Legal
Privacy
Policy.
This policy explains what personal data Traveloop collects when you buy a pass, book an experience or contact us, why we hold it, who we share it with, and how you can get it corrected or deleted.
Last updated: 19 September 2026
This English version is the definitive text. Where a translation differs from it, this version governs.
1. Who we are
Traveloop is operated by Seni Mega Venture Sdn Bhd. We are the data user responsible for the personal data described in this policy, and we handle it in accordance with Malaysia's Personal Data Protection Act 2010 (PDPA).
- Data user
- Seni Mega Venture Sdn Bhd, registered with the Companies Commission of Malaysia
- Business address
- 50, Jalan Khaw Sim Bee, 10400 Pulau Pinang, Malaysia
- Data enquiries
- traveloop@3d-group.com.my
This policy covers traveloop.my and every service reached through it: pass purchases, the customer portal, experience bookings, the contact form and the Urban Sprint campaign. It does not cover the partner merchants, experience operators or insurers you deal with through us, each of whom handles your data under their own policy.
2. What we collect
We collect only what a given service needs. What that is depends on what you do:
When you buy a pass
Before payment, the registration form asks for the details a pass and its bundled insurance require. One set is collected per pass, so buying for other people means giving us their details too — please make sure they have agreed.
- Full name
- Nationality
- Arrival and departure dates
- Travel document type and number — passport, national ID or residence permit
- Address
- Emergency contact name, phone number and relationship to you (optional)
- The date and time you accepted the participant declaration
Your email address, name and phone number are collected by Stripe on the checkout page rather than by our form, and passed to us once payment completes.
When you pay
Card and bank details are entered on Stripe's own hosted checkout page and are never sent to, seen by or stored on Traveloop's systems. What we keep is the record of the transaction:
- Amount, currency and the passes bought
- Stripe's checkout session and payment reference
- Our invoice number
- Whether the payment succeeded, failed or was abandoned — including the reason a payment was declined, so we can tell you what went wrong
When you have a Traveloop account
Buying a pass creates a customer portal account for the email address you paid with. It holds your email address, your password in hashed form, your purchase history, and the registration details above so you do not have to type them again. We cannot see your password.
When you book an experience
- The experience, date, time, location and package you chose
- How many people are coming, and how many of them are children
- Any notes you add for the operator
- The booking reference and its status
When you use the contact form
Your name, email address, the subject you picked and your message. These reach us as an email and are kept in that inbox — they are not stored in a database.
When you take part in Urban Sprint
A display name, a phone number, your role in the campaign, your team, and the stations your team completed with the times and points awarded. Team names and scores appear on a public leaderboard; phone numbers never do.
Automatically, when you visit
Our hosting and database providers keep standard server logs — IP address, browser user-agent, the page requested and the time — which we use to keep the site running and to investigate abuse or errors. We do not run analytics, advertising or cross-site tracking of any kind.
3. Travel document details
A passport or identity document number is sensitive, and we want to be direct about why we ask for one. It is required to issue the travel insurance bundled with a pass, to identify you if a claim is made under that policy, and for partner venues to confirm that the person presenting a pass is the person it was issued to.
We do not ask you to upload a scan or a photograph of the document itself, and you should not send us one. The number is visible only to Traveloop staff administering your order and to the insurer if you make a claim; it is never shown to partner merchants, never included in marketing, and never sold.
4. How we use it
We use your personal data to:
- Provide what you bought. Process your payment, issue your pass and invoice, register you for the bundled insurance, confirm your experience bookings with the operator, and give you a portal to see it all in.
- Contact you about your order. Send your confirmation email and invoice, your account details, booking confirmations and changes, and answer what you write to us. These are service messages, not marketing, and you cannot unsubscribe from them while an order is live.
- Support and resolve problems. Look into a failed payment, a disputed charge, a cancelled booking or an insurance claim.
- Meet our legal obligations. Keep the accounting and tax records Malaysian law requires, and respond to lawful requests from authorities.
- Keep the service safe. Detect fraudulent transactions and abuse, and diagnose faults.
We do not send marketing email, and we do not sell, rent or trade personal data to anyone. If we ever want to send you offers, we will ask you first and you will be able to say no without losing anything you have paid for.
Most of the data above we process because it is necessary to perform the contract you entered into when you bought a pass or made a booking. Where that is not the basis — the optional emergency contact, for instance — we rely on the consent you give by choosing to provide it, which you can withdraw.
Supplying the fields marked as required is a condition of buying a pass: without them we cannot issue the pass or its insurance, and the purchase cannot proceed.
6. Where your data is held
Our database is hosted in Mumbai, India, and the site is served from a global content network with its closest edge in Singapore. Your personal data is therefore stored and processed outside Malaysia. The processors named in section 5 operate internationally and may process data in the United States and the European Union.
By using Traveloop you consent to that transfer. Each of these providers is engaged under terms that require them to protect your data to a standard comparable to the PDPA and to process it only on our instructions.
8. How long we keep it
- Order and invoice records, including the registration details attached to them: seven years from the date of purchase, which is the retention period Malaysian tax and company law requires of us.
- Your customer portal account and profile: for as long as the account exists. Ask us to close it and we delete the account and profile, keeping only the order records above.
- Experience bookings: two years after the session date, so we can deal with disputes and repeat visits.
- Failed and abandoned payment attempts: 12 months, then deleted.
- Incomplete checkouts you never paid for: deleted automatically, and in any case within 30 days.
- Contact form enquiries: two years in our inbox from your last message on the subject.
- Urban Sprint participant records: deleted within 90 days of the campaign ending. Team names and final scores may stay published as a result.
- Server logs: as long as our hosting and database providers retain them, typically no more than 30 days.
When a retention period ends, data is deleted or irreversibly anonymised. We may keep something longer where an open dispute, claim or legal obligation requires it, and only for as long as that lasts.
9. How we protect it
- Every page and form is served over HTTPS; data in transit is encrypted.
- Passwords are hashed by Supabase Auth. Neither we nor anyone with database access can read them.
- Card details never touch our systems — Stripe handles them on its own PCI-DSS compliant infrastructure.
- Database tables enforce row-level security, so a signed-in customer can read their own orders and profile and nothing else.
- The keys that bypass those rules exist only on the server and are never sent to your browser.
- The admin console is restricted to a single authorised account and is excluded from search engines.
No system is perfectly secure, and we will not pretend otherwise. If a breach occurs that is likely to cause you significant harm, we will notify you and the Personal Data Protection Commissioner as the PDPA requires.
10. Your rights
Under the PDPA you have the right to:
- Access your data. Ask for a copy of the personal data we hold about you. Most of it you can see immediately by signing in to the customer portal.
- Correct it. Have inaccurate or incomplete data put right. You can edit your own profile in the portal, or ask us.
- Withdraw your consent. Withdraw consent for any processing that relies on it. This does not affect processing already carried out, and it may mean we can no longer provide part of the service.
- Limit how we process it. Ask us to stop processing your data for a particular purpose, or in a way that causes you distress.
- Ask us to delete it. Have data erased once we no longer have a legal reason to keep it. Where a retention period in section 8 still applies, we will tell you which one and when it ends.
- Complain. Raise a complaint with the Personal Data Protection Commissioner of Malaysia if you believe we have mishandled your data. We would rather you came to us first, but it is your right either way.
To exercise any of these, email us at traveloop@3d-group.com.my from the address on your order, or write to the business address in section 1. We may ask you to confirm your identity before acting — that check protects you, not us. We respond within 21 days. There is no charge, unless a request is repetitive or excessive, in which case we will tell you the fee before doing any work.
11. Children
Traveloop is not directed at children, and we do not knowingly collect personal data from anyone under 18. Passes and bookings must be made by an adult, who is responsible for any child travelling with them.
Where a booking records how many children are in your party, that is a count for the operator's planning — we do not ask for their names, ages or documents. If you believe a child has given us personal data, tell us and we will delete it.
12. Changes to this policy
We update this policy when what we do with your data changes. The date at the top of the page always shows the current version, and the previous one stops applying from that date.
If a change materially affects your rights — a new category of data, a new recipient, a longer retention period — we will tell customers with an active account by email rather than relying on you to re-read this page.
