1. Who is responsible and how to contact us
Good Earth Construction Sdn Bhd (BRN 199401016482), operator of the Nomad Shophouse, is the data controller for the processing described in this notice.
This notice covers our website, enquiries, coworking passes, facility bookings, managed living spaces and related customer services.
Privacy Contact — Management, Good Earth Construction Sdn Bhd, 20, Jalan Pudu Lama, 50200 Kuala Lumpur, Malaysia. Email: hello@nomadshophouse.com. Telephone or WhatsApp: +60 11-6520 0855.
2. Personal data involved
Please avoid sending unnecessary sensitive information. If an access request involves health information, we will explain the relevant processing and obtain explicit consent where required by law.
If additional identification, monitoring or activity-specific information is required, we will explain it through an appropriate notice before collection.
- Identity and contact information, such as your name, email address, WhatsApp number and any local Malaysian number you provide.
- Booking and transaction information, including the service, dates, quantities, occupants, price, payment status, invoice details and transaction references.
- Account, pass and access information, including email verification, login records, pass status, issued access credentials and attendance or usage records.
- Messages and enquiry information provided through forms, email, WhatsApp or other agreed channels.
- Technical and security information, such as session identifiers, IP-related security records, timestamps, browser or device information and application logs.
- Visitor details and information you provide about access requirements or other booking needs.
3. Where information comes from
We receive information directly from you, from someone authorised to make a booking for you, through your use of our website and services, and from providers involved in payment, communications, security or fulfilment.
If you provide another person’s details, ensure you have authority to do so and give them this notice. We will also provide relevant privacy information to occupants and visitors when dealing with them.
4. Purposes and grounds for processing
Where applicable, processing is necessary to take steps you request before a contract, perform our contract with you, comply with legal obligations, or meet another condition permitted by the Personal Data Protection Act 2010.
Where consent is required, we will obtain it. Sensitive personal data receives the additional treatment required by law.
- Answer enquiries and provide availability information.
- Create and fulfil bookings, passes and managed living arrangements.
- Process payments, invoices, refunds and customer support.
- Issue access credentials and manage authorised access, attendance and security.
- Operate accounts and send verification or sign-in messages.
- Send service information, including confirmations, access instructions, changes and pass-status updates.
- Maintain necessary accounting, tax, fraud-prevention, dispute and legal records.
- Investigate faults and improve the reliability, safety and operation of our services.
- Send optional marketing in accordance with section 5.
5. Operational messages and optional marketing
Booking confirmations, payment and refund information, access instructions, security notices and relevant pass-status messages are operational communications.
We use the contact channels agreed or identified for your booking. If WhatsApp is an operational channel, this will be explained before we send information through it. Contact us to discuss an available alternative.
We will ask separately for your opt-in before sending optional promotional email or WhatsApp messages. Refusing or withdrawing marketing consent does not affect your booking.
You can stop marketing through the instructions in the message or by contacting us. We may retain the minimum information needed to respect your opt-out. A marketing opt-out does not stop necessary service communications.
6. Required and optional information
We identify required information at the relevant collection point. Without information needed for a particular service, we may be unable to answer an enquiry, complete payment, confirm a booking, issue access, provide an invoice or contact you about the service.
Optional information may be omitted. We will explain any specific consequences of withholding additional information when requesting it.
7. Who receives information
We disclose relevant information for the purposes in this notice to appropriate recipients, which may include those listed below. We limit disclosures to information relevant to their purpose.
Some providers process information on our instructions. Others may process particular information for their own payment, regulatory, security or platform purposes under their applicable privacy notices. Their involvement does not remove our responsibilities for our own processing and disclosures.
- Airwallex and associated payment providers for payment processing, fraud checks and transaction administration.
- Hosting, database, technical-support, email and communications providers.
- Providers supporting access credentials, booking fulfilment and security, where used.
- WhatsApp/Meta and relevant communications providers when WhatsApp is used for an agreed communication.
- Advisers, accountants, auditors and insurers where relevant to their work.
- Authorities, courts or law-enforcement bodies where disclosure is required or otherwise lawfully justified.
- A prospective or actual successor in a genuine business transfer or restructuring, subject to appropriate confidentiality, safeguards and any further notice or consent required by law.
8. Processing outside Malaysia
Some providers may store or process information outside Malaysia.
An international transfer must satisfy an applicable condition under section 129 of the Personal Data Protection Act 2010. Depending on the arrangement, this may involve the destination’s legal protection, adequate safeguards, or a statutory exception such as a necessary contractual transfer or informed consent.
We assess the relevant arrangement and use appropriate contractual, security and other safeguards. Where consent is the condition relied upon, we will provide the relevant information and request consent before the transfer.
Contact our Privacy Contact for information about the providers, destinations and safeguards relevant to your service.
9. Payments
Card details are entered through the designated payment provider. We receive payment status and transaction references but do not receive or store your complete card number or card security code through that payment process.
Do not send full card details to us by email, WhatsApp or an enquiry form.
10. Cookies and similar storage
We use cookies or similar storage for functions such as security, checkout continuity, sign-in and account sessions.
Storage that remembers a dismissed notice is a preference function. Blocking storage may affect the relevant feature.
If we introduce optional analytics or advertising tools, we will explain the tools and their purposes and provide appropriate choices before using them. Where consent is required, those tools will not be activated without it.
11. How long information is kept
We keep personal data only for as long as needed for its purpose and applicable legal obligations. Relevant considerations include whether a service remains active, support and dispute periods, security purposes, accounting and tax requirements, legal holds, and the minimum record needed to respect communication choices.
Different categories may have different retention periods. Keeping an invoice does not necessarily require keeping an expired access credential or unrelated visitor information.
When information is no longer required, we delete it or make it no longer identifiable, subject to necessary backup cycles and lawful retention requirements. Restricted information held for a legal obligation is not retained as a reason to continue unrelated marketing.
You may ask about retention or request deletion. We will explain any information that must be retained and why.
12. Security and incidents
We use organisational and technical measures appropriate to the nature of the information and processing, including controls over access and the handling of service-provider arrangements.
No system can guarantee absolute security. This does not remove our obligations to take the security measures required by law.
We assess suspected personal-data breaches and notify the Personal Data Protection Commissioner and affected individuals where required, within the applicable time limits.
13. Your rights and choices
Subject to the Personal Data Protection Act 2010 and its conditions and exceptions, you may exercise the rights listed below.
You may also ask us to explain our processing or consider a request to limit or delete information. These requests are assessed against applicable law; they are not an unrestricted right to erase every record.
Send requests to our Privacy Contact. We may need proportionate information to verify your identity and locate the relevant records. We will respond within applicable legal periods and explain any lawful refusal, extension or prescribed fee.
Withdrawal of consent does not invalidate earlier lawful processing. We will explain any effect on a service and any processing that remains permitted or required by law.
You may raise concerns with the Malaysian Personal Data Protection Commissioner through the Commissioner’s official website at www.pdp.gov.my.
- Request access to your personal data and correction of inaccurate, incomplete, misleading or outdated information.
- Withdraw consent by written notice where processing relies on consent.
- Require us to stop processing for direct marketing.
- Give a written notice concerning processing likely to cause substantial, unwarranted damage or distress, where the statutory conditions are satisfied.
- Request transmission of your personal data to another data controller through the statutory portability process, subject to technical feasibility, compatible formats and applicable requirements.
14. Children and Young Nomads activities
Enquiries and registrations for a child’s participation must be handled by a parent or guardian.
Before collecting information for a children’s activity, we will provide relevant activity-specific privacy information. Where consent is required for a person under 18, we will obtain and record it from the parent or guardian.
We will separately explain any proposed use of sensitive information, photographs or promotional material and obtain the consent required for that use.
15. Changes to this notice
We may update this notice when our services, processing or legal obligations change.
We will publish the revised notice and its date, provide further notice of material changes where required, and obtain fresh consent where the law requires it. Publishing a revision does not by itself authorise a new use requiring consent.