1. About this Privacy Policy
This Privacy Policy explains how G Fix Technologies Sdn Bhd ("GFix", "we", "us" or "our") processes personal data when people use the GFix mobile application, website, customer services, technician services, and related administration. It is intended to support the principles and notice requirements of Malaysia's Personal Data Protection Act 2010 (Act 709), as amended.
2. Information We Collect
Depending on the service and your role, we may collect:
- identity and account details, including name, phone number, email address, preferred language, account status, and password credentials stored as a one-way hash;
- technician application and verification details, including company information, identity or registration numbers, service categories, coverage areas, experience, working hours, bank payout details, verification documents, and an optional public profile photo;
- booking and job information, including service category, service address, location coordinates, preferred date and time, problem description, notes, status history, assigned technician, completion records, and uploaded photos;
- payment and financial records, including selected payment option, payable amount, payment proof, payment status, provider transaction references, wallet entries, top-up records, points entries, rewards, refunds, and payout records;
- communications and service-quality information, including in-app job chat messages, support tickets, replies, disputes, completion remarks, and ratings or reviews;
- security and technical records, including session tokens or cookies, device/platform labels where supplied, login times, IP addresses or hashed IP data, user-agent information, audit records, and verification-attempt information.
3. How We Collect Information
We collect information directly from customers, technicians, and administrators when they register, verify a phone number, submit a booking or application, upload content, communicate, make or verify a payment, use wallet or points features, rate a job, or request support. We also receive status and transaction information from service providers such as Twilio Verify and Billplz when those integrations are enabled. Some technical information is generated automatically when a request reaches GFix.
4. How We Use Information
We use personal data to create and secure accounts; verify phone numbers; process technician applications; display eligible jobs; arrange, assign, deliver, monitor, and support services; calculate and verify payments; maintain wallet, points, refund, reward, and payout records; enable job communications; investigate disputes; prevent misuse; provide support; maintain audit trails; comply with legal obligations; and improve the reliability and safety of GFix.
If required information is not provided, we may be unable to create or verify an account, accept a booking or technician application, process payment, assign a technician, resolve a dispute, or provide the requested feature.
5. Location Information
Customers may provide a service address and map coordinates for a job. Technicians may provide working locations and, when they grant device permission, current GPS coordinates for nearby-job discovery and operational location updates. Location can be linked to an account or job and may be stored with accuracy, source, and update time. We use it to match and display relevant work, support service delivery, and review job events. Device permission can be denied, although location-dependent features may then be unavailable.
6. Photos, Documents and Uploaded Content
GFix accepts booking photos, payment proofs, dispute evidence, completion photos, wallet top-up proofs, technician identity/application documents, and optional technician public profile photos. Files are stored in protected application storage with metadata such as file name, type, size, related account or job, and upload time. Access is restricted by role and purpose. A technician's approved public profile photo may be shown to customers assigned to that technician; verification documents and payout details are not intended for customer display.
7. Customer and Technician Account Information
Customer accounts support bookings, job history, payments, wallet, points, ratings, and support. Technician accounts support applications, approval status, eligible and nearby jobs, job lifecycle work, profile information, payout administration, and support. Authorised GFix personnel may record account status and internal notes for administration, safety, support, and compliance.
8. Authentication and Twilio Verify
GFix supports password and phone verification workflows. Passwords are stored as hashes, not readable passwords. Where Twilio Verify is enabled, GFix sends the phone number and verification purpose to Twilio to request and check a one-time code. GFix stores verification status, provider reference, timing and attempt information, and a hashed request-IP value for rate limiting and security. Twilio processes information under its own service terms and privacy practices.
9. Payments, Billplz, Wallet and Points
GFix records the service amount, selected backend payment option, adjustment, payable amount, payment status, provider and merchant references, and related job. Where Billplz is enabled, information needed to create and reconcile a payment is sent to Billplz, and GFix receives bill, transaction, status, and callback information. GFix does not ask the mobile app to calculate gateway adjustments or expose provider secrets. Manual payment proof remains a separate upload path where available.
Wallet credits, top-ups, refunds, points, awards, adjustments, and reward redemptions are recorded in account-linked ledgers. These records are used to calculate balances, prevent duplicate credits, investigate issues, and maintain financial and audit history.
10. Chat, Support and Ratings
Job chat stores message text, sender role, related job, read status, and timestamps. It is not described as end-to-end encrypted. Support tickets may contain subjects, descriptions, requested adjustments, replies, decisions, and related account or job information. Ratings and reviews are linked to a completed job and the relevant customer and technician.
11. Service Providers and Data Sharing
We share only information reasonably needed for the relevant function with service providers and operational recipients. Current provider categories include hosting and infrastructure providers, Twilio for phone verification when enabled, Billplz for payment processing when enabled, and map-tile or mapping services used to display maps. Customers and assigned technicians receive job information needed for service coordination, subject to role-based privacy rules. Information may also be disclosed where required by law, to protect users or GFix, or in connection with professional advice or a corporate transaction.
The inspected GFix application does not contain an advertising SDK or a general-purpose behavioural analytics SDK, and GFix does not use the audited implementation to sell personal data.
12. Internal GFix Personnel Access
Authorised administrators and internal service personnel may access information necessary for account review, technician approval, job support, payment verification, wallet and points administration, disputes, payouts, safety, security, audit review, and legal compliance. Admin access is session- and permission-controlled, and many sensitive actions create audit records.
13. Data Security
GFix uses measures including hashed passwords and session tokens, secure HTTPS transport in the deployed service, role and permission checks, protected file-download routes, request validation, rate limits, audit logging, and restricted provider credentials. No online system can guarantee absolute security. Users should protect their login credentials and notify us of suspected unauthorised access.
14. Data Retention
GFix retains information while it is needed to provide the service and for legitimate operational, payment, fraud-prevention, dispute, security, audit, accounting, and legal purposes. Different records may require different retention periods. The current system does not apply one automatic deletion period to every record. When data is no longer required, GFix will delete, anonymise, or restrict it in accordance with an approved retention process and applicable law.
15. Account Deletion and Data Requests
Customers and technicians can start a verified deletion request from Profile in the GFix app or review the process on the Account & Data Deletion page. GFix verifies account ownership before deactivating access and anonymising eligible account data. Transaction, fraud, dispute, security, audit, tax, accounting, and legal records may need to be retained or access-restricted.
16. Access and Correction
You may request access to or correction of your personal data by contacting admin@gfix.asia. We may ask for information needed to verify your identity and locate the relevant records. Requests are handled subject to applicable law and permitted exceptions.
17. Cookies, Sessions and Device Information
The Admin website uses a secure session cookie. Customer mobile authentication uses a secure local token, while technician mobile authentication uses a protected session credential. GFix may store session identifiers, expiry and revocation state, last-use time, device/platform labels when supplied, IP address, and user-agent details for security and administration. Public corporate pages do not use advertising cookies in the audited implementation.
18. Cross-Border Processing
Some providers may process or support information from infrastructure located outside Malaysia. Where this occurs, GFix will use the provider for the stated service purpose and take reasonable steps to require appropriate protection, subject to applicable Malaysian cross-border data requirements and the provider's contractual safeguards.
19. Children's Use
GFix is intended for people who can lawfully request or provide services. A person who does not have legal capacity to enter the applicable agreement should use GFix only with the involvement and authorisation of a parent or legal guardian. If we learn that personal data was provided without appropriate authority, contact us so the situation can be reviewed.
20. Changes to this Policy
We may update this Privacy Policy to reflect service, provider, legal, or security changes. The current version will be posted at this URL with an updated effective date. Where a material change requires additional notice or consent, GFix will use an appropriate in-app or account communication.
21. Contact Us
G Fix Technologies Sdn Bhd (1690023-T)
2, Jalan Impian 2, Taman Impian Skudai,
81300 Skudai, Johor, Malaysia
Email: admin@gfix.asia
Phone / WhatsApp: +60 12-696 6601