ListBelanja
Data security: what we do, and what you control
Your receipts tell the story of your life — clinics, the children's school, your business. This page explains honestly how ListBelanja protects them: what is encrypted, who can see what within a group, what never leaves your device, and how you export or delete everything yourself. The full legal detail is in the Privacy Policy (PDPA) & Terms; this page is the plain-language version, for individuals, families, businesses, associations and accountants.
No credit card · BM, English & 中文 · your records live in the cloud, not on one phone
Updated
★★★★★ 5 out of 5 — based on 5 ratings from ListBelanja users
In transit & at rest
- Every connection is encrypted (HTTPS) and enforced by the server; there is no unencrypted version.
- Your session lives in an encrypted cookie that scripts in the browser cannot read (HttpOnly, Secure) — one essential session cookie only, no tracking or third-party analytics cookies.
- A strict content security policy: no inline scripts, no scripts from third-party servers on the app's pages.
- Receipt images & documents are kept in closed cloud object storage; they travel through the app's server, and view links expire by themselves.
- A cloud database in the South-East Asia region; daily backups kept 14 days and monthly backups 90 days, encrypted.
- New passwords are checked against public breach lists using k-anonymity — your password is never sent; Google sign-in is available without a password.
Isolation per group — enforced by the database
- Every data row (receipts, expenses, claims, settings) is tagged with its group — family, company, association, firm — and the database itself refuses any cross-group read or write, even if the app code were wrong.
- The platform owner sees only aggregate statistics (number of groups, usage) — they cannot read any group's receipts; that restriction is enforced by the database too.
- Separation of duties in claims (checker ≠ approver) and the locking of filed years are enforced by database triggers, not only by buttons in the app.
- Every API call needs a valid session; writes are rejected when they come from another site (layered CSRF protection) and rate-limited per account.
Who sees what in your group
- Your receipts: you and the group admin; receipts marked private are seen only by you & the admin — other members do not see them.
- The shopping list & the household money picture: shared; your full tax profile (income, PCB, reliefs) is closed to admins & auditors unless you open it yourself (default: closed).
- Claim checkers, approvers & payers (treasurer, finance manager): only the claims submitted for their decision, including that claim's receipt images.
- Invited auditors & accountants: read-only — filed or locked records and closed years; they use no seat in the plan and cannot scan or change anything.
- In an organisation space, staff & committee members' personal tax is open to nobody. Receipts members send by email or Telegram are recorded under the sender's name.
What never leaves your device
- Bank, card & e-wallet statement files (CSV, Excel, PDF) are parsed in your browser — the file is not uploaded to the server; only the rows you confirm for import are stored.
- Social-media share cards are drawn on the device and contain no name, income, shop or date.
- The public calculators, relief finder & "Can I claim X?" pages send nothing — the computation happens in the browser.
- Receipt images you scan ARE sent to an AI service to be read; under the provider's terms, submitted content may be used to improve the provider's products. Manual entry sends nothing to the AI — you can stop using the AI features at any time.
Export, trash & delete — in your hands
- A full JSON backup & a ZIP audit pack (every receipt image, HK-4, summaries) can be downloaded any time — More → Data & recovery.
- Deleted receipts sit in the trash for 30 days (recoverable), then are deleted permanently; unprocessed receipt emails are deleted after 30 days.
- Delete my data: any user deletes their own data & account inside the app, immediately — no email, no form. Exceptions: receipts of a locked year (filed with LHDN) and approved claims pass to the group admin because the law requires tax records to be kept.
- Close the group: every member is deactivated immediately and all the group's data is permanently deleted after 30 days; export first.
- No ads, no data selling, no sharing with advertisers, data brokers or LHDN. Data is disclosed only when Malaysian law requires it.
Reporting a security weakness
If you find a weakness, tell us first, confidentially — through the in-app feedback form (More → Feedback, tick "Allow the owner to contact me") or the support email address listed in the Privacy Policy under "Contact us". We reply, fix and inform affected users; please allow a reasonable time before public disclosure. Do not test with other people's data.
Full documents
- Privacy Policy (PDPA) — including "Contact us" & account deletion — What is collected, where it is stored, for how long, your PDPA rights.
- Terms of Service — Plans, payments, dormant accounts, group closure.
- Service status — App components & a live check from your browser.
Frequently asked questions
Who can see my receipts?
You and your group's admin; private receipts only you & the admin. Other members, auditors (read-only, filed/locked records) and the platform owner cannot — and that restriction is enforced by the database, not only by the app.
Is my data used for ads or sold?
No — no ads, no data selling, no data brokers, no sharing with LHDN. One honest exception: scanned receipt images are read by an AI service and, under that provider's terms, may be used to improve the provider's products; manual entry involves no AI.
How do I delete everything?
More → Data & recovery → Delete my data — immediately, inside the app. An admin can close the whole group (data permanently deleted after 30 days). Download the JSON backup first if you want your own copy.