BackBeyondClass

    BeyondClass Privacy Policy

    Last Updated: January 2026

    Effective Date: January 2026

    Entity: Fitzgerald Ventures Sdn. Bhd.

    Company Registration No.: 202501020554 (1621967-U)

    Registered Address: Unit 3A08, Block C, Pusat Dagangan Phileo Damansara 1, No. 9, Jalan 16/11, Off Jalan Damansara, 46350 Petaling Jaya, Selangor, Malaysia

    Contact: hello@beyondclass.app

    1. Introduction

    Fitzgerald Ventures Sdn. Bhd. ("we", "us", or "our") operates the BeyondClass platform, a marketplace connecting parents and guardians with enrichment activity providers for children in Malaysia. This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when you use our mobile applications and services.

    We are committed to protecting your personal data in accordance with the Personal Data Protection Act 2010 (PDPA) of Malaysia. Where our services are used by individuals in other jurisdictions, we also comply with applicable international data protection standards, including the General Data Protection Regulation (GDPR) where relevant, and the Children's Online Privacy Protection Act (COPPA) for United States users.

    By downloading, installing, or using the BeyondClass applications, you acknowledge that you have read and understood this Privacy Policy and consent to our collection and use of your personal data as described herein.

    2. Scope and Application

    2.1 Applications Covered

    This Privacy Policy applies to two separate mobile applications:

    • BeyondClass (Parents App): Used by parents and legal guardians to discover, browse, and book enrichment activities for their children
    • BeyondClass Providers (Providers App): Used by activity providers, schools, and enrichment centres to list activities, manage bookings, and receive payments

    2.2 User Categories

    • Parents and Guardians: Adult individuals (18 years or older) who create accounts on the Parents App to book activities for children in their care
    • Providers: Businesses, schools, and individuals who create accounts on the Providers App to offer and manage enrichment activities
    • Children: Minors under 18 years of age who are data subjects only. Children do not create accounts or interact directly with either application. All data concerning children is provided and managed exclusively by their parent or legal guardian.

    2.3 Features Covered

    This Privacy Policy covers data processing for the following platform features:

    • Activity discovery and browsing
    • Account creation and management
    • Booking and payment processing
    • Provider verification
    • Communications and notifications

    3. Data We Collect

    We collect different categories of personal data depending on whether you use the Parents App or Providers App. The following sections provide an exhaustive list of all data types collected.

    3.1 Data Collected from Parents and Guardians (Parents App)

    Account and Identity Data

    • Full name
    • Email address
    • Phone number
    • Profile photograph (optional)
    • Account credentials (password stored in hashed form only)
    • Unique account identifier

    Child Profile Data (Provided by Parents)

    • Child's name
    • Child's date of birth or age
    • Activity preferences and interests
    • Health, allergy, or safety notes (entered voluntarily by parents)

    Booking and Transaction Data

    • Booking history and details
    • Activity attendance records
    • Payment transaction identifiers
    • Payment amounts and dates
    • Refund records
    • Wallet credit balances (if applicable)

    Payment Information

    Payment card details are collected and processed directly by Stripe, our third-party payment processor. BeyondClass does not receive, process, or store full payment card numbers. We receive only:

    • Last four digits of the payment card (for display purposes)
    • Card type and expiry month/year
    • Billing postcode (if provided)
    • Stripe customer and payment method identifiers

    Location Data

    • Approximate location (city or area level) for activity discovery
    • Location is collected in foreground only when the app is in active use

    Calendar Data

    When you choose to add a booking to your device calendar, we create calendar events with booking details. We do not read or access your existing calendar events.

    3.2 Data Collected from Providers (Providers App)

    Business Identity Data

    • Business or trading name
    • Business registration number (SSM or equivalent)
    • Business address
    • Business contact email and phone number
    • Business logo and profile images

    Account Holder Data

    • Name of account holder or authorised representative
    • Personal email address
    • Personal phone number
    • Account credentials

    Verification Documents

    • Identity document (IC or passport) of account holder
    • Business registration certificate
    • Other documents required for identity and business verification

    Financial Data

    • Bank account details for payouts
    • Stripe Connect account identifiers
    • Payout history and amounts
    • Tax identification information (if required)

    Activity and Listing Data

    • Activity titles, descriptions, and categories
    • Activity schedules, pricing, and capacity
    • Activity location addresses
    • Activity photographs and media
    • Booking records and fulfilment data

    3.3 Technical and System Data (Both Apps)

    We automatically collect the following technical data from all users:

    • Device type, model, and manufacturer
    • Operating system and version
    • App version
    • Device identifiers (for push notification delivery)
    • Push notification tokens
    • IP address
    • Authentication logs (login times, methods)
    • App usage and interaction events
    • Feature usage statistics
    • Crash reports and performance data
    • Analytics identifiers

    4. Device Permissions

    Our applications request specific device permissions to enable core functionality. Each permission is explained below, including what data is accessed, why it is needed, and whether it is required or optional.

    PermissionData AccessedPurposeRequired
    LocationApproximate device location (foreground only)Find nearby activities / Set accurate activity addressesOptional
    CameraCamera sensor to capture photosCapture profile photos, activity images, and verification documentsOptional
    Photo LibraryAccess to selected photos from device storageSelect existing photos for profile images and activity photosOptional
    CalendarWrite access to device calendar (no read access)Add booking details as calendar events for remindersOptional
    Push NotificationsDevice push notification tokenSend booking confirmations, reminders, and updatesOptional
    BiometricBiometric authentication result (not raw data)Secure and convenient app loginOptional

    You can grant or revoke any of these permissions at any time through your device settings. Denying optional permissions may limit certain features but will not prevent you from using the core functionality of the app.

    5. Purpose of Data Collection

    We collect and process personal data for the following specific purposes:

    5.1 Account Creation and Authentication

    To create and manage your BeyondClass account, verify your identity, authenticate your login sessions, and maintain account security. This includes processing data from email/password registration, Google Sign-In, and Apple Sign-In.

    5.2 Service Delivery

    To enable parents to discover, browse, and book enrichment activities for their children. To enable providers to list activities, manage schedules, and fulfil bookings. To facilitate the matching of parents with appropriate activities based on location, preferences, and availability.

    5.3 Payment Processing

    To process payments for bookings, manage refunds, handle provider payouts, and maintain transaction records for accounting and tax purposes.

    5.4 Provider Verification

    To verify the identity and legitimacy of activity providers, including verification of business registration and identity documents, to protect parents and children from fraudulent or unqualified providers.

    5.5 Communications

    To send booking confirmations, reminders, receipts, and account notifications via push notifications and email. Marketing communications are sent only with your explicit consent and you may opt out at any time.

    5.6 Child Safety and Activity Fulfilment

    To share necessary child information (name, age, and any health or safety notes provided by parents) with booked activity providers solely for the purpose of safe activity delivery and appropriate care.

    5.7 Platform Improvement and Analytics

    To analyse usage patterns, diagnose technical issues, improve app performance, and enhance features based on aggregated user behaviour. Analytics data is used in anonymised or aggregated form where possible. We do not use personal data for cross-app tracking or third-party advertising.

    5.8 Legal Compliance

    To comply with applicable laws, regulations, court orders, and legal processes. To protect our legal rights and interests, and to respond to legitimate requests from regulatory authorities.

    6. Children's Data

    BeyondClass takes the protection of children's data seriously. This section explains our approach to collecting and handling data about children.

    6.1 No Child Accounts

    Children under 18 years of age cannot create accounts on BeyondClass. Both the Parents App and Providers App require users to be 18 years or older. Children are data subjects only, meaning we hold data about them, but they do not interact with our applications directly.

    6.2 Parental Authority

    All data concerning children is provided exclusively by their parent or legal guardian. By adding a child profile and providing child data, the parent or guardian represents that they have legal authority to provide such data and consent to its processing as described in this Privacy Policy. Parents are solely responsible for the accuracy of information submitted about their children.

    6.3 Data Collected About Children

    We collect only the following data about children, provided by their parents:

    • Name (to identify the child for booking purposes)
    • Date of birth or age (to determine eligibility for age-appropriate activities)
    • Activity preferences and interests (to help parents find suitable activities)
    • Health, allergy, or safety notes (entered voluntarily by parents for safe activity delivery)

    6.4 How Child Data is Used

    Child data is used solely for:

    • Processing and managing bookings
    • Determining activity eligibility based on age
    • Sharing with booked providers so they can deliver activities safely and appropriately

    6.5 Provider Access to Child Data

    When a parent books an activity, the relevant provider receives only the information necessary to fulfil the booking: the child's name, age, and any health or safety notes. Providers cannot access child data for children not booked into their activities. Providers are contractually required to use child data only for activity fulfilment and not for marketing or other purposes.

    6.6 Parental Rights Over Child Data

    Parents may access, correct, or delete their child's profile and data at any time through the Parents App or by contacting us at hello@beyondclass.app. When a parent deletes a child profile, all associated data is removed subject to our retention obligations described in Section 9.

    6.7 COPPA Compliance (United States Users)

    For users in the United States, we comply with the Children's Online Privacy Protection Act (COPPA). We do not knowingly collect personal information directly from children under 13. All child data is collected from parents or legal guardians who provide verifiable parental consent through their account registration and acceptance of this Privacy Policy. If we become aware that we have inadvertently collected personal information directly from a child under 13 without proper parental consent, we will promptly delete such information.

    7. Third-Party Services and Data Processors

    We use third-party services to operate the BeyondClass platform. These service providers act as data processors on our behalf and process personal data only as instructed by us and subject to contractual data protection obligations.

    7.1 Firebase (Google LLC)

    We use multiple Firebase services provided by Google LLC:

    • Firebase Authentication: Manages user account creation, login sessions, and authentication tokens
    • Firebase Firestore: Stores user profiles, bookings, activity listings, and other platform data
    • Firebase Cloud Storage: Stores uploaded images including profile photos and activity images
    • Firebase Analytics: Collects app usage data, feature interactions, and performance metrics
    • Firebase Cloud Messaging: Delivers push notifications to user devices

    Firebase Privacy Policy: https://firebase.google.com/support/privacy

    7.2 Stripe

    We use Stripe for payment processing:

    • Parent Payments: Stripe collects and processes payment card details when parents pay for bookings
    • Provider Payouts: Stripe processes bank account details and manages payouts to providers through Stripe Connect
    • Provider Verification: Stripe may collect additional identity verification information from providers

    Stripe Privacy Policy: https://stripe.com/privacy

    7.3 Google Sign-In

    When you choose to sign in with Google, we receive:

    • Your Google account email address
    • Your name as registered with Google
    • Your Google profile picture (if available)

    Google Privacy Policy: https://policies.google.com/privacy

    7.4 Apple Sign-In

    When you choose to sign in with Apple, we receive:

    • Your Apple ID email address (or a private relay email if you choose to hide your email)
    • Your name (on first sign-in only, if you choose to share it)

    Apple Privacy Policy: https://www.apple.com/legal/privacy/

    7.5 Independent Third-Party Policies

    Each third-party service operates under its own privacy policy. While we require our service providers to protect your data, we are not responsible for the independent data practices of these third parties. We encourage you to review their privacy policies directly.

    8. Data Sharing and Disclosure

    8.1 We Do Not Sell Personal Data

    BeyondClass does not sell, rent, or trade your personal data to any third party for their marketing or commercial purposes.

    8.2 Sharing with Activity Providers

    When a parent makes a booking, we share the following information with the relevant activity provider to enable fulfilment: parent contact details, child name, child age, health or safety notes (if provided), and booking details. Providers are contractually prohibited from using this data for purposes other than activity delivery.

    8.3 Sharing with Service Providers

    We share data with the third-party service providers described in Section 7 (Firebase and Stripe) solely to operate our platform. These providers process data as data processors under our instruction.

    8.4 Legal Disclosures

    We may disclose personal data when required by law or when we believe disclosure is necessary to:

    • Comply with a legal obligation, court order, or regulatory requirement
    • Protect the safety of any person, including children
    • Investigate potential violations of our terms of service
    • Protect our legal rights or defend against legal claims

    8.5 Cross-Border Data Transfers

    Our service providers, including Firebase (Google) and Stripe, may process and store data on servers located outside Malaysia, including in the United States and the European Union. When personal data is transferred outside Malaysia, we ensure compliance with the PDPA by implementing appropriate safeguards, including contractual clauses requiring recipients to protect data to standards equivalent to Malaysian law.

    8.6 Business Transfers

    In the event of a merger, acquisition, or sale of all or part of our business, personal data may be transferred to the acquiring entity. We will notify affected users of any such transfer and any changes to this Privacy Policy.

    9. Data Retention

    We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. The following table sets out our retention periods by data category:

    Data CategoryRetention PeriodBasis
    Active account dataDuration of accountRequired to provide services
    Child profilesUntil deleted by parent or account deletionParental control over child data
    Booking records7 years from transactionTax and financial record requirements
    Payment and payout records7 years from transactionTax, accounting, and audit requirements
    Provider verification documentsDuration of account + 2 yearsRegulatory compliance and dispute resolution
    Analytics and usage logs26 monthsPlatform improvement and troubleshooting
    Authentication logs12 monthsSecurity and fraud prevention
    Backup data30 days after source deletionDisaster recovery
    Inactive accounts24 months of inactivityAfter 24 months, account flagged for deletion

    When data is no longer required for any lawful purpose, it is securely deleted or anonymised.

    10. Account Deletion

    You have the right to delete your BeyondClass account at any time. This section explains how to delete your account and what happens to your data.

    10.1 How to Delete Your Account

    Parents App

    1. Open the BeyondClass app
    2. Navigate to Settings (gear icon)
    3. Select Account
    4. Tap Delete Account
    5. Confirm deletion when prompted

    Providers App

    1. Open the BeyondClass Providers app
    2. Navigate to Settings (gear icon)
    3. Select Account
    4. Tap Delete Account
    5. Confirm deletion when prompted

    Alternative Method: You may also request account deletion by emailing hello@beyondclass.app from your registered email address with "Account Deletion Request" in the subject line.

    10.2 What Happens When You Delete Your Account

    Deleted Immediately

    • • Your profile information (name, email, phone, profile photo)
    • • Child profiles and associated data (Parents App)
    • • Activity listings (Providers App)
    • • Saved preferences and settings
    • • Push notification tokens
    • • Active login sessions

    Deleted Within 30 Days

    • • Data stored in backup systems

    Retained as Required by Law

    • • Transaction and payment records (retained for 7 years)
    • • Provider verification documents (retained for 2 years after account closure)
    • • Any data required to comply with legal obligations or resolve disputes

    10.3 Processing Time

    Account deletion requests submitted through the app are processed immediately. Email requests are processed within 7 business days. You will receive a confirmation email once your account has been deleted.

    10.4 Effect on Pending Bookings

    If you have pending or upcoming bookings at the time of deletion, these will be cancelled. For parents, refunds will be processed according to our standard refund policy. Providers with pending payouts will receive their payouts before account data is deleted.

    11. Your Rights

    Under the Personal Data Protection Act 2010 (PDPA) and other applicable laws, you have the following rights regarding your personal data:

    11.1 Right of Access

    You have the right to request access to the personal data we hold about you. We will provide a copy of your data in a commonly used electronic format within 21 days of receiving your request.

    11.2 Right of Correction

    You have the right to request correction of any inaccurate or incomplete personal data. You can update most information directly within the app settings. For data you cannot update yourself, contact us and we will make corrections within 14 days.

    11.3 Right to Withdraw Consent

    Where we process your data based on consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal. Note that withdrawing consent for essential processing may affect our ability to provide services to you.

    11.4 Right to Deletion

    You may request deletion of your account and personal data as described in Section 10. We will delete your data except where retention is required by law or for legitimate business purposes as specified.

    11.5 Right to Complain

    If you believe we have not handled your personal data in accordance with the law, you have the right to lodge a complaint with the Personal Data Protection Commissioner of Malaysia (PDPC) at www.pdp.gov.my.

    11.6 How to Exercise Your Rights

    To exercise any of these rights, contact us at:

    • Email: hello@beyondclass.app
    • Post: Data Protection Officer, Fitzgerald Ventures Sdn. Bhd., Unit 3A08, Block C, Pusat Dagangan Phileo Damansara 1, No. 9, Jalan 16/11, Off Jalan Damansara, 46350 Petaling Jaya, Selangor, Malaysia

    We may need to verify your identity before processing your request. We will respond to all legitimate requests within 21 days. If your request is complex, we will inform you within 21 days and may take up to an additional 14 days to respond.

    12. Security Measures

    We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration:

    Encryption

    • Data in transit is encrypted using TLS 1.2 or higher
    • Data at rest is encrypted using AES-256 encryption

    Authentication Security

    • Passwords are stored using industry-standard hashing
    • Biometric authentication available for secure login
    • Biometric data processed on-device only

    Access Controls

    • Access restricted to authorised personnel only
    • Administrative access requires authentication and is logged

    Infrastructure Security

    • Hosted on Google Cloud with SOC 2 and ISO 27001 certifications
    • Regular security monitoring and vulnerability assessments

    While we implement robust security measures, no method of electronic transmission or storage is 100% secure. We encourage you to use strong passwords, enable biometric login where available, and contact us immediately if you suspect any unauthorised access to your account.

    13. Changes to This Privacy Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

    Notification of Changes

    For material changes that affect how we collect, use, or share your personal data, we will notify you by:

    • Email to your registered email address
    • In-app notification
    • Prominent notice within the app at least 30 days before changes take effect

    Effective Date

    The "Last Updated" and "Effective Date" at the top of this policy indicate when it was last revised.

    Continued Use

    Your continued use of the BeyondClass applications after any changes to this Privacy Policy constitutes your acceptance of the updated policy. If you do not agree with any changes, you should stop using the app and delete your account.

    14. Contact Information

    If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

    Data Protection Officer
    Fitzgerald Ventures Sdn. Bhd.
    Company Registration No.: 202501020554 (1621967-U)

    Unit 3A08, Block C, Pusat Dagangan Phileo Damansara 1,
    No. 9, Jalan 16/11, Off Jalan Damansara,
    46350 Petaling Jaya, Selangor, Malaysia

    Email: hello@beyondclass.app

    We will respond to all enquiries within 14 days.

    15. Legal Basis for Processing

    Under the Personal Data Protection Act 2010 (PDPA) of Malaysia, we process your personal data based on the following legal grounds:

    • Consent: You have provided consent for processing your personal data for specific purposes, including by accepting this Privacy Policy and using our services
    • Contractual Necessity: Processing is necessary to perform our contract with you, including providing the BeyondClass platform services, processing bookings, and facilitating payments
    • Legal Obligation: Processing is necessary to comply with legal obligations, including tax, financial reporting, and regulatory requirements
    • Legitimate Interests: Processing is necessary for our legitimate business interests, such as fraud prevention, platform security, and service improvement, provided these interests do not override your fundamental rights and freedoms

    — End of Privacy Policy —