Applies to: the Hala mobile app and the Hala website at hala.my. Covers: booking a space (a court or a venue space) and booking a class. Last updated: 23 August 2026
1. Who we are
Hala is run by Hala Sport Sdn Bhd, a private limited company incorporated in Malaysia on 15 February 2023.
| Company registration number | 202301005030 |
| Former company number | 1498949-A |
| Registered address | 3-7-6, M City, Jalan Ampang, 55000 Kuala Lumpur, Malaysia |
| Website | hala.my |
| hello@hala.my | |
| Phone | +60 11-6112 0497 |
In Malaysian data protection law we are the data controller for the personal data described here. That means we decide what is collected and why, and we are answerable for it.
This document is our personal data protection notice under section 7 of the Personal Data Protection Act 2010.
You may see a different support email address on a few screens inside the app. We are correcting them. The address to use is hello@hala.my.
This notice also replaces the older privacy text still shown inside the app under Account Settings. That screen is out of date and is being updated. Where the two differ, this document is the one that applies.
2. What we collect, and why
We have split this into what you type in yourself and what the app records without being asked. This is our best account of everything we collect. If we find we have missed something, we will add it here and say so.
2.1 What you give us
When you create an account
| What | Why |
|---|---|
| Your full name | So a venue knows who is turning up |
| Your email address | To sign you in, and to send your booking confirmations and service email |
| Your phone number | Two things. First, so a venue or Hala can reach you about a booking. Second, it is how we confirm the account is yours: the one-time code is checked against this number, and it is the number you enter to reset a forgotten password. The app adds a Malaysian country code in front of the number you type |
| A password | To protect your account |
All four are required. You cannot create an account without them.
Later, if you choose to — on your profile screen
You can add a Facebook handle, an Instagram handle, a WhatsApp number, a short bio and a profile photo. None of these are required. Leave them blank and the app works exactly the same.
The same screen also lets you edit the name you gave at sign-up. That one is not optional — the app will not let you save an empty name.
Who can see these details. Nobody else, today. As the app is built now, there is no player search, no way to reach another person's profile, and the buttons that would let someone contact you directly are switched off. Your handles, bio and photo are stored on your account and shown back to you, and they are not displayed to any other Hala user. If that changes — if we ever switch on a player directory or a way for players to find each other — we will update this notice and tell you before it happens.
To let you set a profile photo, the app asks for permission to use your camera or your photo library. It only reads the one image you pick. See section 2.6.
When you make a booking
We record which venue, which court, space or class, the date and time, the price of each slot, any equipment you rent with the booking, and the status of the booking — for example confirmed or cancelled.
When you pay
We hold a record of the transaction: what the booking was, the amount, and whether the payment succeeded. We collect payment for a booking on the venue's or operator's behalf and pass it on to them, so handling payment is one of the reasons we process your data. Your card, online-banking or eWallet details are entered on the payment provider's own page — see section 4.
2.2 What the app records automatically
| What | What it actually is | Why |
|---|---|---|
| A device identifier | On iPhone, the identifier Apple gives our app for your device — specific to your phone, and reset if you delete all our apps. On Android, what the app currently sends is not a device identifier at all: it is the phone's operating-system build label, which is the same on every phone running that build and does not identify you | Sent to us in a separate request just after you sign in, along with your push token, and stored against your account so notifications reach the right device |
| A push notification token | A delivery address for your device. On Android it is issued by Google (Firebase Cloud Messaging). On iPhone it is issued by Apple (the Apple Push Notification service) | So we can send you a booking confirmation or reminder. See section 4 |
| A one-time code | A short code we send you when you sign up or reset your password | To confirm the account is yours. The code is tied to the phone number on your account — that is the identifier the app sends when it checks the code, and the phone number is also what you enter to reset a forgotten password |
Server records. Like any online service, our servers and the companies that host them record technical details of each request your app or browser makes: the IP address it came from, the time, and what was asked for. This is normal operational logging and we use it to keep the service running and to investigate problems.
Analytics. The Hala app installs no third-party analytics or crash-reporting kit — there is no Mixpanel, no Amplitude, no Segment, no Sentry and no Crashlytics. One exception we have to be straight about: the Android build of the app links Google Analytics for Firebase. Where that library is present it reports app-instance identifiers, sessions and screen views to Google automatically. The iPhone build has it switched off. Separately, the parts of Firebase we use for push notifications register an installation identifier with Google for every install of the app, on both platforms.
2.3 Where we get your information from
Most of what we hold comes from you, typed into the app. We also receive:
- From the venue or operator you booked with — confirmation that a booking stands, or that it has been cancelled or changed.
- From the payment provider — whether your payment succeeded, and a reference for it. Not your card number.
- From your phone's operating system — the push token and the device value described in section 2.2, issued by Apple or Google rather than typed by you.
We do not buy personal data, and we do not take it from data brokers, social networks or public listings.
2.4 What we do not collect
- We never ask you for a date of birth or your gender. Neither appears on the sign-up form or the profile screen.
- No card, bank or eWallet details are entered into Hala. You type them on the payment provider's own page, and Hala's app never reads or stores them.
2.5 Usage information
We look at aggregate measures, such as how many people use Hala on a given day, to decide what to build next.
This information is held anonymously. It is not attached to you or to your account. The same goes for any demographic information we use to make product decisions — it is held only in anonymous form.
We do not use any of it for advertising targeting. We do not sell it and we do not share it with advertisers.
2.6 Permissions the app asks for
- Camera and photo library. Asked for only so you can set a profile photo, and only on iPhone. On Android the app uses the system picker and asks for no permission at all.
- Location. The iPhone app's configuration file declares location access, including background location. There is no location code anywhere in the app and no location library installed, so the app does not read, send or store your location. This is a leftover declaration and it should be removed. The Android app declares no location permission.
- Background activity. The iPhone app declares background fetch and remote notification. The Android app declares internet access, vibration, and permission to restart notifications after your phone reboots. None of these collect personal data.
3. Our legal basis
Under the PDPA we process your personal data because:
- You consented. You gave us your details to open an account and to book.
- We need it to perform our contract with you. We cannot give a venue your booking without your name and a way to contact you.
- We have a legal obligation. For example, keeping the transaction records tax law requires us to keep.
Giving us your name, email address, phone number and password is obligatory — without them we cannot create your account or take a booking. Everything on the profile screen is voluntary and nothing happens if you leave it out.
4. Who we share it with
We do not sell your personal data. We share it only with the organisations below, only for the reason given.
| Who | What they get | Why |
|---|---|---|
| The venue or operator you book with | Your name, your contact details, and your booking details | So they know who is coming and can contact you about your booking |
| Heroku (Salesforce, Inc.) | Everything in section 2 — it hosts our servers and database today, so it holds all the account and booking data | Current production hosting. Its servers are outside Malaysia. See section 5 |
| Microsoft Azure | The same data, once the move is finished | We are moving our hosting to Azure. That move is in progress and not complete, so Azure does not hold your data yet. Its servers are outside Malaysia. See section 5 |
| SiteGround | The contents of the email we send you, including your email address and name | Hosts the mailboxes that send your verification code and service email |
| Your Android device's push token, an installation identifier for the app, and — on Android — the analytics signals described in section 2.2. Also the contents of the notification we send | Delivers push notifications to Android phones, and runs the Firebase components the app is built on | |
| Apple | Your iPhone's push token, and the contents of the notification | Delivers push notifications to iPhones |
| Billplz | Your name and email address, your Hala user ID and booking reference, and a description of what you are paying for — the venue, the slots and any equipment you added. Then, on their own page, your payment details: a card, an FPX online-banking login or an eWallet | Creates the bill and takes your payment |
| Vercel | The IP address, browser and request of everyone who visits hala.my | Hosts the website and builds its venue pages. See section 6 |
About payments. When you pay, the app opens the payment provider's own page inside a browser window in the app. You type your payment details into their page, not into Hala. Hala's own code never reads or stores your card number, expiry date or security code. How the provider handles what you type is governed by their privacy policy, not this one. Note that we send them your name, email address and booking reference before that page opens, so they can raise the bill.
We may also share personal data where the law requires it — for example a valid order from a court or a regulator.
5. Where your data is processed, and transfers out of Malaysia
Today our servers and database are hosted on Heroku, which is part of Salesforce. We are moving that hosting to Microsoft Azure. That migration is in progress at the time of writing — it is not finished, and Azure is not holding your data yet. We will update this notice when the move is complete.
Both Heroku and Azure are outside Malaysia. So are SiteGround, Google, Apple and Vercel. That means personal data described in this notice is transferred out of Malaysia.
Section 129 of the PDPA, as amended, no longer works from a government whitelist of approved countries. A transfer out of Malaysia now has to rest on a proper legal footing — for example that the receiving country has laws giving substantially similar protection, or that we have taken reasonable precautions such as binding contract terms with the recipient. We are telling you about these transfers here because the law requires that you be told.
6. The website
The Hala website at hala.my is a simple site.
- It sets no cookie.
- It loads no analytics, no advertising pixel and no tracker.
- It does not ask you to log in and has no sign-up form. The buttons that look like contact forms open your own email app or WhatsApp. Nothing is sent to us until you press send yourself.
- It saves the site's own display settings in your browser's local storage. That is the site's content, not information about you.
Three honest technical notes, because a careful reader would want them:
- The site's host receives your IP address and browser details on every visit, and builds the venue pages you see. That host is outside Malaysia.
- The site loads its fonts from Google Fonts. That is a request from your browser to Google's servers, which discloses your IP address and browser type to Google. It is not a tracker and it sets no cookie, but it is a third party seeing that you visited.
- The site fetches its own content — the venue directory and its layout settings — from a hosted database service. That store holds the site's content, not visitor personal data. But your browser makes the request, so that service's servers see your IP address.
A map on the site loads from Google Maps only if a map key has been configured. When it does, Google sees your IP address.
7. How long we keep things
| What | How long |
|---|---|
| Your account details | While your account is open |
| Transaction and payment records | 7 years, for tax and accounting, as published on hala.my. This applies even after your account is closed |
| Booking records that are not transaction records | While your account is open |
| Verification codes | They expire quickly and are then useless. |
| Push tokens and device identifiers | While your account is open, or until the device stops being used |
| Server and hosting logs | |
| Anonymous usage counts | Indefinitely. They are not linked to you, so they are not your personal data |
The PDPA's retention principle says personal data must not be kept longer than is necessary for the purpose it was collected for. When it is no longer needed, it should go.
8. Your choices — how to limit what we do
Beyond the formal rights in section 11, here is how you can actually turn things down:
- Push notifications. Turn them off in your phone's own settings, under notifications for the Hala app. We will stop sending them and your bookings still work.
- Optional profile fields. Your Facebook handle, Instagram handle, WhatsApp number, bio and photo are all optional. You can clear any of them at any time on the profile screen, including removing a photo you have already uploaded. Your name is the one field the app will not let you leave empty.
- Marketing email. If we send you marketing, every message carries an unsubscribe link, and you can also email hello@hala.my and tell us to stop. We must stop, and we will. Service messages about a booking you have made are not marketing and will continue while the booking stands.
- Everything else. Email hello@hala.my and tell us what you want us to stop doing. If we cannot run your account without it, we will say so plainly rather than quietly carrying on.
Other people's information. Please do not put someone else's personal details — their phone number, their photo, their name — into your bio or your profile fields without asking them first. If you tell us about another person in an email to support, we will use it only to deal with what you asked us about.
9. Cancellations and refunds
The refund rules for your session are set by the venue or operator you booked with, and we cannot overrule them. They differ from venue to venue.
We should also be straight that Hala applies a rule of its own today. When you cancel in the app, the app tells you that refunds are not given for cancellations caused by “user negligence or oversight”, that a refund from Hala will only be granted where the cause was a failure of the Hala app, and that you must supply proof such as a screenshot.
If you contact us about a cancellation, we will pass your request and the relevant booking details to the venue and follow it up.
None of this removes your rights under Malaysian consumer law, including the Consumer Protection Act 1999, which continue to apply whatever a venue's own policy says.
10. Security — and its limits
What we actually do:
- Traffic between the app and our servers goes over an encrypted connection. Every address the app talks to is HTTPS, and neither the iPhone nor the Android build allows an unencrypted exception.
- Payment card details never touch our systems (section 4).
Three weaknesses we know about, and are fixing. So that you are not asked to sign in every time you open the app, the app saves your email address and your password in its own storage on your device, and re-sends them to sign you in. The password is saved as ordinary text, not scrambled. On an iPhone that storage is included in iCloud and iTunes device backups, so the password can be copied off the phone in a backup; on Android, backups of the app's data are switched off. Separately, the app writes the details of each request it makes — including headers and, on sign-in, the password — to your phone's own device log, and it does this in the released app as well as in test builds. None of this is how it should be. We are saying it rather than letting you assume otherwise, and all three are on the list to fix: sign-in should use a token rather than a stored password, and the logging should be switched off in released builds. In the meantime, do not reuse a password that matters elsewhere.
What we are not going to claim:
- We do not claim your data is perfectly safe. No one can honestly claim that.
- We hold no security certification such as ISO 27001, and we are not saying we do.
If there is a breach. If personal data is lost or exposed, Malaysian law requires us to notify the Personal Data Protection Commissioner as soon as practicable, and in any case within 72 hours, where the breach causes or is likely to cause significant harm. If the breach is likely to cause you significant harm, we must also tell you, without unnecessary delay and within seven days of telling the Commissioner. We will do both.
11. Your rights, and how to use them
Write to hello@hala.my or WhatsApp +60 11-6112 0497. Tell us the name, phone number and email address on your account so we can find it and check the request really came from you.
Asking is free. We do not charge a fee for an access request.
We reply to access and correction requests within 21 days, which is the period the PDPA allows a data controller. For deletion requests we do better: see below.
| Your right | What it means |
|---|---|
| Access | Ask for a copy of the personal data we hold about you |
| Correction | Tell us something is wrong or out of date and we will fix it. Most of it you can edit yourself in the app |
| Withdraw consent | Tell us to stop processing your data. Some of it we need to keep the account running, so withdrawing consent will usually mean closing your account |
| Stop direct marketing | Tell us to stop sending you marketing and we must stop |
| Prevent processing that causes you damage or distress | Ask us to stop a specific use of your data on those grounds |
| Data portability | Ask us to transmit your personal data directly to another data controller. This right was added by the Personal Data Protection (Amendment) Act 2024 and applies where it is technically feasible and the formats are compatible |
| Deletion | See below |
Deletion
You can ask us to delete your account and the personal data attached to it, and we will carry that out in full. You do not need the app installed and you do not need to be signed in to ask.
There are two ways to ask, and a page that explains it:
- Email hello@hala.my with the subject "Delete my Hala account".
- Message us on WhatsApp at +60 11-6112 0497.
The account deletion page at hala.my/delete-account — the route the App Store and Play Store listings point to — explains the process and sends you to one of those two channels. There is no form on it.
Include the name, phone number and email address on the account.
Our timings, as published on hala.my: we acknowledge your request within 2 business days and complete it within 30 days.
What we keep. Transaction and payment records are kept for 7 years for tax and accounting, as set out in section 7. If anything else has to stay, we will tell you what it is and why.
Important, and please read this. The app has a "Delete Account" button in Account Settings. Its warning message says it will erase your account. As the app is built today, that button does not delete anything. It signs you out and clears the app's local storage on your phone. Your account and your data remain on our servers. This is a defect, not a policy. Until it is fixed, use one of the three routes above and we will act on the request in full.
12. Age
Hala is for people aged 18 and over. In Malaysia the age of majority is 18, and a person under 18 generally cannot enter into a binding contract. Accounts, bookings and payments are for adults.
If you are under 18, please do not create an account. An adult can make a booking in their own name and bring you along.
If we learn that an account belongs to someone under 18, we will close it and delete the personal data held on it, except anything we are required by law to keep. If you believe a child has given us personal data, email hello@hala.my and we will deal with it.
13. When and how you get this notice
The PDPA requires us to give you this notice when we first ask you for personal data, and at the latest when we first collect it.
We are not doing that properly yet, and we would rather say so. The sign-up screen in the app does not currently link to this notice or ask you to acknowledge it, and hala.my does not yet publish it. Today it reaches you only through the privacy screen inside the app, which is out of date. That is a gap we are closing:
14. Data protection officer, and registration
The Personal Data Protection (Amendment) Act 2024 requires a Data Protection Officer where an organisation processes the personal data of more than 20,000 people, or sensitive personal data including financial information of more than 10,000 people, or where its activities involve regular and systematic monitoring. Where a DPO is appointed, the Commissioner must be notified within 21 days, the DPO's contact details must be published, and the guidelines require a dedicated email address for the DPO — a general support address will not do.
Until this is settled, questions about your personal data should go to hello@hala.my.
15. Changes to this notice
We will update this notice when what we do changes — and the hosting move in section 5 is one such change already in progress.
When we change something that matters, we will change the date at the top and tell you in the app or by email before it takes effect. We will not quietly widen what we do with your data and hope you do not notice.
16. How to complain
Come to us first. Email hello@hala.my or call +60 11-6112 0497. Tell us what went wrong and we will look into it.
If we do not fix it, you can complain to the Personal Data Protection Commissioner:
Jabatan Perlindungan Data Peribadi (Department of Personal Data Protection) Website: www.pdp.gov.my
You can also take the matter to court. Complaining to us does not remove any other right you have.



Comments