Legal
Privacy Policy
Last updated: 12 April 2026
TWELL (“we”, “us”, “our”) is a startup ecosystem platform accessible at tinkerwell.com. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the TWELL platform.
We are committed to complying with the Malaysia Personal Data Protection Act 2010 (PDPA) and handling your data responsibly.
1. Data We Collect
- Email address— provided when you sign in via magic link authentication.
- Profile information— any data you submit when claiming or editing a startup, investor, or grant profile on the platform.
- Browsing behaviour— pages visited, search queries, and feature usage within the TWELL platform. This data is collected server-side and is not shared with any third-party analytics provider.
2. Directory Data from Public Sources
The TWELL directory is seeded with publicly available information from government and regulatory sources including MYStartup.gov.my, the Companies Commission of Malaysia (SSM), and HRD Corp. This data — such as company names, registration numbers, and publicly listed contact details — is used to populate directory listings.
If you represent an organisation listed in our directory, you may claim and manage that profile. See Section 5 below.
3. How We Use Your Data
- To authenticate you and maintain your session.
- To display and manage your claimed profiles.
- To improve the platform based on aggregated, anonymised usage patterns.
- To communicate with you about your account or significant changes to the platform.
4. Data Storage and Security
Your data is stored in a Supabase-managed PostgreSQL database hosted in the US East (Virginia) region. Supabase provides encryption at rest and in transit, row-level security policies, and regular backups.
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse.
5. Profile Claiming and Data Ownership
TWELL allows authorised representatives to claim directory profiles for their organisations. Once a profile is claimed, the claimant can edit the listing, add additional details, and control what information is publicly displayed.
Data you submit through the profile claiming process is considered user-generated content. You retain ownership of the content you provide, and you grant TWELL a licence to display it on the platform.
6. Cookies
TWELL uses only essential cookies required for authentication and session management. We do not use tracking cookies, advertising cookies, or third-party cookie-based analytics.
7. Third-Party Analytics and Tracking
We do not use Google Analytics, tracking pixels, or any third-party analytics service. We do not serve advertisements. Your browsing data stays within our platform infrastructure.
8. Data Sharing and Selling
We do not sell, rent, or trade your personal data to any third party. We may share data only when required by law or to comply with a valid legal process under Malaysian law.
9. Your Rights Under the PDPA
Under the Malaysia Personal Data Protection Act 2010, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Withdraw consent for processing (which may affect your ability to use certain features).
- Request deletion of your account and associated data.
To exercise any of these rights, contact us at the address below.
10. Data Retention
We retain your account data for as long as your account is active. If you request account deletion, we will remove your personal data within 30 days, except where retention is required by law.
Directory data sourced from public records may be retained independently of any user account.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via the platform or by email to registered users. The “Last updated” date at the top of this page reflects the most recent revision.
12. Contact Us
For privacy-related enquiries or data access requests, contact:
Email: privacy@tinkerwell.com