Privacy Policy
How GOIE collects, uses and protects your personal data, in line with Malaysia's Personal Data Protection Act 2010 (PDPA).
Last updated 7 October 2026
1. Who we are
GOIE is the vendor and event-operations platform run by Foodie ("we", "us"). Foodie decides how and why your personal data is processed on GOIE.
This policy covers the GOIE website and vendor portal. Each event may also have its own terms and conditions, which you accept separately when you book a booth.
2. Personal data we collect
Depending on how you use the platform, we collect:
- Account details: your name, email address and password (stored only as a secure one-way hash). If you sign in with Google, we receive your name, email address and Google account identifier, never your Google password.
- Vendor business details: business and legal name, SSM registration number, tax and SST numbers, business address, contact person, business email, phone and WhatsApp number, operating regions, cuisine, menus, product photos, logo and social media links.
- Compliance documents you upload, such as your SSM certificate, food handler certificates, typhoid vaccination records, halal certificate and food licence.
- Event activity: applications, answers to Foodie's questions, booth bookings, add-ons, accepted event terms, invoices, payment receipts you upload, deposit and refund records, and daily sales reports.
- Records Foodie creates about vendors: review decisions, internal notes, social media and content reviews, and post-event performance ratings.
- Enquiries you send us, for example about a duplicate SSM registration, and our replies.
- Technical data: the date, time, IP address and browser of security-relevant actions (such as signing in or accepting event terms), and the cookies described in section 7.
If you browse public events without an account, we only use the cookies needed to run the site.
3. How we use your data
- To create and secure your account, verify your email address and let you sign in.
- To review and verify vendor businesses and their documents before they can take part in events.
- To process event applications, allocate booths, issue invoices, verify payments, hold and refund security deposits, and handle cancellations.
- To send you service emails, such as email verification, password resets, application decisions, payment confirmations and event announcements.
- To plan and run events, including sharing event briefings and assessing vendor performance after an event.
- To keep financial, audit and operational records, meet our legal and tax obligations, and prevent fraud or misuse.
- To improve the platform and our events using aggregated information.
We do not sell your personal data, and we do not send marketing emails without your consent.
5. Data stored outside Malaysia
Our servers and file storage are located in Singapore, and some service providers may process data in other countries. We only use providers that protect personal data to a standard comparable to the PDPA.
6. How long we keep it
We keep account and vendor business data for as long as your account is active and as needed to provide the service.
Booking, invoice, payment, deposit and refund records are kept for at least seven years to meet Malaysian tax and accounting requirements. Audit history, review decisions and ratings are kept so that past events remain accurate, even if a vendor business is later suspended.
8. How we protect it
Data is encrypted in transit. Passwords are stored only as secure hashes, sign-in links and tokens are stored only in hashed form, private documents are served through short-lived links, and staff access is permission-based and recorded.
No system is completely secure. If a breach affects your personal data, we will notify you and the authorities as the law requires.
9. Your rights
Under the PDPA you may:
- ask for a copy of the personal data we hold about you;
- ask us to correct data that is wrong, incomplete or out of date (most of it you can edit yourself in your profile);
- withdraw your consent or ask us to limit how we use your data, although we may then be unable to provide some services;
- ask us to transfer your data to you or another provider, where the law gives you that right.
To make a request, use Help & Support in your GOIE account. We may need to confirm your identity first and will reply within the time the law requires. We may keep records we are legally required to keep.
Providing your personal data is voluntary, but we need the details marked as required to create an account, review a vendor business or process a booking.
10. Children
GOIE accounts are for people aged 18 and over. We do not knowingly collect data from children.
11. Changes to this policy
We may update this policy. The date at the top shows the latest version, and we will tell you by email or on the platform about important changes.
12. Contact us
For privacy questions or requests, use Help & Support in your GOIE account.
If there is any difference between the English and Bahasa Malaysia versions of this policy, the English version applies.
See also our Terms of Service.