1. Who we are
DonorCARE is a donation management platform operated by Omakase Software Sdn Bhd ("DonorCARE", "we", "us", "our", or the "Platform Operator"), a company incorporated in Malaysia. This Privacy Policy describes how we collect, use, disclose, and protect personal data in connection with donorcare.my, the DonorCARE admin dashboard, and any website or checkout page we host on behalf of a customer organisation (each, an "Organisation").
This Policy is issued in compliance with the Personal Data Protection Act 2010 (PDPA) of Malaysia and applies to personal data processed by DonorCARE as part of operating the platform.
2. Two roles: data user and data processor
DonorCARE occupies two different positions under the PDPA depending on whose data is involved, and this distinction runs through the rest of this Policy:
- As a data user, for the account data of the Organisation's own staff — the names, emails, phone numbers, and login credentials of the people who sign up for and administer a DonorCARE account. For this data, DonorCARE decides the purposes and means of processing and is directly responsible to those individuals under the PDPA.
- As a data processor, for donor and beneficiary data that an Organisation collects and stores in the platform — donor names, contact details, identification numbers, donation history, and tax-exemption status. This data belongs to the Organisation. We process it only on the Organisation's documented instructions, as set out in our Data Processing Addendum, and the Organisation — not DonorCARE — is the data user responsible to its own donors under the PDPA.
If you are a donor and have a question about how your data is used, your first point of contact is the Organisation you donated to, not DonorCARE directly. We will still assist an Organisation in responding to you, as described in our Data Processing Addendum.
3. What we collect
Account data (as data user). When an Organisation or an individual staff member registers for DonorCARE, we collect name, email address, phone number, job role, password (stored as a salted hash, never in plain text), and organisation details (registered name, registration number, tax-exemption status where supplied).
Donor and donation data (as data processor). On an Organisation's instructions, the platform stores donor names, contact details, identification type and number (NRIC, passport, or business registration number) where supplied for tax-receipt purposes, donation amounts and dates, payment method, campaign or ceremony/ritual registration details, and — where the Organisation has enabled it — MyInvois e-invoice submission records filed with the Inland Revenue Board (LHDN).
Technical data. IP address, browser and device type, pages visited, and session cookies, collected automatically for security, fraud prevention, and — on the DonorCARE marketing site and on tenant sites where the Organisation has configured its own Google Analytics measurement ID — usage analytics. See our Cookie Policy for the specifics.
Payment data. Card and bank details entered at checkout are collected directly by our payment gateway, CHIP, and are not stored on DonorCARE's own servers. We receive and store only the transaction outcome (success, amount, reference number), not the underlying card or bank credentials.
4. Why we collect it
We use personal data to:
- Create and administer Organisation and staff accounts;
- Process donations, issue tax-deduction receipts, and — where engaged — submit e-invoices to LHDN through the MyInvois system on an Organisation's behalf;
- Operate donor-facing features an Organisation has enabled, such as recurring donations, ceremony/ritual registration, and email campaigns;
- Detect and prevent fraud, abuse, and unauthorised access to the platform;
- Respond to support requests and communicate service updates;
- Comply with Malaysian legal obligations, including tax record retention and requests from LHDN or other authorities; and
- Improve the platform, using aggregated or de-identified data wherever practicable.
5. Disclosure of your data
We do not sell personal data. We disclose personal data only to:
- The Organisation an individual donated to or registered an account with;
- Subprocessors who provide infrastructure or services necessary to operate the platform, listed in full on our Subprocessors page;
- Government authorities — principally LHDN for e-invoice submission and the Registrar of Societies / Companies Commission of Malaysia (SSM) where an Organisation's registration requires it — where the Organisation has instructed or authorised the disclosure, or where required by law;
- Professional advisors (auditors, lawyers) bound by confidentiality, where necessary to protect our legal position; and
- A successor entity in the event of a merger, acquisition, or sale of assets, subject to that entity assuming the obligations in this Policy.
6. Retention
Donation and receipt records are retained for seven (7) years from the end of the relevant financial year, consistent with the record-keeping requirements of the Income Tax Act 1967 and LHDN's MyInvois guidance. Account data is retained for as long as the Organisation's account remains active, plus a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce our agreements.
Where an Organisation terminates its DonorCARE account, donor and donation data is retained for the same statutory period on the Organisation's behalf unless the Organisation exercises its export and deletion rights under our Subscription Terms, subject always to the statutory retention period for tax records, which we cannot shorten even at an Organisation's request.
7. Your rights under the PDPA
If DonorCARE is acting as a data user with respect to your data (see "Two roles" above), you have the right, under the PDPA, to:
- Request access to the personal data we hold about you;
- Request correction of inaccurate or incomplete personal data;
- Withdraw consent to processing, where consent is the basis for that processing;
- Request that we stop processing your data for direct marketing; and
- Be informed of the purposes for which your data is used.
We will respond to a data access or correction request within 21 days of receipt, as required by the PDPA. To make a request, contact [email protected]. If your request concerns donor data held by an Organisation, we will refer you to that Organisation and, where the Organisation instructs us to, assist in fulfilling the request.
8. Security measures
We apply technical and organisational measures appropriate to the sensitivity of the data we hold, including encryption of data in transit (TLS) and at rest, role-based access control scoped to each Organisation's own data, audited administrative actions, and per-field encryption of sensitive credentials such as payment gateway keys. Further detail is published on our Security & Compliance page. No system is completely secure, and we cannot guarantee absolute security of information transmitted to us.
9. Cross-border data transfer
Some of our subprocessors operate infrastructure outside Malaysia. Where personal data is transferred outside Malaysia, we rely on the subprocessor's own data-protection commitments and, where applicable, standard contractual safeguards, consistent with the PDPA's cross-border transfer restrictions. The current list of subprocessors, what each one does, and where each is located (to the extent we can confirm) is maintained on our Subprocessors page, which we update as our vendor list changes.
10. Children's data
DonorCARE is not directed at children, and we do not knowingly collect personal data from individuals under 18 except where an Organisation records a minor as a named beneficiary of a ceremony, ritual, or dedication entry at the instruction of, and with responsibility resting with, an adult donor or the Organisation itself.
11. Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices or in the law. The "Last updated" date at the top of this page will always reflect the latest version. Material changes affecting Organisations will be communicated by email where we hold one on file.
12. Contact us
Questions about this Privacy Policy, or a data access or correction request, can be sent to [email protected].

