Privacy Policy
Last updated: 23 September 2026 · Terms of Service
Dorraim is operated by Smartflow Ai Digital Enterprise (SSM 202603094424 (LA0088346-P)), Malaysia (“we”, “us”). This policy explains what personal data we collect, why, who we share it with and your rights. We handle personal data in line with Malaysia's Personal Data Protection Act 2010 (PDPA).
1. The short version
- We collect what we need to build and host your website and to contact you.
- What you put on your website is public. Your business name, WhatsApp number, address and prices can be seen by anyone who visits it.
- We do not sell your personal data, and we do not use advertising trackers.
- You can ask us to see, correct or delete your data at any time.
2. What we collect
- Account details: your email address and password (stored scrambled, never in plain text). If you sign in with Google, we receive your name, email address and profile picture from Google.
- Business details you give us: your business name, what you do, location, WhatsApp number, services and prices, opening hours, and anything else you type into the questions. On paid plans, also your domain, and your company name and SSM number if you add them.
- Payment details: handled by our payment provider. We receive a record that you paid (amount, date, plan) but not your full card or bank details.
- Messages: what you send us on WhatsApp or by email, and reports about websites.
- Technical data: your IP address, browser and device type, and logs of requests to our servers, used to keep Dorraim secure and working. Visitor statistics for Pro websites are counted in total (for example, number of visits and where they came from), not to identify individual visitors.
- What you type into AI features (paid plans), so the AI can produce a result.
3. Why we use it
- To create your account, build, publish and host your website, and register your domain.
- To take payment and keep records we are required to keep.
- To send you service messages: sign-up confirmation, password resets, payment and renewal reminders, and important changes. You cannot turn these off while you have an account.
- To send you news or offers about Dorraim, only if you agree. You can stop them anytime with the link in the email.
- To keep Dorraim safe: to check websites for illegal businesses and scams, prevent abuse, and respond to reports and lawful requests.
- To answer your questions and improve Dorraim.
4. Who we share it with
We share personal data only with service providers who help us run Dorraim, and only what they need:
| Provider | What for |
| Supabase | Accounts, sign-in and database |
| Google | Sign in with Google (if you choose it) |
| Cloudflare | Security, speed and delivering websites |
| Our hosting provider | The servers your website runs on |
| Email delivery provider | Sending sign-up, password and service emails |
| Payment provider | Taking payments for paid plans |
| Domain registrar | Registering your domain in your name (the registrar may be required to keep your contact details) |
| AI providers | Organising and editing your website text (paid plans) |
| Business email provider | Business email on your domain (Pro) |
We may also share data when the law requires it, for example with the Royal Malaysia Police (PDRM) or the Malaysian Communications and Multimedia Commission (MCMC), or to protect people from harm or fraud.
5. Data outside Malaysia
Some of our providers store or process data outside Malaysia. By using Dorraim, you agree that your data may be transferred there. We only use providers that protect personal data to a standard comparable to the PDPA.
6. How long we keep it
- Your account and website data: while your account is open. If you close your account or cancel, we keep your content for 30 days so you can come back, then delete it.
- Payment records: as long as Malaysian tax and accounting law requires (usually 7 years).
- Backups: deleted automatically on their normal schedule.
- Server logs: kept for a short time for security, then deleted.
7. How we protect it
All websites and our service use HTTPS. Passwords are never stored in plain text. Access to our systems is limited and protected. No system is perfectly secure, but if a breach affects your personal data, we will tell you and the authorities as the law requires.
8. Cookies and similar storage
We use your browser's storage to keep you signed in, remember your language, and save a website you are still making. Google (for sign-in) and Cloudflare (for security) may set their own cookies. We do not use advertising or cross-site tracking cookies.
9. Your rights
Under the PDPA you can ask to:
- See the personal data we hold about you
- Correct data that is wrong or out of date
- Stop receiving marketing messages
- Withdraw your consent and close your account (we will then delete your data as described above)
Email hello@dorraim.com from the email address on your account. We may need to confirm it is you, and we will reply within 21 days. Some requests may take longer if the law allows.
10. Children
Dorraim is for businesses and people aged 18 and over. We do not knowingly collect data from children. If you think a child has given us data, contact us and we will delete it.
11. Websites made with Dorraim
Each business is responsible for its own website and for how it uses the details its customers send it, for example through WhatsApp. This policy covers Dorraim itself, not how each business handles its own customers' data.
12. Changes
We may update this policy. If a change is important, we will tell you by email or on dorraim.com before it takes effect.
13. Contact
Smartflow Ai Digital Enterprise (SSM 202603094424 (LA0088346-P)), Malaysia
Email: hello@dorraim.com