Privacy Policy
Last updated: March 2026
Chao Events ("we", "our", or "us") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your information when you use our ticketing platform.
1. Information We Collect
We collect the following types of information:
- Email address — provided during ticket purchase for order confirmation and ticket delivery.
- Last 4 digits of your NRIC/Passport — collected for identity verification at event entry. We do not store your full identification number.
- Payment information — payments are processed entirely by our payment partner (Billplz). We do not collect, store, or have access to your credit card numbers, bank account details, or other financial information.
- Usage data — we may collect non-personally identifiable information such as browser type, device type, pages visited, and interaction patterns to improve our Service.
2. How We Use Your Information
Your personal information is used to:
- Process and fulfil your ticket orders.
- Send order confirmations, tickets (QR codes), and event updates to your email.
- Verify your identity at event check-in.
- Provide customer support and respond to inquiries.
- Improve the Service, analyse usage trends, and enhance user experience.
- Comply with legal obligations and enforce our Terms of Service.
3. Data Storage and Security
Your data is stored securely using industry-standard encryption and security measures. We use secure hosting infrastructure and implement appropriate technical and organisational safeguards to protect your personal data against unauthorised access, alteration, disclosure, or destruction.
While we take reasonable steps to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data.
4. Data Sharing
We do not sell, rent, or trade your personal information. We may share your data only in the following circumstances:
- Event organisers — we share attendee information (name, email, ticket details) with the respective event organisers for event management and entry verification purposes.
- Payment partner — your payment is processed by Billplz under their own privacy policy and terms.
- Legal requirements — we may disclose your information if required by law, regulation, legal process, or government request.
5. Your Rights Under PDPA
Under the Malaysian Personal Data Protection Act 2010 (PDPA), you have the right to:
- Access your personal data held by us.
- Request correction of inaccurate or incomplete data.
- Withdraw consent for processing your personal data (which may affect our ability to provide certain services).
- Request deletion of your personal data, subject to legal retention requirements.
To exercise any of these rights, please contact us via WhatsApp or through the contact information on our website.
6. Cookies
We may use cookies and similar technologies to enhance your browsing experience, remember your preferences, and analyse site traffic. Session cookies are used to maintain your session during the ticket purchase process. You can control cookie settings through your browser preferences, though disabling cookies may affect certain functionalities of the Service.
7. Data Retention
We retain your personal data for as long as necessary to fulfil the purposes for which it was collected, including order records, legal compliance, and dispute resolution. Order and ticket data is typically retained for a minimum of 7 years in accordance with Malaysian business record-keeping requirements.
8. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or via email. We encourage you to review this policy periodically to stay informed about how we protect your data.
9. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us via WhatsApp or through the contact information provided on our website.