Union/European Economic Area, and other applicable global data protection laws. By using KiraNow, you consent to the data practices described in this policy.

2. Information We Collect

A. Personal Information You Provide:

B. Information Collected Automatically:

C. Third-Party Information:

3. How We Use Your Information

Purpose Legal Basis
To provide core App functionality (creating groups, splitting bills) Performance of contract
To calculate balances and simplify debts Performance of contract
To send notifications about expenses, settlements, and reminders Legitimate interest
To improve App performance and fix bugs Legitimate interest
To develop new features and personalize experience Consent (where required)
To prevent fraud and ensure security Legal obligation
To comply with applicable laws and regulations Legal obligation

For GDPR users: We process your data based on: (1) Contractual necessity, (2) Legitimate interest, (3) Consent, or (4) Legal obligation as outlined above.

4. How We Share Your Information

We do NOT sell your personal data. We only share information in these circumstances:

Recipient What is Shared Purpose
Other KiraNow Users Your name, profile picture, expense details within groups you join, and bank account information if added to your user profile Core App functionality and settlement facilitation
Service Providers Email services, cloud hosting, analytics (e.g., Firebase) App operation and improvement
Legal Authorities If required by law or valid legal process in your jurisdiction Legal compliance

5. International Data Transfers & Global Compliance

For Malaysian Users:

For EU/EEA & UK Users:

For Other Jurisdictions:

6. Your Data Protection Rights

Depending on your location, you may have the following rights:

Malaysian Users (PDPA Rights):

  1. Access your personal data
  2. Correct inaccurate data
  3. Withdraw consent for processing
  4. Limit processing of your data
  5. Request deletion of your data
  6. Data portability
  7. Complain to the Personal Data Protection Commissioner

EU/EEA/UK Users (GDPR Rights):

  1. Right to access
  2. Right to rectification
  3. Right to erasure ("right to be forgotten")
  4. Right to restrict processing
  5. Right to data portability
  6. Right to object to processing
  7. Rights related to automated decision-making

To exercise these rights, contact: [email protected]

7. Data Retention

We retain your personal data only as long as necessary:

Data Type Retention Period
Active account data Until account deletion
Financial transaction records 7 years (for regulatory compliance)
Inactive accounts 24 months after last login, then anonymization
Deleted accounts 30-day recovery window, then permanent deletion

8. Data Security

We implement appropriate security measures:

9. Children's Privacy

KiraNow is not intended for users under 18 years old. We do not knowingly collect data from children. If we learn we have collected such data, we will delete it immediately.

10. Third-Party Services

Our App integrates with:

These third parties have their own privacy policies. We recommend reviewing them.

11. Automatic Data Collection

We use:

12. Changes to This Policy

We may update this policy. We will notify you via:

Continued use after changes constitutes acceptance.

13. Contact Information

Data Protection Officer:

KiraNow Services

A-30-11, The Era, Jalan Segambut, Kawasan Perusahaan Segambut,

51200 Kuala Lumpur, Malaysia

Email: [email protected]

Phone: +60 12-764 0370

For general support: [email protected]

Malaysian Personal Data Protection Commissioner:

Department of Personal Data Protection

Ministry of Communications and Digital

Level 8, Galeria PjH, Jalan P4W, Persiaran Perdana,

Presint 4, Pusat Pentadbiran Kerajaan Persekutuan

62100 Putrajaya, Malaysia

Tel: +603-8000 8000

Website: https://www.pdp.gov.my


Appendix: Specific Data Practices

For Group Members:

When you join a group, other members see:

  • Your name and profile picture
  • Expenses you add and their details
  • Your balance within that group
  • Your bank account information (if you have added it to your user profile)

For Expense Tracking:

We store:

  • Expense amounts and descriptions
  • Who paid and who owes
  • Settlement history
  • Receipt images (if you upload them)

Bank Account Information:

  • Bank account details are optional to add to your profile
  • Visible only to other users in groups you join
  • Used solely for manual settlement facilitation
  • We do not process payments through these accounts

Additional Global Compliance Notes

  1. Data Transfer Mechanisms: For international transfers, we use:
    • Standard Contractual Clauses (EU)
    • Adequacy decisions where applicable
    • Binding Corporate Rules for intra-group transfers
  2. Breach Notification: We will notify users and authorities of data breaches as required by local laws (72 hours for EU under GDPR, promptly for Malaysia under PDPA).
  3. Data Protection Impact Assessments: Conducted for high-risk processing activities.
  4. Record of Processing Activities: Maintained as required by GDPR and other regulations.