Privacy Policy
Last updated: 30 July 2026
Jemput (jemput.io) is operated by Kin Solutions Sdn. Bhd. (Company No. 202201046506 (1492203-H)) (“we”, “us”). This policy explains how we handle personal data under Malaysia’s Personal Data Protection Act 2010 (PDPA). By using Jemput you agree to this policy.
1. Data we collect
- Account data — your email address and login credentials when you create an account.
- Event content — everything you add to your invitation: names, dates, venues, photos, music, videos and messages.
- Guest data — guest names, phone numbers, party sizes, dietary needs, seating, attendance, wishes and (if you enable it) gift records, whether entered by you or submitted by guests through the RSVP form.
- Payment data — payments are processed by Stripe. We never see or store your card or bank details; we keep only the payment reference and tier purchased.
- Technical data — hashed IP addresses used solely for spam and abuse prevention (rate limiting), and essential cookies for login sessions.
- Waitlist & enquiries — contact details you choose to leave us.
2. Guest data — a shared duty
Couples (account holders) provide their guests’ details and are responsible for having the right to do so. We process guest data only to run the couple’s event — RSVP collection, seating, check-in, and on-screen displays at the venue. We never contact guests ourselves, never send guests marketing, and never sell or share guest data with anyone other than the couple who invited them.
3. How we use data
To provide the service (invitations, RSVPs, wedding-day tools), to process payments, to prevent abuse, to respond to support requests, and to meet legal obligations. We do not sell personal data. We do not run advertising. We do not email guests.
4. Where data lives
Data is stored with trusted infrastructure providers: Supabase (database and file storage), Vercel (hosting) and Stripe (payments). These providers may store data on servers outside Malaysia; each maintains industry-standard security certifications. Invitation pages are private-by-default: they are not indexed by search engines, and guest lists are visible only to the account holder.
5. Retention
Your invitation and event data stay available for as long as we operate the service — that’s part of what you pay for. You may delete your event or account at any time, and you may ask us to erase specific guest records. Anti-spam technical logs are kept briefly and purged automatically.
6. Your rights
Under the PDPA you may request access to, correction of, or deletion of your personal data, and withdraw consent to processing. Guests may also contact us to have their details corrected or removed from an event; we may involve the couple to verify the request. Write to us using the contact below and we will respond within a reasonable time.
7. Security
All traffic is encrypted (HTTPS). Database access is protected by row-level security so each couple can only reach their own event. Payment credentials never touch our servers. No system is perfectly secure, but we design for privacy first — including never exposing guest phone numbers in links or public pages.
8. Changes & contact
We may update this policy from time to time; material changes will be posted on this page with a new date. Questions or requests: support@jemput.io.
Kin Solutions Sdn. Bhd. (Company No. 202201046506 (1492203-H)), a Beyonary company, Malaysia.