On this page
This Privacy Policy explains how we handle personal data when you visit ORBIT, contact us, request a preview, purchase a report, join early access, or use another ORBIT service.
Who we are
ORBIT is operated by ShareMo Technologies Sdn Bhd (Company No. 202401016930) in Malaysia. In this policy, “ORBIT”, “we”, “us”, and “our” refer to ShareMo Technologies Sdn Bhd. Where we determine the purposes and means of processing personal data in connection with ORBIT, we act as the data controller and are responsible for that processing under applicable Malaysian law.
Scope of this policy
This policy applies when you visit an ORBIT website, submit a form, contact us, request a preview or demo, join a waitlist or early-access programme, purchase or receive a report, interact with an AI-assisted feature, or otherwise use an ORBIT service.
It does not govern a third-party website or platform merely because ORBIT links to it, refers to it, or analyzes information from it.
Information we may collect
We may collect identity and contact details such as your name, business email address, phone number, job title, company, and billing contact. We may also collect restaurant and business details, restaurant names and locations, objectives, questions, form responses, files, report requests, order information, transaction references, feedback, support messages, and other information you choose to provide.
When you use our website or digital services, we may collect technical and usage data such as IP address, device and browser information, approximate location derived from IP, referring page, pages viewed, dates and times, feature interactions, cookie identifiers where used, diagnostic data, and security logs. The information actually collected depends on the features and providers in use at the relevant time.
Some information will be marked or explained as required when we need it to answer your request, process an order, protect the service, comply with law, or provide a service. If you do not provide required information, we may be unable to proceed. We seek to avoid collecting personal data that is not reasonably necessary for the relevant purpose.
Where information comes from
We may obtain personal data directly from you; from the company or restaurant you represent; through forms, emails, calls, payments, support conversations, and service interactions; automatically from the device or browser you use; from service providers that support our operations; and from lawfully available public sources.
If another person submits your business contact details to us, we may use them to respond to the relevant introduction or request and for related business communications where permitted by law. You should only provide another person's personal data when you are authorized or otherwise permitted to do so.
Restaurant and public market data
ORBIT may collect, organize, summarize, or analyze lawfully available information about restaurants, locations, competitors, listings, ratings, reviews, menus, websites, articles, maps, social content, and other market signals. Public content may sometimes include a reviewer's name, username, profile image, opinion, business affiliation, or other personal data that the person or platform made publicly available.
We use public-source information to produce restaurant and market intelligence, understand market signals, verify or contextualize business information, and maintain an appropriate analytical record. We do not use ORBIT to identify anonymous individuals, build covert private consumer dossiers, infer unnecessary sensitive characteristics, or obtain information by bypassing access controls.
Where an identifiable reviewer or other individual is not reasonably necessary to the analysis, we aim to minimize, redact, aggregate, pseudonymize, or avoid retaining identifying details. A limited public-source snapshot or excerpt may be retained with the supporting record where reasonably necessary for source integrity, audit, correction, dispute handling, or legal compliance. Public availability does not mean that third-party content has no privacy, copyright, contractual, or other restrictions.
How we use information
We may use personal data to respond to enquiries; provide previews, paid reports, research, market analysis, and decision-support services; confirm restaurant and location details; process and administer orders; personalize requested analysis; provide support; maintain business and transaction records; secure the service; detect fraud or misuse; troubleshoot and improve ORBIT; measure performance; conduct research; create aggregated or de-identified insights; communicate service and policy updates; and comply with legal or regulatory duties.
We may send relevant ORBIT news or offers where you have opted in or where otherwise permitted by applicable law. You can stop direct marketing at any time without affecting service messages relating to an active request, account, security matter, or order.
Where consent is required, we will ask for it. Depending on the context and applicable law, personal data may also be processed where reasonably necessary to provide a service you requested, administer our business relationship, exercise or defend legal rights, protect legitimate interests and security, comply with legal obligations, or for another purpose permitted by law. We do not rely on a general statement in this policy to authorize processing that applicable law requires us to handle on a different basis.
AI-assisted and automated processing
ORBIT may use artificial intelligence, automated classification, summarization, extraction, matching, and analytical tools to help process restaurant information and produce insights. Information relevant to your request may be processed by technology providers acting for us under contractual or other appropriate arrangements.
AI-assisted outputs may not always receive human review before they are first shown. ORBIT is designed to support restaurant business decisions. We do not intend to use ORBIT to make a decision based solely on automated processing about an identifiable individual where that decision produces legal or similarly significant effects, unless applicable law permits it and appropriate safeguards are implemented.
We seek to limit personal data sent to AI or automated systems to what is reasonably necessary for the relevant purpose. Please do not submit unnecessary personal data, sensitive personal data, passwords, full payment-card details, or confidential customer records into an ORBIT prompt, form, or report request.
Data minimisation and accountability
We aim to collect and use personal data that is reasonably relevant and not excessive for the stated purpose. We may use aggregation, de-identification, pseudonymisation, redaction, access restrictions, and retention controls where appropriate to reduce privacy risk, particularly when working with large volumes of public restaurant and review data.
We periodically review the privacy obligations that apply to ORBIT as its data sources, analytics, user volumes, monitoring activities, and AI features develop. Where applicable law requires a specific governance measure, such as a Data Protection Officer, data-protection impact assessment, additional processor terms, registration, or enhanced notice, we will take reasonable steps to implement that requirement.
Cookies and analytics
Our website may use cookies or similar technologies for essential operation, preferences, security, analytics, performance measurement, and, where enabled and legally permitted, marketing measurement. We may use analytics providers to understand how visitors reach and use ORBIT.
You can control many cookies through your browser and any cookie controls we make available. Blocking or deleting certain cookies may affect website functionality. Where applicable law requires a choice or consent before a non-essential technology is used, we will seek to provide the relevant control before activating that technology.
Payments
If payments are enabled, a third-party payment provider may collect and process payment details directly. We may receive the payer's name, billing contact, payment status, amount, currency, transaction identifier, and limited fraud-prevention information. We do not ordinarily need to receive or store full payment-card numbers.
How we share information
We may share personal data only as reasonably needed with providers that support hosting and cloud infrastructure, AI and data processing, analytics, communications, email delivery, customer support, payments, security, file storage, and professional advice. These providers may process information for us under contractual or other appropriate safeguards.
We may also disclose information when required or permitted by law; to respond to a valid authority request; to investigate fraud, misuse, or security concerns; to protect rights, property, or safety; with your consent; or in connection with a financing, reorganization, merger, acquisition, or sale of all or part of the business.
We do not sell personal data as a standalone product.
International processing
Some service providers, cloud systems, AI tools, or other recipients that support ORBIT may process personal data outside Malaysia. Where personal data is transferred internationally, we will take reasonable steps to use a transfer condition, contractual arrangement, assessment, or other safeguard recognized by applicable Malaysian law and guidance, taking into account the nature of the data, recipient, destination, and processing.
Privacy and data-protection laws in another country may differ from those in Malaysia. Where required, we will take additional reasonable measures or obtain the relevant consent or authorization before a transfer.
How long we keep information
We retain personal data only for as long as reasonably needed for the purposes described in this policy, including providing services, maintaining business and transaction records, resolving disputes, handling correction requests and complaints, preventing misuse, enforcing agreements, establishing or defending legal claims, and meeting legal, tax, accounting, regulatory, security, or audit obligations.
Retention periods differ by the type, sensitivity, source, purpose, legal requirement, and context of the information. When identifiable data is no longer reasonably needed, we may delete it, securely dispose of it, anonymize it, or aggregate it so that it no longer identifies an individual. Public-source material included in a completed report or its supporting record may remain with that report where reasonably necessary for integrity, source verification, dispute handling, or record-keeping.
Security and data incidents
We use reasonable administrative, technical, and organizational measures intended to protect personal data against loss, misuse, unauthorized access, disclosure, alteration, or destruction. Measures may include access controls, provider due diligence, data minimization, secure configuration, backups, authentication, logging, staff or contractor controls, and other safeguards appropriate to the nature of the processing where reasonably practicable.
No website, system, provider, or transmission method is completely secure, so we cannot guarantee absolute security. If a personal data breach occurs, we will assess the incident, take reasonable containment and remediation steps, preserve appropriate records, and notify the Personal Data Protection Commissioner and affected individuals within the time and circumstances required by applicable Malaysian law.
Your rights and choices
Subject to the Personal Data Protection Act 2010 (Act 709), as amended, and other applicable law, you may have rights to request access to or correction of personal data, withdraw consent where processing depends on consent, object to or stop direct marketing, request information about how personal data is handled, make a complaint, and request data portability where the statutory requirements for portability apply. Other rights or restrictions may apply depending on the circumstances and the nature of the processing.
We may need to verify your identity, authority, and enough detail to locate the relevant information. We may refuse or limit a request where permitted or required by law and will handle applicable requests within the legally required period. Withdrawing consent does not affect earlier lawful processing and may mean we can no longer provide a requested service where that data is necessary.
To exercise a privacy right or preference, contact us using the details in section 19. Where applicable law requires us to appoint a Data Protection Officer, we will maintain the required appointment and contact arrangements in accordance with applicable requirements.
Children
ORBIT is intended for business users and is not designed for children. We do not knowingly seek to collect personal data from children through the service. If you believe a child has provided personal data to us without appropriate authorization, please contact us.
Third-party links, platforms and providers
ORBIT may link to third-party websites or obtain information from maps, review sites, social networks, payment providers, public websites, and other external platforms. Their own collection, use, disclosure, retention, and security of personal data are governed by their notices, terms, and applicable law. We encourage you to review them before providing information directly to those parties.
Where a provider processes personal data on our behalf, we will take reasonable steps appropriate to the relationship to select and manage the provider and to use contractual or other safeguards where required. Nothing in this policy makes us responsible for independent processing carried out by a third party for its own purposes.
Changes to this policy
We may update this Privacy Policy as ORBIT, our providers, or applicable requirements change. The latest version will appear on this page with a revised effective date. If a change is material, we may also provide notice through the service, by email, or by another reasonable method.
Contact us
For a privacy question, request, or complaint, contact: