Privacy Policy

Learn how we collect, use, and protect your personal information on Penang Cafe & Restaurant Directory

Privacy Policy

Last updated: June 15, 2025

1. Introduction

Welcome to Penang Cafe & Restaurant Directory ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our restaurant directory website PenangTime.com.

Commercial Website Notice: This website operates with advertising revenue and is subject to Malaysia's Personal Data Protection Act 2010 (PDPA). We are committed to full compliance with PDPA requirements and protecting your personal information according to Malaysian data protection standards.

Advertising Disclosure: Our website displays advertisements from third-party advertising networks (such as Google AdSense) which may collect and use your information for targeted advertising purposes. We also may receive compensation for featuring certain restaurants or services.

Please read this Privacy Policy carefully. By accessing or using our website, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use our website.

Your PDPA Rights: Under Malaysia's PDPA, you have specific rights regarding your personal data including access, correction, deletion, and data portability. We are committed to responding to your requests within the timeframes required by law.

2. Legal Basis for Data Processing

As a commercial website subject to Malaysia's PDPA, we process your personal data based on the following legal grounds:

  • Consent: When you voluntarily provide information through our forms, features, or cookie preferences
  • Contractual Necessity: To provide services you have requested (restaurant listings, directory access)
  • Legitimate Business Interest: For website operation, security, analytics, and advertising optimization
  • Legal Compliance: To comply with Malaysian law and regulatory requirements

Advertising-Related Processing:

  • Advertising Consent: For personalized advertising and marketing communications
  • Performance Measurement: To measure and optimize advertising effectiveness
  • Revenue Generation: To support our business model through advertising partnerships

Commercial Processing Notice: As we generate revenue through advertising, your data may be processed for commercial purposes. You have the right to object to such processing and can manage your advertising preferences through our cookie settings.

3. Information We Collect

Personal Information

We may collect personal information when you voluntarily provide it to us through:

  • Submitting a restaurant listing
  • Contacting us through our contact form
  • Reporting incorrect information
  • Participating in voting features
  • Using location-based services (with your permission)

This personal information may include:

  • Identification Data: Name, business name, contact person details
  • Contact Data: Email address, phone number, business address
  • Business Information: Restaurant details, operating hours, menu information
  • Location Data: GPS coordinates, address information (with your consent)
  • Communication Data: Messages sent through our contact forms

Minimal Collection: We only collect information that is necessary for the functionality you're using and do not collect excessive information.

Automatically Collected Information

When you visit our website, we automatically collect certain technical information about your device and usage patterns. This information helps us improve the website experience and optimize our advertising:

  • Technical Data: IP address, browser type and version, operating system, device identifiers
  • Usage Data: Pages visited, time spent on our site, click patterns, referring website, search terms
  • Device Data: Screen resolution, device type, browser language settings, installed plugins
  • Location Data: Geographic location (city/state level) for localized content and advertising
  • Advertising Data: Ad impressions, clicks, and interaction data for campaign optimization

Third-Party Data Collection:

Our advertising partners may collect additional information through:

  • Google AdSense: Browsing behavior, demographics, interests for targeted advertising
  • Analytics Providers: Detailed usage statistics and user journey mapping
  • Social Media Pixels: Interaction data for social media advertising and remarketing

Commercial Data Use: Information collected may be used to generate revenue through targeted advertising and to improve our commercial offerings. You can control much of this data collection through your cookie preferences.

4. How We Use Your Information

We use your personal information for legitimate business purposes in operating our commercial restaurant directory website:

Primary Business Uses:

  • Directory Service: Display and maintain our restaurant directory
  • Listing Management: Process, verify, and publish restaurant listings
  • Communication: Respond to your inquiries and provide customer support
  • Website Operation: Maintain website functionality and user experience
  • Revenue Generation: Support our business model through advertising and partnerships

Advertising and Marketing Uses:

  • Targeted Advertising: Display relevant advertisements based on your interests and behavior
  • Campaign Optimization: Measure and improve advertising effectiveness
  • Remarketing: Show you relevant ads on other websites you visit
  • Sponsored Content: Deliver personalized restaurant recommendations and featured listings
  • Newsletter Marketing: Send promotional emails about restaurants and special offers (with your consent)

Analytics and Improvement:

  • Website Analytics: Analyze usage patterns to enhance user experience and business performance
  • Performance Monitoring: Track website performance and advertising revenue
  • Business Intelligence: Generate insights for business development and growth

Security and Legal Uses:

  • Prevent spam, fraud, or inappropriate submissions
  • Protect the website and users from security threats
  • Comply with legal requests and PDPA obligations
  • Enforce our terms of service and policies

Commercial Use Transparency: As a commercial website, we use your information to generate revenue through advertising while providing valuable restaurant directory services. You can opt out of non-essential data processing through your privacy preferences.

5. Information Sharing and Disclosure

As a commercial website, we share your information with third parties in specific circumstances to operate our business and provide our services:

Commercial Sharing:

  • Advertising Partners: We share data with advertising networks (like Google AdSense) for targeted advertising and revenue generation
  • Analytics Providers: Website usage data shared with analytics services for business intelligence
  • Marketing Partners: Email addresses and preferences shared with marketing platforms (with your consent)
  • Sponsored Content: Restaurant engagement data may be shared with featured restaurant partners

Essential Service Sharing:

  • Public Listings: Restaurant information you submit for listing will be made publicly available on our website
  • Technical Service Providers: Website hosting, CDN, and infrastructure services
  • Payment Processors: For any paid services or premium listings
  • Legal Requirements: When required by law, court orders, or to protect legal rights
  • Safety Situations: To protect the safety of individuals or the public when necessary

Third-Party Advertising Services:

We work with the following types of advertising partners:

  • Google AdSense: Displays targeted advertisements and collects user data for ad personalization
  • Social Media Platforms: Facebook, Instagram for remarketing and lookalike audiences
  • Affiliate Networks: Restaurant booking platforms and delivery services
  • Local Business Partners: Featured restaurant promotions and sponsored content

Commercial Data Sharing: Unlike a personal website, we do share your information with commercial partners for advertising and business purposes. You can control much of this sharing through your cookie and privacy preferences.

Data Protection: All third-party partners are required to comply with applicable data protection laws and maintain appropriate security measures for your personal information.

6. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your browsing experience, analyze site traffic, and understand user preferences. This section explains our cookie usage in detail:

What Are Cookies?

Cookies are small text files stored on your device when you visit our website. They help us remember your preferences and improve your user experience.

Types of Cookies We Use:

Cookie Type Purpose Duration Consent Required
Essential/Functional Website operation, security, form submissions Session/30 days No (necessary for service)
Analytics Usage statistics, performance monitoring 2 years Yes
Preferences Remember your settings and favorites 1 year Yes
Advertising Targeted ads, ad performance, remarketing Up to 2 years Yes
Social Media Social sharing, remarketing pixels 1-2 years Yes

Managing Your Cookie Preferences:

You have several options to control cookies:

  • Browser Settings: Configure your browser to accept, reject, or request permission for cookies
  • Cookie Consent Banner: Use our cookie consent tool to manage your preferences
  • Opt-Out Links: Use third-party opt-out mechanisms for analytics and advertising cookies

Note: Disabling essential cookies may affect website functionality. Non-essential cookies require your explicit consent before being set.

Third-Party Cookies:

We use trusted third-party services that set their own cookies for commercial purposes:

  • Google AdSense: For targeted advertising and revenue generation
  • Google Analytics: For detailed website usage analytics and business intelligence
  • Facebook Pixel: For social media advertising and remarketing campaigns
  • Social Media Plugins: For social sharing and engagement tracking
  • Affiliate Networks: For tracking referrals and commission-based partnerships
  • Maps Services: For location-based features and local advertising

Advertising Revenue Notice: Third-party advertising cookies are essential to our business model. Blocking these cookies may affect website functionality and our ability to provide free services, but you retain the right to control your cookie preferences.

7. Data Security (Security Safeguards)

In compliance with Malaysia's PDPA, we implement comprehensive technical and organizational security measures to protect your personal data against unauthorized access, disclosure, alteration, or destruction:

Technical Safeguards:

  • Encryption: Data transmission secured with SSL/TLS encryption
  • Access Controls: Role-based access restrictions and authentication systems
  • Data Backup: Regular, secure backups with encryption at rest
  • Network Security: Firewalls, intrusion detection, and monitoring systems
  • Secure Hosting: Data hosted on secure servers with physical access controls

Organizational Safeguards:

  • Staff Training: Regular privacy and security training for all personnel
  • Access Limitation: Personal data access limited to authorized personnel only
  • Confidentiality Agreements: All staff bound by confidentiality obligations
  • Regular Audits: Periodic security assessments and vulnerability testing
  • Incident Response: Established procedures for data breach detection and response

Data Breach Notification:

In the event of a personal data breach that poses a risk to your rights and freedoms, we will:

  • Notify the Personal Data Protection Department within 72 hours
  • Inform affected individuals without undue delay
  • Provide clear information about the breach and our response
  • Take immediate steps to contain and remedy the breach

Security Limitation: While we implement industry-standard security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but continuously work to enhance our protection measures.

8. Data Retention

In accordance with PDPA's data retention principle, we retain your personal data only as long as necessary to fulfill the purposes for which it was collected or as required by Malaysian law:

Retention Periods:

Data Type Retention Period Justification
Restaurant Listings While business is active + 2 years Service provision and historical records
Contact Form Data 3 years from last contact Customer service and follow-up
Newsletter Subscriptions Until unsubscribed + 1 year Marketing consent and suppression lists
Website Analytics 26 months (anonymized after 6 months) Website improvement and business analytics
Advertising Data Up to 2 years or until consent withdrawn Ad targeting, campaign optimization, revenue tracking
Marketing Lists Until unsubscribed + 3 years Email marketing, promotional campaigns, suppression lists
Legal/Compliance Records 7 years or as required by law Legal obligations and dispute resolution

Secure Disposal:

When personal data is no longer needed, we ensure its secure disposal through:

  • Data Deletion: Secure deletion from all systems and backups
  • Anonymization: Removal of identifying characteristics where statistical data is retained
  • Physical Destruction: Secure destruction of physical documents and storage media
  • Verification: Documentation of disposal processes for audit purposes

Active Review: We regularly review our data retention practices and delete personal data that is no longer necessary for the purposes for which it was collected.

9. Your Privacy Rights (PDPA Data Subject Rights)

As a commercial website subject to Malaysia's Personal Data Protection Act 2010 (PDPA), you have specific legal rights regarding your personal data. We are committed to facilitating the exercise of these rights within the timeframes required by law.

Your PDPA Rights Include:

Right to Access (Section 30)

Request access to your personal data and information about its processing.

Right to Correction (Section 31)

Request correction of inaccurate, incomplete, misleading, or out-of-date personal data.

Right to Withdrawal (Section 34)

Withdraw consent for processing personal data at any time (limitations may apply).

Right to Object

Object to processing for direct marketing, automated decision-making, or legitimate interests.

Right to Data Portability

Request your personal data in a structured, machine-readable format.

Right to Restrict Processing

Request limitation of processing in certain circumstances.

How to Exercise Your Rights:

Contact Methods:

  • Email: [email protected]
  • Subject Line: "PDPA Data Subject Rights Request" for formal requests
  • Include: Your full name, contact details, specific request, and identity verification documents
  • For advertising opt-outs: Use "Advertising Opt-Out Request" in subject line

Response Time: We will respond within 21 days as required by PDPA (may be extended by additional 30 days for complex requests).

Commercial Processing Considerations:

Advertising and Revenue: Some data processing is essential for our advertising revenue model. While you can withdraw consent for marketing activities, certain processing may continue based on legitimate business interests. We will clearly explain any limitations when responding to your requests.

No Cost: Exercising your PDPA rights is free of charge for the first request per year. Subsequent requests may incur reasonable administrative fees.

Right to Lodge a Complaint:

If you believe your privacy rights have been violated, you have the right to lodge a complaint with:

Personal Data Protection Department

Ministry of Digital

Email: [email protected]

Website: www.digital.gov.my

10. Third-Party Links and Services

Our website may contain links to third-party websites and use third-party services. These external sites and services have their own privacy policies and data handling practices. We are not responsible for the privacy practices or content of these third-party sites.

Third-Party Service Providers:

  • Google Analytics: Website analytics and user behavior analysis (anonymized data)
  • Google Maps: Location services and mapping functionality
  • Social Media Platforms: Social sharing and engagement features
  • CDN Providers: Content delivery and website performance optimization

Third-Party Privacy: Each third-party service provider operates under its own privacy policy. We encourage you to review these policies when interacting with third-party services through our website.

External Links:

When you click on links to other websites from our site:

  • You will be subject to those sites' privacy policies
  • We are not responsible for their data collection practices
  • We recommend reviewing their privacy policies before providing personal information

11. Important Disclaimer

While we strive to provide accurate and up-to-date information in our restaurant directory, we cannot guarantee the completeness, accuracy, or reliability of all information displayed on our website.

Information Accuracy:

  • User-Generated Content: Much of our content is provided by restaurant owners and users. We do not verify all submitted information.
  • Third-Party Information: Some information may be sourced from publicly available data or third-party services.
  • Regular Updates: We encourage users to report inaccuracies to help maintain data quality.

Limitation of Liability:

We are not liable for:

  • Decisions made based on information found on our website
  • Changes in restaurant hours, prices, or availability
  • Quality of food or service at listed establishments
  • Temporary or permanent closure of listed restaurants

Recommendation: We recommend contacting restaurants directly to confirm current information before visiting, especially for special events or during holidays.

12. Children's Privacy

Our website is not intended for children under 13 years of age, and we do not knowingly collect personal information from children under 13 without verified parental consent.

Our Commitment:

  • No Targeted Collection: We do not actively seek to collect personal data from children under 13
  • Prompt Deletion: If we become aware that we have collected personal data from a child under 13, we will delete it promptly
  • Parental Rights: Parents have the right to review, delete, or refuse further collection of their child's personal data

Parental Notice:

If you are a parent or guardian and believe that your child has provided us with personal information, please contact us immediately at [email protected].

Commercial Website Notice: This policy reflects our commitment to protecting children's privacy online as a responsible commercial website operator, in compliance with PDPA requirements and international best practices.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational, legal, or regulatory reasons.

How We Notify Changes:

  • Website Notice: Updated policies will be posted on this page with a new "Last updated" date
  • Significant Changes: For material changes, we may provide additional notice through email or website banners
  • Continued Use: Your continued use of our website after changes constitutes acceptance of the updated policy

Reviewing Changes:

We encourage you to:

  • Review this Privacy Policy periodically
  • Check the "Last updated" date when visiting
  • Contact us if you have questions about any changes

Your Rights: If you disagree with changes to this policy, you have the right to discontinue using our services and request deletion of your personal data.

14. Regulatory Information and PDPA Compliance

As a commercial website generating advertising revenue in Malaysia, we are subject to the Personal Data Protection Act 2010 (PDPA) and are committed to full compliance with its requirements.

Commercial Processing Disclosure:

Revenue Model: This website operates as a commercial service with revenue generated through advertising partnerships, including Google AdSense and affiliate marketing. Personal data processing supports these legitimate business activities while maintaining full PDPA compliance.

Data Processing Scope:

  • Commercial Purposes: Data processing includes advertising targeting, marketing analytics, and revenue optimization
  • Third-Party Partnerships: Data sharing with advertising networks and analytics providers under PDPA-compliant agreements
  • International Transfers: Some data processing may involve transfers to countries with adequate data protection laws
  • Retention Periods: Commercial data retention periods established based on business needs and legal requirements

Regulatory Oversight:

Our PDPA compliance is subject to oversight by:

Personal Data Protection Department

Ministry of Digital

Email: [email protected]

Website: www.digital.gov.my

Contact them for current information or to file complaints about our data practices.

Continuous Compliance:

Ongoing Commitment: We regularly review and update our data protection practices to maintain compliance with PDPA requirements and best practices in commercial data processing.

15. Contact Us

If you have any questions about this Privacy Policy, our data practices, or wish to exercise your privacy rights, please contact us using the information below:

General Contact Information

Penang Cafe & Restaurant Directory

Email: [email protected]

Website: PenangTime.com

For Privacy-Related Inquiries:

  • Use subject line: "Privacy Policy Inquiry" for general questions
  • Use subject line: "PDPA Data Subject Rights Request" for rights requests
  • Include your full name and contact details in all correspondence

Response Times:

  • General Inquiries: We aim to respond within 5-7 business days
  • Privacy Rights Requests: We will respond within 21 days as required by PDPA
  • Data Breach Reports: Immediate acknowledgment within 24 hours
  • Advertising Opt-Out Requests: Processed within 48 hours for immediate effect

We Value Your Privacy: Your privacy is important to us. We are committed to addressing your concerns promptly and transparently.