Privacy Policy
Effective date: 19 May 2026 · Last updated: 19 May 2026
Bike Community Malaysia (BCM) is committed to protecting your personal data. This Privacy Policy explains what information we collect, why we collect it, how we use and protect it, and your rights under Malaysia's Personal Data Protection Act 2010 (PDPA).
By registering on this platform, you acknowledge that you have read and understood this policy and consent to the collection and use of your personal data as described herein.
1. Data Controller
The data controller responsible for your personal data is Bike Community Malaysia (BCM), operating this portal at bcm.my. For data-related enquiries, contact us at:
Email: admin@bcm.my
WhatsApp: +60 13-247 1056
2. Personal Data We Collect
When you register or use BCM, we collect the following personal data:
| Data | Purpose | Required? |
|---|---|---|
| Full legal name | Identity verification & member card | Yes |
| Username | Account login & community display name | Yes |
| Email address | Account login & notifications | Yes |
| Gender & age | Community demographics | Yes |
| WhatsApp number | Membership notifications & community updates | Yes |
| State / area | State leaderboard & regional grouping | Yes |
| Bike model & plate number | Community rankings & ride management | Yes |
| Malaysian IC / Passport number | Identity verification by admin only — not displayed publicly | Yes |
| Performance data (speed, range) | Public leaderboard (with your consent) | If submitting to rankings |
| IP address & activity logs | Security, fraud prevention & audit | Automatic |
3. How We Use Your Data
- Verifying your identity before granting membership
- Displaying your community profile, ride posts, and ranking records
- Sending WhatsApp notifications about membership approvals, events, and community updates
- Preventing fraudulent or duplicate registrations
- Generating anonymous aggregate statistics (e.g. number of members per state)
- Maintaining security audit logs
⚠️ Your IC / passport number is accessed only by authorised BCM administrators for identity verification purposes. It is never displayed publicly or shared with third parties.
4. Public vs. Private Data
Visible to the public
- Username / display name
- State / area
- Bike model
- Verified ranking records (distance, speed)
Visible to logged-in members only
- Plate number (on rankings)
- WhatsApp contact (on ride posts)
Visible to BCM admins only
- IC / passport number
- Full email address
- Activity logs & IP addresses
5. Data Retention
We retain your personal data for as long as your membership account is active. If you request account deletion, your personal data will be removed within 30 days, except where retention is required by law (e.g. security audit logs are retained for up to 6 months).
6. Data Security
- Passwords are hashed using BCrypt — never stored in plain text
- All pages are served over HTTPS (SSL)
- CSRF tokens protect all form submissions
- Admin access is role-restricted
- Login attempts are rate-limited to prevent brute force attacks
- Uploaded files are stored outside the web-executable directory
7. Third-Party Services
- WhatsApp (Meta): We use the WhatsApp API to send you notifications. Your number is used solely for this purpose and is not sold or shared.
- Google AdSense: This site displays ads. Google may use cookies to personalise ads. See Google's Privacy Policy.
We do not sell, rent, or share your personal data with any other third parties for marketing purposes.
8. Your Rights Under PDPA 2010
As a data subject under Malaysia's Personal Data Protection Act 2010, you have the right to:
- Access — request a copy of the personal data we hold about you
- Correction — request correction of inaccurate or outdated data
- Withdrawal of consent — withdraw consent to processing at any time (may result in account deactivation)
- Erasure — request deletion of your account and personal data
- Limit processing — request that we restrict how we use your data
To exercise any of these rights, contact us at admin@bcm.my or WhatsApp +60 13-247 1056. We will respond within 14 working days.
9. Changes to This Policy
We may update this Privacy Policy from time to time. The effective date at the top of this page will be updated accordingly. Continued use of the BCM platform after changes are posted constitutes acceptance of the updated policy.
This policy is governed by the laws of Malaysia.
For complaints, you may also contact the Department of Personal Data Protection (JPDP) at pdp.gov.my.