BeyondClass Privacy Policy
Last Updated: January 2026
Effective Date: January 2026
Entity: Fitzgerald Ventures Sdn. Bhd.
Company Registration No.: 202501020554 (1621967-U)
Registered Address: Unit 3A08, Block C, Pusat Dagangan Phileo Damansara 1, No. 9, Jalan 16/11, Off Jalan Damansara, 46350 Petaling Jaya, Selangor, Malaysia
Contact: hello@beyondclass.app
1. Introduction
Fitzgerald Ventures Sdn. Bhd. ("we", "us", or "our") operates the BeyondClass platform, a marketplace connecting parents and guardians with enrichment activity providers for children in Malaysia. This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when you use our mobile applications and services.
We are committed to protecting your personal data in accordance with the Personal Data Protection Act 2010 (PDPA) of Malaysia. Where our services are used by individuals in other jurisdictions, we also comply with applicable international data protection standards, including the General Data Protection Regulation (GDPR) where relevant, and the Children's Online Privacy Protection Act (COPPA) for United States users.
By downloading, installing, or using the BeyondClass applications, you acknowledge that you have read and understood this Privacy Policy and consent to our collection and use of your personal data as described herein.
2. Scope and Application
2.1 Applications Covered
This Privacy Policy applies to two separate mobile applications:
- •BeyondClass (Parents App): Used by parents and legal guardians to discover, browse, and book enrichment activities for their children
- •BeyondClass Providers (Providers App): Used by activity providers, schools, and enrichment centres to list activities, manage bookings, and receive payments
2.2 User Categories
- •Parents and Guardians: Adult individuals (18 years or older) who create accounts on the Parents App to book activities for children in their care
- •Providers: Businesses, schools, and individuals who create accounts on the Providers App to offer and manage enrichment activities
- •Children: Minors under 18 years of age who are data subjects only. Children do not create accounts or interact directly with either application. All data concerning children is provided and managed exclusively by their parent or legal guardian.
2.3 Features Covered
This Privacy Policy covers data processing for the following platform features:
- •Activity discovery and browsing
- •Account creation and management
- •Booking and payment processing
- •Provider verification
- •Communications and notifications
3. Data We Collect
We collect different categories of personal data depending on whether you use the Parents App or Providers App. The following sections provide an exhaustive list of all data types collected.
3.1 Data Collected from Parents and Guardians (Parents App)
Account and Identity Data
- •Full name
- •Email address
- •Phone number
- •Profile photograph (optional)
- •Account credentials (password stored in hashed form only)
- •Unique account identifier
Child Profile Data (Provided by Parents)
- •Child's name
- •Child's date of birth or age
- •Activity preferences and interests
- •Health, allergy, or safety notes (entered voluntarily by parents)
Booking and Transaction Data
- •Booking history and details
- •Activity attendance records
- •Payment transaction identifiers
- •Payment amounts and dates
- •Refund records
- •Wallet credit balances (if applicable)
Payment Information
Payment card details are collected and processed directly by Stripe, our third-party payment processor. BeyondClass does not receive, process, or store full payment card numbers. We receive only:
- •Last four digits of the payment card (for display purposes)
- •Card type and expiry month/year
- •Billing postcode (if provided)
- •Stripe customer and payment method identifiers
Location Data
- •Approximate location (city or area level) for activity discovery
- •Location is collected in foreground only when the app is in active use
Calendar Data
When you choose to add a booking to your device calendar, we create calendar events with booking details. We do not read or access your existing calendar events.
3.2 Data Collected from Providers (Providers App)
Business Identity Data
- •Business or trading name
- •Business registration number (SSM or equivalent)
- •Business address
- •Business contact email and phone number
- •Business logo and profile images
Account Holder Data
- •Name of account holder or authorised representative
- •Personal email address
- •Personal phone number
- •Account credentials
Verification Documents
- •Identity document (IC or passport) of account holder
- •Business registration certificate
- •Other documents required for identity and business verification
Financial Data
- •Bank account details for payouts
- •Stripe Connect account identifiers
- •Payout history and amounts
- •Tax identification information (if required)
Activity and Listing Data
- •Activity titles, descriptions, and categories
- •Activity schedules, pricing, and capacity
- •Activity location addresses
- •Activity photographs and media
- •Booking records and fulfilment data
3.3 Technical and System Data (Both Apps)
We automatically collect the following technical data from all users:
- •Device type, model, and manufacturer
- •Operating system and version
- •App version
- •Device identifiers (for push notification delivery)
- •Push notification tokens
- •IP address
- •Authentication logs (login times, methods)
- •App usage and interaction events
- •Feature usage statistics
- •Crash reports and performance data
- •Analytics identifiers
4. Device Permissions
Our applications request specific device permissions to enable core functionality. Each permission is explained below, including what data is accessed, why it is needed, and whether it is required or optional.
| Permission | Data Accessed | Purpose | Required |
|---|---|---|---|
| Location | Approximate device location (foreground only) | Find nearby activities / Set accurate activity addresses | Optional |
| Camera | Camera sensor to capture photos | Capture profile photos, activity images, and verification documents | Optional |
| Photo Library | Access to selected photos from device storage | Select existing photos for profile images and activity photos | Optional |
| Calendar | Write access to device calendar (no read access) | Add booking details as calendar events for reminders | Optional |
| Push Notifications | Device push notification token | Send booking confirmations, reminders, and updates | Optional |
| Biometric | Biometric authentication result (not raw data) | Secure and convenient app login | Optional |
You can grant or revoke any of these permissions at any time through your device settings. Denying optional permissions may limit certain features but will not prevent you from using the core functionality of the app.
5. Purpose of Data Collection
We collect and process personal data for the following specific purposes:
5.1 Account Creation and Authentication
To create and manage your BeyondClass account, verify your identity, authenticate your login sessions, and maintain account security. This includes processing data from email/password registration, Google Sign-In, and Apple Sign-In.
5.2 Service Delivery
To enable parents to discover, browse, and book enrichment activities for their children. To enable providers to list activities, manage schedules, and fulfil bookings. To facilitate the matching of parents with appropriate activities based on location, preferences, and availability.
5.3 Payment Processing
To process payments for bookings, manage refunds, handle provider payouts, and maintain transaction records for accounting and tax purposes.
5.4 Provider Verification
To verify the identity and legitimacy of activity providers, including verification of business registration and identity documents, to protect parents and children from fraudulent or unqualified providers.
5.5 Communications
To send booking confirmations, reminders, receipts, and account notifications via push notifications and email. Marketing communications are sent only with your explicit consent and you may opt out at any time.
5.6 Child Safety and Activity Fulfilment
To share necessary child information (name, age, and any health or safety notes provided by parents) with booked activity providers solely for the purpose of safe activity delivery and appropriate care.
5.7 Platform Improvement and Analytics
To analyse usage patterns, diagnose technical issues, improve app performance, and enhance features based on aggregated user behaviour. Analytics data is used in anonymised or aggregated form where possible. We do not use personal data for cross-app tracking or third-party advertising.
5.8 Legal Compliance
To comply with applicable laws, regulations, court orders, and legal processes. To protect our legal rights and interests, and to respond to legitimate requests from regulatory authorities.
6. Children's Data
BeyondClass takes the protection of children's data seriously. This section explains our approach to collecting and handling data about children.
6.1 No Child Accounts
Children under 18 years of age cannot create accounts on BeyondClass. Both the Parents App and Providers App require users to be 18 years or older. Children are data subjects only, meaning we hold data about them, but they do not interact with our applications directly.
6.2 Parental Authority
All data concerning children is provided exclusively by their parent or legal guardian. By adding a child profile and providing child data, the parent or guardian represents that they have legal authority to provide such data and consent to its processing as described in this Privacy Policy. Parents are solely responsible for the accuracy of information submitted about their children.
6.3 Data Collected About Children
We collect only the following data about children, provided by their parents:
- •Name (to identify the child for booking purposes)
- •Date of birth or age (to determine eligibility for age-appropriate activities)
- •Activity preferences and interests (to help parents find suitable activities)
- •Health, allergy, or safety notes (entered voluntarily by parents for safe activity delivery)
6.4 How Child Data is Used
Child data is used solely for:
- •Processing and managing bookings
- •Determining activity eligibility based on age
- •Sharing with booked providers so they can deliver activities safely and appropriately
6.5 Provider Access to Child Data
When a parent books an activity, the relevant provider receives only the information necessary to fulfil the booking: the child's name, age, and any health or safety notes. Providers cannot access child data for children not booked into their activities. Providers are contractually required to use child data only for activity fulfilment and not for marketing or other purposes.
6.6 Parental Rights Over Child Data
Parents may access, correct, or delete their child's profile and data at any time through the Parents App or by contacting us at hello@beyondclass.app. When a parent deletes a child profile, all associated data is removed subject to our retention obligations described in Section 9.
6.7 COPPA Compliance (United States Users)
For users in the United States, we comply with the Children's Online Privacy Protection Act (COPPA). We do not knowingly collect personal information directly from children under 13. All child data is collected from parents or legal guardians who provide verifiable parental consent through their account registration and acceptance of this Privacy Policy. If we become aware that we have inadvertently collected personal information directly from a child under 13 without proper parental consent, we will promptly delete such information.
7. Third-Party Services and Data Processors
We use third-party services to operate the BeyondClass platform. These service providers act as data processors on our behalf and process personal data only as instructed by us and subject to contractual data protection obligations.
7.1 Firebase (Google LLC)
We use multiple Firebase services provided by Google LLC:
- •Firebase Authentication: Manages user account creation, login sessions, and authentication tokens
- •Firebase Firestore: Stores user profiles, bookings, activity listings, and other platform data
- •Firebase Cloud Storage: Stores uploaded images including profile photos and activity images
- •Firebase Analytics: Collects app usage data, feature interactions, and performance metrics
- •Firebase Cloud Messaging: Delivers push notifications to user devices
Firebase Privacy Policy: https://firebase.google.com/support/privacy
7.2 Stripe
We use Stripe for payment processing:
- •Parent Payments: Stripe collects and processes payment card details when parents pay for bookings
- •Provider Payouts: Stripe processes bank account details and manages payouts to providers through Stripe Connect
- •Provider Verification: Stripe may collect additional identity verification information from providers
Stripe Privacy Policy: https://stripe.com/privacy
7.3 Google Sign-In
When you choose to sign in with Google, we receive:
- •Your Google account email address
- •Your name as registered with Google
- •Your Google profile picture (if available)
Google Privacy Policy: https://policies.google.com/privacy
7.4 Apple Sign-In
When you choose to sign in with Apple, we receive:
- •Your Apple ID email address (or a private relay email if you choose to hide your email)
- •Your name (on first sign-in only, if you choose to share it)
Apple Privacy Policy: https://www.apple.com/legal/privacy/
7.5 Independent Third-Party Policies
Each third-party service operates under its own privacy policy. While we require our service providers to protect your data, we are not responsible for the independent data practices of these third parties. We encourage you to review their privacy policies directly.
8. Data Sharing and Disclosure
8.1 We Do Not Sell Personal Data
BeyondClass does not sell, rent, or trade your personal data to any third party for their marketing or commercial purposes.
8.2 Sharing with Activity Providers
When a parent makes a booking, we share the following information with the relevant activity provider to enable fulfilment: parent contact details, child name, child age, health or safety notes (if provided), and booking details. Providers are contractually prohibited from using this data for purposes other than activity delivery.
8.3 Sharing with Service Providers
We share data with the third-party service providers described in Section 7 (Firebase and Stripe) solely to operate our platform. These providers process data as data processors under our instruction.
8.4 Legal Disclosures
We may disclose personal data when required by law or when we believe disclosure is necessary to:
- •Comply with a legal obligation, court order, or regulatory requirement
- •Protect the safety of any person, including children
- •Investigate potential violations of our terms of service
- •Protect our legal rights or defend against legal claims
8.5 Cross-Border Data Transfers
Our service providers, including Firebase (Google) and Stripe, may process and store data on servers located outside Malaysia, including in the United States and the European Union. When personal data is transferred outside Malaysia, we ensure compliance with the PDPA by implementing appropriate safeguards, including contractual clauses requiring recipients to protect data to standards equivalent to Malaysian law.
8.6 Business Transfers
In the event of a merger, acquisition, or sale of all or part of our business, personal data may be transferred to the acquiring entity. We will notify affected users of any such transfer and any changes to this Privacy Policy.
9. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. The following table sets out our retention periods by data category:
| Data Category | Retention Period | Basis |
|---|---|---|
| Active account data | Duration of account | Required to provide services |
| Child profiles | Until deleted by parent or account deletion | Parental control over child data |
| Booking records | 7 years from transaction | Tax and financial record requirements |
| Payment and payout records | 7 years from transaction | Tax, accounting, and audit requirements |
| Provider verification documents | Duration of account + 2 years | Regulatory compliance and dispute resolution |
| Analytics and usage logs | 26 months | Platform improvement and troubleshooting |
| Authentication logs | 12 months | Security and fraud prevention |
| Backup data | 30 days after source deletion | Disaster recovery |
| Inactive accounts | 24 months of inactivity | After 24 months, account flagged for deletion |
When data is no longer required for any lawful purpose, it is securely deleted or anonymised.
10. Account Deletion
You have the right to delete your BeyondClass account at any time. This section explains how to delete your account and what happens to your data.
10.1 How to Delete Your Account
Parents App
- Open the BeyondClass app
- Navigate to Settings (gear icon)
- Select Account
- Tap Delete Account
- Confirm deletion when prompted
Providers App
- Open the BeyondClass Providers app
- Navigate to Settings (gear icon)
- Select Account
- Tap Delete Account
- Confirm deletion when prompted
Alternative Method: You may also request account deletion by emailing hello@beyondclass.app from your registered email address with "Account Deletion Request" in the subject line.
10.2 What Happens When You Delete Your Account
Deleted Immediately
- • Your profile information (name, email, phone, profile photo)
- • Child profiles and associated data (Parents App)
- • Activity listings (Providers App)
- • Saved preferences and settings
- • Push notification tokens
- • Active login sessions
Deleted Within 30 Days
- • Data stored in backup systems
Retained as Required by Law
- • Transaction and payment records (retained for 7 years)
- • Provider verification documents (retained for 2 years after account closure)
- • Any data required to comply with legal obligations or resolve disputes
10.3 Processing Time
Account deletion requests submitted through the app are processed immediately. Email requests are processed within 7 business days. You will receive a confirmation email once your account has been deleted.
10.4 Effect on Pending Bookings
If you have pending or upcoming bookings at the time of deletion, these will be cancelled. For parents, refunds will be processed according to our standard refund policy. Providers with pending payouts will receive their payouts before account data is deleted.
11. Your Rights
Under the Personal Data Protection Act 2010 (PDPA) and other applicable laws, you have the following rights regarding your personal data:
11.1 Right of Access
You have the right to request access to the personal data we hold about you. We will provide a copy of your data in a commonly used electronic format within 21 days of receiving your request.
11.2 Right of Correction
You have the right to request correction of any inaccurate or incomplete personal data. You can update most information directly within the app settings. For data you cannot update yourself, contact us and we will make corrections within 14 days.
11.3 Right to Withdraw Consent
Where we process your data based on consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal. Note that withdrawing consent for essential processing may affect our ability to provide services to you.
11.4 Right to Deletion
You may request deletion of your account and personal data as described in Section 10. We will delete your data except where retention is required by law or for legitimate business purposes as specified.
11.5 Right to Complain
If you believe we have not handled your personal data in accordance with the law, you have the right to lodge a complaint with the Personal Data Protection Commissioner of Malaysia (PDPC) at www.pdp.gov.my.
11.6 How to Exercise Your Rights
To exercise any of these rights, contact us at:
- •Email: hello@beyondclass.app
- •Post: Data Protection Officer, Fitzgerald Ventures Sdn. Bhd., Unit 3A08, Block C, Pusat Dagangan Phileo Damansara 1, No. 9, Jalan 16/11, Off Jalan Damansara, 46350 Petaling Jaya, Selangor, Malaysia
We may need to verify your identity before processing your request. We will respond to all legitimate requests within 21 days. If your request is complex, we will inform you within 21 days and may take up to an additional 14 days to respond.
12. Security Measures
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration:
Encryption
- •Data in transit is encrypted using TLS 1.2 or higher
- •Data at rest is encrypted using AES-256 encryption
Authentication Security
- •Passwords are stored using industry-standard hashing
- •Biometric authentication available for secure login
- •Biometric data processed on-device only
Access Controls
- •Access restricted to authorised personnel only
- •Administrative access requires authentication and is logged
Infrastructure Security
- •Hosted on Google Cloud with SOC 2 and ISO 27001 certifications
- •Regular security monitoring and vulnerability assessments
While we implement robust security measures, no method of electronic transmission or storage is 100% secure. We encourage you to use strong passwords, enable biometric login where available, and contact us immediately if you suspect any unauthorised access to your account.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
Notification of Changes
For material changes that affect how we collect, use, or share your personal data, we will notify you by:
- •Email to your registered email address
- •In-app notification
- •Prominent notice within the app at least 30 days before changes take effect
Effective Date
The "Last Updated" and "Effective Date" at the top of this policy indicate when it was last revised.
Continued Use
Your continued use of the BeyondClass applications after any changes to this Privacy Policy constitutes your acceptance of the updated policy. If you do not agree with any changes, you should stop using the app and delete your account.
14. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Fitzgerald Ventures Sdn. Bhd.
Company Registration No.: 202501020554 (1621967-U)
Unit 3A08, Block C, Pusat Dagangan Phileo Damansara 1,
No. 9, Jalan 16/11, Off Jalan Damansara,
46350 Petaling Jaya, Selangor, Malaysia
Email: hello@beyondclass.app
We will respond to all enquiries within 14 days.
15. Legal Basis for Processing
Under the Personal Data Protection Act 2010 (PDPA) of Malaysia, we process your personal data based on the following legal grounds:
- •Consent: You have provided consent for processing your personal data for specific purposes, including by accepting this Privacy Policy and using our services
- •Contractual Necessity: Processing is necessary to perform our contract with you, including providing the BeyondClass platform services, processing bookings, and facilitating payments
- •Legal Obligation: Processing is necessary to comply with legal obligations, including tax, financial reporting, and regulatory requirements
- •Legitimate Interests: Processing is necessary for our legitimate business interests, such as fraud prevention, platform security, and service improvement, provided these interests do not override your fundamental rights and freedoms
— End of Privacy Policy —