1. Introduction

InvoisPlus (“we”, “our”, “us”) is committed to protecting the privacy and security of payment-related information processed through our platform.

This Payment Gateway Privacy Policy explains how we collect, use, store, and protect personal and financial information when users make payments through our integrated third-party payment service providers.


2. Scope

This policy applies to:

  • Subscription payments

  • Invoice payments

  • One-time transactions

  • Recurring billing transactions

  • Any transaction processed through integrated payment gateways


3. Payment Gateway Providers

InvoisPlus uses secure third-party payment processors to handle financial transactions. These providers may include licensed Malaysian or international payment service providers.

When you make a payment, your financial information is processed directly by the payment gateway provider and is subject to their own privacy policies and security standards.

We do not store full credit/debit card numbers on our servers.


4. Information Collected During Payment

When processing payments, the following data may be collected:

  • Name of cardholder or account holder

  • Billing address

  • Email address

  • Phone number

  • Transaction amount

  • Payment method details

  • IP address

  • Transaction ID

  • Device/browser information

Sensitive payment data such as full card numbers are encrypted and handled directly by the payment gateway provider.


5. Purpose of Processing

Payment-related data is processed for:

  • Subscription activation

  • Invoice settlement

  • Fraud detection and prevention

  • Transaction verification

  • Financial reporting and reconciliation

  • Compliance with legal and regulatory obligations


6. Data Security Measures

InvoisPlus implements industry-standard security practices including:

  • SSL/TLS encryption (HTTPS)

  • Tokenized payment processing

  • Secure API integrations

  • Access control restrictions

  • Regular system monitoring

  • Firewall and intrusion detection mechanisms

All payment communications are encrypted end-to-end.


7. Data Sharing

We may share payment-related information only with:

  • Licensed payment gateway providers

  • Financial institutions involved in transaction settlement

  • Regulatory authorities (if legally required)

  • Fraud prevention services

We do not sell, rent, or trade payment information.


8. Data Retention

Payment transaction records are retained:

  • For accounting and auditing purposes

  • To comply with Malaysian tax and financial regulations

  • For dispute resolution

Sensitive payment credentials are not stored beyond what is legally required.


9. International Data Transfers

If payment processors operate outside Malaysia, your payment information may be transferred internationally. In such cases, we ensure appropriate safeguards are in place consistent with applicable data protection laws.


10. Fraud Prevention & Monitoring

We reserve the right to:

  • Conduct fraud checks

  • Suspend suspicious transactions

  • Request additional verification documents

  • Report fraudulent activities to authorities


11. User Responsibilities

Users must:

  • Provide accurate billing information

  • Ensure authorization for payment method used

  • Protect their login credentials

InvoisPlus is not responsible for unauthorized transactions caused by user negligence.


12. Your Rights (Under PDPA)

In accordance with the Malaysian Personal Data Protection Act (PDPA), users have the right to:

  • Request access to payment-related data

  • Request correction of inaccurate information

  • Withdraw consent (subject to service impact)

Requests may be sent to:
📧 privacy@invoispls.my