Privacy Policy
Effective Date: 23 July 2026
This Privacy Policy sets out the practices of Royouss Sdn Bhd, the operator of the Royouss mobile application and its related online services (referred to in this document as “Royouss,” “we,” “us,” or “our”). It explains what personal information we handle, why we handle it, who else sees it, how long we keep it, and the choices you have. The Royouss mobile application, our website at royouss.com (including any waitlist sign-up made available on it), and any associated features and surfaces operated by us, are referred to collectively in this document as the “Service.”
You should read this Privacy Policy alongside the Royouss Terms of Service and the Royouss Code of Conduct; together those three documents set the framework for your relationship with us. Where this Privacy Policy uses defined terms that are not separately defined here, they carry the meaning given in the Terms of Service.
Registering for an account, joining our waitlist, or otherwise using the Service is taken as an indication that you have read this Privacy Policy and accept how we describe our practices. If anything in it is unacceptable to you, the appropriate response is to refrain from using the Service.
1. Scope and Applicability
This Privacy Policy governs personal information that we handle in the course of providing the Service to you, regardless of whether you are visiting our website or joining our waitlist before launch, interacting with the community feeds, posting your own content, browsing or listing items on the Marketplace, sending direct messages to other users, or communicating with us for support.
The Service is intended for individuals aged sixteen (16) and older. We do not knowingly process personal information from anyone below that age, and if it comes to our attention that an account has been created by someone under sixteen, we will close the account and remove the associated personal information without unnecessary delay. To use the Marketplace — that is, to post listings, send or receive offers, or coordinate transactions with other users — you must additionally be old enough to enter binding contracts under the law of your country of residence.
The community side of the Service is available to users in most jurisdictions worldwide. Marketplace functionality is offered in supported jurisdictions only, and the availability of particular listings and features may vary based on your location and on applicable law.
Some third parties referenced in this Privacy Policy — for example, identity providers, push notification systems, website hosting and analytics providers, and infrastructure vendors — process personal information independently of us under their own privacy policies and legal arrangements. This Privacy Policy does not extend to their independent processing activities, only to the limited information that we receive from or send to them in order to operate the Service.
2. Royouss’s Role in the Platform
We operate the Service for two related but distinct purposes: hosting a content community focused on designer bags, and providing a peer-to-peer Marketplace where users can list bags for sale and contact one another to coordinate transactions. To support both of those purposes, we decide what personal information is processed and how it is processed in order to run accounts, store and display user-generated content, moderate the community, route Marketplace interactions, support safety reporting, and meet our operational and compliance obligations. Under the Malaysian Personal Data Protection Act 2010 (as amended, including by the Personal Data Protection (Amendment) Act 2024) (the “PDPA”) and equivalent frameworks elsewhere, we are therefore the data controller for the personal information described in this Privacy Policy.
Community functions. For the community side of the Service, we use personal information to set up and manage user accounts; receive, store, organise, and display posts, photographs, polls, reviews, pickup posts, daily-carry posts, comments, replies, and reactions; track follows, bookmarks, mutes, and blocks; rank and surface editorial content; respond to user reports; investigate suspected abuse; and otherwise maintain a safe, functional community space.
Marketplace functions. The Marketplace is operated as a listing board, not as a transactional platform. Our role is limited to publishing listings, helping prospective buyers and sellers find one another, enabling them to communicate through in-application direct messages, and capturing post-transaction reviews when users leave them. We do not collect payment, we do not hold funds in escrow, we do not arrange shipping or insurance, we do not verify the authenticity of bags, and we are not a broker, dealer, money transmitter, or financial institution. Transactions are arranged and settled directly between buyer and seller, off-Service.
Direct messaging functions. Direct messages are intended as a private channel for users to communicate with one another for community purposes and for Marketplace coordination. Only the participants in a conversation can see the messages exchanged in it, with limited exceptions described in this Privacy Policy (for example, when a message is reported, when moderation is required, or when disclosure is compelled by law).
How we operate the Service contractually is described in the Terms of Service. This Privacy Policy does not change or extend the role that the Terms of Service set out for us; it just describes the personal-information practices that flow from that role.
3. Categories of Information We Collect
We gather personal information in the categories described below. What we collect in any given case depends on which parts of the Service you use; not every category will apply to every user.
Website and waitlist information. While our app is in development, our website operates as a marketing page. During the waitlist period, if you choose to join our waitlist, the sign-up form collects the email address you submit. When you submit the form, we also generate a unique internal identifier (UUID) for our own record-keeping and record the date and time of your submission. We use this information solely to administer the waitlist and to contact you about the launch of the Service. Once the waitlist period ends and the form is replaced with app download links, the website collects nothing through the website itself and functions purely as a marketing page; from that point, the collection of personal information takes place within the app during onboarding, as described below. We may use a privacy-focused analytics tool provided by our website hosting provider to understand aggregate website traffic. This tool is designed not to require cookies or consent and does not track you across other websites or build an individual profile of you.
Account and identity information. Creating an account requires one or more authentication identifiers — typically a phone number, an email address, or an account identifier issued by Apple, Google, or Meta (Facebook), depending on which sign-in method you choose. We verify the phone number or email address you provide by sending a one-time passcode. We do not store user-chosen passwords ourselves; account credentials are held by the authentication infrastructure provider described later in this Privacy Policy.
Profile and onboarding information. When you set up your profile and walk through onboarding, you supply information that you intend to be associated with your account. That typically includes your full name, the username you select, an optional profile photograph, your date of birth, your gender (if you choose to share it), the country in which you live, how long you have been collecting bags, and the bag brands you indicate you are interested in. You can also opt in or out of push notifications during onboarding. Most of this information can be updated later through the in-application settings.
Community and content information. Using the social side of the Service generates content and engagement records that we store on your behalf. These include the posts, daily-carry submissions, polls (and poll choices), reviews, pickup posts, comments, and replies that you create, along with the photographs (up to eight per post), descriptive text, tags, and bag attributes (such as brand, model, size, colour, type, material, hardware, and production year) that you include. We also keep track of the reactions, bookmarks, follows, and poll votes attributable to your account, the mute and block lists you maintain, the drafts you save for later, the reports you file against other users or content, any feedback you submit through the “Share feedback” form (with the screenshots you choose to attach), and engagement signals such as items viewed and the times at which engagement occurred. This material is used to operate the community, enforce our policies, investigate reports, and protect users and the platform.
Collection information. If you maintain a bag collection on the Service, we store the bag entries you add, which can include photographs and a set of bag attributes such as brand, model, size, colour, type, material, hardware, production year, ownership status, and tags. You may also choose to attach private purchase records to a collection entry — the date and place of purchase, the purchase price and currency, a serial number, an uploaded image of the receipt, a warranty expiry date, and a history of ownership status changes. Private purchase records sit behind row-level access controls that limit visibility to the account that created them: they are not shown to other users, not surfaced in search, and not displayed in public profiles.
Marketplace activity information. When you participate in the Marketplace, we record the data that the listing flow requires from you — photographs of the item, asking price and currency, brand, model, condition, included accessories, country of location, preferred deal method (meet-up or shipping), an optional reference number, and any descriptive text you add. We also keep records of the offers exchanged in connection with a listing (the amount, the currency, and the offer’s status), the reviews left by buyers and sellers after a transaction is marked complete, and activity timestamps relating to listing creation, modification, and status changes. We do not capture payment credentials, financial-account information, government-issued identification, off-Service shipping addresses, or other transaction details that the buyer and seller exchange outside the Service.
Direct messaging information. Using direct messaging causes us to store the text and image content of the messages you send, the identifiers of the participants in each conversation, message timestamps, message reactions, and read-status indicators. We also store system messages that the Service issues automatically (for example, in connection with notifications or moderation). Direct messages are visible only to the participants of a conversation, with the limited exceptions noted in this Privacy Policy.
Device, technical, and usage information. Some information is captured automatically when you interact with the Service. This category covers your IP address, application and operating-system versions, device model, the push notification token issued by Apple Push Notification Service or Firebase Cloud Messaging once you grant notification permission, log files, session timestamps, and in-application interaction events. It also includes diagnostic and crash data captured by our error-monitoring infrastructure for the purpose of debugging the application and improving its stability. We use this category of information for security, fraud prevention, performance monitoring, analytics, and product improvement, and we aggregate or pseudonymise it where doing so is feasible.
Things we do not collect. We do not gather precise GPS location, the contact lists stored on your device, microphone audio, files outside the photographs you explicitly upload, or your browsing activity on websites and apps other than ours. The current version of the Service does not process payments, hold funds, or facilitate financial transactions, so we do not collect or store payment card numbers, bank-account details, or related financial credentials. We do not engage in cross-application tracking, we do not use third-party advertising identifiers, and we do not display third-party advertising in the current version of the Service.
If you decide not to supply certain personal information, some features of the Service may not be available to you.
4. How We Use Information
The processing activities we carry out are limited to what is reasonably necessary to deliver, maintain, secure, and improve the Service. The categories below describe how the personal information we collect is put to use in practice.
Running the Service. Personal information is used to authenticate users, set up and administer accounts, render feeds, deliver direct messages and notifications, operate Marketplace listing functionality, save and restore drafts, support reactions, comments, follows, and other community interactions, and provide the day-to-day functionality that users expect from the Service.
Operating the waitlist. Where you join our waitlist, we use the email address you submit, together with the internal identifier and submission timestamp we generate, to administer the waitlist and to notify you when the Service becomes available.
Personalisation. We use the brand interests you express, the country of residence you indicate, and your engagement signals to surface content and listings that are likely to be relevant to you, to order items within feeds, and to determine when curated editorial content should appear. Personalisation relies on first-party data only. It does not involve third-party advertising identifiers or cross-application tracking.
Trust, safety, and community integrity. Personal information is used to enforce the Terms of Service and the Code of Conduct, to triage and act on user reports, to detect spam, fraud, counterfeit listings, scams, harassment, and other harmful conduct, to investigate suspected violations, to take enforcement action against accounts (ranging from a warning through to permanent termination), and to protect the integrity of the community more generally. Automated tools may be involved in identifying potentially suspicious activity, but decisions that materially affect account access or carry enforcement consequences are reviewed by a person.
Communications with you. Personal information is used to send the transactional and operational notifications that the Service depends on — for example, telling you when someone has reacted to your post, replied to your comment, followed you, or sent you a direct message — as well as service announcements, security-related messages, and optional notifications you have opted in to (such as the Daily-carry reminder). You can manage notification categories in the in-application settings and, for push notifications, in your device’s operating-system settings.
Legal and regulatory compliance. Personal information may be processed to comply with our obligations under applicable law, to respond to lawful requests from regulators, courts, or law enforcement, to enforce our contractual rights under the Terms of Service, and to defend ourselves against legal claims.
Product and operational improvement. Personal information may be used for analytics, auditing, debugging, security monitoring, service improvement, and the protection of Royouss, our users, and third parties. We prefer to use aggregated, de-identified, or pseudonymised data for these purposes wherever doing so is workable.
The lawful bases on which we process personal information depend on the activity and on the jurisdiction in which you are located, and typically include the performance of the contract represented by the Terms of Service, our legitimate interests in operating and improving the Service safely, your consent (for example, when you submit your email address to join our waitlist, or in respect of push notifications), and compliance with legal obligations. Where a processing activity relies on your consent, you may withdraw that consent at any time without affecting the lawfulness of anything done before the withdrawal took effect.
5. How We Share Information
We do not sell personal information.
Personal information is shared only as described in this Privacy Policy, where required by law, or where the Terms of Service expressly authorise it. Sharing happens for limited reasons — typically to operate the Service, to meet our contractual or legal obligations, to protect users, or to maintain the integrity and security of the community.
Visibility to other users. Some of the information you provide is, by the nature of the Service, visible to other users. That includes your public profile (avatar, display name, username, biography, country of residence, follower and following counts, and account creation date), the posts, polls, reviews, pickup posts, daily-carry submissions, comments, public collection items, and active Marketplace listings you publish, and any reactions and bookmarks of yours that the Service surfaces through its features. Direct messages are visible only to the participants of the conversation. Private collection items, private purchase records, drafts, and your account settings are visible only to you and sit behind row-level access controls in our underlying database.
You should bear in mind that content you publish on the Service can be screenshotted, quoted, downloaded, or otherwise reshared by other users, and we have no way of recalling such copies once they exist. Deleting content later will remove it from our systems, but it cannot reach any copies that already exist elsewhere.
Service providers and infrastructure. A small set of third parties helps us run the Service. Each of them processes personal information only on our instructions and under written terms that include confidentiality obligations.
The database, the file storage that holds uploaded photographs, the authentication infrastructure, and the row-level access controls referenced above are operated for us by Supabase, Inc. SMS messages used to deliver one-time passcodes for phone-based sign-in are sent through Twilio Inc. or a comparable telecommunications carrier. When you choose to sign in with a third-party identity provider, the limited account identifier exchange needed to complete authentication is handled by Apple Inc., Google LLC, or Meta Platforms, Inc., depending on which provider you select, each acting under its own privacy policy. Push notifications are delivered to iOS devices through Apple Push Notification Service and to Android devices through Firebase Cloud Messaging, which is operated by Google LLC. The mobile application is built and distributed (and over-the-air updates are delivered) through Expo, Inc., which may also handle push notification delivery. Our website is hosted by our website hosting provider, which also provides the privacy-focused, aggregate website analytics referred to above and processes limited technical information (such as IP address) in order to serve and secure the website. Application errors and crash reports may be routed through a third-party error-monitoring service for debugging purposes.
If you use one of the third-party sign-in options, that provider will be aware that you are using Royouss, and anything that provider does beyond completing the sign-in is governed by its own privacy policy rather than ours.
Disclosures for legal, safety, and fraud-prevention reasons. We may disclose personal information where we believe in good faith that doing so is necessary to comply with a law, regulation, court order, subpoena, or other lawful governmental request; to enforce the Terms of Service, the Code of Conduct, or another agreement with users; to protect the rights, property, or safety of Royouss, our users, or the public — particularly when investigating fraud, counterfeit activity, scams, harassment, or comparable conduct; to address technical or security issues; or to defend against legal claims.
Corporate transactions. If Royouss is ever the subject of a merger, acquisition, financing, reorganisation, sale of assets, or insolvency proceeding, personal information may be transferred or disclosed as part of the transaction, subject to ordinary confidentiality undertakings. Where required, we will notify affected users — through the Service or by email — before the information becomes governed by a materially different privacy policy.
6. International Data Transfers
Royouss is operated from Malaysia, while many of our service providers process personal information from infrastructure they maintain in the United States, the European Union, and other locations. By using the Service from any country, you accept that your personal information will be transferred across these jurisdictions in order for the Service to function.
Before transferring personal data outside Malaysia, we satisfy ourselves that at least one of the bases permitted under the PDPA applies — in particular, that the receiving jurisdiction has in force a law that is substantially similar to the PDPA or otherwise ensures an adequate level of protection at least equivalent to that afforded by the PDPA. Where appropriate, we carry out a transfer impact assessment and put in place additional safeguards, such as the contractual confidentiality and data-protection undertakings included in our service-provider agreements. Where another applicable law requires further safeguards (for example, standard contractual clauses or an adequacy decision), we put those in place as well.
7. Data Retention
Personal information is kept for as long as it is needed to deliver the Service, comply with our legal obligations, resolve disputes, enforce agreements, and protect the integrity and security of the community.
Profile and account information is retained for the life of the account. If you delete your account through the in-application settings (or by written request), the personal information associated with it is removed from active systems within thirty (30) days, with limited exceptions for material we must hold longer in order to comply with a legal obligation, defend a legal claim, or enforce our rights. The posts, comments, listings, collection items, drafts, and other content you create are kept until you delete them or until your account is deleted, whichever comes first. Direct messages are kept until either participant deletes them. When an account is closed, its messages remain in the other participant’s conversation history but are no longer attributed to the closed account, and that conversation can no longer receive new messages.
Notifications generated by activity on the Service are kept for around ninety (90) days, or until you clear them. Server logs, security logs, and crash reports are kept for up to twelve (12) months, after which they are deleted or aggregated to strip out identifying elements. Records relating to user reports, moderation actions, and trust-and-safety investigations are kept for up to twenty-four (24) months after the matter is closed, so that we can identify patterns and apply our rules consistently. Records relating to banned accounts are kept indefinitely, so that we can prevent re-registration and protect the community from repeat violators. Where a banned account is subsequently deleted, that record is reduced to an irreversible one-way cryptographic hash of the email address and phone number used to register, together with the date and reason for the ban; it does not include your name, profile, or content, and it cannot be used to recover the email address or phone number from which it was derived. Records relating to a personal data breach are kept for at least two (2) years from the date of notification to the Commissioner, in line with the PDPA. Backup copies of production data persist for up to thirty (30) days after deletion from primary systems before being overwritten in the ordinary course of backup rotation.
When personal information is no longer required for any of the purposes that justified its collection, we delete it or, where deletion is not feasible, take steps to de-identify it.
8. Your Rights
Depending on the jurisdiction in which you live, and subject to our ability to verify your identity, you may exercise the following rights in respect of the personal information we hold about you: a right of access (to receive a copy of your personal information); a right of correction (to have inaccurate or incomplete information put right); a right of erasure (to have your personal information deleted); a right to restrict or object to certain processing activities; a right to portability (to receive your personal information in a structured, commonly used, machine-readable format); and a right to withdraw consent in respect of processing that relies on consent as its lawful basis.
Many of these things are within your direct control through the in-application settings — your profile and onboarding information can be edited there, your account can be deleted from the same place, and your notification preferences can be managed both inside the application and at the operating-system level. For requests that cannot be handled through the in-application controls, write to privacy@royouss.com, and we will respond within thirty (30) days or the period required by applicable law, whichever is shorter. We may ask you to reasonably verify your identity before acting on a request, and we may decline requests to the extent allowed by law — for example, where a request is manifestly unfounded, excessive, or would compromise the rights of other users.
If you are in Malaysia and feel we have not adequately addressed a privacy concern, you can lodge a complaint with the Personal Data Protection Commissioner (Pesuruhjaya Perlindungan Data Peribadi) of Malaysia. If you are in the European Economic Area or the United Kingdom, you can lodge a complaint with the data-protection authority in your country of residence.
Be aware that some content published on the Service is, by design, public to other users, and that deleting such content from the Service will not reach copies that other users may have made.
9. Security
We apply industry-standard technical and organisational measures to protect personal information against unauthorised access, accidental loss, alteration, and destruction. In practice that includes HTTPS and Transport Layer Security for all client-to-server traffic; encrypted storage of user credentials and one-time passcodes by our authentication infrastructure provider; row-level security policies in the database, so that users can read only the data they are entitled to (including private collection records, drafts, and direct messages, which are scoped to their owners); per-user folder scoping on file storage, so that uploaded photographs can only be written under the uploader’s own path; and limitation of internal access to production systems on a need-to-know basis.
Even with reasonable measures in place, no system is completely secure. If we become aware of a personal-data breach, we will notify the Personal Data Protection Commissioner of Malaysia as soon as practicable in accordance with the PDPA. Where the breach causes or is likely to cause significant harm to you, we will also notify you without unnecessary delay.
10. Push Notifications and Communications
If you grant notification permission, your device communicates a push token to Apple Push Notification Service or Firebase Cloud Messaging, and we store that token against your account so that we can send notifications to you. You can withdraw notification permission at any time through your device settings, and you can fine-tune which categories of notification we send through the in-application notification settings.
11. Analytics and Advertising
The current version of the Service does not display third-party advertising and does not use third-party advertising identifiers or cross-application tracking technologies. We may use first-party, privacy-preserving analytics — for example, aggregated information about how features are used and which screens are viewed, and aggregate website-traffic analytics provided by our website hosting provider that do not rely on cookies or build an individual profile of you — to inform product decisions. This Privacy Policy will be updated before any introduction of third-party advertising, advertising identifiers, or cross-application tracking.
In line with Apple’s privacy-manifest requirements, the categories of personal information we handle are disclosed in the App Store listing. If we were ever to introduce cross-application tracking on iOS, we would request your permission through Apple’s App Tracking Transparency framework before doing so.
12. Children
The Service is not directed to anyone under the age of sixteen (16), and we do not knowingly collect personal information from individuals younger than that. If you believe a child under sixteen has provided personal information to us, please write to privacy@royouss.com so that we can remove the account and its associated data.
13. Data Protection Officer
We have appointed a Data Protection Officer who is accountable for our compliance with the PDPA and who serves as the point of contact for matters relating to this Privacy Policy and your personal information. You can reach our Data Protection Officer at privacy@royouss.com.
14. Language
This Privacy Policy is published in English. A Bahasa Malaysia version is also available. In the event of any inconsistency or conflict between the English version and the Bahasa Malaysia version, the English version shall prevail to the extent permitted by applicable law.
15. Changes to This Privacy Policy
This Privacy Policy may be updated from time to time. If a change is material, we will alert users through the Service or by email and update the “Effective Date” at the top. Continued use of the Service after the effective date of an update is taken as acceptance of the updated Privacy Policy.
16. Contact
For questions, rights-related requests, or other communications about this Privacy Policy, please contact us at:
Royouss Sdn Bhd
[202601025008 (1687105-H)]
7-2, Plaza Danau 2, Jalan 2/109f,
Taman Danau Desa, 58100 Kuala Lumpur,
W.P. Kuala Lumpur, Malaysia.
privacy@royouss.com