Last updated: Sep 18, 2026
Mono & Co ("we", "us", "our") is an e-commerce enabler based in Malaysia. We manage online marketplace stores, including Shopee and Lazada, on behalf of brands and businesses, and we run marketing and advertising for those stores.
This policy explains how we collect, use, share and protect personal data when you visit our website, contact us, engage our services, or interact with our social media pages. It applies to data we control. Where we handle data on behalf of a client, for example customer data inside a client's Shopee or Lazada store, we act on that client's instructions and the client's own privacy policy also applies.
By using our website or contacting us, you agree to this policy. If you do not agree, please do not use our services.
| Registered name | NOVABRIDGE SDN BHD |
|---|---|
| Company registration number | 201701040198 |
| Registered address | 1-6, Level 1, PJ Midtown Office, Jalan Kemajuan, Section 13, Petaling Jaya, 46200 Selangor |
| Website | https://monodigital.my |
| Contact email | gary.lum@monodigital.my |
| Contact phone / WhatsApp | +60 10-231 1602 |
We collect personal data that you provide directly, including:
You are not obliged to give us this data, but without it we may be unable to respond to your enquiry or provide our services.
When you visit our website, we and our analytics providers may collect:
This data helps us keep the website working, understand how it is used, and measure our advertising.
We receive data from platforms when you interact with us there, or when a client authorises us to manage their accounts:
| Source | What we receive |
|---|---|
| Meta (Facebook, Instagram) | Public profile name and picture of people who message or comment on our pages; page insights and post performance data; message content you send us |
| Shopee, Lazada, TikTok Shop | Store performance, orders, listings, advertising and customer chat data inside client stores we manage |
| Analytics and advertising providers | Aggregated website and campaign statistics |
| Referrals | Contact details a partner or existing client shares when introducing you, with your knowledge |
We only access platform data for accounts whose owners have authorised us, and only to the extent needed to provide our services.
| Purpose | Examples |
|---|---|
| Responding to you | Replying to enquiries by email, WhatsApp or social media |
| Providing our services | Managing your marketplace stores, listings, campaigns and advertising |
| Publishing our own content | Scheduling and publishing posts to our own Facebook Page and Instagram account |
| Billing and administration | Issuing quotations and invoices, collecting payment, keeping accounts |
| Improving our services | Understanding website use and the performance of our content |
| Marketing | Sending updates about our services to people who have asked for them or are existing clients |
| Legal and security | Meeting legal obligations, preventing fraud and misuse, resolving disputes |
We do not sell your personal data. We do not use your personal data to make automated decisions that produce legal effects for you.
We operate a Meta application that connects to our own Facebook Page and Instagram account, and, where authorised, to client pages and accounts.
Access tokens are stored securely and are used only for the purposes above. A client or page administrator can revoke our access at any time in Meta Business Settings, which immediately stops all access.
We share personal data only as described here:
We require our service providers to protect personal data and to use it only for the purposes we specify. We do not sell personal data to anyone.
Our systems and service providers operate on cloud infrastructure that may be located outside Malaysia, including in Singapore, the European Union and the United States. Where we transfer personal data outside Malaysia, we take reasonable steps to ensure it is protected to a standard comparable to the Personal Data Protection Act 2010, including contractual commitments from our providers.
| Type of data | Retention period |
|---|---|
| Enquiries that do not become clients | Up to 24 months from last contact |
| Client records and correspondence | For the engagement, then up to 7 years |
| Accounting and tax records | 7 years, as required by Malaysian law |
| Store access tokens and credentials | Until the engagement ends or access is revoked, then deleted |
| Website analytics data | Up to 26 months |
| Marketing contact details | Until you unsubscribe or ask us to delete them |
When data is no longer needed, we delete it or anonymise it so that it can no longer identify you.
We take reasonable technical and organisational measures to protect personal data, including:
No system is completely secure. If a data breach occurs that is likely to cause you significant harm, we will notify you and the relevant authorities as required by law.
Under the Personal Data Protection Act 2010, you have the right to:
To exercise any of these rights, email us at gary.lum@monodigital.my with the details of your request. We may ask you to verify your identity. We will respond within 21 days, as required by the Act, and will tell you if a fee applies for a data access request.
If you are unhappy with our response, you may lodge a complaint with the Personal Data Protection Department (Jabatan Perlindungan Data Peribadi) of Malaysia.
You can ask us to delete the personal data we hold about you at any time.
Data obtained through Meta platforms. If you have interacted with our Facebook Page or Instagram account, or authorised our Meta application, we will delete the data we hold from that platform on request. You can also remove our application's access yourself at any time:
We may keep certain records after a deletion request where the law requires it, such as invoices and accounting records, which we retain for seven years. We will tell you when this applies.
Our website uses cookies and similar technologies to keep the site working, remember your preferences, measure traffic and understand the performance of our advertising. These may include cookies set by Google Analytics and Meta.
You can block or delete cookies in your browser settings. Some parts of the website may not work properly if you do.
Our services are for businesses and are not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.
Our website and social media content may link to other sites, including Shopee, Lazada, TikTok Shop and Meta platforms. We are not responsible for their privacy practices. Please read their privacy policies before providing personal data to them.
We may update this policy as our services, technology or the law change. The date at the top shows when it was last updated. Material changes will be announced on this page, and we will notify existing clients directly. Continuing to use our services after an update means you accept the revised policy.
For any question about this policy, or to exercise your rights or request deletion:
| Person responsible | GARY LUM (CEO) |
|---|---|
| gary.lum@monodigital.my | |
| Phone / WhatsApp | +60 10-231 1602 |
| Address | 1-6, Level 1, PJ Midtown Office, Jalan Kemajuan, Section 13, 46200 Selangor |
In case of conflict between the English and Bahasa Malaysia versions of this policy, the English version prevails.