PRIVACY POLICY
CBP EXPRESS & LOGISTICS / BAGAS INC.
Cargo and Baggage for Pilgrims Logistics Services
Data Protection, Privacy, and Cybersecurity Policy
Introduction
CBP Express & Logistics ("Company," "we," "us," or "our") is committed to protecting your privacy and safeguarding your personal data. This Privacy Policy explains how we collect, use, disclose, process, and protect your personal information in relation to the Bagasi Haji 2026 mobile application, website, and associated logistics services.
This Privacy Policy is compliant with the Personal Data Protection Act 2010 (PDPA) of Malaysia and applicable data protection laws of the Kingdom of Saudi Arabia, as well as international cybersecurity standards and best practices. This policy applies to all users, customers, partners, and any individual whose personal data we collect or process.
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable individual, including but not limited to name, identification number (ID card, passport, phone number, email address, physical address, payment information, location data, and any other information collected through the application or website.
- "Sensitive Personal Data" means personal data concerning health, religion, racial/ethnic origin, political opinion, or trade union membership.
- "Data Subject" means any individual to whom personal data relates.
- "Processing" means any operation performed on personal data, including collection, recording, organization, storage, use, transmission, disclosure, or deletion.
- "Data Controller" means CBP Express & Logistics, the entity that determines the purposes and means of personal data processing.
- "Data Processor" means third parties (payment providers, cloud service providers, logistics partners) who process personal data on behalf of the Company.
- Account Registration Data: Full name, email address, mobile phone number, identification number (passport, national ID, or Iqama), date of birth, nationality, residential address in both Saudi Arabia and Malaysia, and emergency contact information.
- Pickup and Delivery Location Data: Hotel name and room number (or location) in Makkah or Madinah, destination address in Malaysia, GPS coordinates, and any special location notes provided by you.
- Shipment Information: Description of parcel contents, weight, dimensions, declared value, type of item (luggage, souvenir, zamzam water, etc.), and photograph of the parcel.
- Payment Information: Credit/debit card details, bank account information, mobile wallet details (Apple Pay, Google Pay, local payment providers), transaction history, and payment confirmation records. Note: We do not store complete credit card numbers; payment processing is handled by PCI-DSS compliant third-party providers.
- Communication Data: Messages, inquiries, complaints, feedback, and correspondence exchanged via WhatsApp, email, or in-application chat.
- Device and Usage Data: Device type, operating system, app version, IP address, and usage patterns within the application.
- Location Data: Real-time GPS location (with your permission), device location history, and geofencing data for tracking driver locations and shipment progress. This data is collected only when the Bagasi Haji application is active or running in the background.
- Cookies and Local Storage: Session cookies, authentication tokens, and device identifiers stored locally to maintain your login session, remember preferences, and track app usage patterns.
- Log Files: Server logs containing IP address, access times, URLs accessed, pages viewed, errors, and actions performed within the application.
- Analytics and Performance Data: Aggregate usage statistics, crash reports, app performance metrics, and user interaction patterns (collected via Firebase Analytics or similar service).
- Payment processors (payment authorization and transaction history)
- Customs authorities and government agencies (customs declarations and regulatory information)
- Third-party logistics partners and carriers (delivery confirmation and tracking data)
- Referral sources, including Tabung Haji, travel agents, and group organizers (bulk shipment registrations)
- Marketing platforms and social media networks (if you engage with our promotional content)
- Service Delivery: Processing shipment requests, coordinating pickups, tracking packages, managing delivery, and providing customer support.
- Payment Processing: Billing, invoice generation, payment authorization, refund processing, and transaction verification.
- Authentication and Account Security: Verifying your identity, managing your account, implementing two-factor authentication (OTP), and preventing unauthorized access.
- Customs and Regulatory Compliance: Generating customs declarations, providing data to Saudi customs authorities (Zakat, Tax & Customs Authority) and Malaysian customs authorities (Royal Malaysian Customs Department), and meeting anti-money laundering (AML) and sanctions screening requirements.
- Fraud Prevention and Security: Detecting fraudulent transactions, preventing unauthorized access, monitoring suspicious activities, and protecting the integrity of our services.
- Communication: Sending service updates, shipment tracking notifications, promotional offers, and responding to inquiries and complaints.
- Analytics and Service Improvement: Analyzing usage patterns, improving application features, optimizing user experience, and developing new services.
- Legal Compliance and Dispute Resolution: Responding to legal requests, enforcing our agreements, resolving disputes, and protecting legal rights.
- Marketing and Advertising: Sending newsletters, promotional communications, and personalized offers based on your preferences (only with consent).
- Payment Processors: Stripe, local payment gateways (for payment authorization only)
- Cloud Infrastructure Providers: Google Cloud (Firebase), Amazon Web Services, or equivalent secure hosting
- SMS/Email Communication Providers: SendGrid, Twilio, or local telecom providers (for OTP and notifications)
- Analytics Services: Google Analytics, Firebase Analytics (anonymized data only)
- Mapping and Location Services: Google Maps API (for real-time tracking)
- Third-party carriers and logistics companies (for transportation)
- Customs brokers and freight forwarders
- Warehouse and storage partners
- Institutional partners (Tabung Haji, travel agencies, tour operators)
- Saudi customs authorities (Zakat, Tax & Customs Authority)
- Malaysian customs authorities (Royal Malaysian Customs Department)
- Police and security agencies (for investigations)
- Financial intelligence units (for AML and sanctions compliance)
- Courts and legal representatives (in response to legal orders or litigation)
- Account Information: Retained for the duration of your account, plus 2 years after account termination (for archival, disputes, or legal requirements).
- Transaction and Shipment Data: Retained for 3 years from the date of transaction (per Malaysian PDPA and Saudi Arabian accounting regulations).
- Payment Information: Credit card data is not retained; payment records are retained for 7 years (per international tax and accounting standards).
- Location Data: Real-time location is deleted 30 days after shipment delivery; historical tracking is retained for 1 year.
- Log Files and Analytics: Server logs are retained for 90 days; aggregated analytics are retained for 24 months.
- Communication Records: Customer support messages are retained for 2 years.
- Marketing Communications: Retained until you unsubscribe, after which they are deleted within 30 days.
- Data in Transit: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher (HTTPS). We enforce secure socket layer (SSL) certificates with 256-bit encryption.
- Data at Rest: Sensitive personal data (payment information, identification details) is encrypted at rest using AES-256 encryption standards.
- Key Management: Encryption keys are securely stored and managed using industry-standard key management services (KMS). Keys are rotated annually.
- Multi-Factor Authentication: User accounts are protected by OTP (One-Time Password) sent via SMS, email, or authenticator apps. All administrative access requires multi-factor authentication.
- Role-Based Access Control: Employee and contractor access to personal data is restricted based on job roles and the principle of least privilege. Access logs are maintained and monitored.
- Password Security: Passwords are hashed using bcrypt or PBKDF2 algorithms. We enforce minimum password complexity requirements and session timeout policies.
- Firewalls and Intrusion Detection: We deploy enterprise-grade firewalls, Web Application Firewalls (WAF), and intrusion detection/prevention systems (IDS/IPS) to prevent unauthorized access.
- DDoS Protection: We implement DDoS mitigation services to protect against distributed denial-of-service attacks.
- Network Segmentation: Production and development environments are separated. Database and payment systems are isolated on secure network segments.
- Secure Software Development: The Bagasi Haji application is developed following OWASP (Open Web Application Security Project) top 10 standards. Code reviews and static analysis are performed regularly.
- Vulnerability Management: We conduct regular penetration testing and vulnerability assessments. Security patches are applied promptly.
- API Security: All APIs are protected with rate limiting, input validation, and API authentication tokens.
- Code Obfuscation: The Bagasi Haji mobile app code is obfuscated to prevent reverse engineering.
- Certificate Pinning: The mobile app uses certificate pinning to prevent man-in-the-middle (MITM) attacks.
- Secure Local Storage: Sensitive data stored locally on devices is encrypted and protected from unauthorized access. Authentication tokens are stored securely using platform-specific secure storage mechanisms.
- Regular Backups: Personal data is backed up daily to geographically redundant secure locations. Backups are encrypted and tested for restoration quarterly.
- Disaster Recovery Plan: We maintain a comprehensive disaster recovery and business continuity plan with recovery time objectives (RTO) of 4 hours and recovery point objectives (RPO) of 1 hour.
- Background Checks: All employees and contractors with access to personal data undergo background verification.
- Security Training: All staff receive mandatory data protection and cybersecurity training annually, with specific training for those handling customer data.
- Confidentiality Agreements: All employees and contractors sign confidentiality and data protection agreements.
- Security Monitoring: We maintain 24/7 security monitoring and logging of all system access, data access, and suspicious activities using Security Information and Event Management (SIEM) tools.
- Incident Response Team: We maintain a dedicated incident response team trained to detect, investigate, and respond to data breaches within 24 hours of discovery.
- Notify affected data subjects within 72 hours of discovery (or as required by law)
- Notify the Malaysian Personal Data Protection Commissioner (PDPC) or Saudi Arabian data protection authority as required by law
- Provide a clear description of the breach, the types of personal data affected, and the measures taken to mitigate harm
- Offer complimentary credit monitoring or identity theft protection services where applicable
- Conduct a forensic investigation and implement corrective actions to prevent future breaches
- Standard Contractual Clauses (SCCs) with third-party processors
- Binding Corporate Rules (BCRs) within Company groups
- End-to-end encryption ensuring data cannot be accessed by intermediaries
- Session Cookies: Automatically deleted when you close the browser; used for authentication and session management.
- Persistent Cookies: Remain on your device for a specified period; used to remember preferences and improve service features.
- Third-Party Cookies: Used by analytics services and advertising partners; you can disable these via your device settings.
- Do Not Track: If your browser sends a Do Not Track (DNT) signal, we will respect your preference and refrain from tracking your activity.
- Saudi Arabia's Law on Data Protection and Privacy (2018), which establishes requirements for lawful data collection, processing, and protection.
- The Personal Data Protection Law (PDPL), which governs private sector data protection and has been adopted in Saudi Arabia.
- Payment Card Industry Data Security Standard (PCI-DSS), for handling of payment card data.
- SAMA (Saudi Arabian Monetary Authority) Cybersecurity Requirements, for protecting financial and banking information.
- General Principles: Following the principles of notice, choice, disclosure, security, and access (NCDSA)
- Sensitivity Principles: Handling sensitive personal data (health, religion, etc.) with heightened protection
- Accountability: Maintaining records of personal data processing and responding to data subject requests within 30 days
- Cooperation: Cooperating with the Malaysian Personal Data Protection Commissioner (PDPC) in investigations and audits
- Malaysia – Personal Data Protection Commissioner (PDPC)
- Address: Level 11, Plaza Sentral, Jalan Stesen Sentral, 50470 Kuala Lumpur, Malaysia
- Phone: +603-2200-6060
- Website: www.pdpc.gov.my
- Saudi Arabia – General Authority for Data Protection (GADP)
- Address: Riyadh, Kingdom of Saudi Arabia
- Contact: via official government portals and GADP procedures
- Website: www.gadp.gov.sa (pending official launch)
- You have read and understood this Privacy Policy in its entirety.
- You consent to the collection, processing, and use of your personal data as described herein.
- You understand that your personal data may be transferred, processed, and stored in multiple jurisdictions.
- You acknowledge the cybersecurity measures in place and understand that no system is 100% secure.
- You understand your rights as a data subject and how to exercise them.
- You agree that the Company is not liable for damages arising from your own actions, failure to secure your account, or third-party interference.
2. Personal Data We Collect
2.1 Data Collected Directly from You
We collect the following personal data when you register for and use the Bagasi Haji 2026 application:
2.2 Data Collected Automatically
We automatically collect certain data when you interact with our application and services:
2.3 Data Received from Third Parties
We may receive personal data about you from:
3. Legal Basis for Data Processing
We process your personal data based on the following legal grounds:
- Contractual Performance: Processing necessary to fulfill our logistics services contract with you, including shipment collection, tracking, and delivery.
- Legal Obligation: Processing required to comply with laws of Saudi Arabia, Malaysia, and international regulations (customs declarations, anti-money laundering, sanctions screening, tax compliance).
- Legitimate Interest: Processing necessary for the Company’s legitimate business interests, including fraud prevention, security, customer service improvement, and service optimization.
- Your Explicit Consent: Processing based on your voluntary consent, such as receiving marketing communications, analytics tracking, or location-based services.
- Vital Interest: In emergencies or security incidents, we may process data necessary to protect the safety or security of individuals, property, or public interest.
- Right to Access: You have the right to request and obtain a copy of your personal data held by us. Requests should be submitted in writing to our Data Protection Officer (see contact details below). We will respond within 30 days.
- Right to Correction: You can request correction of inaccurate, incomplete, or misleading personal data. We will update your information within 30 days of verification.
- Right to Deletion (Right to Be Forgotten): You may request deletion of your personal data, except where we are required to retain it for legal or contractual reasons. Data will be deleted within 60 days of request.
- Right to Withdraw Consent: If we are processing your data based on your consent (e.g., marketing communications), you can withdraw consent at any time by clicking “Unsubscribe” or notifying us in writing. Withdrawal does not affect the legality of processing prior to withdrawal.
- Right to Object: You may object to processing of your personal data on grounds relating to your particular situation, especially for direct marketing.
- Right to Data Portability: You have the right to request your personal data in a structured, commonly used, and machine-readable format, to be transmitted to another organization if technically feasible.
- Right to Lodge a Complaint: If you believe your personal data rights have been violated, you have the right to lodge a complaint with the Malaysian Personal Data Protection Commissioner (PDPC) or equivalent Saudi Arabian authority.
- In the event of a suspected or confirmed data breach involving your personal data, the Company will:
- Data Transfer Mechanisms: Data transfers to countries outside Saudi Arabia and Malaysia are protected using:
- Adequacy Assessment: We ensure that recipient countries provide adequate levels of data protection, or we implement supplementary technical measures (encryption, anonymization) to ensure your rights are protected.
- Cooperation with Authorities: We may transfer data to government authorities in compliance with legal obligations; however, we will notify you and challenge any request that is excessive or outside the scope of law.
4. How We Use Your Personal Data
We use your personal data for the following purposes:
5. Data Sharing and Disclosure
Your personal data may be shared with the following parties for legitimate business and legal purposes:
5.1 Third-Party Service Providers
We share personal data with third-party data processors who provide services on our behalf, including:
5.2 Business Partners and Logistics Networks
We share shipment and delivery data with:
5.3 Government and Legal Authorities
We may disclose personal data to government agencies and law enforcement when required by law, including:
6. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. Retention periods are as follows:
Upon expiration of the retention period, data is securely deleted or anonymized. Legal holds may extend retention periods if required for litigation or regulatory investigations.
7. Your Rights as a Data Subject
Under the Malaysian Personal Data Protection Act 2010 (PDPA) and Saudi Arabian data protection regulations, you have the following rights:
8. Cybersecurity and Data Protection Measures
We implement comprehensive technical, organizational, and administrative safeguards to protect your personal data against unauthorized access, loss, alteration, and misuse:
8.1 Encryption and Secure Communication
- Data in Transit: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher (HTTPS). We enforce secure socket layer (SSL) certificates with 256-bit encryption.
- Data at Rest: Sensitive personal data (payment information, identification details) is encrypted at rest using AES-256 encryption standards.
- Key Management: Encryption keys are securely stored and managed using industry-standard key management services (KMS). Keys are rotated annually.
8.2 Personnel Security
- Background Checks: All employees and contractors with access to personal data undergo background verification.
- Security Training: All staff receive mandatory data protection and cybersecurity training annually, with specific training for those handling customer data.
- Confidentiality Agreements: All employees and contractors sign confidentiality and data protection agreements.
8.3 Monitoring and Incident Response
- Security Monitoring: We maintain 24/7 security monitoring and logging of all system access, data access, and suspicious activities using Security Information and Event Management (SIEM) tools.
- Incident Response Team: We maintain a dedicated incident response team trained to detect, investigate, and respond to data breaches within 24 hours of discovery.
9. Data Breach Notification
In the event of a suspected or confirmed data breach involving your personal data, the Company will:
- Notify affected data subjects within 72 hours of discovery (or as required by law)
- Notify the Malaysian Personal Data Protection Commissioner (PDPC) or Saudi Arabian data protection authority as required by law
- Provide a clear description of the breach, the types of personal data affected, and the measures taken to mitigate harm
- Offer complimentary credit monitoring or identity theft protection services where applicable
- Conduct a forensic investigation and implement corrective actions to prevent future breaches
10. Cross-Border Data Transfers
Because the Bagasi Inc service operates between Saudi Arabia and Malaysia, your personal data may be transferred, processed, and stored outside your country of residence:
11. Third-Party Links and Services
The Bagasi Inc application may contain links to third-party websites and services (payment providers, social media, maps, etc.). This Privacy Policy does not apply to such third-party services. We encourage you to review the privacy policies of third-party services before providing your personal data. The Company is not responsible for the privacy practices of third parties.
12. Children's Privacy
The Bagasi Inc. service is intended for individuals aged 18 and above. We do not knowingly collect personal data from children under the age of 13. If we become aware that a child has provided us with personal data without parental consent, we will delete such data promptly. Parents or guardians who believe a child has provided personal data to us should contact our Data Protection Officer immediately.
13. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to improve your user experience and provide personalized services:
14. Compliance with Saudi Arabian Data Protection Laws
Our data protection practices comply with applicable Saudi Arabian laws, including:
15. Compliance with Malaysian Personal Data Protection Act 2010 (PDPA)
The Company complies fully with Malaysia 2019;s Personal Data Protection Act 2010 (PDPA), including:
16. Data Protection Officer and Contact Information
The Company has appointed a Data Protection Officer (DPO) responsible for overseeing data protection compliance and handling data subject requests. You may contact the DPO regarding privacy concerns:
Data Protection Officer
CBP Express & Logistics / Bagas Inc.
Email: privacy@bagas inc.com
Response Time: We aim to respond to all inquiries within 10 business days.
17. Regulatory Authority Contacts
If you wish to lodge a complaint regarding our data protection practices, you may contact the following regulatory authorities:
18. Modifications to This Privacy Policy
The Company reserves the right to modify, amend, or supplement this Privacy Policy at any time, without prior notice. Continued use of the Bagasi Inc. application after modifications constitutes acceptance of the revised Privacy Policy. We will notify you of significant changes via email or in-app notification. The Effective Date; at the bottom of this policy will be updated to reflect the date of the most recent revision.
19. Governing Law and Jurisdiction
This Privacy Policy is governed by and construed in accordance with the laws of Malaysia (Personal Data Protection Act 2010) and Saudi Arabia, as applicable based on where the data collection and processing occurs. Any disputes arising from this Privacy Policy shall be resolved through negotiation, mediation, or arbitration in accordance with the laws of the jurisdiction where the Company elects to proceed.
20. Acknowledgment
By using the Bagasi Inc. services, you acknowledge and agree that:
CBP EXPRESS & LOGISTICS / BAGAS INC.
Bagasi Haji & Umrah Cargo and Luggage Logistics Services
Privacy Policy, Data Protection, and Cybersecurity
Effective Date: 28 April 2026 | Last Updated: 28 April 2026