Legal
Privacy Policy
Effective: 5 September 2026 · Applies to the willydo Platform at willydo-project.vercel.app
1. Who we are
willydo (the "Platform") is a SaaS ecommerce analytics and business intelligence platform for merchants. It lets each customer organisation securely connect the commerce and advertising platforms they already use — such as Shopee, Lazada, TikTok Shop, WooCommerce, Google Ads, Meta and AutoCount — and consolidate their authorised sales, order, product and performance data into a unified dashboard with access control built in.
The Platform is operated by DASHOIL THRIVE SDN BHD. (Company No. 202401050604 (1596447-H)) ("we", "us", "our"), incorporated in Malaysia. You can contact our privacy team at support@dashoil.asia.
2. What this policy covers
This policy explains what personal data we collect through the Platform (hosted at willydo-project.vercel.app) and its public marketing pages, why we collect it, how we use, store and share it, and the choices you have.
The Platform is provided to organisations ("customer tenants"). When a tenant connects a third-party platform, we process that platform's data on the tenant's instructions, as a service provider, so the tenant can view its own data. The tenant remains responsible for the data it uploads or connects and for its own use of the Platform.
This policy does not cover the third-party platforms themselves (Meta, Shopee, Lazada, TikTok Shop, WooCommerce, Google Ads, AutoCount). Those services are governed by their own privacy policies.
3. Data we collect
Account data: name, email address, password (stored as a hash, never in plain text), role, and the tenant memberships that decide which modules you can open.
Connection data: when a tenant connects a platform, we receive and store the OAuth credentials issued by that platform, together with account and business identifiers (such as ad account or business names). All connection credentials are encrypted at rest (AES-256-GCM). One legacy manually-entered Meta Ads connection is stored in its original form until the tenant re-saves it. Credentials are held in restricted database tables that only our backend service account can read, and are never exposed to the browser or to other tenants. For AutoCount, the desktop connector runs on the tenant's own machine and synchronises financial records (invoices, customer lists, outstanding balances) into the tenant's isolated view.
Synced operational data: orders, sales figures, advertising insights and other marketing data captured from the connected platforms into the tenant's dashboard snapshots.
People-module data: where the tenant enables the HR/People module — employee profiles, leave records, and meeting recordings or transcripts.
Support data: whatever you include when you contact us, plus the records of that correspondence.
Technical data: strictly functional cookies needed for sign-in and security, and basic technical logs (for example IP address and user agent) collected by our error-monitoring provider (Sentry) when something goes wrong.
4. How we use personal data
We use personal data to: provide, operate and maintain the Platform and its modules; keep each tenant's data isolated from every other tenant; authenticate you and enforce the access controls your tenant configured; sync and display the connected platforms' data in dashboards; answer support requests; secure the Platform and detect misuse; and meet our legal and accounting obligations.
We do not sell personal data, and we do not use your data to advertise to you.
5. AI processing
Some Platform features use artificial intelligence — for example meeting transcription and summaries, marketing and sales insights, and creative analysis. When those features are used, the content needed for the task (such as meeting audio and transcripts, an excerpt of marketing data, or a creative you submit for analysis) is sent to third-party AI providers — currently OpenAI (meeting transcription and analysis), Google (creative analysis) and OpenRouter (sales insights) — and processed under those providers' terms.
AI processing is limited to the feature you invoke. Outputs are stored with your tenant's data and are not used to build profiles of individuals or to market to you.
8. International transfers
We are based in Malaysia. Our providers may store and process data in other countries (for example Singapore or the United States). Where data leaves Malaysia or the EEA, we rely on the providers' contractual safeguards and standard contractual clauses, or on the consent embodied in the tenant's connection to a platform.
9. How long we keep data
Account and synced operational data is kept while the tenant's account is active. When a tenant account is deleted, its data is deleted together with the account — the deletion cascades through all of the tenant's records. Suspended accounts keep their data for 30 days so the service can be resumed; if a suspension continues beyond 30 days, the tenant's data is deleted automatically. Verified deletion requests are completed within 30 days. Connection credentials are deleted or deactivated when the tenant disconnects the platform, and are never shown to the browser. Support correspondence is kept according to our normal business-record practice.
Data received from Meta is used only to provide the connected dashboards. If the authorisation is removed on Meta's side (deauthorisation), we disable the connection and stop processing that data. The stored credentials are deleted when the tenant disconnects the platform or when we receive a deletion request through Meta's data deletion flow, in line with Meta's platform requirements.
10. How we protect data
We apply industry-standard measures: encrypted transport (TLS); encrypted storage for all platform connection credentials (AES-256-GCM, with a fresh random initialisation vector for every encryption); database-level tenant isolation and row-level security, with credential tables accessible only to our backend service account; role-based access control enforced server-side; and monitoring for errors and abuse. No security measure is perfect, but we treat tenant isolation and credential protection as core design constraints, not afterthoughts.
11. Your rights and choices
Depending on where you are — including rights under the Malaysian Personal Data Protection Act 2010 and, where applicable, the GDPR — you may ask us to access, correct, delete, export or restrict the processing of your personal data, or to object to processing.
To exercise any of these rights, email support@dashoil.asia. We verify requests before acting and respond within 30 days. If you are an employee or user of a customer tenant, we may need to route your request through that tenant where they control the data.
For data received from Meta, you can also use Meta's "send a data deletion request" flow: it reaches our dedicated deletion endpoint and is processed in the same 30-day window. You can check the status of a Meta deletion request on the status page we provide.
12. Facebook / Meta integration (Facebook Login for Business)
When a tenant connects Meta Ads, the Platform uses Facebook Login for Business with the permissions ads_read and business_management. We receive the business name, ad account identifiers, and advertising insights available through Meta's Marketing API.
We use this data only to display the tenant's own advertising performance in their dashboards. It is stored encrypted, associated with the tenant's isolated workspace, and never shared with other tenants. When the tenant disconnects, the authorisation is revoked with Meta and the stored credentials are deleted. If the authorisation is removed on Meta's side (deauthorisation), we disable the connection and stop processing it; the stored credentials are then removed on disconnect or via a Meta data deletion request. Deletion requests received through Meta's data deletion callback are processed as described in section 11.
In this integration we act as a service provider processing data on behalf of the tenant, in accordance with Meta's platform terms.
13. Children
The Platform is a business tool and is not intended for individuals under 18. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact support@dashoil.asia and we will delete it.
14. Changes to this policy
We may update this policy from time to time. The effective date at the top of this page shows when the current version took effect. When we make material changes, we will also notify tenant administrators by email. Continued use of the Platform after an update means you accept the revised policy.
Questions about this policy?
Contact our privacy team at support@dashoil.asia.