Legal
Privacy Policy
This Privacy Policy explains how FREEZEIT TISSUE collects, uses, shares, stores, and protects personal data when you use Bond.
Effective date: 2026-08-12 · Version 1.0
1. Data controller
FREEZEIT TISSUE (KT0609003-H) is the data controller for personal data processed through Bond.
Privacy requests and questions may be sent to jasonlee@bondtgt.com or +60 11 5918 8939. This notice is issued with regard to Malaysia’s Personal Data Protection Act 2010 [Act 709], as amended, and other applicable requirements.
2. Scope
This Policy applies to the Bond mobile application, public legal pages, account and recovery flows, service infrastructure, private media delivery, and communications that link to it. It does not govern an organizer, venue, or other third party acting for its own purposes under its own privacy notice.
Bond is designed mainly for Malaysia but may be used from other countries. Additional mandatory privacy rights may apply where you live.
3. Adults only
Bond is only for people aged 18 or older. We use the birthday you provide to assess eligibility. Bond does not currently request an identity document or biometric age estimate.
If we learn or reasonably suspect that an account belongs to someone under 18, we may suspend it, investigate, request proportionate assurance, and delete the data subject to safety, legal, and account-recovery requirements. Contact us if you believe a minor has created an account.
4. How we collect personal data
We collect data directly from you when you register, complete onboarding, edit your profile, create or join a bond, search a location, send a message, make a friend request, save an event, report or block someone, change settings, contact us, or request deletion or recovery.
We also receive data from your device and permissions, from other members’ interactions with you, and from service providers that support authentication, hosting, maps, places, notifications, security, and app delivery.
5. Data you provide and create
Depending on how you use Bond, this includes:
- Account data: email address, private login username, password credential, verification and recovery information, account state, and relevant timestamps.
- Profile and eligibility data: full name, exact birthday, legacy self-declared numeric age if previously supplied, gender, avatar, biography, interests, and onboarding or permission-step completion.
- Bond data: title, description, category, date, times, capacity, address, exact event coordinates, selected place information, audience, join mode, cover image, organizer, participant records, and status.
- Social and communication data: friend requests, friendships, event and private messages, timestamps, read states, hidden-conversation preferences, saved bonds, participation requests, and approvals.
- Safety and support data: blocks, report target, report reason and details, moderation status and limited case information, account-deletion or recovery requests, and messages you send to our monitored contact channels.
6. Required and optional data
Email verification, a password, username, full name, birthday confirming that you are at least 18, and a supported gender selection are required to complete the current account flow. If you do not provide required data, we cannot create or activate your Bond account or provide account-only discovery.
Avatar, biography, interests, device location permission, notification permission, bonds, participation, friendships, messages, saves, and reports are generally optional. You may decline optional data, but the related feature may be unavailable, less useful, or unable to respond to your request. You can use map discovery without granting device location by navigating or searching manually.
Do not submit another person’s personal data unless you have a lawful reason and any required permission. Report details should be relevant and should not contain unnecessary identity documents, financial credentials, medical records, or highly sensitive material.
7. Device, session, and technical data
The app stores authentication tokens in secure device storage on mobile devices and browser storage on the web. It stores a per-account Messages-tab preference locally. The operating system supplies permission status and, if granted, the current foreground location and notification token described below.
Service providers supporting hosting, authentication, maps and places, notifications, app distribution, network delivery, security, and technical operations may process technical request data such as IP address, device or browser type, operating system, request time, identifiers, crash or security information, and service logs under their respective roles and notices. Bond does not currently integrate a separate product analytics or advertising-tracking SDK.
To prevent automated login abuse, Bond briefly stores HMAC-keyed digests of the normalized email-or-username login identifier and, when supplied by the gateway, the network address, together with an attempt count and window timestamps. These throttle records do not store the raw password, raw login identifier, raw email or username, or raw network address. They are removed after a successful login or when stale records are cleaned under the security schedule.
8. Why we process data
We process personal data with your consent, to provide the Service you request under the Terms, for the legitimate purposes described in this notice, and where needed to comply with law or protect people and the Service.
- Create, verify, secure, recover, and administer accounts and sessions.
- Enforce the 18+ rule, onboarding, active-account status, audience eligibility, capacity, blocking, participation, friendship, and chat access.
- Display the map, find nearby or searched bonds, calculate distance, resolve place information, and allow members to create and manage bonds.
- Deliver profiles, participant lists, private media, messages, read state, saves, and settings to authorized members.
- Prevent abuse, investigate reports, moderate content, protect rights and safety, debug failures, maintain integrity, and comply with legal obligations.
- Handle support, privacy, safety, legal, deletion, and recovery requests and communicate material service or policy changes.
9. What other members can see
Bond is a closed, account-only network. Eligible active members may see your profile ID, full name, avatar, bio, gender, and interests, subject to account status and blocking. Your email, private login username, exact birthday, legacy self-declared numeric age if previously supplied, permission timestamps, account state, and deletion information are not member-visible profile fields.
Eligible members may see bond details, including exact event address and coordinates, organizer, audience, date, time, capacity, cover image, and joined participant information. Event chat is limited by existing participation and eligibility rules. Private chat is limited to the two accepted friends. Blocking hides relevant records and interactions in both directions, but a report and a block are separate actions.
Choose bond locations carefully. Do not publish a home address or another private location unless you understand that eligible members can see the exact event location.
10. Location and maps
If you grant foreground location permission, Bond uses your device’s current coordinates to center the map, show your location, support nearby discovery, and estimate distance. Bond keeps this current location temporarily in screen memory and does not store it as a profile field. Your operating system and map provider may process it to provide location and map services.
Bond uses Google Maps Platform for maps and place search. When you use these features, Google may receive search terms, IP address, and latitude/longitude coordinates needed to provide and improve its services. If you create a bond, Bond stores the selected address and exact event coordinates with that bond.
Google processes this information under the Google Privacy Policy. You may deny location permission and navigate or search the map manually.
11. Messages, relationships, reports, and blocks
Event messages are available only to members authorized for that event chat; private messages are available only to the two members of that private room under the friendship and blocking rules. Authorized recipients may copy, screenshot, or disclose what you send, so do not send information you cannot safely share.
A report contains the reporter, target, reason, optional details, timestamps, and limited moderation fields. Restricted operators and service providers may access what is necessary to triage safety or legal matters. A block records the two affected account IDs and time and is visible to the blocker through the blocked-user list.
12. Notifications and device permissions
Bond asks separately for location, photo-library, and notification permission. Your operating system controls these permissions, and you can change them in device settings. Photo-library access is used to choose an avatar or bond cover for upload.
If you allow notifications, Bond may request a device notification token. Bond does not currently store notification tokens or send push notifications. Before enabling these functions, we will update this Policy and implement the required controls.
13. Who receives data
We disclose only what is reasonably needed for the purposes described above to these classes of recipients:
- Other eligible Bond members, as described in the member-visibility section.
- Cloud, authentication, database, realtime, storage, edge-function, and email infrastructure providers to operate and secure accounts and Service data.
- Map and place providers to display maps and process place searches and selected locations.
- Notification and platform providers, when permission is granted, to issue device tokens and eventually deliver notifications.
- App stores, device-platform operators, connectivity providers, and security or technical vendors as needed to distribute, operate, protect, or troubleshoot the Service.
- Professional advisers, insurers, auditors, prospective transaction parties under confidentiality, courts, regulators, law enforcement, emergency services, or other authorities where lawful and necessary.
14. Processing outside Malaysia
Some service providers and their infrastructure, support teams, or subprocessors may process personal data outside Malaysia. The recipient classes are cloud and authentication providers; map and place providers; notification and mobile-platform providers; and the technical, security, professional, or legal recipients described above. The purposes are hosting, authentication, storage, realtime delivery, maps and places, token issuance and notifications, support, security, legal compliance, and the other Service purposes stated in this Policy.
Before a cross-border transfer, FREEZEIT TISSUE must use a condition permitted by applicable Malaysian law and take required steps, which may include notice, recorded consent where applicable, contractual safeguards, security review, and a transfer impact assessment. Provider locations and subprocessors may change; contact us for current information relevant to your data.
15. Retention and account deletion
We keep active account, profile, bond, participation, relationship, message, saved-event, report, block, media, and settings data while needed to provide and secure Bond, handle a request or dispute, or meet a legal obligation. Retention is based on the data’s purpose, sensitivity, safety and security needs, limitation periods, legal requirements, and whether it can be deleted or de-identified.
After Bond accepts a password-confirmed deletion request, the account becomes unavailable immediately and a seven-day recovery period begins. If you do not recover it by the displayed deadline, eligible database, authentication, and stored media data is queued for permanent deletion. Operational retries may be needed if a provider is temporarily unavailable.
We may retain narrowly scoped encrypted evidence until the expiry of an authorized legal hold, limited service/security logs under provider schedules, and a deletion receipt containing a non-reversible keyed digest, timestamps, outcome, and removed categories. The receipt does not contain your email, username, content, IP address, or a reversible user ID. Backups and provider systems may remove copies on their normal secure cycles. We delete or de-identify retained data when its purpose and legal need end.
16. Security
We use technical and organizational measures intended to protect personal data, including authentication, database access controls, account-status and blocking checks, private storage, time-limited authorized media delivery, restricted service access, encryption where appropriate, and secure token storage. Access is limited by role and purpose.
No app, transmission, device, or storage system is completely secure. Protect your password and device, install updates, avoid sharing codes, and contact us if you suspect unauthorized access. Where required, we will assess personal data breaches and notify the Personal Data Protection Commissioner and affected people in accordance with applicable law.
17. Your choices and data rights
Subject to Act 709 and applicable exceptions, you may ask to access personal data we hold about you, correct inaccurate or incomplete data, withdraw consent, prevent processing likely to cause damage or distress, object to or prevent direct marketing, and request data portability where that right applies. You may also request account deletion and complain to us or the Malaysian Personal Data Protection Commissioner.
You can edit supported profile fields in Bond, change device permissions in system settings, block members, leave or unsave eligible bonds, and use the deletion flow. Send other requests to jasonlee@bondtgt.com. We may verify your identity, ask for enough detail to locate the data, apply lawful limits, and explain a refusal where required.
Withdrawing consent does not affect processing already carried out lawfully. If consent or required data is necessary for a feature or the account-only Service, withdrawal may mean we cannot continue that feature or your account.
18. Advertising, analytics, and direct marketing
Bond currently has no advertising, no advertising trackers, no separate product analytics SDK, and no direct-marketing programme. We do not sell personal data.
Before introducing advertising, personalized advertising, advertising measurement, or direct marketing, we will update this Policy, identify the recipients and data involved, and obtain consent or provide opt-out controls where required. Service, safety, security, legal, and account messages are not direct marketing.
19. Automated rules and recommendations
Bond uses deterministic and recommendation logic for map bounds, distance, event capacity, account status, blocks, friendship or participation access, saved content, and gender-audience eligibility. It may suggest or randomly surface an eligible bond. These functions do not make a decision that produces a legal or similarly significant effect on you.
Bond does not currently use biometric profiling or a solely automated moderation system for serious safety outcomes. Contact us if you believe an automated rule has been applied incorrectly.
20. Personal data breaches
If we become aware of a personal data breach, we will investigate, contain and assess it, keep required records, and notify the Malaysian Personal Data Protection Commissioner and affected individuals when applicable law requires. Affected notices will use available contact information and explain practical protective steps where appropriate.
21. Changes, language, and contact
We may update this Policy when the law, Service, providers, data uses, advertising status, verification methods, or security practices change. We will publish the updated version and effective date and provide reasonable notice of material changes. We will seek fresh consent where required.
This Policy is available in English and Bahasa Melayu and both versions are intended to have the same meaning. If there is an inconsistency, the English version prevails to the extent permitted by law, without affecting a mandatory Bahasa Melayu requirement.
Contact FREEZEIT TISSUE at jasonlee@bondtgt.com, +60 11 5918 8939, or by post to P.O. Box 03190, 47500 Subang Jaya, Selangor, MYS.