Privacy Policy
Updated on: 4th May 2026
- INTRODUCTION
1.1 This Privacy Policy (“Policy”) is issued by Kumpool Sdn. Bhd. (Registration No. 1493722P / 202201048025) and Kumpool Singapore Pte. Ltd. (UEN No. 202339496Z) (collectively, the “Company”, “we”, “us”, or “our”) in accordance with the Personal Data Protection Act 2010 and all other applicable data protection laws.
1.2 This Policy governs the processing of Personal Data in connection with the Kummute mobility platform, including:
- Kumpool (on-demand ride pooling services)
- Kumride (e-hailing services)
- CB Taxi (cross-border Malaysia–Singapore transport services)
- KumCharter (chartered transport services)
- Kumpool for Business (enterprise mobility solutions)
(collectively, the “Services”) accessible via the Company’s website and mobile application (the “Platforms”).
1.3 By using the Services and/or providing your Personal Data to the Company, you consent to the collection, use, processing, and disclosure of your Personal Data in accordance with this Policy.
- PERSONAL DATA
2.1 Personal Data
“Personal Data” shall have the meaning ascribed to it under the Personal Data Protection Act 2010 and refers to any information in respect of commercial transactions that relates directly or indirectly to a data subject, who is identified or identifiable from that information or from that and other information in the possession of the Company.
This includes, without limitation:
- identity data (such as name, NRIC number, passport details);
- contact data (such as email address, telephone number, and residential or mailing address);
- financial and payment information;
- location, journey, and trip-related data;
- device, system, and technical information; and
- behavioural, transactional, and usage data.
2.2 Cross-Border Transport Context
In connection with the provision of cross-border transportation services (including CB Taxi and similar services), Personal Data may additionally include, where necessary for operational, regulatory, or compliance purposes:
- immigration and border control information (including passport, visa, and entry or exit details); and
- travel itinerary, routing, scheduling, and border crossing data.
2.3 Sensitive Personal Data
“Sensitive Personal Data” shall have the meaning ascribed to it under the Personal Data Protection Act 2010 and includes, without limitation, information relating to a data subject’s physical or mental health or condition, political opinions, religious beliefs, or any other categories prescribed under applicable law.
The Company may collect, use, and process Sensitive Personal Data, including, where applicable, biometric information (such as fingerprints, facial images, or other unique identifiers), strictly where:
(a) such processing is necessary for the purposes of security, identity verification, service provision, or compliance with legal or regulatory obligations; and
(b) the data subject has provided explicit consent, or such processing is otherwise permitted under applicable law.
The Company shall implement enhanced technical and organisational safeguards to protect Sensitive Personal Data against unauthorised or unlawful processing, accidental loss, destruction, damage, misuse, or disclosure, in accordance with applicable data protection laws.
2.4 National Identification Data
The Company shall only collect, use, or process national identification numbers (including NRIC numbers, passport numbers, or other government-issued identifiers) where such collection is required by applicable law, or where it is strictly necessary for the purposes of identity verification, safety, or regulatory compliance, including in connection with cross-border transportation services.
The Company shall implement enhanced security and access controls in respect of such data and shall not use such identifiers for purposes that are incompatible with or unrelated to the purposes for which they were collected.
Where applicable, such collection and use shall be carried out in accordance with relevant data protection laws and regulatory guidelines, including restrictions applicable to national identification numbers.
2.5 User’s Obligations
You are responsible for ensuring that all Personal Data provided to the Company is accurate, complete, and kept up to date. The Company shall not be liable for any consequences arising from inaccurate or incomplete Personal Data provided by you.
- COLLECTION OF PERSONAL DATA
3.1 Sources of Collection
Personal Data may be collected by the Company through various lawful means, including:
- directly from you, including when you create an account, submit information, or communicate with us;
- through your access to and use of the Services, including interactions with the Platform and related features;
- from third-party partners, including but not limited to payment processors, identity verification providers, and service integration partners; and
- from corporate clients or contracting entities, including in relation to users registered under corporate or enterprise accounts (e.g., Kumpool for Business).
3.2 Methods of Collection
The Company may collect Personal Data through various channels and technologies, including:
- the use of mobile applications, web platforms, and backend systems;
- location-based technologies, including GPS, Wi-Fi, and cellular network data;
- software development kits (SDKs), analytics tools, telematics systems, and other tracking technologies integrated into the Platform; and
- communications and interactions with the Company, including voice calls, messaging, emails, and customer support tickets.
3.3 Data Minimisation
The Company shall adhere to the principle of data minimisation, and shall collect, process, and retain only such Personal Data as is reasonably necessary and proportionate for the purposes disclosed, in accordance with applicable laws and regulatory requirements, including the Personal Data Protection Act 2010.
- PURPOSES OF PROCESSING
4.1 General Purposes
The Company may collect, use, process, and disclose Personal Data for purposes that are necessary or directly related to the provision of the Services, as well as for purposes permitted under applicable law, including but not limited to the following:
(a) Provision of Services (Core Functionality)
- facilitating ride matching, booking, and dispatch services (including Kumpool, Kumride, and related offerings);
- enabling route optimisation, ride-pooling, and allocation algorithms;
- coordinating cross-border transportation services (including CB Taxi); and
- managing charter services, fleet allocation, and scheduling operations.
(b) Safety, Security, and Compliance
- conducting identity verification and authentication of users, drivers, and partners;
- detecting, preventing, and investigating fraud, misuse, or unlawful activities;
- managing incidents, complaints, disputes, and investigations; and
- ensuring compliance with applicable laws, regulations, and licensing requirements, including transport, safety, taxation, and immigration laws.
(c) Payment, Billing, and Financial Processing
- processing payments, settlements, and refunds;
- issuing invoices, receipts, and financial records; and
- administering accounts, credit arrangements, and financial reconciliation.
(d) Customer Support and Communications
- providing customer support and assistance;
- communicating service-related updates, notifications, and transactional messages; and
- responding to queries, feedback, and complaints.
(e) Business Operations and Improvement
- performing data analytics, research, and service optimisation;
- monitoring platform performance, usage trends, and operational efficiency; and
- developing, enhancing, and improving products, features, and services.
(f) Enterprise and Corporate Services
- administering corporate or enterprise accounts (including Kumpool for Business);
- facilitating employee mobility tracking, reporting, and management for corporate clients; and
- generating aggregated and anonymised insights, including for ESG reporting, sustainability initiatives, and business intelligence.
(g) Marketing and Promotional Activities
- sending promotional materials, offers, newsletters, and marketing communications, where consent has been obtained or where otherwise permitted under applicable law; and
- conducting marketing analysis and campaign effectiveness assessments.
(h) Legal and Administrative Purposes
- enforcing the Company’s terms, policies, and contractual rights;
- complying with legal obligations, regulatory requirements, and lawful requests from authorities; and
- establishing, exercising, or defending legal claims or proceedings.
- LOCATION, TELEMATICS, AND TRIP DATA
5.1 Nature of Data Processed
Given the nature of mobility and transportation services, the Company processes location and trip-related data, including:
- real-time and historical geolocation data (e.g., GPS, Wi-Fi, and cellular signals);
- trip details, including routes, stops, and timestamps;
- vehicle, driver, and ride identifiers; and
- ride-pooling and matching data, including proximity and service zone information.
5.2 Use of Location Data (Kumpool Services)
For Kumpool and similar services, location data may be used to:
- group passengers within defined service radii or zones; and
- optimise routing, scheduling, and pooling efficiency within localised service areas.
5.3 Cross-Border Data Sharing (CB Taxi)
In connection with cross-border transportation services (including CB Taxi), location and trip-related data may be disclosed to relevant third parties, where required or permitted by law, including:
- immigration and border control authorities;
- transport regulators and enforcement agencies; and
- licensed cross-border operators or partners.
Such disclosures shall be carried out strictly in accordance with applicable legal and regulatory requirements.
- DISCLOSURE OF PERSONAL DATA
6.1 General Disclosure
The Company may disclose Personal Data to third parties where such disclosure is necessary or incidental to the purposes set out in Section 4, or otherwise permitted or required under applicable law. Such disclosure shall be limited to what is reasonably necessary and proportionate for the relevant purpose.
6.2 Categories of Recipients
Personal Data may be disclosed to the following categories of recipients:
(a) Service Providers and Partners
- third-party transport operators, drivers, and fleet partners for the purpose of providing transportation services;
- payment processors, financial institutions, and billing service providers for payment processing and settlement;
- identity verification, fraud prevention, and security service providers;
- technology service providers, including cloud hosting, data storage, analytics, and platform infrastructure providers;
(b) Corporate Clients and Enterprise Users
- corporate or enterprise customers (e.g., Kumpool for Business) for the purposes of account management, reporting, and employee mobility services, subject to applicable contractual safeguards;
(c) Regulatory and Government Authorities
- government agencies, statutory bodies, regulators, and enforcement authorities where disclosure is required to comply with applicable laws, regulations, or lawful requests, including transport, safety, taxation, and immigration authorities;
(d) Professional Advisers
- legal, financial, audit, and other professional advisers on a need-to-know basis for the purposes of compliance, risk management, or dispute resolution;
6.3 Cross-Border Disclosure
Given the nature of cross-border transportation services, Personal Data may be transferred to, accessed by, or disclosed to recipients located outside Malaysia, including in Singapore or other relevant jurisdictions.
The Company shall take reasonable steps to ensure that such recipients are subject to comparable data protection obligations and that such transfers are carried out in accordance with applicable data protection laws.
6.4 Disclosure in Business Transactions
In the event of a merger, acquisition, restructuring, or sale of assets, Personal Data may be disclosed or transferred to the relevant third party, subject to appropriate confidentiality and data protection safeguards.
6.5 Data Anonymisation
The Company may disclose aggregated or anonymised data (which does not identify any individual) for purposes including analytics, research, reporting, or business development. Such data shall not be considered Personal Data.
- CROSS-BORDER DATA TRANSFER
7.1 Due to the nature of cross-border transportation services (including CB Taxi), Personal Data may be transferred to, stored in, or accessed from jurisdictions outside Malaysia, including Singapore, in connection with the provision of the Services.
7.2 The Company shall take reasonable steps to ensure that any such cross-border transfer of Personal Data is carried out in accordance with applicable data protection laws, including the Personal Data Protection Act 2010, and that:
- such transfer is necessary for the performance of the Services or for purposes directly related thereto;
- the recipient is subject to legally enforceable obligations or contractual arrangements that ensure a level of protection comparable to that required under applicable data protection laws; and
- the transfer complies with relevant legal and regulatory requirements in both Malaysia and the receiving jurisdiction, including Singapore.
- SECURITY
8.1 Security Measures
The Company shall take practical and reasonable steps to protect Personal Data from any loss, misuse, modification, unauthorised or accidental access or disclosure, alteration, or destruction, in accordance with the security principle under the Personal Data Protection Act 2010.
8.2 Safeguards Implemented
Such security measures may include, without limitation:
- technical safeguards, including encryption, access controls, authentication mechanisms, and secure data storage systems;
- organisational measures, including internal policies, staff training, and confidentiality obligations; and
- physical security controls, where applicable, to prevent unauthorised access to systems and infrastructure.
8.3 Access Limitation
Access to Personal Data shall be restricted to authorised personnel, contractors, and service providers who have a legitimate business need to access such data for the purposes set out in this Policy, and who are subject to appropriate confidentiality obligations.
8.4 Third-Party Security
Where Personal Data is processed by third-party service providers, the Company shall take reasonable steps to ensure that such parties implement adequate security measures consistent with applicable data protection requirements.
8.5 Limitation of Liability
While the Company implements appropriate safeguards, no system of transmission or storage is completely secure. The Company shall not be liable for any unauthorised access, loss, or misuse of Personal Data arising from factors beyond its reasonable control, including cyberattacks or failures of third-party systems.
- RETENTION OF PERSONAL DATA
9.1 Retention Principle
The Company shall retain Personal Data only for as long as necessary to fulfil the purposes for which it was collected, or as required or permitted under applicable laws and regulations, including the Personal Data Protection Act 2010.
9.2 Retention Periods
Retention periods may vary depending on the nature of the data and the purposes of processing, including but not limited to:
- operational requirements, such as the provision of services and account management;
- legal and regulatory obligations, including record-keeping, tax, and compliance requirements; and
- dispute resolution and enforcement, including the establishment, exercise, or defence of legal claims.
9.3 Deletion and Anonymisation
Where Personal Data is no longer required for the purposes for which it was collected, the Company shall take reasonable steps to delete, destroy, or anonymise such data in a secure manner.
9.4 Backup and Residual Data
Notwithstanding the above, Personal Data may be retained in backup systems for a limited period, subject to appropriate safeguards, after which it will be securely deleted or overwritten in accordance with the Company’s data retention policies.
- DATA SUBJECT RIGHTS
10.1 Right of Access
Subject to the provisions of the Personal Data Protection Act 2010, you have the right to request access to your Personal Data held by the Company and to obtain information on how such Personal Data has been used or disclosed.
10.2 Right to Correction
You have the right to request the correction of any Personal Data that is inaccurate, incomplete, misleading, or not up to date. The Company shall take reasonable steps to ensure that such Personal Data is corrected promptly upon verification of the request.
10.3 Right to Withdraw Consent
Where the processing of Personal Data is based on your consent, you may withdraw such consent at any time by providing written notice to the Company. The withdrawal of consent shall not affect the lawfulness of processing carried out prior to such withdrawal.
10.4 Limitation and Consequences
You acknowledge that the exercise of certain rights, including withdrawal of consent or refusal to provide Personal Data, may affect the Company’s ability to provide the Services, and the Company shall not be liable for any inability to perform or limitation in service arising therefrom.
10.5 Requests and Verification
All requests for access or correction of Personal Data must be made in writing to the Company. The Company may require sufficient information to verify your identity and process your request, and reserves the right to charge a reasonable administrative fee as permitted under applicable law.
10.6 Exceptions
The Company reserves the right to refuse access to or correction of Personal Data in accordance with the provisions of the Personal Data Protection Act 2010, including where such refusal is permitted or required under law.
- AUTOMATED DECISION-MAKING
11.1 Use of Automated Systems
The Company may utilise automated processing systems and algorithms in connection with the provision of the Services, including for purposes such as:
- ride matching and allocation;
- dynamic pricing calculations and fare estimation; and
- fraud detection, risk assessment, and security monitoring.
11.2 Impact of Automated Processing
Such automated processing is implemented to enhance operational efficiency, service reliability, and user experience. Where such processing may have a material or significant effect on you, the Company shall take reasonable steps to ensure that such decisions are fair, proportionate, and subject to appropriate safeguards.
11.3 Rights of Data Subjects
Where applicable, you may request:
- a review of the decision by a human representative, where reasonably practicable; and
- further information or clarification on the general logic involved in such automated processing, to the extent permitted under applicable law.
- COOKIES AND TECHNOLOGIES
12.1 Use of Cookies and Technologies
The Platform utilises cookies, software development kits (SDKs), and other similar tracking technologies to collect and process information for purposes including:
- enabling core functionality and operation of the Platform;
- conducting analytics and usage measurement;
- supporting performance monitoring and optimisation; and
- delivering marketing, advertising, and promotional content, where you have provided your consent or where otherwise permitted under applicable law.
12.2 Nature of Cookies
Cookies are small text files that are placed on your device when you access or use the Platform. These technologies allow the Company to recognise your device, store preferences, and improve your overall user experience.
12.3 Third-Party Technologies
The Platform may also utilise cookies and similar technologies provided by third-party service providers, including analytics and advertising partners. Such third parties may collect and process information in accordance with their own privacy policies.
12.4 Control and Preferences
You may manage or disable cookies through your device or browser settings. However, please note that disabling certain cookies or technologies may affect the functionality, performance, or availability of certain features of the Platform.
- THIRD-PARTY LINKS
13.1 The Platform may, from time to time, contain links to, or integrations with, third-party websites, applications, or services (collectively, “Third-Party Services”) which are not owned, operated, or controlled by the Company.
13.2 The Company does not exercise control over, and shall not be responsible or liable for, the content, security, availability, or privacy practices of such Third-Party Services. The inclusion of any such links or integrations shall not be construed as an endorsement, recommendation, or representation by the Company of such Third-Party Services.
13.3 Any access to or use of Third-Party Services shall be at your sole risk, and you acknowledge and agree that the Company shall not be responsible for any loss, damage, or claim arising from or in connection with your use of such Third-Party Services.
13.4 You are advised to review the applicable terms of use and privacy policies of such Third-Party Services prior to providing any Personal Data or engaging with such services.
- CHILDREN
14.1 The Services are not directed to, and are not intended for use by, individuals under the age of eighteen (18) years.
14.2 The Company does not knowingly collect, use, or process Personal Data of individuals under the age of eighteen (18) years without the consent of a parent or legal guardian, or as otherwise permitted under applicable law.
14.3 If the Company becomes aware that Personal Data of a minor has been collected without such consent, the Company shall take reasonable steps to delete such data or obtain appropriate consent, in accordance with applicable laws.
- LIMITATION OF LIABILITY
15.1 To the fullest extent permitted by applicable law, the Company shall not be liable for:
- any indirect, incidental, consequential, special, or punitive losses or damages, including loss of profits, revenue, goodwill, or data;
- any loss, unauthorised access, or disclosure of Personal Data arising from events beyond the Company’s reasonable control, including but not limited to cyberattacks, system failures, or failures of third-party systems; and
- any acts, omissions, or defaults of third-party service providers, partners, or external platforms not under the direct control of the Company.
- AMENDMENTS
16.1 The Company reserves the right to amend, update, or revise this Policy from time to time at its sole discretion, to reflect changes in legal, regulatory, operational, or business requirements.
16.2 Any such amendments shall take effect upon publication on the Platform or through such other means of notification as the Company may deem appropriate. Your continued access to or use of the Platform following such amendments shall constitute your acknowledgement and acceptance of the revised Policy.
- DATA PROTECTION OFFICER
17.1 Contact Details
If you have any questions, concerns, or requests relating to this Policy or the processing of your Personal Data, including requests for access or correction, you may contact the Company’s Data Protection Officer at:
Email: cs@kummute.com.my
Telephone: +60127738840
17.2 Data Protection Officer
The Company has appointed a Data Protection Officer to oversee compliance with applicable data protection laws, including the Personal Data Protection Act 2010, and to handle inquiries and requests in relation to Personal Data.
17.3 Response Time
The Company shall use reasonable efforts to respond to all legitimate requests within a reasonable timeframe, and in any event in accordance with applicable legal requirements.
The Company reserves the right to request sufficient information to verify your identity before processing any request relating to Personal Data.