Press.
§ 07 / Privacy Policy

Your data, plainly accounted for.

This policy explains what personal data Press collects, why we process it, who we share it with, where it goes, how long we keep it, and the rights you can exercise, written to be read.

Press hand-builds a four-page website preview for you, free and with no obligation, within five working days; you pay only if you decide to keep it. To do that, we process some personal data about you. This Privacy Policy describes that processing in plain English and sets out the privacy choices you can exercise over your data.

Press is established in Malaysia, so our primary data-protection regime is the Personal Data Protection Act 2010 (PDPA, Act 709), as amended by the Personal Data Protection (Amendment) Act 2024. We offer the Service to customers worldwide. For California residents, this policy also describes rights under the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA). As a matter of Press policy, we offer a general baseline of privacy choices to all users wherever they live.

Note

This document is provided for transparency and is a DRAFT pending review by qualified counsel. It describes what each clause is designed to do and which right it provides; it is not a statement that Press "is compliant" with any particular law, and it is not legal advice. Where you and Press have signed a separate written agreement (for example, a Data Processing Agreement or a bespoke services contract), that signed agreement governs to the extent it conflicts with this policy. A Bahasa Melayu version of this notice will also be made available, as the PDPA requires a Notice & Choice statement in both Bahasa Melayu and English (PDPA s.7(3)).

01 Who we are (data controller)

The data controller responsible for your personal data, the "data controller" under the PDPA (a term renamed from "data user" by the 2024 Amendment), is:

  • Legal entity: PRESS STUDIO, trading as "Press"
  • Business registration (SSM): RA0136980-M
  • Registered address: available on the SSM register (Companies Commission of Malaysia)
  • Website: gopress.studio
  • Contact (all enquiries, including privacy and data-protection requests, and legal notices): support@gopress.studio

Our data-protection contact

For any question or request about your personal data, you can reach our privacy contact point at support@gopress.studio. This single contact point handles all access, correction, deletion, and other privacy requests described in this policy.

02 Scope of this policy

This policy covers personal data we collect and process through:

  • the Press website at gopress.studio and its sub-pages;
  • the preview-request (brief) form;
  • your Press account and sign-in (email/password or Google);
  • checkout, billing, and the Care Plan subscription;
  • the preview pages we deliver to you; and
  • our transactional emails and support correspondence.

What this policy does not cover. It does not cover the separate, independent websites that clients ultimately build, operate, or host for their own businesses. The content, visitors, and data of a finished website are controlled by the client, not by Press. Where Press hosts a website you have purchased under the Care Plan, Press may act as your data processor for the visitor data passing through that hosted site; that relationship is governed by a separate Data Processing Agreement rather than this policy. This policy also does not cover third-party websites or services we link to (such as Stripe, Google, or Resend), which have their own privacy policies.

Note

A Data Processing Agreement (DPA) for the hosted-website / processor relationship is not yet drafted. See Open Issues: counsel should prepare a controller-to-processor DPA (PDPA Security Principle s.9, which now binds processors directly) for Care Plan hosting.

03 Which law governs

Press is established in Malaysia, and Malaysian law, principally the PDPA, is the primary legal framework governing our processing of your personal data. Because we serve customers in the United States, this policy also gives effect to privacy rights under the CCPA/CPRA (and comparable US state laws) where they apply to you.

Nothing in this policy is intended to remove or limit any data-protection or consumer right you have under the laws of your own country that cannot be waived or excluded by agreement. Where a mandatory local right gives you greater protection than this policy describes, that right applies.

04 The data we collect, why, and how long we keep it

The table below maps each category of personal data we process to its purpose, the basis we rely on under the PDPA, and how long we keep it. The criterion is always that we keep data no longer than necessary for the stated purpose (PDPA Retention Principle, s.10).

Data categoryPurposeBasis (PDPA)Retention
Brief / contact data: your brand name, email, industry, the free-text "what goes in it" project brief, and an optional uploaded logo imageTo respond to your preview request, build and deliver your 4-page preview, and contact you about itPDPA: consent (General Principle s.6) and the steps you ask us to take; consent for any optional logoKept while we are building or discussing your preview, then deleted 6 months after the file is closed, or sooner on request (see Erasure below)
Account & authentication data: your name, email, and a password stored only as an argon2id hash (never in plain text); email-verification and password-reset tokensTo create and secure your account, sign you in, verify your email, and let you reset your passwordPDPA: consent (s.6); necessary for the service you requested and for account securityKept for the life of your account; short-lived tokens expire automatically; deleted 30 days after account closure
Google OAuth data (if you sign in with Google): Google account id, email, name, and avatar provided by GoogleTo let you sign in with Google instead of a passwordPDPA: consent (s.6); necessary for the sign-in service you requestedKept for the life of your account; deleted 30 days after account closure
Payment data via Stripe: we do not see or store full card numbers; card details are entered directly into Stripe. We store a Stripe customer id and display only the card brand and last 4 digits returned by StripeTo take the one-time keep-payment and to charge saved cards off-session for add-ons and the Care PlanPDPA: consent (s.6); necessary to perform your purchase, and to meet our fraud-prevention and tax/record-keeping obligationsCustomer reference kept while you have an account or active subscription; transaction records retained for 7 years for accounting/tax purposes (Malaysian record-keeping law)
Billing & invoice records: subscription, customer, invoice, and add-on records (amounts, dates, status, and a hosted Stripe receipt URL)To manage your subscription and add-ons, show your billing history, issue receipts, and keep financial recordsPDPA: necessary to perform the contract (s.6) and to meet our record-keeping obligationsRetained for 7 years for accounting/tax purposes
Uploaded logo & preview bundles: the logo you upload and the website preview files we build and store for youTo build, store, and serve your previewPDPA: consent (s.6); necessary to perform the serviceYour logo is kept with your brief file (deleted 6 months after the file is closed). An unsold preview is available for 7 days after we tell you it is ready; if you do not purchase within that window, the file closes and the preview files are deleted. A purchased preview is your delivered website and is kept for as long as we provide or host it for you. Everything is deleted sooner on request ("one email and it's gone")
Preview-views audit log: records of preview page views, the path viewed, and (when a signed email link is used) the recipient email; we also process your IP address / X-Forwarded-For headerTo attribute preview views to the right recipient, prevent abuse and theft of preview work, and apply rate-limiting and security controlsPDPA: consent (s.6); legitimate basis for security, fraud prevention, and protecting our workKept for a 30-day security window, then deleted or aggregated
Support & correspondence: emails and messages you send us, including any data you choose to includeTo answer your questions and provide supportPDPA: consent (s.6); legitimate basis for supporting customersKept as long as needed to resolve the matter and for 24 months after it is resolved
Transactional email metadata (via Resend): delivery status of the emails we send you (request received, preview ready, receipts, verification, reset, billing notices)To make sure important service emails reach you and to diagnose delivery problemsPDPA: necessary to perform the service (s.6); legitimate basis for deliverabilityKept for a 90-day operational window

Sensitive personal data. Press does not seek sensitive personal data, which, under the PDPA (as amended), includes biometric data used for identification, health, religious or philosophical beliefs, political opinions, and the commission of offences. Please do not include such data in your brief or correspondence. If we ever need to process sensitive personal data, we will obtain your explicit consent first (PDPA s.40).

Is providing your data obligatory?

Providing your data is voluntary: you choose whether to request a preview, create an account, or buy a website. However, some data is necessary for the part of the service you ask for: without a name and email we cannot respond to your brief or create your account; without payment data Stripe cannot process a purchase. If you choose not to provide the data marked as necessary for a given function, we will not be able to provide that function (PDPA Notice & Choice Principle, s.7(1)(e)–(f)).

Where we get your data

Most data comes directly from you. Some comes from third parties acting at your direction or on our behalf: Google (your profile details, if you sign in with Google) and Stripe (your card brand, last 4 digits, and payment outcomes). We disclose these sources so you know where your data originates (PDPA Notice & Choice Principle, s.7).

05 Keeping your data accurate

We take reasonable steps to keep the personal data we hold about you accurate, complete, not misleading, and up to date for the purposes for which it is used (PDPA Data Integrity Principle, s.11). Much of your data is data you give us directly, so the simplest way to keep it accurate is to update your account details or tell us about a change.

If you believe any data we hold about you is inaccurate or incomplete, you can ask us to correct it (see Your rights). We will correct it, or explain why if we are unable to, and we will pass corrections on to recipients of your data where that is required and practicable.

06 How we handle your password (HIBP check)

We never store your password in plain text. When you set or reset a password, it is converted to an argon2id hash, a one-way function, and only that hash is stored. We cannot recover your original password from it.

When you choose a password, we also check it against the Have I Been Pwned (HIBP) database of passwords exposed in known data breaches, using a privacy-preserving technique called k-anonymity: we compute the SHA-1 hash of your password locally and send only the first 5 characters of that hash to the HIBP range API. Your password, and its full hash, never leave Press's servers. HIBP returns a list of partial matches, and the comparison that determines whether your password is breached happens on our side. This protects your account by steering you away from compromised passwords, while disclosing nothing that could identify your password to a third party.

07 Cookies & local storage

Press currently uses only strictly-necessary and functional cookies, for example, the sign-in session cookie, the internal operator-console cookie, and the per-preview cookie that attributes a preview view to its recipient. Stripe may set its own cookies during checkout for fraud prevention. Press does not currently use any third-party analytics, advertising, or cross-site tracking cookies.

For the full list of cookies and storage, their purposes and durations, and how to control them, see our Cookie Policy. If we ever introduce non-essential cookies (such as analytics or advertising), we will ask for your prior opt-in consent before they load, where the law requires it.

08 Who we share your data with (sub-processors)

We share personal data only with the service providers we need to run Press, and only for the purposes below. We do not disclose your data for purposes you have not consented to (PDPA Disclosure Principle, s.8). Each provider acts as our processor and is bound to process data only on our instructions.

RecipientPurposeLocation
StripePayment processing; card storage for off-session charges; receipts and fraud preventionUnited States (and Stripe's global infrastructure)
ResendSending transactional email (request received, preview ready, receipts, verification, password reset, billing notices)United States
Google LLCOptional Google sign-in (OAuth), if you choose itUnited States
Amazon Web Services (AWS)Infrastructure hosting for our self-managed stack: the Press application, our self-hosted PostgreSQL database (application and account data), our self-hosted MinIO object storage (uploaded logos and preview bundles), and our self-hosted Kill Bill billing system all run on a single AWS EC2 instance we operateSingapore (AWS Asia Pacific, ap-southeast-1)
CloudflareNetwork and security layer: traffic to the Site is routed through Cloudflare's network (Cloudflare Tunnel / CDN), which processes visitor IP addresses and request metadata for routing and securityGlobal network (Cloudflare, Inc., USA)
Have I Been Pwned (HIBP)Breach-corpus check of passwords: receives only a non-identifying 5-character hash prefix, never your password or full hashOperated externally; no identifying data sent

Kill Bill (self-hosted). Our billing-orchestration system, Kill Bill, runs on Press's own infrastructure, the same AWS EC2 instance in Singapore described above, and is not a separate third-party data recipient. It does, however, instruct Stripe to charge your saved card for subscription and add-on invoices.

We may also disclose personal data where we are legally required to (for example, to comply with a court order, lawful regulator request, or applicable law), or to protect the rights, safety, and property of Press, our clients, or others, and to a buyer or successor in the event of a corporate reorganisation, merger, or sale, subject to this policy.

Note

Press does not sell your personal data, and does not share it for cross-context behavioural advertising. We do not trade, rent, or monetise your data with advertisers or data brokers.

09 International data transfers

Our production systems are hosted in Singapore (on Amazon Web Services), so the personal data we hold is stored outside Malaysia as a matter of course. Several of our other processors are based in the United States and elsewhere. Your personal data may therefore be transferred to, stored in, or accessed from outside Malaysia and outside your own country. Where this happens, we rely on one or more lawful bases for the transfer.

Under the PDPA (s.129, as amended in 2025)

The 2024 Amendment replaced the previous "whitelist" of approved destinations. We rely on one of the bases now permitted under s.129: that the destination has a law substantially similar to the PDPA or an adequate level of protection; your consent to the transfer; the transfer being necessary to perform our contract with you; or appropriate safeguards (such as contractual data-protection terms with the recipient and due-diligence / reasonable-precautions measures). [TRANSFER BASIS: confirm with counsel which basis applies to each overseas recipient.]

In practice, our overseas processors are bound by their own data-processing terms, and we ask them to apply protections consistent with the PDPA's principles to the data they handle for us. You can ask us for more detail about the safeguards used for a specific transfer by emailing support@gopress.studio.

Our overseas recipients, and the jurisdictions where they process personal data, are:

  • Amazon Web Services: Singapore (infrastructure hosting: our database, file storage, and billing system);
  • Stripe: United States (payments);
  • Resend: United States (transactional email);
  • Google: United States (optional OAuth sign-in);
  • Cloudflare: global network (traffic routing and security).
Note

The precise PDPA s.129 transfer basis and the contractual safeguards for each recipient listed above remain to be confirmed with counsel.

10 Data retention & deletion

We keep personal data only as long as necessary for the purposes set out above, after which we delete it or irreversibly anonymise it (PDPA Retention Principle, s.10). Specific retention periods are listed in the data table above; some are marked for the owner to confirm with counsel, including records we must keep for accounting and tax reasons.

"One email and it's gone": deletion on request

Consistent with our public promise, you can ask us to delete the personal data tied to your request (your brief, draft, and uploaded logo) by emailing support@gopress.studio. On a verified request we will delete that data and confirm when it is done, except where we are required or permitted by law to retain certain records (for example, financial records for tax purposes, or data we need to defend a legal claim). We will tell you if any exception applies and what we are keeping and why.

11 How we protect your data

We take practical technical and organisational measures designed to protect personal data against loss, misuse, and unauthorised access, modification, or destruction (PDPA Security Principle, s.9, which, since the 2024 Amendment, also directly binds our processors). These measures include:

  • Password hashing: passwords are stored only as argon2id hashes, never in plain text, and weak/breached passwords are screened via the HIBP k-anonymity check;
  • Encryption in transit: data moving between your browser and our servers, and between us and our processors, is protected using HTTPS/TLS;
  • No card storage: full card numbers are handled by Stripe and never stored on Press's systems;
  • Signed, short-lived asset URLs: preview assets are served through opaque, time-limited signed URLs so saved pages stop working shortly after viewing;
  • Watermarking and noindex: preview pages carry a watermark and noindex headers to deter copying and indexing;
  • Access controls and audit logging: access to systems and data is restricted, and a preview-views audit log helps us detect abuse;
  • Vendor diligence: we use established processors (Stripe, Resend, Google, Cloudflare, and Amazon Web Services) with their own security programmes.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We work to protect your data but cannot promise it can never be compromised. If you believe your account or data has been affected, contact us at support@gopress.studio.

12 Your privacy choices

Depending on where you live and which law applies, you have rights over your personal data. We honour the choices below; some are offered to all users as a matter of Press policy, some are statutory rights under Malaysia's PDPA, and some are specific to a particular US regime.

Privacy choices we offer to everyone

As a matter of Press policy, wherever you live, you can ask us to:

  • Access the personal data we hold about you and get a copy of it;
  • Correct data that is inaccurate, incomplete, misleading, or out of date;
  • Delete the personal data tied to your request or account ("one email and it's gone"), subject to records we must keep by law;
  • Withdraw consent at any time (withdrawing consent may mean we can no longer provide part of the service).

These are choices Press chooses to extend to all users; they are not a representation that any particular foreign data-protection law applies to you. We will act on a verified request as described under How to exercise your choices below, except where we are required or permitted by law to retain certain data.

Rights under Malaysia's PDPA

  • Right to be informed via a written Notice & Choice statement, in both Bahasa Melayu and English (s.7);
  • Right of access: to ask whether we hold your personal data and to obtain a copy (Access Principle s.12; data access request s.30);
  • Right to correction: to have inaccurate, incomplete, misleading, or out-of-date data corrected (s.34);
  • Right to withdraw consent at any time (s.38); withdrawing consent may mean we can no longer provide part of the service;
  • Right to data portability (new s.43A, in force from 1 June 2025): to ask us to transmit your personal data to another data controller, where technically feasible and the format is compatible;
  • Right to prevent processing likely to cause you damage or distress (s.42);
  • Right to prevent direct-marketing processing: to require us to stop using your data for direct marketing (s.43).

Your California privacy rights (CCPA / CPRA)

If you are a California resident, you have the following rights, subject to the verification and exceptions in the CCPA/CPRA:

  • Right to know the categories and specific pieces of personal information we collect, the sources, the purposes, and the categories of third parties we disclose it to;
  • Right to delete personal information we hold about you;
  • Right to correct inaccurate personal information;
  • Right to opt out of the "sale" or "sharing" of personal information;
  • Right to limit the use and disclosure of sensitive personal information;
  • Right to non-discrimination: we will not deny you service, charge a different price, or give you a lesser experience for exercising your privacy rights.

We do not "sell" or "share" your personal information as those terms are defined under the CCPA/CPRA, and we do not use or disclose sensitive personal information for purposes that would trigger the "limit" right. Because we do not sell or share, we do not display a "Do Not Sell or Share My Personal Information" link; if our practices ever change, we will add the required link and notice. The categories of personal information we collect, and the purposes for collecting them, are set out in the data table above, which serves as our Notice at Collection. We will treat a valid Global Privacy Control (GPC) browser signal as an opt-out request if and when our processing ever involves a sale or share.

Note

Whether the CCPA/CPRA applies to Press depends on revenue and data-volume thresholds. The owner should confirm Press's scale against the current thresholds with counsel; this section is drafted to surface California rights regardless, which is consumer-protective.

Other US states

Residents of certain other US states (such as Virginia, Colorado, Connecticut, and Texas) have similar rights to access, correct, delete, and opt out. You can exercise those rights using the same contact details below, and we will respond as the applicable law requires.

How to exercise your choices, and our timelines

To exercise any choice, email [support@gopress.studio](mailto:support@gopress.studio). To protect your data, we may need to verify your identity before acting. We will respond:

  • PDPA: within the period required by the PDPA for access and correction requests (we aim to respond as soon as practicable);
  • CCPA/CPRA: within 45 calendar days, extendable once by a further 45 days with notice;
  • General choices (offered to all users): we aim to respond as soon as practicable, and in any event within 45 days.

Exercising these choices is free in most cases; we may charge a reasonable fee or decline a request only where the law allows (for example, manifestly unfounded or excessive requests).

13 Children's data

Press is intended for adults running or starting a business. The service is not directed to minors: you must be at least 18 years old (the age of majority in Malaysia) to enter into a contract with us, and we do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, contact support@gopress.studio and we will delete it.

14 Automated decision-making & profiling

Press does not make decisions about you that produce legal or similarly significant effects based solely on automated processing. The HIBP password check and our security/rate-limiting controls are automated safeguards, but they do not profile you or make significant decisions about you in a way that has legal effect. Our previews are hand-built by people.

15 Data breach notification

If a personal data breach occurs, we will assess it promptly and respond as the law requires.

Under the PDPA (new s.12B and the 2025 Data Breach Notification Guideline), where a breach causes or is likely to cause significant harm, we will notify the Personal Data Protection Commissioner as soon as practicable and in any event within 72 hours of the breach, and notify affected individuals without unnecessary delay (and in any event within 7 days of notifying the Commissioner).

Our processors are required to notify us without undue delay if they experience a breach affecting your data.

16 Changes to this policy

We may update this policy from time to time, for example, as our services evolve, as we add or change processors, or as the law develops (Malaysia's 2024 PDPA Amendment continues to roll out through staged guidelines, and worldwide privacy and subscription rules continue to change). When we make a material change, we will post the updated policy on this page and, where appropriate, notify you by email or an on-site notice; changes take effect when posted. We encourage you to review this page periodically.

17 Complaints & contact

If you have a question or concern about how we handle your data, please contact us first at support@gopress.studio. We would like the chance to put things right.

You also have the right to complain to a data-protection authority:

  • Malaysia: the Personal Data Protection Commissioner / Department of Personal Data Protection (Jabatan Perlindungan Data Peribadi, JPDP), Ministry of Digital, Level 8, Galeria PjH, Jalan P4W, Persiaran Perdana, Precinct 4, 62100 Putrajaya; complaint email aduan@pdp.gov.my; call centre 03-7456 3888; or the JPDP online complaint channel at pdp.gov.my;
  • California: the California Privacy Protection Agency or the California Attorney General.

For related terms, see our Terms of Service, Cookie Policy, and Refund & Subscription Terms.

§ The rest of the paperwork