Privacy policy

Here is the final version formatted as regular text so you can easily copy and paste it into your Shopify editor:

Privacy Policy

Last updated: June 24, 2026

Potty Grass Malaysia ("we", "us", "our") operates this store and website to provide you with our fresh grass products and subscription services ("Services"). This Privacy Policy describes how we collect, use, process, and disclose your personal information in strict compliance with the Malaysian Personal Data Protection Act 2010 ("PDPA"). By accessing our website, purchasing our products, or starting a subscription, you explicitly consent to the collection, processing, and storage of your personal data as described below.

1. Personal Data We Collect

We collect and process the personal information necessary to manage your account, process payments, and coordinate deliveries across Malaysia. This includes:

  • Contact Details: Your full name, shipping/delivery address, billing address, phone number, and email address.

  • Financial Information: Payment card details, transaction records, and payment confirmations. All payments are processed securely through encrypted third-party payment gateways; we do not store your raw credit card numbers.

  • Transaction and Support Data: The items you view, add to your cart, or purchase, as well as records of any communications you have with us regarding customer support.

  • Device and Usage Details: Information automatically collected through cookies, including your IP address, browser type, and interaction details with our website to optimize your browsing experience.

2. Purpose of Collecting and Processing Your Data

In accordance with the PDPA, your personal data is processed strictly for the following operational business purposes:

  • Fulfilling, dispatching, and tracking your fresh grass subscription and one-off orders.

  • Processing automated subscription payments, handling billing accounts, and managing your user portal.

  • Responding to customer service inquiries, dog potty management questions, or complaints.

  • Authenticating your account security and detecting, investigating, or preventing potential fraudulent or malicious activity.

  • Complying with accounting, tax, or legal obligations under Malaysian statutory law.

  • Providing optional marketing and promotional communications if you have explicitly chosen to opt-in to our brand newsletter.

3. Disclosure to Third Parties

To run our business and get your fresh grass to your doorstep, your data may be shared under strict confidentiality with necessary third-party service providers, including:

  • Contracted local third-party logistics and courier fulfillment partners operating within Malaysia.

  • Secure payment gateway providers (such as Stripe or Shopify Payments).

  • Technical vendors who provide website hosting, data analytics, and essential e-commerce tools.

  • Professional advisors (such as lawyers or auditors) or law enforcement authorities if required by statutory legal processes to defend our legal rights.

4. Data Security and Retention

We implement industry-standard administrative, technical, and physical security measures to safeguard your personal data against unauthorized access, alteration, loss, or misuse.

Your personal information will only be retained for as long as necessary to maintain your customer account, fulfill active subscriptions, resolve transaction disputes, or satisfy mandatory statutory financial reporting requirements under Malaysian law.

5. Your Rights and Choices Under the PDPA

Under the Malaysian PDPA, you maintain specific rights regarding your personal information, which are subject to certain legal limitations:

  • Right to Access / Know: You may request a copy of the personal information we hold about you.

  • Right to Correct: You may request that we update or correct any inaccurate personal details.

  • Managing Marketing Preferences: You may opt out of receiving promotional emails at any time by clicking the "unsubscribe" link inside our emails. We will still send you non-promotional transactional emails regarding your account or upcoming deliveries.

Mandatory Operational Notice: If you request the restriction, deletion, or withdrawal of data that is strictly essential for shipping logistics or automated payment processing, your active subscription services will be immediately canceled, and we maintain no liability for order refunds for unfulfilled deliveries resulting from your data removal request.

6. Children's Data

Our Services are not intended for use by children. We do not knowingly collect any personal data from individuals under the age of majority in your jurisdiction.

7. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect structural, legal, or regulatory updates. We will post any updated versions directly on this page and revise the "Last updated" date at the top.

8. Contact Us

Should you have any questions regarding our data privacy practices, wish to make updates to your details, or would like to exercise your user rights under the PDPA, please contact us directly:

  • Email: pottygrass@gmail.com

  • Mailing Address: 2A Changkat Duta Kiara, Kuala Lumpur, KUL, 50480, Malaysia