PDPA Policy


1.1 Yes Travel & Holidays Sdn Bhd (‘the Company’) takes its responsibilities under the privacy laws and regulations of Malaysia (“Privacy Laws”) seriously and is committed to respecting the privacy rights and concerns of all Users of the website (the “Site”) (we refer to the Site and the services we provide as described in our Site collectively as the “Services”). We recognize the importance of the personal data you have entrusted to us and believe that it is our responsibility to properly manage, protect and process your personal data.

1.2 This Privacy Policy (“Privacy Policy” or “Policy”) is designed to inform you how we collect, use, disclose and/or process the personal data you have provided to us and/or we possess about you, whether now or in the future. Please read this Privacy Policy carefully.

1.3 “Personal Data” or “personal data” means data, whether true or not, about an individual who can be identified from that data, or from that data and other information to which an organisation has or is likely to have access. Common examples of personal data could include name, identification number, photos, videos, contact information and banking information etc.

1.4 DO NOT USE OUR SERVICES OR ACCESS OUR WEBSITE IF YOU DO NOT CONSENT TO THE PROCESSING OF YOUR PERSONAL DATA AS DESCRIBED IN THIS PRIVACY POLICY. You acknowledge and agree that you accept the practices, requirements, and/or policies outlined in this Privacy Policy by using the Services, or by registering for an account with us, visiting our website, or accessing the Services. You further consent for us to collect, use, disclose and/or process your personal data as described herein. Any change to our Privacy Policy will be posted or amended on our website. We reserve the right to amend this Privacy Policy at any time without reference to you.


2.1 We will/may collect personal data

(a) when you submit any form, including, but not limited to, application forms or other forms relating to any of our products and services, whether online or by way of a physical form;

(b) when you use our electronic services, or interact with us via our application or use services on our website. This includes, without limitation, through cookies which we may deploy when you interact with our application or website;

(c) when you interact with us, such as via telephone calls (which may be recorded), letters, fax, face-to-face meetings, social media platforms and emails;

(d) when you register and/or engage with our Services or Site;

(e) when you carry out transactions through our Services;

(f) when you enter into any agreement or provide other documentation or information in respect of your interactions with us, or when you use our products and services;

(g) when you provide us with feedback or complaints;

(h) when you register for a contest; or

(i) when you submit your personal data to us for any reason.

The above sets out some instances of when personal data about you may be collected and is not exhaustive.

2.2 Should you visit, use or interact with our mobile application or the Site, we may collect certain information automatically using a variety of technologies, which may be downloaded to your device and may set or modify settings on your device. the unique device identifier (UDID) or mobile equipment identifier (MEID) for your mobile device, the address of a referring web site (if any), and the pages you visit on our website and mobile applications and the times of visit. We may collect, use disclose and/or process this information only for the Purposes (defined below).


3.1 This includes but is not limited to

        a. Name;

        b. Gender;

        c. Date of Birth;

        d. Home address and/or correspondence address;

        e. Payment details, including credit card and banking information;

        f. Telephone number and/or email address;

        g. Identity card number and/or passport number;

And any other information about you when you sign up to engage with our Services and/or website. And aggregate data on content that you engage with.

3.2 If you do not want us to collect the aforementioned information/personal data, you may opt out at any time by notifying our Data Protection Officer in writing about it. However, opting out of us collecting your personal data or withdrawing your consent for the same may affect your use of the Services.


As with browsing web pages, when you watch content and advertising and access other software on our Site or through the Services, most of the same information is sent to us (including, without limitation, IP Address, operating system, etc.). Your computer also sends us information on the content, advertisement viewed and/or software installed by the Services and the website and time.


We provide customer service support through email, WhatsApp/WeChat and feedback forms. In order to provide customer support, we will ask for your email address and mobile phone number. We only use information received from Sales, Operation Coordinator and/or Operation PIC, including, without limitation, email addresses. We do not transfer to or share this information with any third parties.


Participation in any surveys is completely voluntary and you have a choice whether or not to disclose your information to us. Information requested may include, without limitation, contact information (such as your email address), and demographic information (such as interests or age level). Survey information will be used to improve the use and satisfaction of the Services and will also be accessed by our contractors who help us to administer or act upon the survey.


9.1 We may collect, use, disclose and/or process your personal data for one or more of the following purposes:

(a) to consider and/or process your application/transaction with us or your transactions or communications with third parties via the Services;

(b) to manage, operate, provide and/or administer your use of and/or access to our Services and our website, as well as your relationship and user account with us;

(c) to manage, operate, administer and provide you with as well as to facilitate the provision of our Services, including, without limitation, remembering your preferences;

(d) to tailor your experience through the Services by displaying content according to your interests and preferences, providing a faster method for you to access your account and submit information to us and allowing us to contact you, if necessary;

(e) to respond to, process, deal with or complete a transaction and/or to fulfil your requests for certain products and services and notify you of service issues and unusual account actions;

(f) to enforce our Terms of Service or sign on any letters, contracts and/or agreements providing by the company;

(g) to protect personal safety and the rights, property or safety of others;

(h) for identification and/or verification;

(i) to deal with or facilitate operation PIC, carry out your instructions, deal with or respond to any enquiries given by (or purported to be given by) you, Department Head or on your behalf;

(j) to contact you or communicate with you via voice call, WhatsApp message and/or fax message, email and/or postal mail or otherwise for the purposes of administering and/or managing your relationship with us or your use of our Services, such as but not limited to communicating administrative information to you relating to our Services. You acknowledge and agree that such communication by us could be by way of the mailing of correspondence, documents or notices to you, which could involve disclosure of certain personal data about you to bring about delivery of the same as well as on the external cover of envelopes/mail packages;

(k) to inform you when another User has sent you a private message or posted a comment for you on the Site;

(l) to conduct research, analysis and development activities (including, but not limited to, data analytics, surveys, product and service development and/or profiling), to analyse how you use our Services, to improve our Services or products and/or to enhance your customer experience;

(m) where you give us your prior consent, for marketing and in this regard, to send you by various modes of communication such as postal mail, email, location-based services or otherwise, marketing and promotional information and materials relating to products and/or services (including, without limitation, products and/or services of third parties whom we may collaborate or tie up with) that we (and/or its affiliates or related corporations) may be selling, marketing or promoting, whether such products or services exist now or are created in the future;

(n) to respond to legal processes or to comply with or as required by any applicable law, governmental or regulatory requirements of any relevant jurisdiction, including, without limitation, meeting the requirements to make disclosure under the requirements of any law binding on us or on its related corporations or affiliates;

(o) to produce statistics and research for internal and statutory reporting and/or record-keeping requirements;

(p) to carry out due diligence or other screening activities (including, without limitation, background checks) in accordance with legal or regulatory obligations or our risk management procedures that may be required by law or that may have been put in place by us;

(q) to audit our Services or the Company’s business;

(r) to prevent or investigate any fraud, unlawful activity, omission or misconduct, whether relating to your use of our Services or any other matter arising from your relationship with us, and whether or not there is any suspicion of the aforementioned;

(s) to store, host, back up (whether for disaster recovery or otherwise) of your personal data, whether within or outside of your jurisdiction;

(t) to deal with and/or facilitate a business asset transaction or a potential business asset transaction, where such transaction involves the Company as a participant or involves only a related corporation or affiliate of the Company as a participant or involves the Company and/or any one or more of our related corporations or affiliates as participant(s), and there may be other third party organisations who are participants in such transaction. A “business asset transaction” refers to the purchase, sale, lease, merger, amalgamation or any other acquisition, disposal or financing of an organisation or a portion of an organisation or of any of the business or assets of an organisation; and/or

(u) any other purposes which we notify you of at the time of obtaining your consent.

(collectively, the “Purposes”).

9.2 As the purposes for which we will/may collect, use, disclose or process your personal data depend on the circumstances at hand, such purpose may not appear above. However, we will notify you of such other purpose at the time of obtaining your consent, unless processing of the applicable data without your consent is permitted by the Privacy Laws.


8.1 The company collects, uses and discloses your personal data only for the purposes as stated in Clause 7 above.

8.2 We do not share, sell or distribute your personal data with unrelated third parties, except for processing your travel and tour arrangements. We may disclose your personal data to our business partners, associates and third-party service providers (in or outside Malaysia) when reasonably necessary, and on a need-to-know basis. Disclosure of your personal information may include but not limited to the following:

(a) To process and complete your travel and tour arrangements, your information is provided to third parties including service providers such as the airlines, hotels, tour and transport operators, destination management companies, travel insurance agencies and third-party intermediaries (for example, credit card companies and banks) as deemed essential whenever engage with our Services;

(b) As and when required by relevant law to disclose the personal Information.


We implement a variety of security measures to ensure the security of your personal data on our systems. User personal data is contained behind secured networks and is only accessible by a limited number of employees who have special access rights to such systems. We will retain personal data in accordance with the Privacy Laws and/or other applicable laws. That is, we will destroy or anonymize your personal data as soon as it is reasonable to assume that (i) the purpose for which that personal data was collected is no longer being served by the retention of such personal data; and (ii) retention is no longer necessary for any legal or business purposes. If you cease using the Site, or your permission to use the Site and/or the Services is terminated, we may continue storing, using and/or disclosing your personal data in accordance with this Privacy Policy and our obligations under the Privacy Laws. Subject to applicable law, we may securely dispose of your personal data without prior notice to you.


This privacy policy does not apply to infant and/or children. We will remove and/or delete any personal data we believe was submitted by any child under the age of 18.


11.1 We may choose various third party websites to link to, and frame within, the Site. We may also participate in co-branding and other relationships to offer e-commerce and other services and features to our visitors. These linked sites have separate and independent privacy policies as well as security arrangements. Even if the third party is affiliated with us, we have no control over these linked sites, each of which has separate privacy and data collection practices independent of us. Data collected by our co-brand partners or third party web sites (even if offered on or through our Site) may not be received by us.

11.2 WE ALSO DO NOT GUARANTEE THE SECURITY OF PERSONAL DATA AND/OR OTHER INFORMATION THAT YOU PROVIDE ON THIRD PARTY SITES. We do implement a variety of security measures to maintain the safety of your personal data that is in our possession or under our control. Your personal data is contained behind secured networks and is only accessible by a limited number of persons who have special access rights to such systems, and are required to keep the personal data confidential. When you place orders or access your personal data, we offer the use of a secure server. All personal data or sensitive information you supply is encrypted into our databases to be only accessed as stated above.


Your personal data and/or information may be transferred to, stored or processed outside of your country when we need to process your travel and tour arrangements at oversea. In most cases, your personal data will be processed in MALAYSIA.


13.1 If you have any questions or concerns about our privacy practices or your dealings with the Services, please do not hesitate to contact qc@yestravel.com.my.

13.2 If you have any complaint or grievance regarding how we are handling your personal data or about how we are complying with Privacy Laws, we welcome you to contact us with your complaint or grievance.

Please contact us through email with your complaint or grievance:

E-mail: qc@yestravel.com.my and Attention it to the “Personal Data Protection Officer”.

13.3 Where it is an email or a letter through which you are submitting a complaint, your indication at the subject header that it is a Privacy Law complaint would assist us in attending to your complaint speedily by passing it on to the relevant staff in our organisation to handle. For example, you could insert the subject header as “Privacy Complaint”.

We will certainly strive to deal with any complaint or grievance that you may have fairly and as soon as possible.


Please also read the Terms and Conditions of Service establishing the use, disclaimers, and limitations of liability governing the use of the Site and the Services and other related policies.



Scroll to Top